Start here
An effective workplace violence prevention program connects five activities: management and worker involvement, worksite analysis, hazard prevention and control, training, and recordkeeping with program evaluation. It also gives employees a safe way to report concerning conduct, defines who evaluates reports, and links prevention to a usable emergency action plan. A guard or training class may support the program, but neither replaces management ownership, HR procedures, legal review, facility controls, or law-enforcement and EMS coordination.
Key takeaways
- Treat workplace violence as a preventable occupational and operational risk, not only as an active-assailant scenario.
- Assess behaviors, conditions, and credible information; do not profile people or diagnose them from a checklist.
- Give employees more than one reporting route and protect good-faith reporting from retaliation.
- Define a multidisciplinary assessment and response process before a difficult report arrives.
- Use layered controls: facility design, access control, staffing, policies, communication, training, and public-safety coordination.
- Keep prevention, threat assessment, emergency response, security staffing, and HR investigations connected but distinct.
What workplace violence prevention actually covers
Workplace violence can range from threats and intimidation to assault and homicide. It may involve a stranger committing a crime, a customer or client, a current or former worker, or a person with a relationship to an employee. The risk therefore cannot be managed through a single response script.
A complete program should address at least four broad situations:
| Situation | Examples | Planning emphasis |
|---|---|---|
| Criminal intent | Robbery, trespassing that becomes violent, targeted theft | Cash and asset controls, lighting, visibility, access, alarms, police notification |
| Customer, patient, resident, student, or visitor | Escalating dispute, assault, threat toward staff | Service design, staffing, de-escalation, escape routes, alerting, incident review |
| Worker-on-worker | Threats, bullying that escalates, domestic conflict between coworkers | Reporting, HR and legal coordination, fair investigation, access changes, threat management |
| Personal relationship entering the workplace | Stalking, domestic violence, protective-order concern | Confidential reporting, individualized safety planning, reception and parking procedures, law-enforcement coordination |
These categories help a planning team avoid tunnel vision. They are not labels to apply casually to a person, and they do not predict who will become violent.
The National Institute for Occupational Safety and Health notes that violence can occur in any workplace, although exposure differs by job and setting. Relevant conditions may include working alone, handling money, interacting with the public, providing care, working late, enforcing rules, operating in isolated areas, or serving people in distress. An Arizona employer should evaluate its own work rather than copy another company’s risk ranking.
The five-part prevention framework
OSHA’s workplace-violence guidance for healthcare and social-service employers describes five core program elements. The structure is useful beyond healthcare when it is adapted to the organization rather than presented as a universal compliance formula.
1. Management commitment and worker participation
Name an executive owner and give the program enough authority, time, information, and budget to function. Establish a written policy that defines prohibited conduct, available reporting channels, urgent-response expectations, confidentiality limits, and protection for good-faith reporting.
Worker participation is not ceremonial. Employees often know where angry interactions occur, which doors are routinely propped open, when people work alone, and why previous reporting systems failed. Include representatives from different shifts and roles. Contractors, tenants, or volunteers may also need a defined way to raise concerns.
Leadership should be able to answer:
- Who owns prevention policy and program performance?
- Who receives reports during and after normal business hours?
- Who can authorize immediate protective measures?
- How are HR, safety, facilities, legal, security, and management responsibilities separated?
- How will employees know that reports were taken seriously without disclosing confidential case details?
2. Worksite analysis and hazard identification
Use both records and direct observation. Review reported threats, assaults, near misses, workers’ compensation information, safety records, security reports, police calls when lawfully available, access-control exceptions, complaints, and employee feedback. Look for patterns by location, time, task, and interaction—not just total incident counts.
Walk the property on every relevant shift. Examine public entrances, reception, interview or counseling rooms, cash locations, loading areas, employee-only spaces, parking, exterior walkways, isolated workstations, closing procedures, and the route used by emergency responders. Ask whether an employee can summon help, exit an escalating encounter, and communicate an exact location.
Create a simple risk register:
| Field | Question to answer |
|---|---|
| Exposure | Who or what may be exposed, and during which task or time? |
| Scenario | What could reasonably happen based on work, history, and credible information? |
| Existing controls | What currently reduces likelihood or consequence? |
| Gap | Where could the controls fail or be bypassed? |
| Improvement | What physical, administrative, staffing, or training change is practical? |
| Owner and due date | Who will complete it, and when? |
| Verification | How will the organization confirm the change works? |
Do not wait for a completed assault before recording a gap. A threat, near miss, repeated hostile behavior, door failure, duress-alarm problem, or pattern of employees avoiding an area can be useful prevention information.
3. Hazard prevention and control
Use layers because no single control is reliable in every situation.
Engineering and physical controls can include appropriate lighting, clear sightlines, controlled entrances, reception barriers designed for the actual risk, lockable rooms where appropriate, duress alarms, access credentials, monitored cameras, secure cash procedures, safe interview-room layouts, and dependable communications. Physical changes should account for fire and life-safety rules, accessibility, privacy, and emergency egress.
Administrative controls can include visitor procedures, opening and closing rules, staffing for higher-risk tasks, working-alone check-ins, employee-separation protocols, behavioral reporting, emergency contacts, response thresholds, restraining-order procedures developed with counsel, and documented post orders for security personnel.
People and response controls can include supervisors trained to receive reports, a multidisciplinary assessment team, trained security personnel, employee assistance resources, de-escalation instruction appropriate to the role, and relationships with local police, fire, and EMS.
Controls should be proportionate. A difficult customer-service interaction does not automatically justify an armed officer. Conversely, a repeated credible threat should not be reduced to a generic reminder to “stay aware.” The response should follow a documented assessment by qualified people.
4. Safety and health training
Different roles need different depth.
| Audience | Minimum practical learning objectives |
|---|---|
| All workers | How to report, when to call 911, alarms and emergency communications, evacuation or shelter concepts, accountability, access and functional needs |
| Supervisors | Receiving reports without dismissing or overpromising, preserving information, urgent escalation, anti-retaliation, employee support |
| Reception, facilities, and security | Access procedures, distress signals, location communication, prohibited actions, responder access, incident documentation |
| Assessment/response team | Case intake, lawful information sharing, structured assessment, protective options, documentation, follow-up and closure |
| Executives | Decision authority, crisis communication, continuity, family and employee support, after-action oversight |
Training should connect to the actual site, alarm system, reporting channels, and written plan. It should be accessible to employees with disabilities and people with limited English proficiency. Exercises should have clear objectives, advance communication, safety controls, opt-out or accommodation procedures where appropriate, and a structured debrief. Surprise simulations can traumatize participants, create public confusion, or produce unsafe reactions; realism is not a substitute for instructional design.
Active-violence response training addresses a narrow but serious part of preparedness. CISA’s current active-assailant planning guidance says there is no one-size-fits-all response and urges organizations to account for facility layout, threat type, individual judgment, and access or functional needs. Training should not imply that employees are guaranteed a safe outcome or are expected to replace law enforcement.
Bleeding-control skills may add a time-critical capability when taught by an authorized instructor and supported by inspected supplies, emergency communications, and a broader medical-response plan. They do not replace 911, EMS, First Aid/CPR requirements, or medical direction.
5. Recordkeeping and program evaluation
Create a confidential, role-based system for threats, assaults, near misses, response actions, and corrective work. Preserve enough information to identify patterns while limiting access and retention according to law and policy. A security incident report is not automatically an OSHA injury record, police report, workers’ compensation record, or HR investigation file. Each obligation needs the correct owner and process.
Evaluate both implementation and outcomes:
- Are leaders reviewing the program on schedule?
- Do employees know how to report?
- Are reports acknowledged and assessed promptly?
- Are access, alarm, lighting, or staffing defects closed by their due dates?
- Are exercises producing documented improvements?
- Do repeat incidents cluster around a task, entrance, shift, or unresolved control?
- Are affected employees offered appropriate post-incident support?
An increase in reporting after launch may indicate greater trust and visibility rather than a worsening workplace. Use context before drawing conclusions.
Build a reporting and assessment process before you need it
A report should move through an established path:
- Receive. Offer at least two practical channels, including an urgent route outside normal hours. Tell workers when confidentiality cannot be guaranteed.
- Triage. If there is an immediate threat, call 911 and activate emergency procedures. Do not delay for a committee meeting.
- Preserve. Record the exact words or conduct reported, dates, sources, relevant documents, and actions already taken. Do not embellish or diagnose.
- Assign. Send the matter to the appropriate owner: HR, safety, legal, security, a qualified threat-assessment team, or public safety. Some cases require several disciplines.
- Assess. Evaluate behavior, context, capability, access, stressors, protective factors, and changes over time using a qualified process—not a simplistic score or profile.
- Manage. Select proportionate measures such as contact boundaries, schedule or access changes, employee support, additional security, law-enforcement consultation, or other counsel-approved actions.
- Monitor and close. Define follow-up, documentation, communication, and criteria for changing or ending measures.
Managers should not promise secrecy, guaranteed protection, or a predetermined employment outcome. They should explain the process, take urgent safety concerns seriously, and involve qualified decision-makers.
Connect prevention to an emergency action plan
Prevention reduces risk; the emergency action plan organizes action when an emergency occurs. OSHA’s 29 CFR 1910.38 applies when another OSHA standard requires an EAP. When it applies, the plan’s minimum elements include reporting an emergency, evacuation procedures and exit assignments, critical operations before evacuation, accounting for employees, rescue or medical duties, and a plan contact. OSHA also addresses an employee alarm system, training designated evacuation assistants, and reviewing the plan with covered employees when it is developed, responsibilities change, or the plan changes.
Even where that particular standard is not the only governing requirement, an all-hazards plan should address:
- Exact facility address, building, floor, suite, and responder access
- Emergency notification and backup communication
- Evacuation, shelter-in-place, lockdown, or other protective actions as appropriate
- Employees, visitors, contractors, and people with access or functional needs
- Accountability, assembly, and reunification
- Medical response and trained roles
- Primary and alternate leadership
- Media, family, and workforce communications
- Continuity and recovery
- Preservation of evidence and records
Local police, fire, and EMS can identify practical issues such as building identification, key access, staging, radio limitations, or confusing internal room names. Coordination does not transfer responsibility for the employer’s plan to public agencies.
What private security can—and cannot—do
A well-designed security assignment may provide visible deterrence, access support, patrols, observation, communication, incident documentation, employee escorts when contracted, and a trained point of contact for responders. The assignment should be written into site-specific post orders with escalation thresholds and prohibited actions.
Security is not the organization’s HR department, mental-health evaluator, legal adviser, or police force. Arizona law states that employment as a security guard or armed security guard does not confer peace-officer authority; guards perform their duties as private citizens. An officer’s role during a threat or emergency must remain within law, verified training, employer policy, the contract, and post orders.
30-day implementation checklist
Leadership and policy
- Name the executive owner and multidisciplinary planning team.
- Review the policy with Arizona employment and safety counsel.
- Publish urgent and non-urgent reporting routes.
- Define anti-retaliation, confidentiality, and information-sharing rules.
Assessment and controls
- Review at least 12–24 months of relevant incidents and near misses, if available.
- Walk every relevant work area and shift.
- Test alarms, access controls, communications, exterior lighting, and emergency addresses.
- Record corrective actions with owners and deadlines.
Response and training
- Establish 911 and internal escalation criteria.
- Update the emergency action plan and contact lists.
- Train employees by role; document attendance and learning objectives.
- Conduct a controlled tabletop exercise before a complex live exercise.
- Complete an after-action review and track improvements to closure.
Frequently asked questions
Is workplace violence training required by OSHA?
OSHA currently states that there is no federal standard specifically devoted to workplace violence. That does not mean employers can ignore a recognized serious hazard. OSHA points to the Occupational Safety and Health Act’s General Duty Clause and says an employer on notice of workplace-violence risk should implement a prevention program with controls and training. Other OSHA standards, state requirements, accreditation rules, contracts, or industry-specific duties may apply. Employers should obtain advice for their own operations rather than treating a website answer as a compliance determination.
Is an active-shooter class a complete prevention program?
No. Response training addresses what people may do during a particular emergency. A prevention program also needs leadership, worker participation, worksite analysis, reporting, threat assessment, physical and administrative controls, documentation, and evaluation. Training should be connected to the organization’s actual EAP.
How often should training be repeated?
Use a risk- and role-based schedule. Review training when the plan changes, responsibilities change, facilities or alarms change, an incident or exercise exposes a gap, or employee turnover leaves critical roles uncovered. Any course credential has its own renewal period, but a certificate date should not be confused with proof that the workplace plan remains current.
Should employees report behavior that merely feels unusual?
Employees should report conduct or information that raises a genuine safety concern under the organization’s policy, using concrete details rather than labels. A trained team—not the reporting employee—should evaluate context. Policies should discourage discrimination, rumor, and diagnosis while making clear that good-faith safety reporting is welcome.
Does hiring a security guard transfer responsibility for the program?
No. A security provider can perform defined protective duties, but organizational leadership remains responsible for its policies, employee relations, compliance, emergency plan, and coordination with responders. The contract and post orders should state duties, limits, reporting, supervision, and escalation.