
Under OSHA’s General Duty Clause, employers are required to provide a workplace free from recognized hazards likely to cause death or serious physical harm — and workplace violence has been recognized by OSHA as exactly that kind of hazard in high-risk industries and, increasingly, well beyond them. A compliant, defensible workplace violence prevention program combines a documented hazard assessment, a standing threat assessment team, clear reporting channels, regular training, and a recordkeeping and evaluation cycle, built on the same core-elements framework OSHA uses across its safety and health program guidance.
OSHA has no single standalone workplace violence standard covering all industries, which leads some employers to conclude there is no real obligation to act. That reading gets the law backwards. Because OSHA can and does cite employers under the General Duty Clause (Section 5(a)(1) of the OSH Act) for failing to address a recognized workplace violence hazard, and because OSHA has published sector-specific guidance — most notably for healthcare and social service workers — the absence of a single blanket rule is not the absence of an obligation. The practical standard employers are held to combines OSHA’s recognized-hazard doctrine with the voluntary but increasingly cited American National Standard for Workplace Violence Prevention and Intervention (WVPI), jointly published by ASIS International and the Society for Human Resource Management (SHRM).
OSHA’s General Duty Clause and Workplace Violence
The General Duty Clause requires employers to furnish a workplace free from recognized hazards causing or likely to cause death or serious physical harm. For a General Duty Clause citation to hold, OSHA generally must show that a hazard existed, that the employer or its industry recognized the hazard, that the hazard was likely to cause death or serious harm, and that a feasible means existed to correct it. Workplace violence checks each of those boxes in industries with a documented history of incidents — healthcare, late-night retail, social services, security, and taxi or rideshare work among them — and OSHA has issued citations on this basis, particularly following a preventable incident where prior warning signs existed and no corrective program was in place. The practical implication for every employer, not only those in historically high-risk sectors, is that once an organization has notice of a specific risk — a documented threat, a history of violence by a particular individual, or an industry-recognized hazard — inaction becomes legally exposed, not merely imprudent.
The Four Recognized Types of Workplace Violence
Occupational safety researchers, and OSHA’s own guidance, categorize workplace violence into four types. Building a program around this typology matters because the controls for each type are different — a program built only around one type (commonly Type 2) will miss the others entirely.
- Type 1 — Criminal intent: the perpetrator has no legitimate relationship to the business and is present to commit a crime such as robbery. This is the classic external threat and is addressed primarily through physical security, access control, cash-handling protocols, and armed or unarmed guard presence where risk warrants it.
- Type 2 — Customer or client: violence directed at employees by someone they serve — a customer, patient, student, or member of the public. This is the dominant category in healthcare and social services and is addressed through de-escalation training, staffing and layout design, and behavioral flagging of known high-risk individuals.
- Type 3 — Worker-on-worker: violence between employees, including current and former employees. This is the category most directly tied to disciplinary actions, terminations, and interpersonal workplace conflict, and is addressed through behavioral threat assessment, HR escalation protocols, and structured high-risk termination planning.
- Type 4 — Personal relationship: an employee is targeted at work by someone from their personal life, most often in the context of domestic violence or intimate partner violence spilling into the workplace. This category is addressed through access control, safety planning coordinated with the affected employee, and training supervisors to recognize the signs of an at-risk employee.
A defensible program documents which of these four categories the organization has assessed as most relevant to its own facilities, staffing model, and location, rather than adopting a generic template that assumes every workplace faces the same mix of risk.
Core Elements of an OSHA-Aligned Prevention Program
OSHA’s guidance for preventing workplace violence, developed in depth for healthcare and social service settings but applicable in structure across industries, organizes a program around five core elements. These mirror OSHA’s broader Recommended Practices for Safety and Health Programs and give a workplace violence program the same structural rigor as any other recognized safety program:
- Management commitment and employee participation. A written policy signed and visibly backed by senior leadership, with a clear statement that reports of concerning behavior will be taken seriously and that retaliation against a reporting employee will not be tolerated. Employees — not just managers — should have a voice in identifying hazards specific to their own work areas.
- Worksite analysis and hazard identification. A documented review of the physical environment (lighting, entry points, isolated work areas, cash handling), staffing patterns (working alone, late shifts), and historical incident data, updated on a regular cycle and after any reported incident.
- Hazard prevention and control. Engineering controls (access control systems, alarm buttons, barriers, camera coverage), administrative controls (staffing minimums, buddy systems for high-risk situations, visitor management), and, where warranted, a licensed security presence.
- Safety and health training. Role-specific training covering recognition of warning signs, reporting procedures, de-escalation techniques, and emergency response, delivered at onboarding and refreshed on a recurring schedule.
- Recordkeeping and program evaluation. Logging reported incidents and near-misses, tracking corrective actions to completion, and periodically auditing the program against actual outcomes rather than treating the written policy as self-executing.
Each element should produce a document an auditor, an OSHA compliance officer, or opposing counsel in litigation could review and understand: a written policy, a hazard assessment on file, a control inventory, a training log, and an incident log with documented follow-up.
Establishing a Threat Assessment Team
At the center of a mature program is a standing, cross-functional threat assessment team, typically drawing from HR, legal, security, and operational leadership, with a documented intake process for reports of concerning behavior. The team’s job is not to predict violence with certainty — no team can do that — but to apply a consistent, structured process to every report: gather facts, assess risk factors against a validated framework, and manage the case with a proportionate response, whether that is routine HR handling, enhanced monitoring, or a fully security-planned intervention. The ASIS/SHRM WVPI standard treats this team as a required structural element of a conforming program, not an optional enhancement, precisely because ad hoc responses assembled after a specific incident are demonstrably less effective than a team that already has a defined process, established authority, and practiced coordination.
Reporting Mechanisms and Non-Retaliation
A program is only as good as its weakest reporting channel. Employees consistently under-report concerning behavior when they are unsure who to tell, doubt anything will happen, or fear retaliation for reporting a coworker. A defensible program addresses this directly with multiple reporting channels (direct to a supervisor, to HR, and through an anonymous option), a written and communicated non-retaliation commitment, and a defined response time so employees see that reports are actually acted on. FBI behavioral research into active-shooter and targeted-violence cases has repeatedly found that attackers displayed observable concerning behaviors to multiple people before an attack, and that those behaviors were rarely reported through a formal channel — which makes the reporting mechanism itself one of the highest-leverage investments in a prevention program, ahead of almost any physical security control.
Training Requirements
Training should be role-specific rather than a single generic module for the entire workforce. At minimum, a defensible program includes:
- All employees: how to recognize warning signs, how and where to report a concern, and what to do in an active threat (see Run-Hide-Fight guidance from DHS/CISA).
- Frontline supervisors: how to document concerning behavior objectively, how to escalate to the threat assessment team, and how to avoid common documentation pitfalls that create legal exposure.
- HR and threat assessment team members: structured interview and inquiry techniques, risk-factor frameworks, and case management protocols.
- Employees in customer-facing or high-risk roles: de-escalation techniques specific to Type 2 violence scenarios.
Training should be refreshed on a recurring schedule — annually at minimum, and immediately after any significant incident or near-miss — and attendance should be logged as part of the recordkeeping element.
Aligning with the ASIS/SHRM WVPI American National Standard
The Workplace Violence Prevention and Intervention standard gives employers a detailed, auditable framework that goes beyond OSHA’s general guidance, covering governance, risk assessment methodology, threat assessment team composition and authority, intervention strategies, and program evaluation metrics. Aligning a program with this standard, even where it is not independently mandated by statute, strengthens an employer’s position in two concrete ways: it demonstrates that a recognized industry standard of care was followed, which matters directly in a General Duty Clause analysis and in civil litigation following an incident, and it gives the organization a structured basis for continuous improvement rather than a static policy that never gets revisited.
Documentation, Recordkeeping, and Program Evaluation
A program that exists only as a policy document in a drawer does not meet the standard OSHA or the WVPI standard actually describes. Ongoing recordkeeping should capture every reported incident and near-miss, the hazard assessments conducted and when they were last updated, training completion by role, and the outcome of every threat assessment case, including the rationale for the management decision reached. Program evaluation should happen on a defined cycle — commonly annually — and after any incident, comparing what the program assumed against what actually happened, and updating the hazard assessment, controls, and training accordingly. This evaluation step is what separates a living program from a compliance exercise: OSHA’s own safety program guidance treats this closing-the-loop step as one of the five core elements, not an optional add-on.
Common Gaps That Undermine an Otherwise Solid Program
Several recurring gaps show up even in organizations that have invested real effort into a written policy:
- No documented worksite-specific hazard assessment — relying instead on a generic corporate template that does not reflect the actual layout, staffing, or history of a given facility.
- A threat assessment team that exists on paper only — named on an org chart but never trained together, never exercised, and without a clear intake process employees actually know about.
- Training delivered once at onboarding and never refreshed — leaving a gap of years during which staffing, layout, and risk factors have all changed.
- No link between the workplace violence program and the organization’s termination process — meaning Type 3 risk during high-risk separations is handled entirely outside the prevention program rather than as one of its core scenarios.
- No coordination with local law enforcement before an incident — the first contact with responding officers happening during a crisis rather than as part of an established relationship.
Industry-Specific Risk Considerations
While the five core elements apply across industries, the relative weight given to each of the four violence types should shift based on the actual operating environment. Healthcare and social service organizations, where OSHA’s most detailed published guidance exists, typically see Type 2 violence dominate and should weight training, staffing patterns, and facility design accordingly. Retail and hospitality operations with late-night or solo-staffed shifts should weight Type 1 criminal-intent controls — cash handling protocols, access control, visible security presence — more heavily. Office-based professional environments often see their highest-severity risk concentrated in Type 3 worker-on-worker scenarios tied to terminations and disciplinary action, and Type 4 scenarios where an employee’s personal relationship follows them into the workplace. None of this means an organization should ignore the other categories; it means the worksite hazard assessment step should honestly reflect which categories carry the most realistic risk for that specific facility, rather than defaulting to a generic industry template that may not match the organization’s actual exposure.
Integrating the Program with Insurance and Workers’ Compensation
A documented workplace violence prevention program also has a direct bearing on an organization’s insurance and workers’ compensation posture. Carriers increasingly ask about formal prevention programs during underwriting, and a documented program — hazard assessments on file, a trained threat assessment team, logged training completion, and an incident recordkeeping system — can materially affect both eligibility and premium for general liability and workers’ compensation coverage. More importantly, in the event of an incident, the existence of a good-faith, actively maintained program is often the single most important factor in how an employer’s conduct is evaluated after the fact, whether by OSHA, a workers’ compensation board, or a civil court. A program built and exercised before an incident occurs is a fundamentally different legal and financial position than one assembled retroactively after litigation has already begun.
Where Professional Security and Threat Assessment Support Fits
Few organizations have in-house behavioral threat assessment expertise, licensed investigative capability, and physical security operations under one roof — which is precisely why so many workplace violence prevention programs stall at the policy-writing stage and never mature into a functioning, exercised capability. Building the worksite hazard assessment, standing up and training a threat assessment team, running tabletop exercises, and providing licensed physical security or executive protection when a specific case warrants it are all specialized functions that benefit from an outside partner who does this work as a core discipline rather than a side responsibility layered onto an HR generalist’s job description.
About Honeybadger Solutions LLC
Honeybadger Solutions LLC is a licensed, bonded, and insured Arizona security and investigations firm founded and led by veterans and former law enforcement professionals. Our in-house threat assessment team helps organizations nationwide build and exercise OSHA and ASIS/SHRM WVPI-aligned workplace violence prevention programs — from worksite hazard assessments and threat assessment team training to tabletop exercises and post-incident investigations — while our armed guard services are based out of our Casa Grande headquarters and offices in Phoenix and Oro Valley, Arizona. To start building or auditing your workplace violence prevention program, call us directly at 602-725-2818.
Sources and further reading
- OSHA — Workplace Violence — Federal guidance on assessing workplace violence risk and building a prevention program, with current fatal-injury statistics.
- ASIS International — Standards and Guidelines — ANSI-accredited standards covering physical asset protection, security risk assessment, investigations, executive protection and workplace violence prevention.
Honeybadger Solutions staffs Commercial & Corporate Security, Security Awareness Training and Threat Mitigation & SOC directly across Maricopa, Pinal and Pima counties in Arizona, and coordinates the same standard nationwide through vetted partner agencies licensed in their own states — managed from Arizona under a single point of accountability.