How to complete a federal workplace harassment and violence assessment
A federally regulated Canadian employer must jointly assess workplace harassment and violence risks with its applicable partner, identify internal and external risk factors, and develop and implement preventive measures. Under sections 5–9 of the Work Place Harassment and Violence Prevention Regulations, the assessment is monitored as conditions change, reviewed jointly every three years and reviewed after certain occurrences. It is a prevention exercise that ends with implemented controls, not a generic employee survey or a file containing only a policy.
This page is for employers under federal occupational health and safety jurisdiction. The existing Complys Canada overview of violence and harassment programs introduces the topic across Canada. Provincial employers should use the rules of the province or territory that governs their work, even if this federal method offers useful ideas. A company operating in several jurisdictions should determine which legal regime applies to each workforce before standardising one assessment template.
What the assessment must produce
Section 5(1) defines the task through two linked outputs: jointly identify the factors in section 8 that contribute to harassment and violence, then jointly develop and implement the preventive measures in section 9. A risk register that lists threats but leaves every control as “to be decided” has not completed the second part. Equally, a general respect policy without an examination of the actual workplace is not the assessment.
A useful record will show the workplace or work activity covered; the people and committee or representative involved; the evidence considered; the risk factors found; preventive measures, owners and implementation dates; how effectiveness will be checked; and the date and trigger for the next review. The Regulations do not prescribe that exact document layout. It is a practical way to demonstrate and manage the statutory sequence. Keep sensitive occurrence information in an appropriately restricted process rather than putting names and confidential allegations in a broadly shared risk register.
Confirm the right joint participants
The Regulations define the applicable partner as the policy committee, or, if there is no policy committee, the workplace committee or health and safety representative. The employer and that partner jointly conduct the assessment and monitor it. If there is disagreement on a matter required to be done jointly, section 2 states that the employer's decision prevails; that does not erase the duty to engage the partner and record the decision responsibly.
Operationally, appoint an employer representative who can commit resources, involve the applicable partner early, and bring in people who understand the work: supervisors, worker representatives, security, HR, occupational health or others as appropriate. Section 7 requires anyone directed to identify risk factors or develop and implement measures to be qualified through training, education or experience. A specialist can support the work, but buying a template or delegating to a consultant does not transfer the employer's regulatory duty.
The federal Labour Program's employer-duty checklist can be used to check the sequence. Record who consulted whom and which evidence or concern changed the result. The point of joint work is to expose conditions a central office may miss: isolated routes, customer-facing roles, uneven authority, supervisory conduct or a physical area where a worker cannot readily seek help.
Identify risk factors with the statutory lens
Section 8 asks the employer and partner to look at factors inside and outside the workplace. The listed considerations are the culture, conditions, activities and organisational structure; external circumstances such as family violence; reports, records and data related to workplace harassment and violence; the physical design of the workplace; and measures protecting psychological health and safety. The assessment should show how these were considered, including a reason where a factor is genuinely inapplicable.
Work through each distinct environment rather than treating the head office as representative of every shift. For example, a federally regulated transport business may have dispatch staff, drivers, depot workers and public-facing service staff with different patterns of exposure. An office that has no cash-handling risk may still face hierarchical pressure, online abuse or bullying during remote work. These are examples to investigate, not an assertion that a particular employer has those hazards.
Use evidence carefully. Anonymous trend information, interviews, worker consultation, employee feedback, prior assessments, absenteeism or turnover patterns and reports may point to risks. A low complaint count does not prove low exposure; workers may fear retaliation or doubt confidentiality. Conversely, one untested allegation should not be treated as an established fact about an identified person. Preserve the distinction between preventive risk assessment and the Regulations' separate occurrence-resolution process.
Practical questions for a site or role review
- Where do workers interact with the public, customers, contractors or isolated colleagues, and what support can they call on?
- Are there lone-work, night-work, travel or remote-work arrangements that change access to help?
- Could reporting lines, performance practices or an imbalance of authority discourage people from raising concerns?
- Do layout, lighting, access control, reception arrangements or communication channels create predictable exposure?
- What do aggregated incident and concern records show, and what might they fail to show because of under-reporting?
- Which psychological-safety protections already exist, and have workers experienced them as effective?
- Could a control unintentionally increase risk, such as isolating an affected worker or publicising a confidential concern?
The Labour Program's assessment tool offers a starting checklist. Adapt it to the actual culture and work. A checked box is not evidence that the measure works.
Turn identified risks into preventive measures
Section 9 gives the employer and applicable partner six months after identifying risk factors to develop preventive measures, develop an implementation plan and implement those measures according to the plan. The measures must, to the extent feasible, reduce the risk and avoid creating or increasing harassment or violence risks themselves.
Match each significant factor to a control that someone can own and test. For a worker regularly exposed to aggressive third parties, options might include safe staffing, a clear escalation route, physical layout changes and a response procedure. For concerns involving supervisory power, options might include alternative reporting channels, trained managers, protected escalation and review of management practices. For online abuse, access and communications rules may be relevant. The legally appropriate combination depends on the workplace evidence and should be developed jointly.
Write the implementation plan in operational terms: action, owner, resources, target date, people to notify, proof of completion and a way to check whether the control has worked. If a proposed control cannot be put in place, record the constraint, interim protection and decision path. Do not let “train staff” become the only answer to a risk rooted in staffing, design or conduct. Training matters, but it may not remove the underlying exposure.
Keep the assessment connected to the wider federal program
The assessment is one part of the federal prevention regime. Section 10 requires a jointly developed prevention policy with specified content, including roles, risk factors, training, resolution, privacy, support and review circumstances. Section 11 deals with emergency procedures for an occurrence or threat posing immediate danger. Section 12 addresses workplace-specific training. A sound assessment should inform these components; it should not duplicate their full content or claim that one document replaces them.
For example, if the assessment identifies a particular public-contact risk, the policy can explain reporting and support, the emergency procedure can set out what to do when danger is immediate, and training can teach the relevant response. The records should point to one another and use current versions. The annual federal OHS report is a separate reporting task, with its own duties and deadline. If the proposed Complys guide to that filing is later integrated, it can be linked here after the destination is live.
Review, update and learn from occurrences
There are three different review mechanisms to keep straight. First, section 5(2) requires joint monitoring of the assessment's accuracy and updating as needed when risk factors change or a preventive measure becomes ineffective. That is a live obligation, not a once-in-three-years calendar task. Second, section 5(3) requires a joint review every three years and updating if necessary. Third, section 6 requires a joint review and possible update with the workplace committee or health and safety representative after a notice of occurrence when its specific conditions are met: an occurrence is not resolved through negotiated resolution and the principal party ends the process, or the responding party is neither an employee nor the employer. Do not say that every complaint automatically triggers the same section 6 review.
The review under section 6 must consider the circumstances of the occurrence. An occurrence involving a customer, for example, could expose a gap in access control or response support. The assessment may need a new preventive measure without copying a confidential case file into the general register. The resolution and investigation duties have their own rules and privacy safeguards; managers should not treat the risk assessment as a substitute for that process.
An effective review meeting asks whether a risk has changed, whether an implemented measure works in practice, whether workers know how to use it, and whether the measure has caused a new problem. Document changes, consultation and the reasons for retaining or revising controls. If the workplace expands, changes shifts, redesigns premises, changes customer interaction or receives material evidence of a control failure, consider updating now even if the three-year date is distant.
Example: a multi-location service team
Imagine a federally regulated service employer with a central office, a public-facing branch and staff who travel to client sites. A single “violence risk: low” line would hide different risks. The employer and applicable partner map each setting. They find that the branch has occasional threatening customer interactions and the travelling staff may work alone without a reliable escalation contact. Staff also describe reluctance to report behaviour by senior personnel.
The assessment separates these factors rather than merging them into a generic score. The joint group proposes a branch response and exit procedure, a check-in and escalation plan for travel, and a confidential alternative reporting route. It gives each action an owner and implementation date, checks whether staff can actually use it, and records how information will be shared without identifying complainants. When a new location opens, the group revisits the assessment rather than copying the first branch's result. This is illustrative, not a legal conclusion about a particular employer's compliance.
Common mistakes that leave the assessment unfinished
- Using the provincial rule by default. First decide whether the workplace is federally regulated.
- Leaving out the applicable partner. Joint assessment and review are central requirements.
- Copying a national template unchanged. Section 8 requires the actual culture, work, records, design and psychological-safety measures to be considered.
- Treating a policy as the assessment. Section 5 also requires risk-factor identification and implemented prevention measures.
- Recording only physical violence. The federal definition includes harassment and potential psychological injury; take the current Code and Regulations as the source.
- Keeping an open-ended control list. Section 9 contains a defined development and implementation sequence.
- Waiting three years despite a changed risk. Monitor continuously and update when necessary.
- Assuming every occurrence has the same review trigger. Read section 6's actual conditions and protect case confidentiality.
- Publishing sensitive case details in a general register. Use appropriate access controls and separate restricted occurrence records.
What Complys can support
The verified Complys Canada site describes safety, worker and document-record workflows. An employer comparing Canadian OHS compliance software can ask whether the deployed setup can hold an assessment register, evidence of consultation, assigned action owners, policy versions and review dates with appropriate access restrictions. This page does not claim that Complys performs the statutory joint assessment, receives confidential notices, runs the regulated resolution process, determines legal jurisdiction, provides psychological support or guarantees compliance. Those decisions and protections belong to the employer and its appointed people.
Start by identifying the right federal work units and applicable partner. Use the current Regulations and the Labour Program employer checklist to build an evidence-based joint assessment, then implement and monitor the preventive measures. Review the content and actual product configuration before publishing any software claim or cross-link.
For the related Complys product, see Ohs Compliance Software. This guide is general information, not legal advice; verify current requirements against the official sources linked above.