Legal services built around your needs.

With the next wave of Employment Rights Act 2025 changes due in October 2026, employers should now be looking at the practical steps needed to prepare.
Several changes due to come into force on 30 October 2026 will require action well before the implementation date, particularly in relation to sexual harassment prevention, third-party harassment and trade union access to the workplace.
The common thread is that employers will need to understand where risk arises in their own business, who is responsible for addressing it, and whether managers have the training and confidence to respond properly when issues are reported.
The existing duty to prevent sexual harassment already requires employers to take a proactive approach, rather than waiting for a complaint before acting.
The October 2026 changes will strengthen that duty by requiring employers to take “all” reasonable steps to prevent sexual harassment. Further regulations setting out the minimum required steps is expected to be published prior to October, but the likely direction is already clear. Employers should be reviewing policies, carrying out risk assessments, training staff and managers, making sure complaints are handled through a process that is clear and properly understood and that all complaints and investigations are properly documented, and ensuring that remedial measures are identified and implemented following any complaint.
Waiting for final guidance before doing anything would be a mistake, particularly if sexual harassment policies have not been reviewed recently or if the organisation has not yet assessed where the risk of sexual harassment is most likely to arise.
From 1 October 2026, employers will be liable if one of their employees is harassed in the course of their employment by a third party and the employer has failed to take all reasonable steps to prevent that from happening. This not only includes sexual harassment, but harassment related to race, disability, religion or belief, sexual orientation, age, and sex (gender).
Employers should carry out a risk assessment, including conducting an audit of which staff have contact with the public or third parties, and the locations where they are likely to intersect with third parties, and what steps can be taken to reduce the risk of harassment. Employers should review their contracts with customers, suppliers and other third parties to ensure that anti-harassment clauses are included. Where third parties visit company premises or interact with staff online, consider whether signage and/or messaging should be introduced to make it clear that harassment will not be tolerated. Employers should think about other ways to signal a zero-tolerance approach to third parties, such as through website terms or event codes of conduct.
One of the most common gaps is the absence of a meaningful sexual harassment risk assessment. That gap is significant because the duty is preventive. An employer cannot sensibly show that it has taken reasonable steps to prevent sexual harassment if it has not first considered where the risk exists.
The October 2026 changes also mean that employers will need to think not only about sexual harassment, but harassment related to other protected characteristics including race, sex, disability, religion or belief, and age. The will also need to consider the risk of harassment not only between colleagues, but about harassment by customers, clients, visitors, suppliers and others their employees encounter through work.
The assessment should be specific to the organisation. For some businesses, the risk may arise in public-facing roles. For others, it may sit in less visible parts of working life: client entertainment, off-site meetings, late-working arrangements, conferences, networking events or visits to customer premises. Those settings still form part of the working environment, and employers will need to decide what proportionate safeguards are needed.
In some cases, that may include clearer reporting routes, manager guidance, event protocols, notices, booking terms, client-facing policies or contractual wording. The right approach will depend on the business, but doing nothing is unlikely to be a comfortable position in the event of any claim.
Sexual harassment complaints often arise in situations where the facts are messy. There may be alcohol involved. There may be a prior workplace relationship. There may be no CCTV, no independent witness and two conflicting accounts of what happened.
Employers sometimes mishandle such cases by treating the absence of corroborating evidence as proof that nothing happened in cases where there is only one person’s word against another’s. That is a serious mistake, as the account of both the complainant and the respondent should be treated as evidence. The investigator’s task is to gather and test that evidence carefully, ask sufficiently detailed questions, assess each person’s credibility and reach a reasoned conclusion.
Managers need training not only on what constitutes sexual harassment, but also on what to do when concerns are reported, and how to carry out a fair, objective and comprehensive investigation as possible. They should know how to receive a complaint, when to escalate it, how to avoid prejudging the outcome, and why a superficial investigation can create significant legal risk.
Staff should also be trained on how to identify sexual harassment, what to do if they witness harassment taking place, and the ways in which harassment should be reported.
Employers may need to consider whether an external investigator would be appropriate. A sensitive allegation with serious consequences may require someone with specialist experience in evidence gathering, credibility assessment and workplace investigations.
The October 2026 changes will also introduce new trade union rights of access to workplaces. The formal right of access will apply to employers with recognised trade unions and to employers without any history of trade union engagement.
Any trade union holding a certificate of independence can request access, even if they are not a recognised trade union, and once granted, that access must extend to all workers, not just those who are union members. Access has to serve a specific purpose, such as meeting, supporting, representing, recruiting or organising workers, or facilitating collective bargaining. It cannot be used to organise industrial action.
If a trade union makes an access request, employers will be expected to reach a written access agreement with the union, setting out how and when the union can access the workplace — both in person and digitally.
The union and employer are expected to negotiate the terms of access between themselves, but a Code of Practice (currently in draft form) will provide the main practical guidance, and the CAC will publish “model terms”. These are expected to include weekly physical access as standard, a private space for meetings (such as a meeting room) during normal working hours, and digital access — including an obligation on employers to cascade union information to staff and to facilitate online meetings using their existing IT platforms.
Union officials must be allowed to physically enter the premises and/or communicate with workers in any manner that doesn’t unreasonably interfere with the employer’s business, and the employer must take “reasonable steps” to facilitate this. Access can only be refused where it is reasonable in all the circumstances to do so. Union officials must follow reasonable management instructions in the workplace, but there is no guidance
Once a request is submitted, the employer has 15 days to respond, using a “response notice” (a template will be in the Code of Practice), and this deadline can only be extended if the union agrees. If the employer rejects the request, it must give written reasons, and the parties then have just 25 days to negotiate an access agreement — a tight window that cannot be extended. If negotiations fail, or the employer doesn’t respond at all, the union can apply to the CAC, If the CAC disagrees with the employer’s refusal, it will impose its own terms of access.
Failure to comply with CAC-imposed terms carries real financial consequences: up to £75,000 for a first breach, £150,000 for a second, £500,000 for a third, and a further £500,000 for each breach after that. The CAC will also have the power to determine disputes about breaches of access agreements more generally.
Employers should identify who will be responsible for dealing with access requests, usually within HR or a senior management function, and make sure managers know how to recognise one if it arrives. Requests should be recognised early and passed promptly to the right person or team.
Employers should use the time before 30 October 2026 to review sexual harassment policies, carry out or refresh risk assessments, train staff and managers, and check whether reporting and investigation processes would work in practice.
They should also assess where third-party harassment risks may arise and decide what steps are needed to reduce them. Alongside that, businesses should put a clear process in place for trade union access requests, including internal ownership, manager awareness and escalation routes.
The organisations best placed for the October changes will be those that prepare properly, rather than treating implementation as a last-minute policy exercise.
Arbor Law supports employers with Employment Rights Act preparation, including sexual harassment policies, workplace risk assessments, manager training, investigation support and processes for handling trade union access requests.
We help businesses understand what the changes mean in practice and put proportionate steps in place before issues arise. Where additional training is needed, we can work with HR teams, managers and legal teams to make sure the organisation is ready for the new duties.
Several key Employment Rights Act 2025 changes are due to come into force on 30 October 2026. These include strengthened duties around sexual harassment prevention, new protection against third-party harassment, and new trade union rights of access to workplaces.
Employers will be required to take all reasonable steps to prevent sexual harassment. This strengthens the existing duty and means employers should be taking a proactive approach, including reviewing policies, carrying out risk assessments, training staff and managers, and making sure complaints are handled properly.
Yes. A sexual harassment risk assessment is a practical review of where harassment risks may arise in the business and what steps need to be taken to reduce them. It should reflect the employer’s actual working environment, including public-facing roles, client events, off-site meetings, workplace relationships, travel and situations where employees deal with third parties.
Third-party harassment is harassment of an employee by someone who is not employed by the business, such as a customer, client, visitor, supplier or other external contact. The forthcoming changes mean employers will need to consider how they protect staff from harassment by third parties, not only from harassment by colleagues.
The October 2026 changes will introduce new trade union rights of access to workplaces. Employers should put a clear internal process in place so managers know how to recognise a request, who it should be passed to, and how it will be managed. The process will involve specific response requirements and timescales, so requests should be identified early and handled through a clear internal route.
Employers should review sexual harassment policies, carry out or refresh risk assessments, train staff and managers, and check whether reporting and investigation processes would work in practice. They should also consider third-party harassment risks and put a process in place for trade union access requests before the new duties come into force.









