Comprehensive guide to employer duty of care legal requirements: OSHA, UK HSWA, ISO 31030, breach consequences, travel and remote worker obligations, and a step-by-step compliance framework.
The legal duty of care for employers is the obligation to take reasonable steps to protect the health, safety, and wellbeing of employees while they work. It is enforceable through occupational health and safety statutes, common law negligence, and contract law. An employer who fails to meet this standard and causes harm can face regulatory penalties, criminal liability, and civil damages claims.
This duty is not optional and it is not limited to the physical workplace. It follows employees into the field, onto business trips, and into home offices. It covers physical hazards, psychological harm, and security risks across every location where people perform work on the employer's behalf.
In tort law, duty of care describes a legal relationship in which one party must avoid causing foreseeable harm to another. The concept traces to Donoghue v Stevenson [1932], the case that established the modern "neighbour principle": you owe a duty to those who would be closely and directly affected by your acts. For employers, that neighbour is the employee.
Establishing a breach requires four elements to line up in sequence:
When all four are present, liability follows. The Cornell Law definition frames duty of care as the degree of attentiveness and caution a reasonable person would exercise in a given situation. For employers, the law translates "reasonable person" into "reasonable employer," judged against what a competent organization in the same sector would have done.
A legal duty of care is statutory and enforceable. Regulators issue citations, courts award damages, and prosecutors can pursue criminal charges when breaches are severe. A moral duty of care is the ethical expectation that an organization will protect its people because it is the right thing to do, with reputational consequences when it fails.
Both carry practical business cost. The legal obligation sets the floor that keeps the organization out of court. The moral obligation shapes whether employees, customers, and investors trust the company. Treating duty of care as only a compliance checkbox misses how directly it now affects talent retention, brand value, and the cost of capital.
The four main principles of employer duty of care are the four legal elements a claimant must prove to establish negligence: a duty existed, the standard of care was breached, the breach caused harm, and measurable damage resulted. Each principle has a specific employer-context meaning.
These four principles apply identically whether the harm happened on a factory floor, in a hotel abroad, or at a home workstation. The location changes the facts. It does not change the test.
Employer duty of care is codified differently across jurisdictions, but the underlying standard is consistent: take reasonable, practicable steps to prevent foreseeable harm. Organizations with operations in more than one country must comply with each jurisdiction's specific statutes, not a single global rule. The sections below cover the major frameworks corporate security and compliance teams encounter.
In the United States, the Occupational Safety and Health Act of 1970 anchors employer duty of care. Section 5(a)(1), known as the General Duty Clause, requires every employer to provide a workplace "free from recognized hazards that are causing or are likely to cause death or serious physical harm." This clause covers hazards that have no specific OSHA standard, which makes it a broad and frequently cited basis for enforcement.
Penalties scale with severity. In 2024, a willful or repeat violation carries a maximum penalty of $161,323 per violation, while serious and other-than-serious violations top out at $16,131 each. Twenty-two states operate their own OSHA-approved plans that meet or exceed federal requirements, so the applicable standard depends on where the workplace sits.
Two companion statutes extend the obligation. The Americans with Disabilities Act (ADA) requires reasonable accommodation for employees with disabilities, including mental health conditions. The Family and Medical Leave Act (FMLA) protects job security during qualifying medical and family leave. Together with OSHA, they define a large part of the U.S. employer's legal duty.
The Health and Safety at Work etc. Act 1974 (HSWA) is the cornerstone of UK duty of care. It requires employers to ensure, "so far as is reasonably practicable," the health, safety, and welfare of employees. The Management of Health and Safety at Work Regulations 1999 make risk assessment an explicit legal requirement.
The "reasonably practicable" standard asks employers to weigh the risk against the cost, time, and effort of removing it. A serious risk demands action even when the remedy is expensive. The Corporate Manslaughter and Corporate Homicide Act 2007 raises the stakes further: an organization whose gross failure in management causes a death can face an unlimited fine and a publicity order. The Health and Safety Executive (HSE) enforces these duties, with unlimited fines for serious breaches and the possibility of imprisonment for individuals.
Australia's Work Health and Safety Act 2011 places a "primary duty of care" on a "person conducting a business or undertaking" (PCBU). The PCBU must ensure, so far as is reasonably practicable, the health and safety of workers and others affected by the work.
A significant change took effect in April 2023, when model WHS regulations made the management of psychosocial hazards an explicit requirement within mandatory risk assessments. Employers must now identify and control hazards such as excessive workload, bullying, and exposure to traumatic content with the same rigor applied to physical hazards. Safe Work Australia sets national policy, while state and territory regulators handle enforcement.
Canada distributes occupational health and safety authority across federal and provincial levels. The Canada Labour Code Part II governs federally regulated workplaces, while each province and territory maintains its own occupational health and safety act for everyone else.
Bill C-45, often called the Westray Law after the 1992 mining disaster that prompted it, amended the Criminal Code in 2004 to impose criminal liability on organizations and individuals for gross negligence that causes injury or death. It established a legal duty for anyone directing work to take reasonable steps to prevent bodily harm, and it made corporations prosecutable for criminal negligence. The law signaled that severe duty of care failures in Canada can be treated as crimes, not just regulatory matters.
Beyond national law, two international standards shape how organizations operationalize duty of care. ISO 45001:2018 is the global benchmark for occupational health and safety management systems. It is not itself a law, but it is increasingly written into contracts, procurement requirements, and insurance terms, which gives it practical force. Certification signals that an organization has a structured, auditable approach to identifying and controlling workplace risk.
ISO 31030 is the travel risk management standard, and it is the one most directly relevant to organizations with mobile workforces. Published as guidance, it sets out how to manage risk to traveling employees across the full trip lifecycle. Its operational requirements include pre-trip risk assessment, ongoing review of the threat landscape, a 24/7 assistance capability, and a post-trip review. The standard's reference to ongoing threat review means maintaining current visibility into the risk environment at travel destinations. Persistent threat landscape intelligence, refreshed on a regular cadence, is what supports that requirement, distinct from event-driven alerting which the standard treats as a separate response capability. Fewer than three competing resources cover ISO 31030 at any depth, which leaves a gap for organizations that want practical guidance on aligning a travel risk program with the standard.
Duty of care converts into five core responsibilities that recur across every major jurisdiction. Meeting them is how an employer demonstrates the "reasonable steps" the law requires.
The first responsibility is to identify hazards before they cause harm. A complete risk assessment covers physical, chemical, ergonomic, psychosocial, security, and travel or destination-specific risks. In the UK, risk assessment is legally mandatory for any employer with five or more employees, and the same expectation runs through OSHA, the Australian WHS Act, and Canadian provincial law.
Scale makes this hard. One Fortune 10 company needed to assess employee safety across more than 500 offices in 35 countries under return-to-office time pressure, and its existing tools took weeks per location, which created liability exposure while assessments sat incomplete. A Fortune 100 e-commerce and technology company faced the same problem across 441 global locations, where a security manager described the manual approach as unsustainable: leadership wanted more regular updates, and the work was consuming bandwidth the team needed elsewhere. Continuous, location-specific risk scoring addresses this gap. BaseScore™ provides a standardized 0-100 risk score for each location, refreshed monthly, so teams can compare sites and prioritize the highest-risk ones with data rather than guesswork.
Identifying a hazard creates an obligation to control it. The hierarchy of controls runs from engineering solutions and safe systems of work through to personal protective equipment, which OSHA requires employers to provide at no cost to the worker. For mobile and lone workers, controls include lone-worker protocols and documented travel security plans.
Documentation matters as much as the measure itself. A control the employer cannot prove it implemented offers little legal defense after an incident. Location-specific security recommendations, tied to the actual risk profile of each site, give organizations a defensible record of what they did and why. The same intelligence that drives a Fortune 500 travel company's executive protection program lets security teams match protective measures to the specific threats at each location rather than applying a single generic policy everywhere.
Employers must ensure workers are competent to do their jobs safely. Training has to be role-specific, repeated on a regular schedule, and documented. OSHA requires training records to be maintained and accessible. For travelers, this responsibility includes pre-trip briefings on destination-specific risks so employees understand the environment they are entering.
Traveler briefing materials grounded in current destination intelligence turn this from a box-ticking exercise into genuine preparation. One leading technology provider standardized its executive protection memos so every briefing followed the same structure and drew on the same quality of data, which made training consistent across the program and easier to audit.
Workers must be able to raise safety concerns without fear of retaliation. This means formal mechanisms, not just an open-door promise. In the United States, Section 11(c) of the OSH Act protects employees who report hazards from retaliation. In the United Kingdom, the Public Interest Disclosure Act 1998 provides equivalent whistleblower protection.
Effective consultation also surfaces hazards the employer might otherwise miss. The people doing the work often see emerging risks first, and a reporting channel that workers trust turns that frontline knowledge into early warning.
The final responsibility is to plan for the situations risk assessment cannot fully prevent. Documented emergency plans must cover fire, medical emergencies, natural disasters, and, for traveling employees, travel crises such as political unrest, terrorism, and disease outbreaks. In the United States, OSHA standard 29 CFR 1910.38 sets specific requirements for written emergency action plans. ISO 31030 calls for a 24/7 assistance capability for travelers.
Strong preparation reduces how often crisis response is needed at all. A Fortune 500 travel company shifted its security function from reactive incident reporting toward concierge-level travel security, using better intelligence to inform decisions before trips rather than scrambling after something went wrong. Proactive risk visibility does not replace emergency response, but it shrinks the number of emergencies that reach it.
Duty of care follows the employee wherever work takes them. A business trip and a home office are not exceptions to the obligation. They are extensions of it, and courts treat them that way.
The same reasonable-care standard that applies in the office applies on the road. In Palfrey v. Ark Offshore Ltd., an employer was found liable after an employee died of malaria contracted on an overseas assignment, because the employer had failed to provide adequate health protection and advice. The case is a clear precedent: sending someone to a higher-risk destination without proper assessment and preparation is a breach.
More than 50 countries now have duty of care laws that cover business travelers, so the obligation is not confined to the employer's home jurisdiction. Employees feel the gap when it is not met. In a SAP Concur survey, 58% of business travelers said they had changed travel arrangements because of safety concerns, and 52% named travel safety as the most valuable form of training their employer could provide. Duty of care for travelers is both a legal requirement and a factor in whether employees are willing to travel at all.
In practice, travel duty of care follows the lifecycle that ISO 31030 lays out. Each phase carries its own obligations:
A complete travel security assessment walks through these phases in detail, from defining the destination through hotel risk scoring, neighborhood analysis, and traveler briefing materials. A threat intelligence platform delivers phases 1 through 3 directly by supplying the destination intelligence and risk scoring those phases depend on, and it provides the data infrastructure that makes phases 4 and 5 work. A Fortune 500 travel company assessed more than 300 locations in a single year this way, evolving its travel briefs from high-level city summaries into location-specific security recommendations.
Duty of care applies to home-based workers. The obligation does not switch off because the work happens outside a company building. Employers are expected to provide ergonomic guidance, mental health support, emergency preparedness information, and cybersecurity training for remote staff. The standard is "reasonable steps" applied to what the employer can actually control: the employer cannot inspect every home, but it can provide guidance, equipment stipends, and support.
For distributed workforces that operate in the field rather than at home, the duty extends to the locations employees travel through and work in. A healthcare leader managing in-home clinicians built a standardized security framework that scored risk down to the ZIP-code level across all service territories, replacing inconsistent regional efforts with one data-driven approach. The same logic covers the commute. A commute safety assessment evaluates route-specific crime patterns and transit-stop safety, which is exactly the kind of foreseeable risk an employer is expected to consider when it asks people to come into an office.
A one-size-fits-all policy is legally insufficient. The reasonable-employer standard expects precautions to match the actual risk, which means calibrating duty of care to the destination, the employee, and the assignment. Destination factors include political stability, healthcare quality, crime levels, and exposure to natural disasters. Employee factors include health conditions, and assignment factors include duration and activity. A CEO attending meetings in Switzerland and an engineer deploying to a conflict zone do not require the same plan, and treating them identically exposes the employer on both ends.
Failure to account for destination-specific risk is itself a basis for negligence claims, because it shows the employer did not take the reasonable step of assessing what the employee actually faced. Granular intelligence supports this calibration. The same approach used for executive protection risk assessment, working from city-wide context down through hotel comparison, neighborhood analysis, and crime-type filtering, lets an organization justify why one trip warranted enhanced measures and another did not. A reinsurance executive captured the discipline behind this when reviewing the company's risk exposure: there was no value in investing attention in a region where the organization had no people and no underwriting exposure. Matching risk intelligence to actual exposure is what separates a defensible program from a generic one.
Employee mental health is now part of the legal duty of care, not a discretionary wellness perk. Courts and regulators increasingly treat psychological harm the same way they treat physical injury, and the trend is expanding.
The precedent runs back to Walker v Northumberland County Council [1995], in which an employer was held liable for the psychiatric harm a social worker suffered after a foreseeable second breakdown caused by excessive workload. The case established that employers can be liable for psychiatric injury when the harm is foreseeable and they fail to act.
Statutory obligations reinforce the case law. The UK Equality Act 2010 and the U.S. ADA both require reasonable adjustments or accommodations for employees with mental health disabilities. Australia's April 2023 WHS changes went further by mandating explicit psychosocial hazard risk assessments. The scale of the problem explains the legal momentum: roughly 1 in 4 people in England experience a mental health problem each year, and poor mental health costs U.S. businesses an estimated $108 billion annually through lost productivity and absence.
A psychosocial hazard is any aspect of work design or management that can cause psychological harm. Regulators have moved these from the category of soft HR issues into the category of assessable workplace hazards. The recognized hazards include:
Framed correctly, these are employer obligations to identify and control, not suggestions to consider. An organization that knows a role exposes workers to traumatic content, for example, and does nothing to manage that exposure, is failing a duty in the same way it would by ignoring a faulty machine.
Employee assistance programs (EAPs) are not universally mandated, but failing to provide access to support can constitute a breach when the psychological risk is foreseeable. If an employer knows a role carries significant mental health risk and offers no support pathway, that absence becomes evidence of an unreasonable response.
The business case reinforces the legal one. Access to mental health support reduces absenteeism, lowers stress-related turnover, and improves retention. Anchoring EAPs in legal risk reduction, rather than treating them as a benefits-brochure line item, reframes them as part of the organization's defense against foreseeable psychological harm.
A breach of duty of care occurs when an employer fails to meet the standard a reasonable employer would have met, and that failure causes measurable harm. Establishing a breach is a structured legal test, not a judgment call.
Negligence requires four elements, applied in order:
The standard is objective. An employer who genuinely believed it was doing enough still breaches the duty if a reasonable organization would have done more.
Breaches appear across every work context. The table below maps common categories to concrete failures.
The common thread is foreseeability. In each case the risk was knowable in advance, and the breach was the failure to take a reasonable step that would have addressed it. Scattered, slow assessment tools contribute directly to this exposure, because they leave hazards unassessed for longer and make it harder to prove the employer acted with reasonable diligence.
Five conditions recur in unsafe-workplace claims:
Each represents a recognized hazard under OSHA's General Duty Clause and its UK and Australian equivalents. An employer aware of any of these and slow to act is exposed to both regulatory citation and a negligence claim.
The consequences of breaching duty of care fall into two categories: direct legal and financial penalties, and the slower but often larger reputational and operational damage. Together they make the business case for compliance unambiguous.
Regulatory penalties are substantial and rising. In the United States, 2024 OSHA penalties reach $161,323 per willful or repeat violation. In the United Kingdom, the HSE reports an average cost of around $8,800 for a non-fatal injury, while the most serious cases have drawn fines near $10 million, and the agency maintains a conviction rate above 90% in the cases it prosecutes.
Regulatory fines are only the first layer. Civil negligence claims sit on top of them, brought directly by injured employees or their families, and these can far exceed the regulatory penalty. An organization that breaches its duty can therefore face a citation, a civil judgment, and, in severe cases under laws like the UK Corporate Manslaughter Act or Canada's Bill C-45, criminal prosecution.
The reputational cost reaches further than the courtroom. Surveys show that 97% of employees consider safety a key factor in deciding where to work, which ties duty of care directly to recruitment and retention. On the customer side, research from Qualtrics found that 1 in 4 consumers stopped buying from brands they judged to have insufficient safety practices. Poor safety records also feed into ESG ratings and weigh on investor confidence.
There is an upside to handling this well. The same Fortune 500 travel company that strengthened its travel security program elevated security from a cost center into a strategic advisor that leadership consulted on major decisions. Meeting duty of care obligations rigorously is not just risk avoidance. Done with good data, it becomes a source of organizational credibility.
Duty of care imposes specific prohibitions on managers. Under the obligation, a manager cannot:
Each prohibition maps to a recognized legal duty, and crossing any of them can convert routine management into a breach.
Building a compliant duty of care program is a six-step process that moves from understanding legal obligations to operating a continuously improving system. The steps below give security and compliance teams a practical sequence.
Start by auditing current programs against statutory requirements. Build a legal register that lists every obligation the organization faces, jurisdiction by jurisdiction, because each country requires separate analysis. For a multinational, this can mean tracking obligations across 190 or more jurisdictions, which is a common enterprise challenge. The Fortune 100 e-commerce company managing 441 locations found that doing this manually became unsustainable as its program matured and leadership demanded more frequent updates. A gap analysis exposes where current practice falls short of legal requirement, which is where the program work begins.
Assess risk in every context where work happens: the office, the home, business travel destinations, long-term overseas postings, and contractor sites. A single workplace assessment is no longer enough when the workforce is distributed. The framework below structures the assessment by context.
The scale challenge is real. One Fortune 10 company assessed more than 500 offices across 35 countries, a healthcare leader scored risk across 300 ZIP codes for its distributed workforce, and commute-route analysis added another layer for return-to-office planning. Standardized, location-specific scoring is what makes assessment at this scale manageable.
Translate the assessment into a written duty of care policy. The policy must define its scope clearly, covering employees, contractors, and interns, and it must address risk categories, training requirements, incident reporting, emergency response, travel risk management, and mental health support. A documented policy is both a management tool and a legal artifact: it demonstrates the organization identified its obligations and set out how it would meet them.
A policy that workers do not understand provides little protection. Employers have an obligation to communicate so that workers know their rights and responsibilities, and all training must be documented. Where the law requires them, safety committees give workers a formal consultation channel. Traveler briefing materials, drawn from current destination intelligence, are a concrete example of training that meets a specific legal duty rather than a generic safety module.
Modern duty of care requires a technology layer that earlier steps depend on. A complete program needs traveler tracking, threat intelligence that combines a persistent view of the threat landscape with event-driven alerting, alerts from the appropriate platforms, and a 24/7 emergency response capability. The key is to map each technology requirement back to the legal obligations established in the earlier sections, so the stack exists to satisfy duties, not for its own sake.
This is where the distinction between two kinds of intelligence matters. Base Operations provides persistent street-level threat intelligence: 25,000+ data sources aggregated into more than 150 million mapped incidents, refreshed monthly with sub-mile granularity and trend analysis, so teams can understand and forecast the risk environment at every location in their footprint. Event-driven, time-sensitive alerts about unfolding incidents come from complementary platforms such as Dataminr, Everbridge, and AlertMedia. A mature program runs both: the persistent intelligence layer to assess and prioritize risk, and the alerting layer to respond to events as they happen. The payoff from getting the intelligence layer right is concrete. One leading AI provider cut executive protection assessment time by 75% while increasing the insights each assessment produced and tripling the speed of standardized recommendations. A Fortune 10 company replaced scattered tools with a unified intelligence platform across hundreds of sites, and a Fortune 500 travel company assessed more than 300 locations in a year on the same foundation.
See how Base Operations operationalizes duty of care compliance for traveling employees. Request a demo.
Duty of care is not a one-time project. Risk assessments need updating at least annually and after any incident, with post-incident investigation feeding corrective actions that the organization tracks to completion. Auditing the program against ISO 45001 or an equivalent framework provides external structure and evidence of diligence. A global consultancy that standardized its assessment process achieved a 35% efficiency lift within three months, a measurable transformation that also created the consistent records an audit requires. A healthcare leader used predictive risk modeling to anticipate seasonal fluctuations, which moved the program from reacting to last year's incidents toward preparing for next quarter's.
Duty of care compliance is the legal minimum: doing enough to avoid liability. Proactive risk management goes beyond the floor to actively reduce risk before it materializes. Courts and regulators increasingly look for the second, because reactive compliance is becoming harder to defend as a "reasonable" standard. The table below maps the difference across five dimensions.
The direction of travel is clear. Regulators and courts now look for evidence that an employer was actively identifying hazards, not merely responding after harm occurred. AlertMedia's framework describes three types of employer along this spectrum: the Uninformed, the Bare Minimum, and the Employee-First organization. Only the last is consistently defensible. A logistics security leader put the contrast plainly when describing the shift his team wanted: proactively assessing risk instead of staying on defense and waiting for the next bad thing to happen. The same move repeats across organizations that have made it, like the global consultancy that went from cost center to strategic partner once its risk process became data-driven.
Persistent threat landscape intelligence, with monthly updates, sub-mile granularity, and 25,000+ data sources, is what enables the shift from reactive to proactive, complemented by event-driven alert platforms for in-trip response.
Move from reactive compliance to proactive risk management. Explore Base Operations for corporate security.
For U.S. employers, OSHA defines the core of workplace duty of care. The General Duty Clause and supporting standards set obligations that every covered employer must meet. The primary requirements include:
These obligations apply alongside any stricter standards in the 22 states that run their own OSHA-approved plans.
Duty of care is the legal obligation to take reasonable steps to avoid causing foreseeable harm to another party. The concept comes from tort law and the 1932 case Donoghue v Stevenson. For employers, it means taking reasonable, practicable measures to protect the health, safety, and wellbeing of employees while they work. A breach requires four elements: a duty existed, it was breached, the breach caused harm, and the harm is measurable.
The four main principles are the legal elements needed to prove negligence. First, a duty of care existed between the parties. Second, that duty was breached against the standard of a reasonable employer. Third, the breach directly caused harm. Fourth, measurable damage resulted, whether physical, psychiatric, or financial. All four must be present for liability to follow, and the same test applies in the office, on business travel, and in a home office.
Employers have five core responsibilities: conducting regular risk assessments across all hazard types, implementing preventive and protective measures, providing role-specific safety training and ensuring competency, establishing worker consultation and reporting channels free from retaliation, and maintaining emergency preparedness and crisis response plans. These responsibilities recur across U.S., UK, Australian, and Canadian law and apply to office, remote, and traveling employees.
Yes. Duty of care follows the employee wherever work takes them. For travelers, the Palfrey v. Ark Offshore Ltd. case confirmed employer liability when an employee died after a high-risk assignment, and more than 50 countries have laws covering business travelers. For remote workers, employers must provide ergonomic guidance, mental health support, emergency preparedness, and cybersecurity training, applying the "reasonable steps" standard to what the employer can control.
An employer that breaches duty of care can face regulatory penalties, civil negligence claims, and, in severe cases, criminal prosecution. In 2024, OSHA willful violations carry penalties up to $161,323 each, and UK serious cases have drawn fines near $10 million. Injured employees can also bring civil claims that exceed regulatory fines. Reputational consequences follow too, affecting recruitment, customer trust, and investor confidence.
A standalone written "duty of care policy" is not always mandated by a single statute, but the underlying obligations it documents are legally required. UK law mandates risk assessments for employers with five or more employees, OSHA requires written emergency action plans, and Australia mandates psychosocial hazard assessments. A documented policy is the practical way to demonstrate the organization identified and addressed these legal duties, and it serves as evidence of diligence.
Duty of care is the obligation itself: the responsibility to take reasonable steps to protect others from foreseeable harm. Negligence is the legal failure to meet that obligation when the failure causes measurable damage. Put simply, duty of care is the standard, and negligence is the breach of that standard. An employer cannot be negligent without first owing a duty of care, and proving negligence requires showing the duty existed, was breached, caused harm, and produced loss.
ISO 31030 is the international travel risk management standard, and it gives employers a structured way to meet duty of care obligations for traveling employees. It covers the full trip lifecycle: pre-trip risk assessment, ongoing review of the destination threat landscape, a 24/7 assistance capability, and a post-trip review. Following ISO 31030 helps an organization demonstrate it took the reasonable, documented steps the law expects when sending employees to assess and manage travel risk.
Under duty of care, an employer or manager cannot direct untrained employees into unsafe tasks, ignore formally reported hazards, retaliate against workers who raise safety concerns, send employees to high-risk locations without a documented risk assessment, require fatigue-inducing working hours, or discriminate against employees with mental health conditions. Each prohibition maps to a recognized legal duty, and crossing any of them can constitute a breach that supports a negligence claim.
The core standard is consistent across countries, but the statutes differ. The U.S. relies on OSHA's General Duty Clause; the UK uses the Health and Safety at Work Act 1974 with a "reasonably practicable" test; Australia's WHS Act 2011 imposes a "primary duty of care" and now mandates psychosocial hazard assessment; and Canada combines provincial OH&S acts with criminal liability under Bill C-45. Multinationals must comply with each jurisdiction separately, which is why a per-country legal register is the foundation of a compliant program.

Join 1100+ security leaders getting new ideas on how to better protect their people and assets.