A high-risk termination needs a documented, threat-assessment-led plan built jointly by HR, legal, and security. Don’t handle it ad hoc. This means convening a multidisciplinary team before you set a date, following OSHA’s General Duty Clause and the ISC/CISA separation guide, and, when the situation warrants it, bringing in outside expertise like Hub Investigative Group. What follows is the operational checklist we use to get there.
TL;DR:
- High-risk terminations involve employees with documented threats, access to weapons, or recent misconduct investigations, requiring immediate triage and documentation.
- A dedicated threat assessment team should include HR, legal, security, and IT staff, following a seven-step process to categorize and manage risk effectively.
- Scheduling, location, and scripting of the meeting are critical, with remote or off-site options and rehearsed scripts to minimize escalation and ensure safety.
- Pre-planning security, access revocation, and physical logistics is essential, with timing based on risk level and strict coordination across teams.
- External security support, like Hub Investigative Group, is recommended for the most volatile cases to provide expert presence and post-separation monitoring.
Table of Contents
- What Makes a Termination “High Risk”?
- Building a Threat Assessment Team and Process
- Planning the Separation: Timing, Location, and Script
- Coordinating Security and IT Before the Meeting
- Running the Meeting: Scripts and Safe Exits
- What Happens After the Termination
- How Hub Investigative Group Supports High-Risk Separations
- What HR Teams Consistently Get Wrong
- Bring in Direct Security Support for High-Risk Separations
- Where to Go for Deeper Templates
- Sources
What Makes a Termination “High Risk”?
A termination earns the “high risk” label when the person’s history or circumstances suggest they might react violently, not simply because the conversation will be uncomfortable. HR teams that lump every difficult separation into the same bucket end up under-preparing for the ones that genuinely need extra precaution, and over-preparing for the ones that don’t.
Watch for these signals:
- A documented history of threats, intimidation, or physical aggression toward coworkers or supervisors
- Recent boundary-testing behavior: showing up uninvited, excessive personal questions, following staff
- Known or suspected access to weapons
- A role with access to sensitive systems, financial controls, or confidential client data
- Termination triggered by misconduct investigations, fraud findings, or performance disputes involving anger or blame
If any of these apply, pause the process immediately. Gather documented facts from HR, the direct manager, and security before scheduling anything, and never let one manager make the call alone. A Forbes Council piece on compliance planning makes the point bluntly: a one-size-fits-all approach is unsafe because every case depends on the individual’s behavior, role, and access to assets.
Building a Threat Assessment Team and Process
Once triage flags a case as high risk, it moves to a Threat Assessment Team, or TAT. The TAT typically includes HR, legal counsel, a security representative, an employee relations contact, and, depending on the case, facilities and IT staff who understand building access and system permissions.
The ISC/CISA guide lays out a seven-step workflow that keeps the process consistent instead of improvised:
- Identify the risk factors present in the specific case
- Gather information from managers, HR records, and prior incident reports
- Conduct a formal threat assessment with the full team
- Categorize the risk as low, moderate, or high
- Develop a tailored risk management plan matched to that category
- Communicate the plan to everyone who needs to execute it
- Implement the plan and monitor for changes before and after separation
Risk categorization drives everything downstream. A low-risk case might only need a witness present and standard access shutoff at the time of the meeting. A moderate-risk case often adds a security presence in the building and staged access removal. A high-risk case can call for an off-site meeting, uniformed security on-site, immediate access revocation, and a defined post-separation monitoring window, following the ISC/CISA guide’s categorization framework.
Pro Tip: Assign one TAT member as the single point of contact for the day of separation. Splitting decision authority across multiple people during a live event is how plans fall apart in the moment.
Planning the Separation: Timing, Location, and Script
Timing and location decisions shape how the meeting unfolds before anyone says a word. Midweek, midmorning slots tend to work better than end-of-day-on-Friday terminations, since the employee has access to HR, EAP resources, and support systems for the rest of the business day rather than being sent home to stew over a weekend. Exceptions apply when an active safety threat means the separation needs to happen immediately, regardless of the day.
Location matters just as much:
- Neutral, private on-site rooms work for low and moderate risk cases, ideally near an exit with no obstacles between the employee and the door
- Off-site locations reduce exposure to other staff and remove the employee from familiar territory in high-risk cases
- Remote separations, handled through a controlled video call, can lower physical risk but require the same access-revocation timing as an in-person meeting; platforms built for staged video communication, such as those used for one-way interview workflows, show how structured remote formats can reduce unpredictability
Keep the room to two people from the company side wherever possible: the delivering manager and a witness or HR representative. Security should be nearby but out of sight unless the risk category calls for visible presence. Write the script in advance, factual, brief, and free of debate. Pro Tip: Rehearse the script out loud with the TAT beforehand. Reading it silently almost always hides awkward phrasing that triggers defensiveness in the room.
Coordinating Security and IT Before the Meeting
Access revocation and physical logistics need to run on a tight, pre-agreed schedule, not a scramble after the meeting ends. The ISC/CISA guide recommends timing access cuts to the risk category rather than applying one blanket rule.
- Badge and building access: disable at the start of the meeting for high-risk cases, or immediately after for moderate risk
- Network and remote access: revoke email, VPN, and cloud logins in the same window as physical access
- Escorts: use trained personnel, not a random available manager, to walk the employee to collect belongings
- Personal items: have someone else retrieve or box items in advance when possible, limiting the employee’s time near desks, drawers, or shared equipment that could hold a weapon
- Cross-team sync: reception, security, IT, payroll, and legal all need the exact meeting time so no one at the front desk is caught off guard
Employers carry a legal obligation here, not just a best practice. OSHA’s General Duty Clause requires a workplace free from recognized hazards likely to cause serious harm, and unmanaged access during a volatile separation counts as exactly that kind of hazard.
Running the Meeting: Scripts and Safe Exits
Open with facts, not feelings. State the decision, the effective date, and the immediate next steps in under two minutes, then stop talking.
- Deliver the decision in neutral language: state what is happening, when it’s effective, and what happens next with pay, benefits, and belongings
- Watch for escalation cues: raised voice, clenched fists, blocking the exit, or refusing to engage with logistics
- Use a simple scripted redirect if tension rises: acknowledge the reaction, restate that the decision is final, and offer the next practical step
- If de-escalation fails, end the meeting immediately and have the witness signal security
- Escort the employee out using the pre-planned route, and involve law enforcement if there’s any indication of a weapon or imminent danger
The ISC/CISA guide’s two-part meeting model, a short initial notification followed by a separate follow-up for questions and paperwork, tends to stabilize reactions better than trying to cover everything in one long sitting.
What Happens After the Termination
The work isn’t done when the employee leaves the building. Confirm every access point is actually closed, not just scheduled to close.
- Notify reception and parking staff of the separation and provide a photo if the risk level warrants it
- Confirm IT has completed every credential revocation on the list, not just the obvious ones
- Set a defined monitoring window for be-on-the-lookout alerts and public social-media checks, a practice threat-management teams use to catch early escalation signals
- Debrief the TAT and offer EAP resources to any staff who witnessed the separation or worked closely with the employee
- Hold off on aggressive legal steps like automatic restraining orders unless the risk assessment specifically supports it; reflexive legal escalation can provoke the reaction you’re trying to prevent
Document every decision point, from the initial risk categorization through post-separation monitoring, in case the file is ever needed for a wrongful termination defense or a law enforcement report.
How Hub Investigative Group Supports High-Risk Separations
A specialized security and investigative firm has operated in Boston since 2004, drawing on extensive combined law enforcement and loss prevention expertise. That background matters most when an internal TAT lacks the bandwidth or specialized training to manage a genuinely volatile case.
Internal teams handle the majority of low and moderate risk separations well on their own. External support earns its cost when threats have already surfaced, when the employee has a documented history of aggression, or when the organization simply lacks trained security personnel on-site. A typical engagement moves through assessment of the specific risk factors, joint planning with HR and legal, physical presence during the separation itself, and a defined post-event monitoring period.

What HR Teams Consistently Get Wrong
The biggest gap isn’t a lack of policy. It’s the assumption that having a termination policy is the same as having a high-risk termination plan. Most organizations have the former and skip the latter entirely, treating every separation like the easy ones that make up the bulk of their caseload.

The conventional advice tells HR to “trust your instincts” about which terminations feel dangerous. That’s backwards. Instinct catches obvious cases, an employee who’s made direct threats, but it misses the quieter risk factors: a role with financial system access, a recent divorce filing, a pattern of boundary-testing that never quite crossed into a reportable incident. The ISC/CISA framework exists precisely because gut feeling under-detects risk in exactly the cases where the stakes are highest.
If there’s one priority to fix first, it’s this: build the triage habit before you need it. Waiting until a termination is already scheduled to figure out who’s on your threat assessment team is how organizations end up improvising through the exact scenario a documented process is supposed to prevent.
— Derek
Bring in Direct Security Support for High-Risk Separations
Such firms provide HR teams with trained personnel physically present when a separation carries real risk, avoiding the delay of building that capability in-house from scratch. Where internal teams often lack the bandwidth or specialized training a volatile case demands, their combined law enforcement and loss prevention background provides expertise to fill that gap directly.

For organizations preparing a high-risk separation, Hub’s security risk assessment service evaluates the specific factors at play before a date is even set. When the plan calls for a visible security presence during the meeting itself, workplace executive protection and executive protection planning cover both the on-site presence and the advance coordination with your HR and legal teams. If you’re facing a termination that fits any of the high-risk indicators covered above, request a security services consultation before you schedule the meeting, not after something goes wrong.
Where to Go for Deeper Templates
The ISC guide from CISA offers the fullest checklist for risk categorization and access-timing decisions. OSHA’s workplace violence enforcement page explains the legal basis employers operate under. SHRM’s guidance on firing violent employees safely covers policy language and communication scripts worth adapting for your own organization.
Sources
- Managing Risk of Adverse/Involuntary Employee Separations: An ISC Guide (CISA) — 2024
- OSHA — Workplace violence enforcement
- Firing violent employees safely — SHRM