Workplace Threat Assessment: A 2026 Guide for HR and Security Pros

What is workplace threat assessment and why does it matter?
A workplace threat assessment is a structured, behavior-based process for identifying individuals who may pose a risk of violence to an organization, then evaluating that risk and intervening before harm occurs. It is not a background check or a disciplinary review. The goal is prevention, not punishment.
The scale of the problem makes this process urgent. According to OSHA, workplace violence results in numerous murders and assaults of workers every week in the United States. The Bureau of Labor Statistics recorded 740 fatal workplace injuries due to violent acts in 2023 alone. Those numbers reflect a preventable hazard, not an unavoidable reality of Workplace Threat Assessments.
Authoritative bodies including OSHA, the FBI, and ASIS International have each published guidance establishing workplace threat assessment as a professional standard, not an optional add-on. Their frameworks converge on a few core principles:
- Threat assessment focuses on behavior, not profiles or demographics.
- Validated instruments like WAVR-21 and MOSAIC provide structured, defensible risk scoring.
- Multidisciplinary Workplace Threat Assessment Teams (TATs) outperform single-department responses in both speed and accuracy.
- Early identification of concerning behavior is the single most effective violence prevention strategy available to employers. Workplace Threat Assessment
When your organization treats workplace threat assessment as a standing function rather than a crisis reaction, you shift from managing incidents to preventing them.
How do you conduct a workplace threat assessment step by step?
The DHS threat assessment framework outlines a structured process that moves from initial report to ongoing monitoring. Each stage builds on the last, and skipping any of them weakens the whole evaluation.
- Receive and triage the report. A coworker, supervisor, or HR professional flags a concern. This could be a direct threat, a pattern of alarming behavior, or a tip from a third party. Coworkers and friends, not direct targets, are often the first to hear threats, so your reporting channels need to be accessible and trusted.
- Convene the Workplace Threat Assessment Team. The WTAT meets promptly, reviews the initial information, and assigns case responsibilities. Speed matters here. A standing team with defined roles responds faster than an ad-hoc group assembled under pressure.
- Gather facts and context. The team collects incident reports, behavioral observations, personnel records, law enforcement contacts, and any relevant social media or communications. Environmental factors, such as physical access points and shift schedules, are also reviewed.
- Evaluate the risk. Using structured instruments like WAVR-21 or MOSAIC, the team scores behavioral indicators and maps the subject’s potential pathway to violence. The evaluation considers protective factors alongside risk factors, not just warning signs in isolation.
- Implement an intervention plan. Based on the risk level, the team selects a proportionate response. Options range from a supportive conversation and referral to the Employee Assistance Program (EAP) to administrative action, law enforcement notification, or emergency psychiatric evaluation.
- Monitor and reassess. The case stays open until the risk drops to an acceptable level. New information can change the picture entirely, so the team schedules regular check-ins and adjusts the plan as circumstances evolve.
Common triggers for opening a case include termination disputes, restraining order violations, escalating grievances, direct or veiled threats in written communications, and reports of weapons access combined with expressed intent.
Pro Tip: Document every step of the process in a dedicated case management file, including who was contacted, what information was gathered, and what decisions were made. Thorough records protect the organization legally and give future TAT members the context they need if a case reopens.

Who should be on your Threat Assessment Team?
A well-built TAT is multidisciplinary by design. FBI guidance and DHS recommendations both emphasize that no single department has the full picture. HR knows the employment history. Security knows the physical environment. Legal knows the liability boundaries. An EAP clinician understands behavioral health. Together, they form a team that can evaluate the whole person in context.

The core roles and their primary contributions:
| Team Role | Primary Responsibility |
|---|---|
| Human Resources | Employment history, policy enforcement, termination logistics, benefits coordination |
| Security | Physical access control, incident documentation, law enforcement liaison |
| Legal Counsel | Compliance guidance, civil rights protections, documentation review |
| EAP or Mental Health Clinician | Behavioral health assessment, fitness-for-duty referrals, crisis support |
| Operations or Facilities | Environmental risk factors, access points, evacuation planning |
| Labor Relations (if applicable) | Union contract considerations, grievance context |
A standing TAT, one that meets regularly and trains together, consistently outperforms groups assembled only when a crisis hits. Established teams reduce intervention time and produce more consistent decisions because members already understand each other’s roles and constraints.
Key responsibilities shared across all TAT members include:
- Maintaining confidentiality throughout the assessment process.
- Applying validated risk instruments such as WAVR-21 and MOSAIC without substituting personal judgment for structured evaluation.
- Coordinating with external partners, including local law enforcement and mental health providers, when the situation requires it.
- Participating in regular training to stay current on evolving threat behaviors and legal standards.
The supervisor of the subject in question plays a specific supporting role. They provide behavioral context and observations but typically do not attend full TAT deliberations, protecting the integrity of the process.
What legal and regulatory requirements govern threat assessments in the U.S.?
OSHA does not currently have a specific standard dedicated solely to workplace violence. What it does have is a general duty clause requiring employers to provide a workplace free from recognized hazards, and a body of published guidance that treats violence as a preventable occupational hazard. That guidance carries real weight in enforcement and litigation.
OSHA’s worksite analysis recommendations require employers to:
- Review incident records covering at least 2–3 years, including OSHA Form 300 logs, workers’ compensation records, and police reports.
- Conduct periodic physical walkthroughs to identify environmental risk factors such as poor lighting, inadequate access control, and isolated work areas.
- Survey employees to surface hazards that records alone may not capture.
- Evaluate the effectiveness of existing security controls and update them when gaps are found.
Beyond OSHA, the FBI and ASIS International have each published standards that inform best practice. The ASIS International 2011 Workplace Violence Prevention standard calls for organizations to establish Threat Management Teams with members who are trained and formally authorized to act. The FBI’s behavioral threat assessment model, detailed in its Law Enforcement Bulletin, reinforces the need for structured, behavior-focused evaluation over profile-based screening.
Legal compliance also requires balancing safety with employee rights. Teams must weigh environmental, social, and individual factors when building a risk abatement plan, and they must do so without violating contractual protections, civil rights, or privacy laws. Documentation is your protection on both fronts: it demonstrates due diligence and creates a defensible record if the assessment is ever challenged.
What tools and examples help you run an effective assessment?
The two most widely used validated instruments in U.S. workplaces are WAVR-21 and MOSAIC. Each takes a different approach, and many organizations use both.
WAVR-21 (Workplace Assessment of Violence Risk) evaluates 21 behavioral and contextual factors, including fixation on a grievance, weapons access, and evidence of planning. It produces a structured score that helps multidisciplinary teams move from subjective concern to defensible, documented risk evaluation. WAVR-21 and similar tools assess both protective and risk factors, giving teams a more complete picture than a checklist of warning signs alone.
MOSAIC uses a data-driven comparison method, measuring a subject’s profile against a database of known cases to estimate relative risk. It is particularly useful for stalking and threat-of-violence scenarios involving former employees or external individuals.
Beyond these instruments, a practical assessment toolkit includes:
- Standardized incident report forms that capture behavioral details, not just the triggering event.
- Behavioral monitoring checklists for supervisors to track changes in conduct over time.
- Screening questionnaires for use during employee surveys or post-incident reviews.
- A case management log that records every TAT action, decision, and follow-up contact.
“Perpetrators of targeted acts of violence engage in covert and overt behaviors preceding and accompanying their attacks. They consider, plan, prepare, share, and, in some cases, move on to action.” — FBI Law Enforcement Bulletin on Workplace Threat Assessment Teams
That behavioral pathway is exactly what your assessment process is designed to detect early. Technology platforms can support data collection and case tracking, but the analytical judgment still belongs to your trained team. Integration with your broader workplace security evaluation and emergency response plan ensures that assessment findings translate directly into coordinated action when the situation demands it. Sound industrial safety practices reinforce this integration by embedding hazard analysis into everyday operations rather than treating it as a separate exercise.
What do industry experts recommend for workplace threat assessment?
The FBI’s position is clear: workplace threat assessment teams should be standing, trained units, not groups assembled in the middle of a crisis. Established teams bring defined roles, practiced communication, and organizational resilience that ad-hoc groups simply cannot replicate under pressure.
ASIS International reinforces this with a specific emphasis on periodic training as a requirement, not a recommendation. Threat behaviors evolve. Post-pandemic workplaces have introduced new stressors, including remote work isolation, economic instability, and hybrid team dynamics, that change how grievances develop and escalate. A team that trained in 2019 and has not updated its skills is working with an outdated map.
Key expert recommendations that apply directly to your program:
- Treat early behavioral intervention as the primary goal, not disciplinary action.
- Build reporting channels that employees actually trust and use, because most threats are heard by coworkers before they reach management.
- Coordinate with local law enforcement before a crisis, not during one, so relationships and protocols are already in place.
- Review your threat assessment program after every significant case, whether or not violence occurred, to identify gaps.
At Hubsecurityandinvestigativegroup, we bring over seventy-five years of combined law enforcement and loss prevention experience to this work. Our team understands both the behavioral science behind threat assessment and the operational realities of keeping people safe in complex environments.
Pro Tip: Set a standing monthly TAT meeting, even when there are no active cases. Use that time to review near-miss reports, update contact lists, and run tabletop scenarios. Teams that meet regularly respond faster and make better decisions when a real case arrives.
How do you establish and maintain a Threat Assessment Team?
Building a TAT from scratch requires four foundational decisions: who sits on the team, what authority they have, how cases reach them, and how the team stays current.
Start by formalizing the team’s charter in writing. The charter should define membership, meeting frequency, case intake procedures, confidentiality rules, and escalation thresholds. Without a written charter, the team’s authority is ambiguous and its decisions are harder to defend.
Select members based on role, not seniority. The right HR representative is the one with employee relations experience, not necessarily the most senior person in the department. The same logic applies to every seat at the table. Once the team is assembled, conduct a joint orientation so every member understands the full process, not just their own piece of it.
Establish a clear, accessible reporting mechanism. A dedicated email address, a third-party hotline, or a direct line to HR all work, but the channel must be known to employees and perceived as safe to use. Anonymous reporting options increase the volume of tips you receive.
Maintain the team through scheduled training, after-action reviews, and periodic program audits. OSHA recommends reviewing incident records across at least a 2–3 year window as part of any hazard analysis, and that same discipline applies to your TAT’s own performance data.
How should you interview subjects and witnesses during an assessment?
Interviews are where assessments either gain critical insight or lose it. The approach differs significantly depending on whether you are speaking with a witness, a potential victim, or the subject of the assessment.
With witnesses and coworkers, the priority is creating a low-pressure environment where they feel safe sharing what they know. Use open-ended questions and avoid leading language. Ask what they observed, not what they think it means. People often underreport because they fear being wrong or causing trouble for a colleague, so normalizing the conversation matters.
When interviewing the subject directly, the TAT must decide whether a direct contact is appropriate given the current risk level. If it is, the interview should be conducted by someone with behavioral interviewing experience, typically HR or a trained clinician, not security alone. The goal is to gather information and assess current state of mind, not to confront or accuse. Subjects who feel cornered are more likely to disengage from any support being offered.
A few principles that apply across all interviews:
- Document the conversation immediately after it ends, while details are fresh.
- Never promise confidentiality you cannot keep, particularly if the information gathered may require a mandatory report.
- Listen for what is not said as much as what is. Minimization, deflection, and sudden topic changes are behavioral signals worth noting.
- Coordinate with legal counsel before interviewing a subject who is represented by a union or an attorney.
What happens after the assessment: interventions and ongoing monitoring?
Post-assessment action is where the work either pays off or falls apart. Intervention plans should be tailored to the specific risk level and circumstances of each case, not drawn from a generic template.
For lower-risk cases, a referral to the EAP, a supportive conversation with a supervisor, or a modification of work duties may be sufficient. For moderate-risk cases, the plan might include a formal fitness-for-duty evaluation, increased supervisory contact, and a temporary adjustment to physical access. For imminent threats, the response escalates to law enforcement notification, emergency psychiatric evaluation, and immediate protective measures for potential targets.
Monitoring does not end when the immediate intervention is complete. Continuous monitoring remains active until the risk level drops to an acceptable threshold, which the TAT defines in advance. Check-in schedules, behavioral benchmarks, and clear criteria for closing a case all belong in the intervention plan from the start.
Post-assessment actions also feed back into your broader safety program. Every case generates data about where your reporting systems, environmental controls, or training gaps need attention. That feedback loop is what turns individual case management into a continuously improving prevention program.
Case studies: how workplace threat assessment prevents workplace violence
Real cases illustrate what the process looks like in practice, and why early intervention works.
The grievance that escalated. A manufacturing company received a report that a recently disciplined employee had made vague comments about “making people pay.” The TAT convened within 24 hours, reviewed the employee’s personnel file, and contacted his supervisor for behavioral context. A WAVR-21 evaluation identified elevated fixation and access to firearms. The team coordinated a fitness-for-duty referral and temporarily suspended the employee’s facility access while the evaluation was completed. The employee entered a treatment program. No violence occurred.
The terminated employee. A financial services firm terminated an employee for performance reasons. Within days, coworkers reported receiving unsettling messages from the former employee. The TAT, which had a standing protocol for post-termination monitoring, activated immediately. Security reviewed access logs, IT revoked all system credentials, and HR coordinated with local law enforcement to share the communications. The former employee was contacted by police, who assessed the situation and connected him with community mental health resources. The case closed without incident three months later.
These scenarios share a common thread: the TAT had a process, the process was followed, and early action prevented escalation. The federal joint study on workplace violence reinforces that organizations with structured prevention programs consistently achieve better outcomes than those relying on reactive responses.
How Hub Security And Investigative Group supports your workplace threat assessment program

Hubsecurityandinvestigativegroup has been protecting organizations in Boston and across the region since 2004, drawing on over seventy-five years of combined law enforcement and loss prevention expertise. We work directly with HR, security, and risk management teams to build and support threat assessment programs that are practical, legally sound, and ready to act when it matters.
Our services include security assessments, risk management consulting, workplace security during sensitive situations like layoffs, and on-site support for active threat cases. We understand the operational pressures you face and the legal standards you are held to. Whether you need help building a TAT from the ground up or want an outside review of your existing program, we bring the experience and the judgment to make it work.
Explore our business security guide to see how threat assessment fits into a layered protection strategy, or contact us directly to discuss your organization’s specific risk profile.
Key Takeaways from Workplace Threat Assessment
A structured, multidisciplinary workplace threat assessment program, grounded in OSHA guidance, FBI behavioral science, and validated tools like WAVR-21 and MOSAIC, is the most reliable method for preventing workplace violence before it occurs.
| Point | Details |
|---|---|
| Standing TATs outperform ad-hoc groups | Teams with defined roles and regular training respond faster and make more consistent decisions. |
| OSHA requires a multi-year records review | Hazard analysis must include incident logs, OSHA Form 300, and workers’ compensation records. |
| WAVR-21 and MOSAIC add structure | Validated instruments replace subjective judgment with defensible, scored risk evaluations. |
| Monitoring continues post-intervention | Cases stay open until risk drops to an acceptable threshold, with scheduled reassessments built in. |
| Documentation protects the organization | Thorough case records demonstrate due diligence and support legal defense if decisions are challenged. |
Recommended
- 1.Workplace Security: Why Every Business Needs a Strong Protection Plan – Hub Security & Investigative Group
- The Ultimate Guide to Business Security: Protecting Your Assets, Employees, and Future – Hub Security & Investigative Group
- Top Security Threats in the United States: What You Need to Know in 2025 – Hub Security & Investigative Group
- Federal Agencies Release Joint Study on Workplace Violence – Hub Security & Investigative Group