Staff security and duty of care

Learn how to meet your legal and ethical obligations to staff through practical risk management and crisis response steps.

When It Matters

Duty of care means putting suitable protections and support in place so incidents are prevented and handled well, and making sure every member of staff is told about the dangers and the steps that lower them. As a legal concept, it is a duty set by law to act with reasonable care whenever your actions could foreseeably put others at risk of harm.

Security risk management is only one part of it. The wider responsibility covers staff health, safety, security and wellbeing. It also reaches past employees, to contractors, consultants, volunteers, dependants and official visitors acting for the organization.

You will need this page if you run a small team with no security specialist, if you send staff to work inside a partner organization, or if you employ both national and international staff.

How It Works

These steps are drawn from a basic guide to security risk management for small NGOs.

  1. Define your risk attitude. Set a risk threshold, so that everyone shares an understanding of how much risk is acceptable and when a decision must be escalated.
  2. Document informed consent. Keep a process showing staff understand the risks and their part in managing them. The basic guide notes that such documents will not provide a legal waiver in a court of law.
  3. Assess the risks. The process has six stages: establish the context, identify the risks, analyze them, evaluate them, treat them, then monitor and review, with communication and consultation throughout. You should be able to demonstrate that every foreseeable danger tied to a place or activity was identified and weighed, and that you did everything reasonable to manage those dangers.
  4. Write the security plan. It is a document at country level that records which security measures and procedures apply, who is responsible, and what resources are needed to run them. Involve the affected staff in writing it. They are more likely to follow a plan whose reasons they understand.
  5. Set up incident reporting. A security incident is any event that hurt, or might hurt, staff, associated personnel or outsiders, badly disrupted programs, or seriously damaged property or reputation. Expect three reports: an immediate report as soon as it is safe, updates, and a post-incident report.
  6. Prepare for a crisis. An incident becomes a crisis when normal management structures can no longer cope. A common setup is a small crisis management team at headquarters and an incident management team as close to the incident as is safe.
  7. Check and audit. Track a few indicators, then commission an internal or external evidence-based review that tests whether you are meeting your duty of care.

Key Components

  • Written security policy. Every organization needs one, whatever its size. It should state principles such as primacy of life: nobody takes excessive risk to meet program objectives or protect property.
  • Security risk assessment. If an assessment identifies measures that are then not put in place, the organization may be exposed as breaching its duty of care.
  • Informed consent process. A documented record that staff understand the risks of their role and the measures in place.
  • Country security plan. A country-level record of the security measures and procedures that apply, who is responsible, and the resources needed to run them.
  • Security focal point or working group. A smaller organization can name one person, or a group of staff, to lead the framework.
  • Incident reporting. Staff need a clear explanation of why reporting matters, because under-reporting is a problem everywhere.
  • Crisis management structure. Headquarters and incident-level teams, ready before anything happens.
  • Compliance indicators. Examples are the share of security plans that are up to date, briefings given to staff traveling to higher-risk destinations, staff trained, and incidents reported.

National Staff, International Staff and Partners

Aid organizations have a duty to take all reasonable measures to protect staff from foreseeable dangers, including dangers linked to a person's own characteristics. For most national staff, a risk that comes from identity and context alone usually falls outside the employer's duty of care. When identity and context interact with the person's job and employer so that the danger grows, the employing NGO must manage it.

Sharing information about the risks faced by all profiles with all staff helps here. People learn about the risks tied to their own profile without anyone disclosing personal information, which balances duty of care with non-discrimination.

An organization that seconds a staff member to another organization cannot transfer its duty of care. It stays responsible for that person.

In partnerships, local and national NGOs often bear the heaviest share of security risk in day-to-day work in high-risk contexts. Partners also transfer security risk to each other automatically, whether they mean to or not, so agree who carries which risk before work starts. Where a partner or host provides security support, help it develop security plans and procedures where necessary, and if possible help it get access to security training. Do not assume the expertise sits only with the international partner, because that does not reflect what many local organizations can do.

Best Practices

Apply primacy of life and the right to withdraw. Put both in the policy. Nobody should take excessive risk for program goals or property, and all staff can withdraw from or refuse work in an area over security concerns.

Track a few indicators. The share of plans up to date, staff trained, briefings given and incidents reported are examples of what to monitor.

Treat wellbeing as part of duty of care. One sector description calls it an environment that lets an employee flourish, so look beyond physical safety to the working environment you give staff.

Keep mitigation proportionate. The goal is to keep the organization engaged and able to deliver despite the risk, and not to block programs. On 25 November 2015 a district court in Europe awarded a kidnapped employee roughly 4.4 million Norwegian krone (about 465,000 euro), a case widely seen as the aid sector's first test of duty of care. The review of that ruling concludes that it should lead to stronger security risk management, not greater risk aversion.

Involve affected staff in planning. Staff who help prepare the security plans understand the why and not just the what, so they are more likely to follow them.

Common Mistakes

Assessing risks but not acting. An assessment that lists measures nobody implements can expose you as breaching your duty. Assign each measure an owner.

Treating a signed form as a waiver. The basic guide says such documents will not provide a legal waiver in court. Keep the documented process and the measures.

Handing crisis decisions to an outside provider. Outside assistance should complement your response. Critical-incident decisions stay with you.

Setting an arbitrary budget percentage. Some organizations allocate a set share of the program budget, usually no more than 5 percent. Base the amount on the measures your assessment requires.

Never checking compliance. Assess regularly whether guidelines are followed.

Example

A small health NGO has a few staff seconded to a local partner. It has no security specialist, so it names a program manager as security focal point.

The focal point starts by helping define the organization's risk attitude, so all staff share an understanding of what level of risk is acceptable and when to escalate. Staff go through a documented informed consent process. Then comes the risk assessment across the six stages, including how one staff member's identity, combined with their role and organization, might raise the risk in a particular district. Because the secondment does not move its duty of care, the NGO keeps the responsibility and supports the partner to develop its security plan and access security training. The plan, written with the affected staff, includes primacy of life and the right to withdraw.

An incident reporting routine follows, with immediate reports, updates and post-incident reports.

Further Reading