Understanding Duty of Care: The Legal and Ethical Obligations of Business Security
Many business proprietors consider duty of care when it’s too late. In reality, duty of care is a legal and ethical responsibility that arises as soon as you welcome employees, clients, or vendors onto your premises, and it’s as applicable to security issues as it is to a hazardous surface or a malfunctioning fire door.
What Duty of Care Actually Means
Duty of care comes from common law negligence. It’s the requirement that you take reasonable steps to prevent foreseeable harm to people who interact with your business. That’s the legal version. The ethical version is simpler: if you invite people onto your property or employ them to work there, you owe them a basic standard of protection. You don’t get to shrug and say “we couldn’t have known” if the risk was obvious and you did nothing about it.
This isn’t abstract. Under work health and safety legislation, businesses carry a primary duty to ensure the health and safety of workers and anyone else who might be affected by their operations. That includes customers walking through a car park at night, delivery drivers using a loading dock, and contractors working after hours. Security risks – assault, theft, intimidation, unauthorized access – sit inside that duty just as firmly as machinery hazards or slip risks. Courts have made clear that “we’ve never had an incident” isn’t a defense. Foreseeability is the test, not history.
The numbers back up why this matters. The International Labour Organization’s 2022 report found roughly 1 in 5 workers globally has experienced violence or harassment at work. That’s not a fringe issue affecting a handful of high-risk industries. It’s a baseline reality that any business with staff, customers, or public access needs to plan around.
Where Businesses Actually Fail
It’s very rare that duty-of-care breaches stem from some massive failure. Normally, they’re the result of lots of tiny, seemingly inconsequential choices to defer maintenance, ignore warning signs, or just not take the risk seriously.
These are the sorts of scenarios you’ll see again and again in court or in an insurance dispute:
- Your business gets broken into, the lock is bent but it’s still possible to lock it, and nobody calls out a locksmith. Three months later, someone walks in through the same point of entry.
- Staff let you know that a specific customer or an ex-employee has been making threats. You don’t document it for privacy’s sake, or because you feel it’s a personnel issue and not a security issue. So you don’t make a formal note, you don’t change any entry protocols, and six weeks later, they follow through.
- A light goes out in your car park and you figure that with all that ambient light from the 24-hour petrol station across the road, nobody’s going to prioritize fixing it. A worker gets assaulted walking to their car after a late shift.
These aren’t cases of random hatchet-wielding maniacs. These are cases of your business knowing that a specific risk existed and deciding that, all things considered, it wasn’t worth acting on. That’s the exact gap that negligence law is designed to catch and it’s the exact gap that a proper risk assessment is designed to help you avoid.
The Four Steps of a Proper Security Risk Assessment
A security audit isn’t a walk-through with a clipboard. If done properly, it follows a structured process that produces a defensible record – which is as important as the physical fixes themselves.
The first step is Asset identification. What are you actually protecting? People, cash, stock, data, equipment, reputation. You need to list it out. You can’t assess risk to something you haven’t named.
The second step is Threat profiling. What are the realistic threats to those assets, based on your industry, location, and history? A retail store near a transport hub has a different threat profile than a suburban office. Site-specific threat lists are admissible in court; generic ones aren’t.
The third step is Vulnerability analysis, meaning looking at where your current setup falls short against those threats. Blind spots in camera coverage, single points of entry with no monitoring, staff working alone at night with no duress alarm.
Next is Control prioritization. Rank fixes both by risk level and feasibility, so you’re not spending your budget on the least urgent problem while a serious gap sits untouched. This is also where you document your reasoning – because if something happens later, the paper trail showing you assessed the risk and acted on it is your due diligence defense.
The Controls a Reasonably Prudent Business Puts in Place
Once you’ve mapped the risks, the fixes are usually not exotic. They’re the standard toolkit, applied properly rather than half-heartedly.
CCTV surveillance covering entry points, cash handling areas, and car parks – not just for prevention, but because footage is often the only objective evidence available after an incident. Access control systems that restrict who can get into sensitive areas, whether that’s key cards, PIN pads, or biometric locks. Alarm systems tied to monitoring, not just a siren that goes off with nobody listening. Exterior lighting that actually covers walkways and parking, not just the front entrance. And trained personnel – security guards who understand de-escalation, reporting procedures, and how to work alongside the other systems rather than as an isolated add-on.
This is also where many businesses stumble across a second legal problem: privacy. Rules about where cameras can point will vary from state to state but in general, you cannot put cameras in bathrooms, change rooms or lactation rooms. You can’t point a camera at an ATM or credit card terminal. In many states, you cannot record audio at all. Most states also require that businesses tell employees when they are being recorded. When and why you record them goes to the prudent use and retention of data – you have to keep footage safe, staff must be properly trained to access it, you need a process to grant police access, and you must be able to rapidly and fully delete material identifying anybody on request. The rules around all that are your business’s responsibilities to stay current with.
Getting security right and staying well clear of privacy obligations takes care in how cameras are pointed and how footage is managed. That’s quite a bit cleaner when systems are set up right, but it’s far from easy to work out what can be seen from each camera in each direction, so you start with a proper plan rather than doing it on the fly. The goalposts move quickly and breaking the rules can get expensive, so as with physical security, the temptation will be to call in the professionals who live and breathe it. Working with an established security company adelaide businesses trust gives you access to trained personnel, properly configured systems, and the kind of standardized reporting that holds up if you ever need to show a court or regulator that you took your obligations seriously. That’s the practical value a professional provider adds beyond just having guards on site – documentation, consistent procedures, and an audit trail.
Documentation Is What Turns Compliance Into a Defense
Here’s the part a lot of business owners miss. Simply having security measures installed does not guarantee that you can prove their existence and functionality at the specific time an incident occurred.
For example, in a negligence suit following a break-in, the question is not whether you had cameras on the premises but whether they were operational at the time; whether appropriate footage was retained, stored, and monitored; whether you had prior knowledge of potential weaknesses and opportunities for theft; and, if so, whether and how you responded to that information. A professional security provider will have records of all these facets through maintenance logs, incident reports, and standard operating procedures. This level of documentation is what sets a business with due diligence apart from one forced to look back after the fact and argue its good intentions.
Vicarious liability means one step further: If your security personnel or your security contractor fails in their duty because of neglect – say, by leaving a gate unlocked – your business could be held responsible. This is an argument for using licensed, well-equipped providers with trained personnel rather than informal arrangements – their knowledge and procedures can be cited as your own defense against liability.
Duty of Care Isn’t a Loophole to Manage Around
Let’s be honest about something: We shouldn’t think of Duty of Care as a compliance box that you check off so you don’t get sued. Organizations that view security as an actual obligation to their employees and customers generally recognize that in higher morale and trust. When people feel safe, they report issues sooner. When customers feel safe, they return. That doesn’t show up on any compliance checklist, but it does show up in retention and reputation over time.
When we talk about Corporate Social Responsibility, most of the focus is on environmental or supply chain – but the physical safety of the people in your building is just as much a stakeholder responsibility. The business that decides to reduce lighting or ignore employee safety issues to save a few dollars a month is making the same decision as the business ignoring a safety issue in the warehouse.
What Happens When Businesses Get This Wrong
The financial costs associated with failing to meet the duty of care obligation may already be on your radar; fines, legal fees and compensation are all important factors. But there are other costs that are both less visible and often greater: the costs to your reputation and your business. If your company is the scene of a violent incident, the consequences can be financial in the short term as well as reputational in the longer term. Significant costs can be incurred in evacuation, lost productivity, property damage and increased security. Then there are the less direct but no-less-real costs of business disruption, lost customers and reduced staff morale.
The Proactive Approach Beats the Reactive One Every Time
Businesses that manage this well don’t respond after the event. They contract a risk assessment before there is a problem, engage registered security practitioners rather than backyard fixes, and view security expenditure as insulation against damages rather than a cost to minimize. The professional industry organizations like ASIAL are there to specifically create a yardstick for what ‘reasonable’ security practice is and this means that a business has a clear measure to test themselves against, rather than flying on good intentions.
Having your business wake up to the need for security after a robbery, an injury, or a lawsuit is the worst way to do it – legally and financially. Doing so before that point is not just the safer legal strategy. It’s also the only approach that actually provides the duty of care you owe.













Leave a Reply
Want to join the discussion?Feel free to contribute!