Compliance
What Does California Require for Workplace Violence Prevention?
Direct answer
California requires nearly every employer to establish, implement, and maintain a written, site specific Workplace Violence Prevention Plan, keep a Violent Incident Log, and provide interactive annual training. The requirement took effect July 1, 2024 under Labor Code section 6401.9, enacted by SB 553, and it is enforceable by Cal/OSHA. A permanent Cal/OSHA general industry standard must be adopted no later than December 31, 2026, and every existing plan will need to be reviewed against it.
What the law actually requires
Five things, and all five are enforceable now. A written plan that is specific to the site rather than generic. A hazard identification and evaluation process, applied on a schedule and repeated after any incident. A Violent Incident Log recording every incident, retained for five years. Effective training delivered when the plan is established and annually thereafter, with training records retained for at least one year. And a procedure for employees to report incidents and threats without fear of reprisal, along with a defined process for investigating and responding.
The plan may sit inside the existing Injury and Illness Prevention Program or stand alone. Either is acceptable. What is not acceptable is a document that has never been tailored to the actual site, the actual work, and the actual people doing it.
Who is covered
In practical terms, nearly every California employer. The statute applies broadly, and the exemptions are narrow enough that most organizations that assume they are exempt are not.
The exemptions cover employers already subject to the Cal/OSHA workplace violence prevention in health care standard, employees teleworking from a location of their own choosing outside the employer's control, locations not open to the public where fewer than 10 employees work at any given time, and certain corrections and law enforcement agencies.
The fewer than 10 employees exemption is the one organizations reach for and the one that most often fails. It requires that the location be closed to the public. A workplace that accepts deliveries, receives vendors, or has any routine outside foot traffic will struggle to claim it.
The training requirement most programs fail
Training must be interactive. Employees have to be able to ask questions and receive answers in real time, and the content has to be tailored to the specific job assignments of the people being trained.
This is where the largest share of nominally compliant programs break. A recorded e-learning module purchased at a per seat price satisfies neither condition. It is not interactive in the sense the statute requires, and it is not tailored to a specific site or a specific job. Organizations that bought a compliance product often have documentation showing training was completed and a program that would not survive an inspection.
The same problem appears in the plan itself. A downloaded template with a company name inserted is a document, not a program, and the hazard assessment it contains describes a workplace that does not exist.
The Violent Incident Log
The log records every incident of workplace violence, and the definition of an incident is broader than most managers assume. It captures threats, verbal abuse, and incidents that produced no injury, not only physical assaults.
Each entry requires detail: the date, time, and location, a description of the incident, the classification of the type of violence, the circumstances, the consequences, and who completed the entry. Personal identifying information about the people involved is excluded from the log.
Logs are retained for five years. This is the record an inspector will ask for first, because it is the fastest way to determine whether a program is real. An empty log at an organization with a busy incident history is a finding, not a clean record.
What changes when the permanent standard arrives
SB 553 required Cal/OSHA to propose a general industry workplace violence prevention standard, with the Occupational Safety and Health Standards Board required to adopt it no later than December 31, 2026. Draft versions have moved through advisory and comment stages, with the most recent public comment period closing in mid 2026.
The drafts released so far build on the statutory framework rather than replacing it, and go further on hazard assessment, post incident response, and program implementation. Reporting and communication obligations expand, including communication with authorized employee representatives about how incidents are reported, investigated, and resolved.
The practical consequence is straightforward. Organizations that built a substantive, site specific program will handle the transition as a routine review. Organizations that relied on a template will face a rebuild, under time pressure, at the same moment every other California employer is doing the same thing.
How a real program is scoped
Program development is a project, not a subscription. The work is a site walk and hazard assessment, a written plan built from what the walk found, a records system including the Violent Incident Log, on site interactive employee training, a separate supervisor module covering recognition and response, and a train the trainer handoff so the organization can deliver future sessions without buying them.
Cost is driven by headcount and shift count rather than by the length of the scope description, because the number of training sessions required is the dominant variable. A single shift operation with 13 employees and a three shift operation with 130 are different engagements even where the written plan is nearly identical.
Ongoing work is retained annually and banded to headcount, covering the annual plan review, the annual training cycle, incident log oversight, and the transition to the permanent standard when it is adopted.
Compliance and threat management are the same discipline
A workplace violence prevention plan that exists only to satisfy Cal/OSHA is a filing exercise. The statute happens to describe, in regulatory language, the same work that behavioral threat assessment describes in operational language: identify who might act, evaluate capability and access, remove what in the environment makes acting easier, and define who decides what happens next.
Organizations that treat the requirement as an opportunity to build actual threat management capability get a compliant program and a functioning one. The reporting procedure becomes a real intake channel. The hazard assessment becomes a live picture of the site. The supervisor training becomes early detection.
That capability carries directly into higher risk moments the statute does not address: a termination involving a person who has made threatening statements, a workforce reduction, a public facing event, or an executive whose exposure has grown. The program is the foundation, and the protective work sits on top of it.
A note on scope
This page describes statutory and regulatory requirements in general terms and is not legal advice. Cal/OSHA rulemaking is active and the permanent standard is not final. Verify current requirements against the Department of Industrial Relations and, where the stakes warrant it, with counsel.
Key facts
- Statute
- California Labor Code section 6401.9, enacted by SB 553
- Effective
- July 1, 2024
- Enforced by
- Cal/OSHA
- Required
- Written plan, hazard assessment, incident log, training, reporting procedure
- Violent Incident Log retention
- 5 years
- Training record retention
- At least 1 year
- Training standard
- Interactive, with real time questions, job specific
- Permanent standard deadline
- Adoption no later than December 31, 2026
Frequently asked
Does SB 553 apply to my company?
Almost certainly, if you have employees in California. The statute applies broadly and the exemptions are narrow: employers under the health care workplace violence standard, employees teleworking from locations outside the employer's control, locations closed to the public with fewer than 10 employees present at a time, and certain corrections and law enforcement agencies.
Is online training enough to satisfy California workplace violence requirements?
Generally no. Training must be interactive, meaning employees can ask questions and receive answers in real time, and it must be tailored to the specific job assignments of the people being trained. A recorded e-learning module purchased per seat satisfies neither condition on its own.
What has to go in the Violent Incident Log?
Date, time, and location, a description of the incident, the classification of the type of violence, the circumstances, the consequences, and who completed the entry. Personal identifying information about those involved is excluded. Incidents include threats and verbal abuse, not only physical assaults, and logs are retained for five years.
Can I use a template for my workplace violence prevention plan?
A template can inform structure, but the statute requires a plan specific to the site. A downloaded document with a company name inserted contains a hazard assessment describing a workplace that does not exist, which is the deficiency inspectors identify most readily.
What is the Cal/OSHA permanent standard and when does it take effect?
SB 553 required Cal/OSHA to propose a general industry workplace violence prevention standard, with adoption required no later than December 31, 2026. Drafts released so far expand on the statutory framework, particularly on hazard assessment, post incident response, and communication obligations. Every existing plan will need review against the final standard.
How much does a workplace violence prevention program cost?
Program development is scoped as a project and priced primarily off headcount and shift count, because the number of required training sessions is the dominant cost driver. Ongoing compliance is retained annually and banded to organizational size, covering the annual plan review, the training cycle, incident log oversight, and the transition to the permanent standard.
Source and authority
Shadow was founded by Michael de Geus, a former U.S. Secret Service Special Agent. He spent 12 years in federal service on the Presidential Protective Division, followed by 6 years in private sector global security, a career of nearly two decades. Shadow has secured more than 500 events across four continents with a zero incident record.
Every engagement begins with a confidential consultation.
Request protection