TREADSTONE LAW · ONTARIO · DIGITAL LEGAL SERVICES · EST. MMXXI ·TSL
Home/Case Studies/Corporate
№ 290 Case Study — Corporate

A threatening customer, a compliance deadline, and a startup with no policy in place

A small Waterloo startup had days left to complete a workplace violence risk assessment after a customer threatened an employee, and no policy on file to build it from.

Corporate9 min readWaterloo, OntarioViolence and harassment policies
All Corporate case studies
ClientHaruto, co-founder of a growing startup where Sampath was threatened by a customer
The issueA threatening customer incident triggered a mandatory risk assessment deadline the company had no policy or process in place to meet
ServiceBuilt a compliant workplace violence and harassment policy and risk assessment on a fixed timeline and budget
ResolutionLoss contained: the company met its deadline and avoided an order, but the incident exposed months of compliance gaps that could not be undone retroactively

The situation

The deadline was eight days out when Haruto first called. An inspector had visited the company's small Waterloo office after a customer had threatened Sampath, one of the team's support staff, during an in-person meeting that turned hostile over a billing dispute. The inspector's order was specific: the company needed a completed risk assessment addressing the incident and a documented workplace violence and harassment policy on file within a set number of days, or the file would escalate.

Haruto and his co-founder Takeshi, who had spent years before that working as a transit operator, ran a growing startup, still small, generating somewhere between two hundred and fifty thousand and a million dollars a year, that had scaled from a two-person operation to a team of a dozen or so in under two years. Like a lot of companies that grow that fast, the formal policy documents that were supposed to exist alongside a workforce that size had not kept pace. There was no written workplace violence and harassment policy, no documented process for how the company would respond to an incident like the one with Sampath, and no risk assessment on file at all.

Sampath had joined the company a year earlier after years of doing landscaping work, glad for the steady desk job, and had not expected the client-facing side of the role to involve anything close to a physical threat. The customer had raised his voice, moved toward Sampath's desk, and made a comment that Sampath and two coworkers, including Takeshi, understood as a threat of physical harm before he was asked to leave. Nobody was hurt, but the incident was serious enough that it had to be reported, and reporting it exposed how far behind the company's policies actually were. An incident like this also has to be reported to the workplace's joint health and safety committee or health and safety representative, not just handled internally, and the startup had neither one in place, which was its own gap sitting on top of the missing written policy.

What worried Haruto most, when he called, was not really the legal exposure in the abstract. It was the uncertainty. He wanted to know exactly what the deadline required, exactly what it would cost to get there, and exactly how much time it would actually take, because the company was already stretched thin and an open-ended legal process was its own kind of risk to a business this size.

The complication

The complication was that a proper risk assessment is not a form you fill out in an afternoon. Done correctly, it requires looking at the actual physical layout of the workplace, how client meetings are conducted, what warning signs staff are trained to recognize, and what response options exist if a situation escalates again. None of that existed as a starting point, and building it from nothing inside an eight-day window meant compressing work that would normally happen over weeks.

There was a definitional wrinkle underneath all of it. Ontario's Occupational Health and Safety Act treats workplace violence and workplace harassment as separate categories, each carrying its own policy and program obligations, and a customer's threat of physical force against Sampath was squarely workplace violence. But the two categories are not mutually exclusive — the same incident can also amount to harassment, and the safer course was to treat both sets of obligations as engaged rather than close the file under one while leaving the other unaddressed. That mattered because the risk assessment had to be built around the specific duty to assess and control the risk of violence, not folded into a generic conduct policy that blurred the two together. Employers with more than five regular employees are also required to keep these policies in writing, a threshold the startup's headcount was well past, so an informal, verbal understanding among the founders was never going to satisfy the obligation even before the incident forced the issue.

There was another complication layered on top. Because Sampath had been the one directly threatened, any policy the company produced needed to genuinely reflect what had happened to him, not a generic template copied from somewhere else. A risk assessment that did not specifically address the circumstances of this incident, the layout of the space where it occurred, and the specific hazard it revealed, ran a real risk of being rejected as inadequate on review, which would have restarted the clock under worse circumstances.

Cost was a further complication, and it was the one Haruto raised most directly. The company did not have a large compliance budget, and Haruto was candid that an open-ended engagement with an unclear final bill was, for a company this size, almost as stressful as the underlying deadline. He needed to know upfront roughly what the work would cost and how long it would take, not because the legal risk did not matter, but because unpredictable cost and unpredictable timing were themselves business risks he could not absorb on top of everything else.

Underneath both of those was a harder truth Haruto had to accept: even a well-built policy completed within the deadline could not erase the fact that the company had operated for a year with client-facing staff and no violence and harassment policy in place at all. Whatever we built forward, the gap in the months before the incident was already part of the record.

What we did

  1. Gave Haruto a fixed scope and estimate on day one. Because predictability mattered as much to him as the outcome, we scoped the engagement into two clear phases, the immediate risk assessment and policy needed to meet the deadline, and a lighter follow-up phase for staff training, with a defined estimate for each so Haruto could plan around real numbers instead of an open-ended bill, and so he could tell his co-founder exactly what the process would cost before agreeing to it.
  2. Walked the physical space with Haruto and Takeshi. We reviewed exactly where client meetings happened, how the front desk was positioned relative to exits, and what, if anything, staff could do in the moment if a meeting turned hostile again, because a risk assessment needs to describe the actual environment, not a hypothetical one, and the office layout turned out to have a genuine blind spot near the meeting area that nobody had flagged before.
  3. Interviewed Sampath and the coworkers who witnessed the incident. Getting a precise account of what was said, how the threat escalated, and what response staff attempted in the moment let us build a risk assessment that addressed this specific incident directly, which mattered both for the deadline and for making the document genuinely useful if something similar happened again, rather than a generic narrative that could apply to any workplace.
  4. Drafted a workplace violence and harassment policy tailored to the company's size. Rather than adapting a large-employer template, we built a policy scaled to a team of a dozen, with a realistic reporting chain given that Haruto and Takeshi were still hands-on in day-to-day operations, so the policy described a process the company could actually follow rather than one built for a much larger organization with a dedicated human resources department.
  5. Set out concrete response protocols for future incidents. The risk assessment included specific steps staff should take if a client meeting became hostile again, who to call, how to safely disengage, how to document the incident immediately afterward, and who was responsible for notifying the health and safety representative, so the document functioned as a usable reference rather than a filing exercise nobody would open again.
  6. Repositioned the meeting area to remove the blind spot we identified. Beyond the paperwork, we recommended a low-cost physical change, moving the client meeting table closer to the main floor and within sight of other staff, which addressed part of the underlying hazard directly, at minimal cost to the company, rather than relying on policy alone to manage a risk the layout itself had created.
  7. Submitted the completed documents ahead of the deadline. We finished the risk assessment and policy two days before the compliance date, giving Haruto a buffer to review everything with Takeshi and the team before it went to the inspector, and to fix anything that still read as boilerplate, rather than filing at the last possible moment with no room for last-minute questions.
  8. Flagged the pre-incident gap honestly rather than glossing over it. We advised Haruto that the completed policy addressed the company's obligations going forward but did not retroactively fix the period before the incident when no policy existed, and that this history could still factor into how the file was viewed, which was a hard but necessary thing for him to hear clearly before the inspector's review concluded.

The outcome

The company met its deadline, the inspector accepted the risk assessment and policy without requiring revisions, and the file closed without an order or penalty. Sampath returned to his role with a documented process now in place if a client situation escalated again, which he told Haruto directly made him feel considerably safer coming to work, and the repositioned meeting area removed the specific blind spot that had made the original incident harder for coworkers to notice as it developed.

The cost and timeline held close to what we had estimated at the outset, which mattered to Haruto as much as the legal result did. He said afterward that knowing roughly what the process would cost and take, even while the deadline pressure was real, made the eight days manageable in a way an open-ended engagement would not have been for a company at their stage, and it let him communicate clearly with Takeshi and the rest of the team about what was happening and why, instead of the situation feeling like an open-ended crisis.

The company did not come away entirely clean. The months of operating without any workplace violence and harassment policy in place, despite growing well past the size where that gap is easy to overlook, remained part of the record and part of what the inspector's visit had exposed. Nothing about the completed policy erased that history, and Haruto was clear-eyed that a different, less cooperative inspector might have pushed harder on that earlier gap than this one did.

What the process did produce was durable. It stopped the situation from getting worse, gave Sampath and the rest of the team an actual process to rely on rather than an informal sense that management would figure it out if something happened again, and gave Haruto a template he now reviews and updates as the company continues to grow, rather than something he discovers is missing the next time a client situation goes wrong. For a founder whose biggest worry going in was unpredictability, that repeatable process turned out to be worth as much as the closed file itself.

What you can learn from this

  • A workplace violence and harassment policy is not optional once you have client-facing staff, regardless of company size; build it before growth outpaces your paperwork, not after an incident forces the issue.
  • A risk assessment produced under deadline pressure still needs to reflect the actual incident and actual workplace, not a generic template, or it risks being rejected on review.
  • If cost predictability matters to your business, ask for a scoped estimate upfront; a fixed-scope engagement is often available even under a compliance deadline.
  • Completing required documentation on time limits ongoing exposure but does not erase a pre-existing compliance gap; be honest with yourself about what forward-looking fixes can and cannot resolve.
  • A usable safety policy includes concrete response steps staff can follow in the moment, not just a filing that satisfies a regulator; build it as a tool your team will actually use.
This case study is entirely fictional. It does not describe any real client, file, or matter handled by Treadstone Law, and it is not a real file with details changed. All names, people, properties, businesses, dollar amounts, dates, and events are invented, and any resemblance to a real person, business, or situation is coincidental. Fictional scenarios like this one illustrate the kinds of legal issues people in Ontario commonly face and how a lawyer can help. They are general information, not legal advice — no two matters unfold the same way, and nothing here predicts the outcome of any real case. Reading a case study does not create a lawyer-client relationship. If you are facing something similar, speak with a lawyer about your specific circumstances.

This is a corporate problem we handle

Start a file online — flat, published fees, reviewed by a licensed lawyer before a dollar is owed.

ContactStart a File →