← All PostsMultidisciplinary behavioral threat assessment team reviewing a workplace case file
Workplace Violence

What Actually Happens in a Behavioral Threat Assessment

By Thomas W. Raftery III —
A former Inspector General, Raftery has extensive experience advising boards and audit committees, and is a member of the Association of Inspector Generals. He built Falcon's associate network from former federal, state, and local law enforcement officers and certified financial professionals.

A behavioral threat assessment evaluates whether a person is on a pathway to violence. It is not an HR investigation and does not determine policy violations or discipline. A trained multidisciplinary team gathers information, weighs warning behaviors against known risk factors, and builds a management plan. Most cases end in monitoring and support rather than removal.

Key Takeaways

Introduction

A behavioral threat assessment evaluates whether a person is on a pathway to violence. It is not an HR investigation and does not determine policy violations or discipline. A trained multidisciplinary team gathers information, weighs warning behaviors against known risk factors, and builds a management plan. Most cases end in monitoring and support rather than removal.


What is a behavioral threat assessment?

A behavioral threat assessment is a structured process for evaluating whether an individual poses a risk of committing targeted violence, and for managing that risk over time. It is behavior-based rather than profile-based. It does not attempt to identify a type of person. It examines what a specific individual is doing, saying, planning, and acquiring, and whether those behaviors indicate movement along a pathway toward an attack.

The discipline came out of protective intelligence work. The U.S. Secret Service National Threat Assessment Center was created in 1998 and formally authorized by Congress through the Presidential Threat Protection Act of 2000 to conduct research on threat assessment and targeted violence, provide training, facilitate information sharing, and consult on individual cases. The methods developed to protect federal officials were adapted for schools, and from schools into workplaces.

The core premise is that targeted violence is not spontaneous. It is preceded by observable behavior. The FBI's study of the pre-attack behaviors of active shooters found that in cases where it could be determined, 77 percent of the shooters studied spent a week or longer planning their attack, and 46 percent spent a week or longer preparing. Each displayed an average of 4.7 concerning behaviors that were observable to people around them.

That is the operating window. The question a threat assessment program answers is whether your organization can see into it.


Why a threat assessment is not an HR investigation

This is the distinction most organizations get wrong, and getting it wrong tends to produce the worst version of both processes.

An HR investigation is retrospective and adjudicative. It establishes what happened, whether policy was violated, and what discipline applies. It has a defined endpoint. It produces a finding.

A threat assessment is prospective and preventive. It asks where this person is heading. It has no endpoint until risk is judged to have abated, which may take months or years. It produces a management plan rather than a finding.

Running the second process inside the first is where organizations fail. An HR investigation concludes, discipline issues, the file closes, and the person who was assessed as concerning is now a terminated employee with an unmanaged grievance and no organizational visibility.


Making a threat versus posing a threat

Threat assessment professionals draw a distinction that sounds like wordplay and is not.

Many people who make threats never act on them. Many people who commit targeted violence never made a threat to their target. The FBI study found that among active shooters who had an identifiable target, 55 percent had made threats or had a prior confrontation with that target. Which means 45 percent did not. When threats or confrontations did occur, they were almost always in person, at 95 percent, and only infrequently in writing or electronically, at 14 percent.

The practical consequence is that an organization triaging solely on explicit threats will miss roughly half of the cases that matter, while spending its resources on angry statements that carry no intent.

What matters more than the threat is leakage. Leakage occurs when a person reveals clues to a third party about feelings, thoughts, fantasies, attitudes, or intentions signaling intent to commit a violent act. It includes indirect threats, subtle innuendo about a desire to commit an attack, and boasts about the ability to harm others. Leakage is usually directed at someone other than the target, which is precisely why coworkers, not managers, are most often the ones who hear it.

That has a design implication. If your reporting channel routes only to the subject's direct supervisor, you have built a system that misses the most reliable signal you are going to get.


What the research says about warning behaviors

A short list of findings from the FBI study, because these are the points most often misstated inside organizations:

Mental illness is not the predictor people assume. The FBI could verify that 25 percent of the active shooters studied had ever been diagnosed with a mental illness. Of those, only three had been diagnosed with a psychotic disorder. Treating diagnosis as the screening criterion produces both false positives and false negatives, and it exposes the organization to disability discrimination claims.

Stressors cluster before an attack. Shooters typically experienced multiple stressors in the year before the attack, averaging 3.6 separate stressors. Financial strain, relationship breakdown, job loss, and legal problems compound.

Grievance is frequently work-related. Where a primary grievance could be identified, 49 percent related to an adverse interpersonal or employment action against the shooter. That statistic should shape how organizations sequence terminations, investigations, and performance actions involving individuals already flagged as concerning.

Most were not isolated loners. The study found the loner stereotype largely inaccurate. There were people in relationship with these individuals who were positioned to observe and report concerning behavior. That is the premise the entire discipline rests on.

Targeting is common. In 64 percent of cases, at least one victim was specifically targeted.

One caveat, stated plainly because it affects how the findings should be used. The FBI study examined active shooters across all settings, not workplace incidents exclusively. The behavioral findings translate well to workplace threat assessment and are used that way throughout the field, but they are not a workplace-specific dataset and should not be cited as one.

Structured worksheet documenting warning behaviors during a workplace threat assessment

Who belongs on the team

A behavioral threat assessment team needs four functions represented. Fewer than four, and predictable failures follow.

Human resources brings employment history, performance record, prior complaints, and knowledge of pending actions that may serve as triggering events.

Legal manages privilege, documentation exposure, ADA and disability considerations, privacy constraints, and the interaction between assessment activity and any parallel disciplinary process.

Security handles access control, physical protective measures, coordination with law enforcement, and any protective detail requirement.

Behavioral health interprets the behavior. This is the function most commonly missing, and its absence is the reason so many teams default to either dismissal or overreaction. A licensed clinician who understands violence risk assessment reads a pattern of behavior differently than an HR generalist does, and the difference is usually the case.

Add operational leadership from the subject's business unit as a case-by-case participant, not a standing member.

Two structural rules matter. The team needs a standing charter, a named leader, defined authority to act, and a documentation protocol established before the first case, not during it. And the team needs to meet on a schedule even when there is no active case, because a team that has never worked a case together will not perform well on the one that counts.

Credentialing is worth attention when you staff the function. The Certified Threat Manager designation and formal training through NTAC or comparable programs distinguish practitioners who work this discipline from security generalists who have read about it.


How a case actually moves

The Secret Service's 2024 guide, Behavioral Threat Assessment Units: A Guide for State and Local Law Enforcement to Prevent Targeted Violence, sets out a six-step framework. It was written for law enforcement, and it maps cleanly onto a corporate program.

1. Establish the unit and the policy. Charter, authority, membership, and the policy that governs the process.

2. Create operational protocols and procedures. How a case opens, who decides, what gets documented, what triggers escalation, and how a case closes.

3. Identify and process reports of concerning behavior. Multiple intake channels, a named recipient, defined response times, and a triage standard. This is where most programs leak. A report that reaches no one is the same as a report that was never made.

4. Gather information to assess for risk. Interviews with reporters and witnesses, employment and performance records, prior incident history, publicly available information, and coordination with law enforcement where appropriate. The subject interview happens here or later, and the timing is a tactical judgment rather than a procedural default. Interviewing too early can escalate the situation and eliminate your information advantage.

5. Develop risk management strategies. This is the output. Not a score, not a label, a plan. Options span monitoring, workplace modifications, referral to employee assistance, supervised performance management, security measures, law enforcement notification, protective orders, and in a minority of cases, separation with a structured transition.

6. Promote continuous improvement and a culture of prevention. Case review, program audit, and the reporting culture that determines whether step three works at all.

Note what is absent from that list. There is no step where the team assigns a numerical dangerousness score and moves on. Threat assessment is a management process, not a prediction exercise, and any vendor selling you a violence prediction algorithm is selling something the research does not support.


When to bring in outside assessors

Internal teams handle most cases and should. Bring in outside expertise when:

The cost comparison is not the assessment fee against zero. It is the assessment fee against the incident, the OSHA General Duty Clause citation, the negligent retention claim, and the deposition in which someone reads your team's meeting minutes aloud.


Where active shooter response planning fits

Security and HR leaders reviewing facility plans during active shooter response planning

Threat assessment is prevention. Active shooter response planning is mitigation. They are separate capabilities and organizations regularly buy the second while skipping the first, because response training is easier to schedule and produces a visible deliverable.

Both are necessary. Response planning covers notification, evacuation and shelter decisions, law enforcement interface, reunification, and post-incident support. It assumes the prevention layer failed.

The programs should share governance and information. A response plan built without reference to the specific risk picture your threat assessment team maintains is a generic document, and generic documents perform poorly under stress.

For the regulatory obligations that sit underneath both functions in New Jersey and New York, see our companion article on workplace violence prevention requirements for NJ and NY employers.


Frequently asked questions

What is a behavioral threat assessment? A behavioral threat assessment is a structured process for evaluating whether an individual is moving along a pathway toward targeted violence, and for managing that risk over time. It is based on observed behavior rather than demographic or psychological profiles, and it produces a management plan rather than a finding of fact.

How is a threat assessment different from an HR investigation? An HR investigation looks backward to determine whether a policy was violated and what discipline applies. A threat assessment looks forward to determine whether a person poses a risk of violence and how to reduce it. The two often run in parallel on the same facts, but neither substitutes for the other.

Who should be on a workplace threat assessment team? At minimum, human resources, legal, security, and a behavioral health professional. Business unit leadership participates case by case. Teams missing the behavioral health function tend to either dismiss serious cases or overreact to benign ones.

Does making a threat mean someone will become violent? No. Many people who make threats never act, and a substantial share of those who commit targeted violence never threatened their target directly. FBI research found that among active shooters with an identifiable target, 55 percent had made threats or had a prior confrontation, meaning 45 percent had not.

What is leakage in threat assessment? Leakage is the communication to a third party of intent to harm someone. It includes indirect threats, innuendo about a desire to commit violence, and boasts about the capability to harm others. Because leakage is usually directed at someone other than the target, coworkers are often the first to hear it.

Should we fire an employee who has been assessed as a threat? Not automatically, and not as a substitute for management. Termination removes organizational visibility and can serve as a triggering event. FBI research found that where a primary grievance could be identified, 49 percent related to an adverse interpersonal or employment action. Separation is sometimes correct, but it is a decision the team makes with a transition plan attached, not a reflex.

Can you predict who will become violent? No, and any tool marketed as doing so should be treated skeptically. Threat assessment identifies and manages risk. It does not predict individual behavior. The measure of a successful program is that violence does not occur, not that a forecast proved accurate.


Where Falcon fits

Falcon's workplace violence investigations and training practice provides threat assessments, active shooter response planning, and workplace violence prevention training built for the organization rather than pulled from a template. Falcon Associates include former federal, state, and local law enforcement officers, Certified Protection Professionals, and Licensed Clinical Social Workers, which means the behavioral health function is staffed rather than assumed. Learn more about the team.

Where a matter escalates into litigation, Falcon associates are available for criminal and civil testimony. Our article on what makes a credible expert witness covers what counsel should look for. For organizations assessing personal security exposure at the executive level, our risk-based guide to executive protection addresses a related question.

Contact Falcon to discuss standing up a threat assessment capability or bringing in outside assessment on an active case.

About the author. Thomas W. Raftery III is the Founder and Managing Partner of The Falcon Consulting Group. A former Inspector General, Raftery has extensive experience advising boards and audit committees, and is a member of the Association of Inspector Generals. He built Falcon's associate network from former federal, state, and local law enforcement officers and certified financial professionals.