Professional & Financial Services

Set up and run a safe management consultancy

Management consultancies and head offices face typical office-based risks — display-screen equipment, workstation assessment, stress and mental health. On top of those workplace duties, if you market by email, text or automated calls, the PECR electronic-marketing rules bite. This is the universal spine: it takes you through your core workplace health and safety duties, fire safety, employers' liability insurance, equality, data protection and PECR.

UK-wide
On this page
UK-wide

Management consultancy, business advisory and head-office work is office-based with relatively low physical risk, but your duties as an employer still run deep. Display-screen equipment assessments, workstation set-up, stress and mental health, and lone or home working all need managing. Get this spine in place first, then confirm everything with the compliance checklist.

Health and safety law here is largely reserved. The Health and Safety Executive (HSE) is the regulator in Great Britain and the Health and Safety Executive for Northern Ireland (HSENI) in Northern Ireland; the underlying duties are equivalent across the UK. Work through the sections below in order.

A. Meet your general health and safety duty

The Health and Safety at Work etc. Act 1974 is the foundation. You must ensure, so far as is reasonably practicable, the health, safety and welfare of your employees and of anyone else affected by your work. In an office environment that means risk-assessing display-screen equipment use, workstation ergonomics, stress and mental health, lone working and any client-site visits, and providing information, instruction, training and supervision.

B. Manage fire safety

Even in an office, the responsible person must carry out a fire risk assessment and maintain fire-safety arrangements. The duty is devolved: the Regulatory Reform (Fire Safety) Order 2005 in England and Wales; the Fire (Scotland) Act 2005 and Fire Safety (Scotland) Regulations 2006 in Scotland; and the Fire and Rescue Services (Northern Ireland) Order 2006 in Northern Ireland.

C. Hold employers' liability insurance

As soon as you employ anyone, you must hold employers' liability compulsory insurance — normally at least £5 million of cover — and display or make available the certificate. This is a legal requirement across Great Britain, with an equivalent duty in Northern Ireland.

D. Meet your equality duties

As an employer you must not discriminate against, harass or victimise people because of a protected characteristic. In Great Britain this is governed by the Equality Act 2010; in Northern Ireland separate equality legislation applies, enforced by the Equality Commission for Northern Ireland.

E. Handle personal data lawfully

Consultancies routinely process personal data — about staff, clients and their people, and prospective clients. You must comply with the UK GDPR and the Data Protection Act 2018, and in most cases pay the data protection fee to the Information Commissioner's Office (ICO). This applies UK-wide.

F. Follow the PECR electronic-marketing rules

If you market your consultancy services by email, text message or automated telephone calls, the Privacy and Electronic Communications Regulations 2003 (PECR) set specific consent and screening duties on top of the UK GDPR. You need prior consent for most electronic marketing to individuals (with a limited soft opt-in exception for existing clients), you must screen telephone call lists against the TPS and CTPS registers at least every 28 days, and automated calls always require prior consent. The ICO enforces PECR UK-wide, with fines now aligned with UK GDPR levels.

  1. 1

    1. Write your health and safety risk assessments

    Assess display-screen equipment use, workstation ergonomics, stress and mental health, lone working and client-site visits under HASAWA 1974.

  2. 2

    2. Carry out your fire risk assessment

    Assess fire risk for your office premises under the fire-safety regime for your nation.

  3. 3

    3. Take out employers' liability insurance and register with the ICO

    Arrange at least £5 million of cover before anyone starts work, and pay the data protection fee unless you are exempt.

  4. 4

    4. Put your PECR compliance in place if you market electronically

    Get consent mechanisms, unsubscribe processes and TPS/CTPS screening in place before any email, text or automated-call marketing.

What to do next

This spine covers the duties every management consultancy and head office shares. Confirm you have covered everything with the management consultancy compliance checklist.

Official sources

Authoritative health and safety, data-protection and marketing guidance.