Behavioral Threat Assessment Management: The Missing Piece in Most SB 553 Compliance Plans

A conceptual graphic of interlocking puzzle pieces with icons for safety, documentation, behavioral risk assessment, data analysis, and alerts, surrounded by a hard hat, scales of justice, and office items on a dark desk

Most California employers we work with have a written Workplace Violence Prevention Plan by now. SB 553 made that a requirement in July 2024, and the deadline pressure got plans onto paper. What we see less often is a plan that actually works when something happens. That gap has a name: Behavioral Threat Assessment Management, or BTAM.

What BTAM actually is

BTAM is not a training class you complete once. It is an ongoing process for identifying people who show early warning signs, gathering facts about their behavior, and managing the situation before it turns into a crisis. It sits between having a policy and knowing what to do when someone actually reports a concern.

The discipline traces back to threat assessment work developed for protective and law enforcement settings, where the core insight was simple but counterintuitive: most people who commit targeted violence do not simply snap. They move along a pathway, often over weeks or months, and that pathway usually leaves observable signs along the way. BTAM exists to catch those signs early, evaluate them honestly, and intervene before the situation escalates. It is fundamentally a prevention discipline, not a response discipline. By the time an active threat is unfolding, BTAM has already done what it can do. Its value is entirely upstream.

A working BTAM program has three parts, working together: a reporting channel that employees actually use, a multidisciplinary team that reviews and investigates concerns, and a documented process for managing a case over time, not just closing it after one meeting.

Why the written plan alone doesn't cover it

SB 553 requires a plan, a training record, and an incident log. It does not require a functioning threat assessment team. We have reviewed plans that check every regulatory box and still leave the organization with no real answer to the question: an employee just told HR their coworker is scaring them, now what?

That question is where most workplace violence incidents actually start: not with a stranger walking through the door, but with an escalating situation involving someone the organization already knows. BTAM is built for exactly that scenario. A written plan can tell an employee who to call. It cannot tell the person who answers the phone how to evaluate what they are hearing, how urgently to act, or what happens after the first conversation. That is the part organizations tend to skip, because it requires building a capability rather than filling out a document.

What a working BTAM team needs

  • Members from HR, security or safety, legal, and, where available, a behavioral health resource. Each of these roles sees a different slice of the picture, and a team missing one of them tends to miss whatever that role would have caught.
  • A clear, low friction way for any employee to report a concern, not just their direct supervisor. A reporting path that only runs through one person's judgment will lose reports that person does not recognize as serious.
  • Defined criteria for what moves a report from noted to actively assessed. Without this, teams either treat every report as an emergency, which burns out the process, or treat nothing as urgent until it is too late.
  • A documented case management process that continues after the first meeting, since concerning behavior rarely resolves in one conversation. Most cases that turn out well involve multiple touchpoints over weeks, not a single intervention.

What a case actually looks like moving through the process

A typical BTAM case does not begin with a threat of violence. It begins with something smaller: a coworker mentions that someone has become withdrawn and made a comment that felt off, or a supervisor notices a pattern of escalating conflict that does not match the employee's usual behavior. The report reaches the team, and the first job is simply gathering facts, not forming conclusions. What has actually been observed, by whom, and over what period of time.

From there, the team assesses whether the behavior represents a genuine escalation or a one-time reaction to a stressful event, which is common and usually resolves on its own. If it looks like a pattern, the team decides on next steps: a supportive conversation, a referral to an employee assistance program, a change in supervision, or in more serious cases, a formal safety plan. The case stays open with a designated follow-up date, and someone checks back in. That follow-up step is the one most informal processes skip entirely, and it is often the one that matters most.

The mistake we see most often

Organizations treat BTAM as a training topic instead of a standing function. Staff sit through a one hour session on warning signs, and the organization considers the box checked. Six months later, nobody remembers who is on the threat assessment team, or whether it still meets.

A BTAM program has to survive turnover, budget cycles, and the fact that most years, thankfully, nothing happens. That means real ownership, a documented process, and a way for new team members to get up to speed without starting from zero. We recommend a standing calendar reminder, even when there are no active cases, so the team reviews its own readiness rather than waiting for a report to force the issue.

How this connects to SB 553 compliance, and why it goes beyond it

A functioning BTAM process does more than satisfy the spirit of SB 553. It changes what your incident log actually captures. An organization with no functioning threat assessment process tends to have an incident log full of completed events: the things that already happened. An organization with a working BTAM process has a log that also shows the things that were caught early and never became incidents at all. That second kind of log is harder to build, and it is the one that actually demonstrates prevention rather than paperwork.

Practically, this means tracking not just incidents that occurred, but concerns that were reported, assessed, and resolved without escalation. Recording the number of reports received, the average time to initial assessment, and the outcome category for each closed case gives you data you can actually use, both to demonstrate the program is functioning and to spot patterns, such as a particular department generating a disproportionate share of reports, that deserve closer attention.

Where scenario-based practice fits

Reading about BTAM is not the same as practicing it. The normal path for building a working threat assessment team is realistic tabletop scenario training, not tactical simulation. We walk a team through a case built to look like one they could actually get: what gets reported, what questions to ask, who needs to be in the room, when to escalate, and when to involve law enforcement. A team that has worked through a tabletop scenario together makes faster, calmer decisions than a team seeing its first real case cold.

If your organization has an SB 553 plan on paper but no functioning threat assessment process behind it, that is a gap worth closing before it gets tested for real. We offer a complimentary review of your current plan, focused specifically on the BTAM piece: where the gaps sit, and what it would take to close them. Reach out to schedule one.

This article covers general information about SB 553 and BTAM practices. It is not legal advice. Talk to counsel about compliance questions specific to your organization.