Skip to Content

Vicarious Liability Is the Silent Risk in Advisory Work

In risk, security, safety and resilience consulting, harm rarely stops at the adviser, it pulls the client into the same liability exposure.
22 July 2026 by
Tony Ridley
Quick answer: In risk, security, safety and resilience consulting, harm rarely stops at the adviser. Vicarious liability means client exposure can follow an adviser's conduct without fault on the client's part, something most consultants and their clients underestimate.

Originally published on LinkedIn: 31 January 2026.

Vicarious liability is a form of strict liability. One party, typically an employer or principal, is held legally liable for the wrongful act of another with whom it has a qualifying relationship, committed in the course of that relationship. It does not depend on the organisation's own fault, though a separate finding of direct negligence can attach alongside it. The test used across common-law jurisdictions generally asks whether a qualifying relationship exists, usually employment or an analogous arrangement, and whether the wrongful act is sufficiently closely connected to that relationship to be considered in the course of it. UK case law has narrowed liability for genuinely independent contractors in recent years, but the boundary has not disappeared, and in advisory work it is frequently tested. Advice in risk, security, safety and resilience consulting is never abstract. It shapes controls and safeguards, emergency and crisis responses, security postures, life-safety decisions and regulatory compliance. When harm occurs, the operative legal question becomes who gave the advice, who relied on it, and who had the power to prevent it, a question that routinely draws the consultant and the client into the same exposure together. This is general risk management commentary, not legal advice, and organisations should seek jurisdiction-specific legal counsel before relying on it.

How the exposure attaches in consulting relationships

Three patterns recur. A consultant formally labelled an independent contractor can still trigger vicarious liability exposure for the client through de facto agency, where they are embedded in governance or incident management structures, exercise genuine decision-shaping authority, are held out as the expert voice, or draft policies the client adopts wholesale without independent review. Consulting drift is equally persistent: generalist consultants give specialist security advice, auditors advise on safety engineering, cyber consultants opine on physical security, and travel or resilience advisers make medical or evacuation judgements outside their training. Where advice sits outside demonstrable competence, courts focus on the adviser's actual qualifications and peer-recognised credentials, not their confidence or general reputation. Exposure escalates sharply in life-safety and high-consequence domains, workplace health and safety, security design, emergency management, enterprise risk, critical infrastructure and cyber risk with downstream physical consequences, where courts are markedly less tolerant of a reasonable-opinion defence once injury or systemic failure has occurred. Liability findings do not require bad faith. Errors, omissions or misplaced confidence are sufficient on their own, and disclaimers offer weak protection if the adviser knew the client would rely on the advice or was presented as expert in the relevant domain. Outsourcing does not insulate a client either. Courts expect genuine due diligence on qualifications specific to the domain in question, and paying for advice does not transfer responsibility for it.

ISO 31000 and the controls that actually hold

Courts increasingly treat ISO 31000:2018 as evidence of reasonable practice. Under Clause 5, risk ownership sits with organisational leadership and cannot be fully delegated away; where an organisation treats consultant advice as a decision substitute rather than governing it, courts are likely to read this as retained control, leaving vicarious liability with the organisation regardless. Under Clause 6.2, an unbounded advisory scope makes it easier to argue reliance occurred and harder to show informed consent was genuinely given. Under Clause 6.4, treatment decisions remain with the organisation, and a consultant who recommends a control without presenting alternatives may be found negligent while the client remains vicariously liable for adopting the advice regardless. Under Clauses 6.5 and 6.6, documented assumptions and traceable decisions function as a practical shield in litigation, because courts rely heavily on contemporaneous records. For consultants, the practical response is to define and hold to scope rigorously, document qualifications and the limits of competence, and keep contemporaneous records of advice given. For clients, it is to vet credentials specifically rather than on general reputation, match qualifications to each distinct advisory domain, and maintain genuine internal challenge of advice received.

Vicarious liability is a silent amplifier of risk across risk, safety, security and resilience advisory work. Clients cannot outsource accountability by paying for advice, and consultants cannot improvise competence outside their genuine expertise.

Tony Ridley provides risk, security and resilience advisory with clearly documented scope, competence and governance, structured to withstand scrutiny. Contact us to discuss your requirements.

Same Numbers, Different Decisions: Why Your Board's Risk Numeracy Determines What Your Risk Data Actually Means
Identical risk figures produce different board decisions depending on the numeracy of the people reading them, which means risk communication is not a formatting choice but a governance control.