We have applied the Outlook exclusion, and no crashes.
We have many clients and this only affects one, they work in Insurance and run Act! and Acturis. They are our only client running those, anyone else using either? They both have plugins to Outlook but as the crashes happen in safemode I had discounted 3rd party addins.
None of my clients use those applications. I think it is just something with the Sophos Mitigation component messing with Outlook.
As a next level test I have enabled Exploit Mitigation but turned off all the sub-components for Mitigation on Microsoft Outlook. So far there have been no crashes. So it looks like it is one of these sub-components causing the crash.