Psychosocial Safety & WHS

ISO 45001 and psychosocial safety: where WHS systems meet workplace risk

ISO 45001 is a voluntary management-system standard, not a source of Australian legal duties. This briefing explains how psychosocial risk can be integrated into an existing OH&S system — obligations mapping, consultation, source controls, evidence and assurance — without building a parallel HR process.

By the AWS Editorial Team
WHS specialist reviewing management-system documentation with an operations leader

Key points

  • ISO 45001:2018 is a voluntary management-system standard; it does not replace enacted WHS or OHS law, an approved code or the organisation's own risk assessment.
  • Certification, or a clean audit, is not proof of legal compliance, and an uncertified employer can still use the disciplines the standard describes.
  • ISO 45003:2021 is guidance for managing psychosocial risk within an ISO 45001 system; it is not separately certifiable and creates no Australian legal duties.
  • Map obligations by jurisdiction first: Victoria's OHS Act 2004, Psychological Health Regulations 2025 and compliance code differ from model-WHS jurisdictions.
  • Controls must address the source and the design of the work; training, wellbeing and assistance programs do not control workload, low control, change or aggression.
  • Documents, completion rates and dashboards show activity — effectiveness is tested by whether controls are used and exposure has actually reduced.

What ISO 45001 can and cannot do

ISO 45001:2018, adopted in this country as AS/NZS ISO 45001:2018, is a voluntary requirements standard for an occupational health and safety management system. It sets out how an organisation establishes context and obligations, plans for risk, assigns resources and roles, operates controls, consults workers, monitors performance, audits itself and reviews the system at senior level. Used well, it gives psychosocial risk the same operating rhythm that physical risk has had for decades.

What it does not do is set the legal standard. ISO 45001 does not replace enacted work health and safety or occupational health and safety law, regulations, an approved code of practice, regulator guidance, consultation duties or the organisation's own risk assessment. It is a framework for organising work, not a source of duties. An employer that satisfies every clause of the standard may still be failing a statutory obligation, and an employer with no management-system documentation at all can still be discharging its duties.

The practical value of the standard for psychosocial risk is integration. Where psychosocial hazards are handled outside the safety system, they tend to be handled as people matters: raised as complaints, resolved individually, and never subjected to hazard identification, control design, monitoring or audit. Bringing them inside an existing ISO 45001-aligned system avoids building a second, weaker apparatus alongside the first.

ISO 45001, ISO 45003, certification and Australian law

Four things are routinely conflated, and separating them prevents most of the errors that follow. ISO 45001 is the certifiable requirements standard. ISO 45003:2021, adopted as AS/NZS ISO 45003:2021, is guidance on managing psychosocial risk within an ISO 45001-based system — it is not a separately certifiable requirements standard, and it does not create legal duties in Australia. Certification is an optional third-party attestation about the management system. Legal obligation is a fourth and separate thing, arising only from enacted law in the applicable jurisdiction.

Certification, or a clean surveillance audit, is therefore not proof of compliance with Australian work health and safety law. Audits sample; they assess conformity with the standard and the organisation's own documented arrangements, on the evidence available at the time. Equally, the absence of certification does not prevent an employer from adopting the disciplines the standard describes. Many organisations use the architecture without ever seeking a certificate, and are better assured for it.

For currency: as at 6 August 2026 ISO 45001:2018 remains the current edition, incorporating Amendment 1:2024 on climate action, with a revision under development. A draft standard is not operative, and system design should not be deferred while one is written. Standards Australia has published background on the joint adoption of AS/NZS ISO 45001 and of AS/NZS ISO 45003.

Map the jurisdiction before mapping the clauses

The obligations register comes first. Australian duties arise under the applicable Commonwealth, State or Territory statute and regulations. The Safe Work Australia model laws and the model Code of Practice on managing psychosocial hazards at work are drafting instruments; as Safe Work Australia itself explains in its material on codes of practice, they have no legal effect until adopted or approved in a jurisdiction. Multi-state employers need the register at jurisdiction level, not at national level.

In jurisdictions that have adopted the model framework, the duty is expressed in a particular way and should be recorded in those terms: eliminate psychosocial risks so far as is reasonably practicable and, where elimination is not reasonably practicable, minimise them so far as is reasonably practicable, having regard to the matters the enacted law requires to be weighed. Safe Work Australia's overview of psychosocial hazards is a useful orientation, but the operative text is the enacted regulation in the relevant State or Territory.

Victoria sits outside that framework and must be treated separately. The relevant instruments are the Occupational Health and Safety Act 2004 (Vic), the Occupational Health and Safety (Psychological Health) Regulations 2025 and the associated WorkSafe compliance code and guidance, which have operated since 1 December 2025. Victorian duties attach to employers in relation to employees; PCBU and worker terminology drawn from the model laws should not be imported into Victorian documents, risk registers or training. WorkSafe's material on psychological health and on how to use the compliance code is the starting point for Victorian operations.

Once the register exists, ISO clause architecture can organise the work — context, planning, support, operation, evaluation, improvement — provided it never overwrites jurisdiction-specific language. A Victorian record that describes an employer duty in model-WHS terms, or a Queensland record that omits the regulation's required steps because a clause heading did not prompt them, is a system artefact, not evidence of compliance.

A five-stage assurance matrix

The table maps five system stages to the question each must answer, the evidence that supports it, the test of whether it is working, and who is accountable when it is not. It is a planning aid for system design; it does not resolve any legal question and does not replace the applicable instrument or advice on the facts.

System stage or signalLegal and ISO questionEvidence requiredEffectiveness testEscalation and owner
Context and obligationsWhich enacted law, regulation and approved code apply in each jurisdiction of operation, and what does the system have to deliver?Jurisdiction-level obligations register, scope statement covering all worker categories and sites, currency date and review trigger.A sampled obligation can be traced to a named control, an owner and current evidence.System owner; unresolved gaps to the executive risk forum with a due date.
Hazard identificationHave psychosocial hazards, and their interactions, been identified from more than one source?Risk assessments, consultation records, incident and complaint themes, absence and turnover patterns, exit information, workload and rostering data.Hazards known to workers in a work area appear in the assessment for that area, in recognisable terms.Line manager with health and safety support; contested or organisation-wide hazards escalated.
Control design and consultationDo the controls address the source and the design of the work, and were affected people consulted before the decision?Control register with named owners, work-design changes, consultation records showing what was raised and how it affected the decision, implementation dates.The control is in use in practice, exposure has reduced, and no new risk has been introduced elsewhere.Accountable manager; unresolved or resourced-out controls escalated to the officer with the budget.
Monitoring and internal auditIs performance measured against something other than completion rates, and is the audit independent of the work audited?Leading and lagging indicators, audit plan and sampling basis, working papers, nonconformities raised, de-identification and access controls applied to sensitive data.Audit sampling reaches operating reality — worker interviews, records, observation — not only the document set.Audit function reporting to a level above the audited area; repeat findings escalated.
Management review and corrective actionAre exceptions, failures and trends reaching decision-makers, and are corrective actions closed on evidence?Corrective action register with root cause, owner and due date; verification records; management review minutes showing decisions and resourcing.Closed actions can be shown to have changed the exposure, and the same finding is not recurring.Executive and officer-level assurance; overdue or repeatedly reopened actions reported by exception.

Consultation and participation as operating controls

Consultation is a duty in its own right in most jurisdictions and a clause requirement in ISO 45001, but its practical function is diagnostic: it is the most reliable source of information about how work actually runs. Safe Work Australia's material on consultation sets out the general expectations in model jurisdictions; Victorian arrangements are governed by the Victorian Act.

Treating consultation as a survey exercise wastes it. A survey measures perception at a point in time and rarely explains cause. Useful consultation happens through existing structures — health and safety representatives and committees where they exist, team-level discussion, supervisor conversations, and direct engagement with affected groups — and it happens before decisions are settled, while the design of the work can still change. Consulting after implementation is communication.

Design for the people least likely to be reached: shift and night workers, remote and isolated workers, labour hire and contracted personnel, workers with limited English, and those in areas where the hazard is the manager. Be explicit about confidentiality and its limits, including where a safety risk, a notification duty or a serious allegation requires escalation. Promising absolute confidentiality and then breaking it does more damage than a candid limit stated at the outset.

The evidence that matters is not attendance. It is the record of what was raised, what was decided, what changed because of the input, and what was not adopted and why. That feedback loop is what keeps participation alive after the first cycle.

Control design: the source, the work, then the person

Psychosocial hazards should be identified from multiple sources and considered together rather than in isolation. The recognised categories include work demands, job control and autonomy, support from supervisors and colleagues, role clarity and conflict, poor organisational change management, organisational justice and recognition, remote or isolated work, exposure to traumatic events or material, violence and aggression, bullying, harassment including sexual harassment, and interpersonal conflict. No list should be treated as exhaustive in every jurisdiction; the enacted regulation in the relevant jurisdiction governs, and hazards frequently interact — high demand becomes materially more harmful where control is low and support is absent.

Control design then follows the ordinary discipline: address the source and the design of the work so far as is reasonably practicable, before moving to systems, supervision, training and individual support. Workload is controlled by resourcing, prioritisation, rostering and realistic deadlines. Low control is addressed by decision rights and scheduling flexibility. Poor change management is addressed by consultation, sequencing and manager capability. Violence and aggression are addressed by physical design, staffing levels, response procedures and post-incident support.

Employee assistance programs, wellbeing initiatives and resilience training have a legitimate place, but they operate after exposure and on the individual. They do not control workload, low job control, defective change management, aggression, harassment or a broken system of work, and presenting them as the primary control for those hazards is one of the clearest weaknesses an auditor or regulator will identify. Our guidance on practical steps for managing psychosocial hazards and on what employers should be reviewing now covers the control set in more detail.

Prevention, complaints, investigation and support are related but distinct

A management system has to hold four processes at once without collapsing them into each other. Preventive risk management asks what in the design of the work could cause harm and what will control it. Complaint handling responds to a concern raised by an individual. Investigation determines disputed facts about conduct. Injury management and support respond to a person who has been harmed.

The connections are real and should be built deliberately. De-identified complaint themes, incident reports, workers compensation claims and return-to-work information are legitimate inputs to hazard identification, and an investigation may expose a systemic cause that requires a control change. But the processes answer different questions and should not substitute for one another. A finding that an allegation was not substantiated says nothing about whether the underlying work design is safe, and a risk assessment identifying a hazard is not a finding of misconduct against any individual.

Keeping them distinct protects the integrity of both. Investigations conducted as risk assessments produce unfair outcomes for individuals; risk assessments conducted as investigations produce a register full of unresolved personal disputes and no work-design controls.

Evidence architecture and privacy

ISO 45001 distinguishes documented information from operating evidence, and psychosocial work exposes the difference sharply. The documented layer includes the obligations register, the risk assessment methodology, the hazard and risk register with control owners, consultation arrangements, competency requirements and the audit programme. The operating layer is what shows the system actually ran: dated consultation records, implementation evidence for each control, indicator data, audit working papers, nonconformity and corrective action records, verification of effectiveness and management review minutes recording decisions.

Psychosocial evidence carries privacy exposure that physical safety evidence often does not. Personal information should be de-identified before it enters trend reporting, and small-cohort risk taken seriously: results reported for a team of six, or a single-role category, can identify individuals regardless of the label on the report. Set minimum reporting thresholds, aggregate carefully, and resist the temptation to drill into a concerning result until the privacy consequence has been considered.

Health information and other sensitive information warrant restricted access and separate storage from general management-system records, with access limited to those who need it for a defined purpose. Employers should also understand the limits of the federal employee-records exemption: it is narrow, applies only to certain private-sector employers and only to records directly related to a current or former employment relationship, and does not displace State and Territory privacy or health-records law, surveillance law, workers compensation obligations or confidentiality duties. Where evidence is held in a governance platform, the same controls apply, as discussed in our note on how GRC technology supports workplace risk.

Indicators, internal audit and testing effectiveness

Completion rates, policy currency and dashboard colour describe activity. They do not establish that a control works. A useful indicator set pairs leading measures — consultation actually held before decisions, workload changes implemented, manager capability assessed, control actions closed within time — with lagging measures such as incident and complaint themes, absence and turnover in affected areas, claim patterns and repeat findings. Neither set is meaningful alone.

Effectiveness testing asks three questions of any control: is it implemented as designed, is it being used in practice, and has exposure to the hazard reduced without creating a new risk somewhere else. A workload control that shifts pressure onto a smaller team has not worked. A rostering change that reduces fatigue but increases isolated work has traded one hazard for another. Testing therefore needs contact with the work: interviews, observation, sampling of records, and comparison of what the register says with what people describe.

Internal audit adds independence proportionate to the organisation. Auditors should not audit their own work where that is practicable; in smaller organisations, independence can be approximated by having a different function, a peer site or an external reviewer conduct the audit and by having findings reviewed above the level of the area audited. Auditors handling psychosocial material need competence in the subject and clear protocols for sensitive information — what is recorded in working papers, what is de-identified, what is reported and to whom. Findings need owners, due dates and closure supported by evidence rather than assertion.

Nonconformity, corrective action and management review

The improvement cycle is where most systems quietly fail. A nonconformity should record what was found, why it happened, what will change, who owns it and by when, and how effectiveness will be verified. Corrective action addressed only to the immediate instance — retraining one manager, reissuing one policy — usually leaves the cause in place, which is why the same finding reappears in the next audit.

Verification is a separate step from closure. Closing an action on the basis that the task was completed says nothing about whether the exposure changed. Verification returns to the control some months later and tests it in operation.

Management review, and officer or senior-leader assurance more broadly, should receive material that supports a decision: exceptions, overdue actions, repeated findings, control failures, resourcing constraints, exposure trends by area, and the decisions required. Reporting that consists of green indicators and completion percentages does not enable anyone to exercise judgement, and it does not evidence the acquisition of knowledge and the taking of reasonable steps that officer duties in model jurisdictions contemplate. Structuring that reporting is the same discipline described in our guidance on a compliance framework that is monitored and evidenced.

Certification readiness sits underneath all of this, not above it. Preparing for an external audit is a legitimate exercise, but a system optimised for the certificate — documents tidied, dashboards greened, evidence assembled for the sample — has not been optimised for legal obligation or for the safety of the people doing the work.

Two worked examples

Example A — a workload hazard answered with training. A professional services team records rising overtime, two resignations citing pressure and a spike in short-notice absence during a systems transition. The initial response is a resilience workshop and a reminder about the employee assistance program. The next internal audit tests the control against the hazard and raises a nonconformity: the assessment identified high work demands, low control over scheduling and poor change consultation, but no control addressed the source. The organisation reworks it — the transition timeline is resequenced, two deliverables are deferred, contract support is funded for the peak, team members are given control over their own scheduling within agreed service levels, and the affected group is consulted on the plan before it is settled, with the record showing which suggestions changed it. Overtime and absence are monitored for two quarters and a follow-up review confirms exposure has fallen without displacing pressure onto an adjacent team. The workshop and the assistance program remain, correctly positioned as support rather than as the control.

Example B — certified, green, and still failing. A certified manufacturer reports full training completion, current policies and no open safety actions. Beneath that, one shift has repeated bullying complaints, absence well above the site average, and two consecutive surveillance audits with minor findings about consultation records in the same area. Management review has received only the summary dashboard. On deeper assurance — interviews with workers on that shift, sampling of consultation records, and review of de-identified complaint themes alongside absence and turnover data — the cause becomes visible: a supervisor selection and capability gap, unclear role boundaries after a restructure, and a consultation process running after decisions rather than before. The corrective action addresses the design: role clarity is rebuilt, supervisor capability is assessed and supported, consultation is moved ahead of decisions, and an interim escalation path is provided for the affected team. Effectiveness is verified six months later against complaint themes, absence and worker feedback, and the exception reporting to management review is redesigned so repeated findings surface without waiting for an audit cycle.

Where AWS assists, and when legal advice is required

An ISO 45001-aligned system is a way of organising obligations, controls, evidence and review so that psychosocial risk is managed with the same discipline as any other safety risk. It is not a substitute for the enacted law of the jurisdiction, for the organisation's own risk assessment, or for judgement about the work as it is actually performed.

AWS assists employers with management-system design and gap analysis, integrating psychosocial risk into an existing ISO 45001-aligned framework, consultation design, control and evidence architecture, internal audit and assurance, manager and officer capability building, and workflow and evidence support through Strobe. That work is delivered through psychosocial risk services, governance, risk and compliance and workplace advisory engagements.

AWS is a workplace consultancy and does not provide legal advice, and no platform replaces accountable governance. Where a duty is contested, a notice or claim is live, an incident is notifiable, or the application of a jurisdiction's law to particular facts is unclear, obtain jurisdiction-specific legal advice before acting.

A 12-step ISO-aligned psychosocial assurance cycle

  • Build a jurisdiction-level obligations register from enacted law, regulations and any approved code, treating Victoria separately from model-WHS jurisdictions.
  • Define system scope: sites, worker categories, labour hire and contractors, remote and isolated work, and the interfaces with other duty holders.
  • Identify psychosocial hazards from multiple sources — consultation, incident and complaint themes, workload and rostering data, absence, turnover and exit information — and record how they interact.
  • Assess risk using a documented method that considers duration, frequency, severity and the combination of hazards, not a single severity score.
  • Consult affected workers, and health and safety representatives where they exist, before decisions are settled, and record what was raised and what changed as a result.
  • Design controls that address the source and the design of the work first, positioning training, support and assistance programs as complements rather than primary controls.
  • Assign each control a named owner, an implementation date and a verification method, and record resourcing decisions where a control is deferred.
  • Set leading and lagging indicators for each significant hazard, and define what a deteriorating trend will trigger.
  • Apply privacy controls before reporting: de-identification, minimum cohort thresholds, restricted access for health and sensitive information, and defined retention.
  • Audit against operating reality, not the document set, with independence proportionate to the organisation and clear protocols for sensitive material.
  • Record nonconformities with root cause, owner and due date; verify effectiveness in operation before closing, and treat recurrence as a system finding.
  • Report exceptions, overdue actions, repeated findings and exposure trends to management review and officer-level assurance, and record the decisions and resourcing that follow.

Frequently asked questions

Does ISO 45001 certification prove compliance with Australian WHS or OHS law?
No. ISO 45001 is a voluntary management-system standard, and certification is a third-party attestation that a sampled management system conforms with the standard and the organisation's own documented arrangements. Legal obligations arise only under the enacted Commonwealth, State or Territory law that applies to the organisation, and compliance is assessed against that law and the facts. A certificate or a clean audit may be useful evidence that a system exists and operates, but it does not establish that a duty has been discharged.
Is ISO 45003 separately certifiable?
No. ISO 45003:2021, adopted as AS/NZS ISO 45003:2021, is a guidance document on managing psychosocial risk within an ISO 45001-based occupational health and safety management system. It is not a requirements standard, so there is nothing to certify against, and it does not create legal duties in Australia. Organisations use it to inform hazard identification, control design and evaluation, while the legal standard remains the applicable enacted law and any approved code.
Must an organisation be certified to use the framework?
No. The value of the architecture — obligations register, hazard identification, control ownership, consultation, monitoring, internal audit, corrective action and management review — is available whether or not an organisation seeks a certificate. Many employers adopt the disciplines to strengthen assurance and never certify, or certify later. Certification decisions are usually driven by client, tender or contractual requirements rather than by safety outcomes.
Can psychosocial hazards be managed inside the existing ISO 45001 system?
Yes, and that is usually preferable to building a parallel process. Psychosocial hazards can be brought into the existing context and obligations analysis, risk register, control register, consultation arrangements, indicator set, audit programme and management review. The system needs adjustment rather than duplication: hazard identification draws on different sources, controls focus on work design, and evidence carries greater privacy sensitivity. What should not happen is that clause headings replace jurisdiction-specific legal language in the register or the records.
What evidence shows a psychosocial control is effective?
Three things together. First, evidence that the control was implemented as designed, with a named owner and an implementation date. Second, evidence that it is being used in practice — from interviews, observation and record sampling, not completion statistics. Third, evidence that exposure to the hazard has reduced without creating a new risk elsewhere, tested against indicators such as workload and rostering data, complaint and incident themes, absence and turnover in the affected area, and worker feedback over time.
Are employee assistance programs, wellbeing initiatives and resilience training sufficient controls?
Not for hazards that arise from the design or management of work. They act on the individual and generally after exposure has occurred, so they cannot control excessive demands, low job control, poor change management, role conflict, violence and aggression, harassment or a defective system of work. They remain valuable as support and as part of a broader response, but where they are recorded as the primary control for a work-design hazard, the risk assessment has not addressed the source.
How should internal audit handle psychosocial risks and sensitive data?
Auditors should be competent in the subject matter and, so far as practicable, should not audit their own work; smaller organisations can approximate independence using a different function, a peer site or an external reviewer, with findings reviewed above the level of the area audited. Sampling should reach operating reality rather than the document set. Sensitive material needs protocols set in advance: what goes into working papers, how information is de-identified, minimum cohort sizes for reporting, restricted access to health information, and what is escalated where a serious risk is disclosed.
How do Victorian obligations differ from model-WHS jurisdictions?
Victoria has not adopted the model work health and safety laws. Victorian duties arise under the Occupational Health and Safety Act 2004 (Vic), with the Occupational Health and Safety (Psychological Health) Regulations 2025 and the associated WorkSafe compliance code and guidance operating since 1 December 2025. The framework is expressed in terms of employers and employees rather than PCBUs and workers, and the specific identification, control and review requirements differ from those in model jurisdictions. Multi-state employers should keep Victorian obligations, terminology and records distinct rather than applying a single national template.

Discuss this matter with AWS

Briefings can be scoped on a confidential basis. We respond within two business days.

Contact AWS