Psychosocial risk is usually introduced as a new topic that arrived with ISO 45003 in 2021. It is not. The binding duty to assess and control it has been in European law since 1989, in language that names the hazard precisely.
ISO 45003 is guidance on how to do the work. The obligation to do it came from somewhere else, and it is that distinction that decides where the standard belongs in your management system.
Where the psychosocial risk duty actually comes from

Directive 89/391/EEC, the Framework Directive, sets out the general principles of prevention every employer must apply. Two of them are about psychosocial risk without ever using the phrase.
Article 6(2)(d) requires adapting the work to the individual — the design of work places, the choice of work equipment and of working and production methods — with a view, in particular, to alleviating monotonous work and work at a predetermined work-rate and to reducing their effect on health.
Work pace and work design, named as health hazards, in 1989.
Article 6(2)(g) goes further, requiring a coherent overall prevention policy covering technology, organization of work, working conditions, social relationships and the influence of factors related to the working environment. “Organization of work” and “social relationships” are the psychosocial domain in four words.
And Article 6(3)(a) requires the employer to evaluate the risks to workers’ safety and health, adjusting preventive measures and working methods accordingly. There is no carve-out for hazards you cannot photograph.
What ISO 45003 is, and is not
ISO 45003:2021 is titled Occupational health and safety management — Psychological health and safety at work — Guidelines for managing psychosocial risks. First edition, published June 2021, 23 pages, maintained by ISO/TC 283. Its catalogue record now shows stage 90.20, under review.
Two consequences follow from the word “guidelines”.
You cannot certify to it. It contains no requirements to audit against. Any body offering “ISO 45003 certification” is offering something the standard does not support — the certifiable system is ISO 45001, and psychosocial risk is managed inside it.
It does not create the obligation. Which is liberating: you do not have to adopt ISO 45003 to be compliant, and adopting it does not by itself make you compliant. It is a method for work you already owe.
Psychosocial risk belongs in the hazard identification you already run
The most common implementation error is building a parallel process — a wellbeing survey, owned by HR, running on its own cycle, disconnected from the ISO 45001 risk assessment.
Psychosocial hazards are hazards. They belong in the same identification and assessment process as everything else, with the same controls, the same owners, the same review cycle and the same route into management review. Two registers means two truths, and the one the auditor reads will be the one that omits the finding.
What changes is the source of evidence. You cannot inspect workload the way you inspect a guard rail, so the inputs are different: absence and turnover patterns, working time data, exit interviews, grievance and incident records, workload and staffing metrics, and consultation with workers.
The clause that decides whether your controls are adequate
Article 6(2)(h) requires employers to give collective protective measures priority over individual protective measures.
Applied to psychosocial risk, that principle is uncomfortable and clarifying. Resilience training, counselling and an employee assistance programme are individual measures. Workload limits, staffing levels, shift design, role clarity, manager capability and how change is handled are collective ones.
A programme built entirely from the first category has inverted the hierarchy the Directive sets. It is also the pattern that shows up in enforcement and in litigation, because it treats the person as the thing to be adjusted rather than the work.
This is the same logic as the hierarchy of controls applied anywhere else: eliminate, then reduce at source, then protect the individual. The order is not a preference.
Consultation is not optional
The Framework Directive requires consultation and participation of workers on health and safety matters, and ISO 45001 carries the same duty for non-managerial workers.
For psychosocial risk it is more than a formality. The hazard is often invisible to the people designing the work and obvious to the people doing it. An assessment produced without worker input will identify the risks management already suspected, which is the one outcome that guarantees nothing changes.
How psychosocial risk connects
| Area | Connection |
|---|---|
| ISO 45001 risk assessment | Where psychosocial hazards belong, rather than in a parallel wellbeing process |
| ISO 45001 implementation | The certifiable system; ISO 45003 is guidance that sits inside it |
| ISO 45001 mandatory documents | The records a psychosocial assessment has to produce like any other |
| ISO 45001 certification | What an auditor can actually certify, since ISO 45003 offers no requirements |
Where to start
- Stop treating it as new. The duty predates the standard by three decades, which changes the internal conversation.
- Put psychosocial hazards in the existing register, not a separate one.
- Choose different evidence — working time, turnover, grievances, staffing — because inspection will not surface it.
- Audit your controls against 6(2)(h): count how many are collective and how many individual.
- Consult workers properly, since the hazard is usually invisible from above.
- Use ISO 45003 as method, not as a certificate, and watch its review at stage 90.20.
This guide reflects Directive 89/391/EEC as published on EUR-Lex and the ISO 45003:2021 catalogue record on iso.org, read at 16 August 2026. The Framework Directive is transposed nationally, and several Member States impose more specific psychosocial duties — check your national law.
The ISO 45001 Toolkit provides 50+ editable templates covering the hazard identification and risk assessment process, the consultation and participation records and the management review inputs a psychosocial risk programme has to produce.