A hazard identification that finds only physical hazards is not incomplete by accident: it has looked at half the work. Workload, pace, role ambiguity, relationships and third-party violence cause harm to health, and that harm belongs to occupational health and safety just as much as a fall from height does.
In 2021 ISO published a document that addresses precisely this subject, and its nature is widely misunderstood. It cannot be certified against, which leads many organizations to file it away unread, and many auditors to use it as though it could. The two mistakes are symmetrical and cost the same.
What ISO 45001 requires, and what it leaves open
ISO 45001 requires the organization to establish, implement and maintain processes for the proactive identification of hazards. Nowhere does it restrict that requirement to physical hazards, and its very definition of occupational health and safety covers health, not safety alone.
What it does not provide is the method. A physical hazard can be seen, measured, photographed. A psychosocial hazard is inferred from an organization, a roster, a reporting line, a volume of customer complaints. It does not show up on a site walk, and it does not appear in the hazard lists most organizations inherited from their first attempt. That is why so many hazard identification and risk assessment tables stop at noise, chemicals and work at height.
ISO 45003 cannot be certified against, and that changes everything
ISO 45003 is a guidelines document. It contains no requirements, no body issues certificates against it, and there is no such thing as an ISO 45003 certification audit. This is not a legal detail: it governs how the text is used.
First mistake, on the auditor's side. Raising a nonconformity because an organization has no psychosocial risk prevention plan conforming to ISO 45003 has no basis. The audit criteria are ISO 45001, and ISO 45003 is not part of them.
Second mistake, on the organization's side, and it is the more common one: concluding that because the standard cannot be certified against, the subject is outside the scope of an audit. That is wrong, and the distinction is precise. Nobody can audit you against ISO 45003, but anyone can audit whether your hazard identification, which ISO 45001 does require, covered psychosocial hazards. The question is not about the text you do not apply, it is about the requirement you already apply.
Three families of hazards, two of which come as a surprise
ISO 45003 groups the sources of psychosocial risk into three families, and presents them as tables of examples rather than closed lists.
The first, work organization, is the one people expect: workload, pace, working hours, autonomy, role clarity. The second, social factors, is already less intuitive: interpersonal relationships, leadership, recognition, support, civility, but also violence, harassment and bullying, which appear there as hazards to be identified and not only as facts to be sanctioned after the event.
The third surprises almost everyone: the work environment, equipment and hazardous tasks. Constant noise, extreme temperature, equipment unsuited to the work actually required are not only physical risks, they are also sources of psychosocial risk. Two practical consequences follow: job security and precarious contracts are a hazard to be identified rather than a matter reserved for human resources, and isolated or remote work is another, through the loss of access to the usual support.
The three points where these efforts collapse
Three clauses of ISO 45003 have no equivalent in ISO 45001, and they are the ones on which such efforts most often fail.
Confidentiality (7.5.2). Psychosocial data is personal by nature. A survey whose results allow one person in a team of six to be identified, a report that circulates, minutes that name someone, and the exercise is over: nobody will answer again. The text also asks for something almost nobody does, informing workers of the limits of that confidentiality. Promising absolute anonymity when a legal obligation may compel disclosure is a promise that cannot be kept.
Return to work (8.3). The return itself increases exposure, which is counter-intuitive. The adjustments made to ease the return change tasks, relationships, supervision, and how the person's value is perceived within the team. This holds whatever the reason for the absence.
Review of controls (9.1.2). Control measures are reviewed when a new hazard appears, when a measure proves inadequate, before a significant change, and at the request of workers or their representatives. That last trigger is the forgotten one: an annual review in the calendar does not replace it.
Where to start
The most common reflex is also the least effective: launching a separate project, with its survey, its consultant and its report. It produces a document, rarely any prevention, and it detaches itself from the OH&S management system to which it should belong.
The fastest route is to add the three families of hazards to the hazard identification that already exists, together with workers, recording what has been examined and what has not. The useful output is not a score, it is the list of what nobody has ever looked at.
The grid below does exactly that, across thirty-six points. It calculates no conformity rate, because there is nothing to conform to: it measures the coverage of your approach.
Download the ISO 45003 grid See the ISO 45001 auditor pack
Sources
- ISO 45003:2021, Occupational health and safety management, Psychological health and safety at work, Guidelines for managing psychosocial risks
- ISO 45001:2018, Occupational health and safety management systems, Requirements with guidance for use
This article describes the structure and scope of ISO 45003:2021. It does not reproduce the text of the standard, which is protected by copyright. The clause numbers cited refer to the 2021 edition.