ISO 45003:2021
ISO 45003 Psychological Health & Safety at Work
Manage psychosocial risk with the same rigor as physical safety.
Workload
Demands & pace
Pressure
Role & relationships
Change
Uncertainty
Assessment
Hazards mapped
Prioritize
Controls
Work design first
Support
Recovery routes
Open reporting
Safe to speak
Reassess returns to Assessment
Sustainable workforce
Performs & stays
Speak up returns to Open reporting
SYS/10 · Psychosocial risk
Workload, pressure and change feed structured assessment; controls, support and open reporting sustain the workforce.
What ISO 45003 is
ISO 45003 is the first international guidance standard for managing psychosocial risk: workload, role clarity, support, workplace relationships, remote work, organizational change and the other factors that drive stress, burnout and harm. It extends an ISO 45001 system into psychological health.
CORE audits psychosocial risk management where it sits inside an ISO 45001 certification audit, and assesses practice against ISO 45003 where an organization wants an independent opinion without a certificate. Your auditor looks at how psychosocial hazards were identified and by whom, whether workers could raise them without becoming identifiable, and whether the controls chosen act on how work is designed, resourced and led rather than only on individual coping. Consultation records, risk assessments covering work organization and social factors, workload and role-clarity decisions taken as controls, manager competence, adjustment and return-to-work records, and aggregate indicators handled without exposing individuals all carry weight as evidence. The findings raised most often concern hazard identification that stopped at a survey, controls that offer resilience training in place of a workload decision, and grievances or absence cases closed without the organizational cause being examined.
Who it is for
- Certified organizations extending an ISO 45001 scope so psychological health is examined at audit alongside physical safety
- Employers in sectors where customers and regulators now ask what is being done about psychosocial risk: healthcare, emergency services, legal, finance, contact centres
- Organizations whose duty-of-care position is being tested by claims, absence or turnover and who want it examined by someone outside the business
- Organizations seeking an independent assessment against ISO 45003 for stakeholders, accepting that a guidance standard carries no certificate
Business outcomes
What leadership should expect the system to change, in operational terms.
Risks made visible
Psychosocial hazards assessed systematically instead of surfacing through exits and absence.
Duty of care evidenced
A documented, operating framework demonstrates the organization takes psychological harm seriously.
Better retention
Addressing workload, clarity and support removes the causes people leave over.
Integrated safety
One OH&S system covering physical and psychological harm together.
Benefits beyond the certificate
Consultation with substance
Workers shape hazard identification and controls, which is where accuracy comes from.
Manager capability
Line managers equipped to recognize and act on psychosocial risk within their control.
Confidential measurement
Indicators designed to inform action without exposing individuals.
Reputation resilience
Credible prevention reduces the likelihood and impact of high-profile failures.
45001 synergy
Uses the existing OH&S system rather than creating a parallel wellbeing programme.

The main requirements
The themes your auditor will examine, in plain language. The full clause detail is worked through at Stage 2.
01
Psychosocial hazard identification
Aspects of work organization, social factors and environment assessed for potential harm.
02
Worker participation
Consultation designed so people can speak safely about psychosocial issues.
03
Risk assessment and controls
Prioritized controls addressing causes in how work is designed and managed, not only individual resilience.
04
Competence and awareness
Managers and workers equipped for their roles in prevention and response.
05
Support and recovery
Routes to support, adjustment and return-to-work handled with confidentiality.
06
Evaluation and improvement
Indicators, review and learning from incidents and concerns.
What each requirement buys you
Select a requirement theme to see the business outcomes it chiefly drives. The mapping reflects where audit sampling concentrates, not a normative ISO table.
Requirement themes
Psychosocial hazard identification chiefly drives 2 of 4 ISO 45003 outcomes.
Outcomes it drives
Risks made visible
Psychosocial hazards assessed systematically instead of surfacing through exits and absence.
Duty of care evidenced
A documented, operating framework demonstrates the organization takes psychological harm seriously.
Better retention
Addressing workload, clarity and support removes the causes people leave over.
Integrated safety
One OH&S system covering physical and psychological harm together.
How CORE audits ISO 45003
Step 1
Stage 1 reviews scope, consultation and the risk assessment
Where psychosocial risk sits inside an ISO 45001 scope, your auditor confirms the OH&S scope covers psychological health, reads the psychosocial risk assessment, the consultation arrangements and the support, adjustment and return-to-work routes, and checks that internal audit and management review have covered them. Findings here are raised as improvement requests, not nonconformities.
Step 2
Stage 2 examines controls at the level they act on
The audit tests whether hazard identification reached the people exposed and protected them while doing it, whether the risk assessment covers work organization, social factors and the working environment rather than individual factors alone, and whether the controls in place changed workload, role clarity, support or behaviour standards. Interviews are conducted so that no individual's account is traceable back to them, and confidential case files are examined in a way that does not require them to be disclosed.
Step 3
Surveillance samples what changed and what was learned
Year 1 and Year 2 audits sample consultation and assessments run since the last visit, organizational changes that move psychosocial exposure — restructures, workload shifts, remote and hybrid arrangements — incidents, grievances and absence patterns and what was done with them, manager competence, and the closure of previous findings.
Step 4
Recertification revisits the whole cycle
In Year 3 the audit reviews how psychosocial risk has been managed across the full three years: whether the assessment has been maintained against how the organization now works, whether indicators moved or merely accumulated, whether controls survived contact with operational pressure, and whether the scope still describes the workforce actually covered.
What your auditor expects to see
Before Stage 2 can proceed, the system needs to have run long enough to have produced its own evidence.
01Consultation and assessment records
A psychosocial risk assessment covering work organization, social factors and the working environment, with records showing which workers were consulted, how, and with what protection from identification.
02Internal audit completed
An internal audit of the psychosocial elements within the ISO 45001 cycle, run by auditors independent of the areas they audit, with reports and findings available to your auditor.
03Management review held
A minuted management review in which psychological health appears as an input in its own right, with decisions, resources and owners recorded rather than merely noted.
04Controls and support demonstrable over a period
Records covering long enough a period to show the arrangements operating: workload and role decisions taken as controls, manager competence, support, adjustment and return-to-work routes used in practice, and corrective actions closed.
Certification decision
With that evidence in place, Stage 1 and Stage 2 can run. The decision that follows is taken by a reviewer who was not on your audit team.
CORE is the certification body. We assess and certify management systems. We do not build them — that separation is what makes the certificate worth holding. We do not design, document or implement the systems we audit, and we do not run your internal audits. If you need that work done, our directory of independent consultants is a starting point, and engaging one has no bearing on the decision. More on how we keep the audit and the decision separate.
The optional pre-assessment
Before Stage 1, or before an assessment against the guidance, you can ask for an optional pre-assessment: an audit-style review of current practice against ISO 45003 — hazard coverage, consultation quality, whether controls act on causes or on coping, support and return-to-work routes, and how indicators are collected and handled — returning a written report of findings.
The report states where the evidence would not yet satisfy an auditor. It does not run your consultation, write your risk assessment or design your controls: producing that work would make CORE the author of arrangements it must later audit, which ISO/IEC 17021-1 prohibits, and the same rule stops us running your internal audits. Organizations that want help acting on the report can use the directory of independent consultants at /resources/find-a-consultant, and engaging one has no bearing on the certification decision.
What you receive
- Findings against each clause of the standard
- Where the evidence is missing or incomplete
- Whether Stage 2 could proceed on today's records
- The same sampling method a certification audit uses
Training for ISO 45003
Courses that teach how the standard is written and how it is audited.
ISO 45003 questions, answered straight
Related standards
Ready to certify to ISO 45003?
Tell us your standards, scope, effective headcount and sites. You will get a scope statement and a fixed quotation, with audit duration calculated from the accreditation body's mandatory formula.
