ISO 45003 is the first global standard that gives practical guidance on managing psychosocial risk at work, covering issues like workload, role clarity, and workplace relationships. It's guidance, not a certifiable management-system standard: there's no accredited "ISO 45003 certificate" the way there is for ISO 45001 or ISO 9001. This guide walks through the ISO 45003 psychosocial risk assessment process for UK and EU people-ops teams: what it covers, how it maps to the HSE Management Standards, and how feedback data becomes assessment evidence.
This guide is for HR leads, people ops managers, and health and safety officers at UK and EU companies building or refreshing a psychosocial risk assessment who want it to hold up to scrutiny, whether that's an internal audit, a board question, or an inspector's visit. You'll get the definition, how ISO 45003 sits alongside ISO 45001 and the HSE Management Standards, and a practical workflow that uses feedback data you probably already collect.
Key Takeaways
- ISO 45003 is guidance on managing psychosocial risk at work, not a certifiable requirements standard; no accredited body certifies an organisation "to" ISO 45003.
- It's designed to be used alongside ISO 45001, the certifiable occupational health and safety management standard, covering the psychological side of OH&S.
- Psychosocial hazards fall into three broad groups: how work is organised, social factors at work, and the work environment.
- In Great Britain, the HSE Management Standards (six factors: Demands, Control, Support, Relationships, Role, Change) cover much of the same ground and support employers' legal duty to risk-assess work-related stress.
- Recurring pulse surveys, eNPS trends, and open-text comments give a psychosocial risk assessment dated, repeatable evidence, not a one-off snapshot.
What Is ISO 45003?
ISO 45003:2021, titled Psychological health and safety at work, guidelines for managing psychosocial risks, is the first global standard focused specifically on psychosocial risk. Where most occupational health and safety standards emphasise physical hazards like machinery, chemicals, or falls, ISO 45003 addresses the psychological side: workload, role clarity, relationships, and how change gets managed.
The most important thing to get right about ISO 45003 is what it isn't. It's a guidance document, not a requirements standard. There's no clause structure an auditor certifies you against, and no accredited body issues an "ISO 45003 certificate" the way one would for ISO 45001 or ISO 9001. If a vendor or consultant offers to get your organisation "ISO 45003 certified," that claim is worth a second look; the standard itself doesn't work that way.
That doesn't make it optional busywork. Guidance standards still carry weight with auditors, insurers, and boards, because they describe a recognised, structured approach. Following ISO 45003's approach, and being able to show your workings, what hazards you looked for, what data you used, what you did about it, is what actually matters.
How ISO 45003 Relates to ISO 45001
ISO 45003 doesn't stand alone. It's built to sit alongside ISO 45001, the certifiable occupational health and safety (OH&S) management-system standard. Where ISO 45001 sets out the structure for managing health and safety risk generally, and can be certified by an accredited body, ISO 45003 fills in the psychosocial half of that picture: the risks that don't show up on a hazard walk-round.
In practice: if your organisation already runs an ISO 45001 management system, ISO 45003 gives you guidance for extending your risk assessment and hazard identification process to cover psychosocial hazards specifically. If you don't have ISO 45001 in place, you can still use ISO 45003's approach on its own. Either way, certification, if you pursue one, stays anchored to ISO 45001, not to ISO 45003 directly.
The Three Psychosocial Hazard Categories
ISO 45003 groups psychosocial hazards into three broad areas. None of this is exotic; it's mostly what an engaged HR team already tracks informally. The value of the standard is turning that informal sense into something you can document.
- How work is organised. Workload and work pace, role clarity, autonomy and control over how work gets done, and how organisational change is planned and communicated.
- Social factors at work. Relationships with managers and colleagues, support (or the lack of it), leadership style, and behaviours like harassment or exclusion.
- The work environment. Physical conditions, equipment, and job design that affect how sustainable the work actually is, including remote and hybrid setups.
A useful gut check: most complaints and quiet resignations trace back to one of these three, usually more than one at once. A team that's understaffed (organisation of work) often also reports strained manager relationships (social factors) once the workload pressure has been running for a few months.
How the UK HSE Management Standards Map Alongside ISO 45003
UK employers already have a separate, legal reason to assess psychosocial risk. The Health and Safety Executive (HSE) requires employers in Great Britain to risk-assess work-related stress, and its free Management Standards approach is the tool most organisations use to do it. It isn't the same framework as ISO 45003, HSE's Management Standards predate the ISO standard by well over a decade, and they're a domestic legal-compliance tool rather than an international guidance document, but the two overlap closely in substance.
The HSE Management Standards cover six factors:
| Factor | What it covers |
|---|---|
| Demands | Workload, work patterns, and the work environment |
| Control | How much say someone has over how they do their work |
| Support | Encouragement and resources from managers and colleagues |
| Relationships | Avoiding conflict and dealing with unacceptable behaviour |
| Role | Whether people understand their role and avoid conflicting responsibilities |
| Change | How organisational change is managed and communicated |
Overlay that against ISO 45003's three categories and the fit is close: Demands, Control, and Change map to "how work is organised"; Support and Relationships map to "social factors at work"; Role touches both. A UK organisation already running an HSE-based stress risk assessment is doing work that supports, though doesn't automatically satisfy, since the two are formally separate frameworks, most of what an ISO 45003 approach asks for.
The scale of the underlying problem is real, not theoretical. HSE's most recent figures put work-related stress, depression, or anxiety at 964,000 workers and 22.1 million lost working days in Great Britain in 2024/25, and the World Health Organization's 2024 estimate puts the global toll at 12 billion working days lost every year to depression and anxiety, costing roughly US$1 trillion in lost productivity. A risk assessment on paper is a compliance document. A risk assessment backed by your own trend data is a management tool.
How Recurring Employee Feedback Provides Assessment Evidence
A risk assessment is only as good as the evidence behind it, and one-off surveys make weak evidence. They capture a mood on one day, not a pattern. Recurring feedback data does what ISO 45003 and the HSE approach both actually ask for: a way to identify hazards and show they've been monitored over time, not just noticed once.
Three feedback signals map directly onto the hazard categories above:
- Pulse survey items on workload, autonomy, and role clarity give you a repeatable, dated read on the "organisation of work" category. Run the same items on a recurring cadence and you get a trend line, not a single data point.
- eNPS tracked by team flags where relationships and support are breaking down before it shows up in exit interviews (a pattern covered in more depth in our burnout analytics guide). A department-level score sliding for two or three cycles in a row, while the rest of the organisation holds steady, is exactly the kind of pattern a risk assessment should record.
- Open-text comments explain the "why" behind a number. Themes like "unclear priorities" or "no cover when someone's off" showing up repeatedly, from different people, are qualitative evidence a numeric score alone won't give you.
Picture a 60-person UK logistics firm reviewing its HSE-based stress risk assessment. The engineering team's eNPS holds steady, but the ops team's workload-item score has slipped from 4.0 to 3.1 over three monthly cycles, and open-text comments repeatedly mention "no cover during peak season." That's a documented, three-cycle pattern, exactly what a risk assessment record should contain, not a guess based on one manager's impression.
Anonymous surveys matter here more than almost anywhere else in HR. Psychosocial topics, workload strain, manager conflict, are exactly the questions people answer more honestly when they're not attached to a name. FeedbackPulse holds department-level results back until at least 3 people have responded, so a small team's answers can't be reverse-engineered from a single reply.
None of this replaces judgement. A trend line tells you where to look; a person still has to interpret it, talk to the team, and decide what changes. That's true whether you're assessing against ISO 45003, the HSE Management Standards, or just trying to run a healthier team.
A Practical Psychosocial Risk Assessment Workflow
Both ISO 45003 and the HSE Management Standards describe a version of the same underlying process. Adapted for a team already running feedback surveys, it looks like this:
- Identify the risk factors. Start from the three ISO categories or the six HSE factors, whichever framing your organisation already uses, and map them to specific questions on your recurring pulse or engagement survey.
- Collect evidence on a repeatable cadence. A single survey wave is a snapshot. Run the same core items every cycle so you can see direction, not just position.
- Segment by team, not just company-wide. A flat, healthy-looking company average can hide one team in real difficulty. Review eNPS and pulse trends at the department level wherever headcount allows it without breaking anonymity.
- Evaluate the risk. Look for sustained decline across two or three cycles in the same team or item, corroborated by open-text themes, rather than reacting to any single low score.
- Record your findings. Document what you looked at, what the data showed, and what you decided to do, dated. This is the part an inspector or auditor actually wants to see.
- Monitor and review. Set a fixed cadence, tied to your existing survey cycle, to revisit the assessment rather than treating it as a one-time project.

Documentation and Evidence Table
Whichever framework you're working against, the underlying ask is the same: show your workings. This table maps the kind of evidence a psychosocial risk assessment needs to where it typically comes from in a feedback program.
| Evidence needed | Where it comes from | What it shows |
|---|---|---|
| Hazard identification | Pulse or engagement survey question set | Which of the three ISO categories, or six HSE factors, you're tracking |
| Ongoing monitoring | Recurring survey cadence, cycle over cycle | A trend, not a single reading |
| Team-level risk | Department-level eNPS and pulse breakdowns | Where risk concentrates, without exposing individuals |
| Qualitative context | Open-text comments, themed | The "why" behind a declining number |
| Action taken | Dated notes tied to a specific cycle | That findings led to a decision, not just a report |
| Review and close-out | Follow-up cycle after an action | Whether the action actually moved the trend |
Keep this simple. A spreadsheet or a folder of dated survey exports is enough for most SMB teams; you don't need a dedicated compliance platform to have a defensible paper trail.
Where FeedbackPulse Fits
FeedbackPulse doesn't certify anything, and it isn't a compliance or risk-assessment platform. What it gives you is the evidence layer underneath one: recurring pulse surveys with workload and role-clarity questions, eNPS tracked by cycle and by team, anonymous mode with a 3-response reporting threshold, and dated exports you can drop straight into a risk-assessment record.
It's worth naming what this isn't, too. FeedbackPulse doesn't run automated hazard alerts, doesn't track behavioural or PTO data, and doesn't claim to satisfy your legal duty on its own. The risk assessment is still a human judgement call, informed by data that's actually there when someone asks for it. That's a deliberate boundary, not a missing feature.
This guide focuses on the psychosocial side. If you're building a broader audit-ready feedback program, our guide to audit-ready employee feedback covers the general pattern, and if ISO 9001 is also on your list, Employee Feedback as ISO 9001 Evidence covers the quality-management side of the same data.
Getting Started
A psychosocial risk assessment doesn't need to start from a blank page. If you're already running pulse or eNPS surveys, you're already collecting most of the evidence ISO 45003 and the HSE Management Standards both ask for. You just need to look at it through that lens and start dating your findings.