ISO 45003 in practice

    Written by Nicolai Bjerknes Slinning, Founder, Sydera.io Technologies AS · Working Group Expert, ISO/TC 283/WG 6 and WG 10 · member of SN/K 551. Last reviewed .

    ISO 45003 is a guidance standard on psychosocial risk at work. It cannot be certified against, but it is often used alongside an occupational health and safety management system. Here is what it does, what it does not do, and how psychosocial risk can be written into governance documents in a way that holds up both professionally and under data protection law.

    What ISO 45003 is

    It is guidance, not a requirements document. It describes how psychosocial conditions can be identified and managed within an occupational health and safety management system. It does not replace legal requirements, and it does not produce a certificate. We do not quote it here — it is licensed, and the content is bought or read at ISO.

    What psychosocial risk looks like on paper

    It is conditions in the work, not characteristics of employees: workload and pace, unclear roles and conflicting demands, lack of influence, poor information, shift patterns that do not allow rest, lack of managerial support, unacceptable behaviour. All of this can be described, assessed and followed up without a single detail about a named person's health.

    The mistake that keeps recurring

    The most common mistake is to turn psychosocial risk into a measurement of how people feel. That creates three problems at once: the answers are hard to act on, the information may become special category data under data protection law, and the measures end up as individual follow-up rather than change in the work. Describe the conditions, not the states of mind.

    What a routine that holds up looks like

    It states what is available to everyone, how something is triggered without a person having to explain themselves, who owns follow-up, where concerns are raised, what the limit is on what a manager may write down, and when the routine was last reviewed. It ties measures to conditions in the work, and it leaves evidence an outsider can read.

    How it relates to ISO 45001 and to reporting

    Where an organisation runs a management system to ISO 45001, psychosocial risk belongs inside that system rather than in a parallel document. Where sustainability reporting applies, the same descriptions serve as the basis. The point is that the documentation exists once, at system level, and gets reused.

    Test your own routine

    Send us one routine. We read it against relevant legal requirements and point to up to three areas for improvement, with one suggested rewrite. We read the document, never employees, and the document must not contain personal data.

    Check one routine — free

    One governance document reviewed free of charge. We read the document, never employees. The document must not contain personal data.

    Sources

    Frequently asked questions

    Can we be certified to ISO 45003?
    No. ISO 45003 is a guidance standard. Certification is against ISO 45001, where an organisation chooses it.
    Is ISO 45003 a legal requirement?
    No. Legal requirements come from occupational health and safety legislation. ISO 45003 is guidance alongside them.
    Do we have to assess employees' mental health?
    No. Psychosocial risk concerns conditions in the work. Assessing individuals' health raises questions about a lawful basis under data protection law and is rarely necessary to describe the risk.
    How do we measure psychosocial conditions without surveys?
    By measuring what is controllable: staffing against workload, role clarifications completed, share of concerns closed, how many people actually get breaks and rest, and what changed after the last review.
    How much text is needed?
    Less than most people think. One page stating what applies, who owns it and how it is triggered governs more than twenty pages describing good intentions.

    Related