Psychosocial Safety
How to manage psychosocial hazards: the controls that actually work
How to manage psychosocial hazards using the hierarchy of controls: eliminate at the source first, redesign the work, and treat wellbeing support as a backstop.
By the Whyser Team · 29 July 2026 · 8 min read

Key takeaways
- Managing a psychosocial hazard is a different job from finding one. You can have a perfect hazard register and still change nothing, because a register lists problems and controls fix them.
- The order matters. Eliminate the hazard first, then reduce it at the source, then change how people are exposed, and only then reach for coping support. Most organisations start at the bottom and wonder why nothing moves.
- The controls that actually work are usually design changes: workload, how a role is shaped, who has a say, how change is handled. Rarely a poster or an app.
- The legal standard, eliminate so far as reasonably practicable and minimise what you can't, points you at the top of that list, not the wellbeing session at the bottom.
- Consultation isn't a nice-to-have. The people doing the work usually know the fix, and asking them is part of what makes a control defensible.
In our consulting work, a manager once told us, proudly, that his team's stress problem was handled. We asked what he'd done. "We brought in a mindfulness app and a lunchtime yoga session." His team was two people short and had been for eight months. The yoga was lovely. It was also aimed at the wrong thing entirely.
That's the gap we want to close here. Controlling a hazard is a different skill from finding one, and it's the part of psychosocial safety where good intentions quietly go to die. Identifying the hazard is one job, and we've written about how to run a proper risk assessment elsewhere. Doing something that actually works is another.
Finding a hazard and fixing it are different jobs
A risk assessment ends with a list, and a list is not a control. We've watched organisations produce a genuinely good register, name their top hazards accurately, and then do essentially nothing, because nobody was clear on what a control even looks like.
So be honest about which job you're doing. If you're still working out what your hazards are, start with the full list of psychosocial hazards and build your register. This piece assumes you already know what's hurting people; the question now is what you do about it.
The hierarchy of controls, applied to mental health
Physical safety has used a hierarchy of controls for decades, and psychosocial safety works the same way. You work down the list in order, and only move down a rung when the one above genuinely isn't reasonably practicable.
Eliminate the hazard. Can you remove the source entirely? A broken process that generates constant rework can be fixed. An unsustainable workload can be redistributed. A role built to fail can be redesigned. Elimination sounds drastic, but it's often just doing the obvious thing you've been avoiding.
Reduce it at the source. Where you can't remove the hazard, shrink it. Add the headcount. Move the deadline. Fix the system generating avoidable friction. Give people a real say in decisions that affect their work, because low job control is itself a hazard.
Change how people are exposed. Rotate people out of a high-exposure role before it wears them down. Build recovery time in after a demanding stretch, and cap how long anyone sits in the hardest seat.
Support people to cope. Employee assistance programs, training, wellbeing resources. These come last, a backstop, not a fix. They help someone survive a hazard you haven't removed; they don't remove it.
The mistake is almost universal: reach for the bottom rung first because it's visible, cheap, and doesn't require changing how the work is organised. It doesn't work.
Why redesign beats resilience
The single most effective psychosocial control is usually a change to how the work is designed, and it's the one people are most reluctant to make, because it means touching workload, roles, and management, not just adding a program on the side.
Think about the common hazards. Role overload is a design problem. So is low job control. Poor role clarity, badly handled change, a manager nobody can reach: all design problems. You don't fix a design problem with a resilience workshop. You fix it by changing the design.
Workload. If a team is consistently over capacity, no amount of coping training changes the maths. You add people, cut scope, or change the deadline. That's the control.
Role and job design. Sometimes the role itself is the hazard: too much responsibility with too little authority, or a job stitched together from three others after a departure nobody backfilled. Reshaping the role is the fix.
Support and management. A team with high demands but strong, reachable support holds up. The same demands under an absent or punitive manager are a different risk. Building real support is a control, not a soft skill.
None of this is exotic, just harder and slower than buying an app, which is exactly why so many organisations don't do it.
What the law actually asks you to do
The regulatory standard, set out in the Code of Practice that now sits behind Australia's model WHS Regulations, is to eliminate psychosocial risk so far as reasonably practicable, and minimise what you can't eliminate. That sentence is doing real work.
"Eliminate so far as reasonably practicable" points you at the top of the hierarchy. It doesn't say "offer support". It says remove the hazard where you reasonably can, and only minimise where you genuinely can't. An organisation that jumps straight to an employee assistance program has skipped the part the law actually emphasises.
This is also why controlling hazards is inseparable from your duty of care. The duty isn't discharged by a wellbeing program. It's discharged by identifying real hazards and doing something proportionate about them at the source. Safe Work Australia's guidance is consistent on this: source-level control first, support second.
Don't skip consultation, it's part of the control
Here's the part leaders underuse. The people doing the work almost always know what the hazard is and often have a good instinct for the fix. Consultation isn't a courtesy you add at the end. It's how you find controls that actually work, and part of what makes the whole thing defensible if it's ever tested.
Ask the team what would make the biggest difference. You'll frequently get a cheaper, sharper answer than the one you'd have designed in a meeting room, and people are far more likely to accept a change they helped shape. That loop, spotting the hazard, choosing a source-level control, checking it worked, is exactly what we built the Culture module at Whyser Work to keep turning.
A short example
A mid-sized services firm had a claims team clearly struggling: high sick leave, two resignations in a quarter, tense one-on-ones. The first instinct was a resilience program.
Instead, they sat down with the team, and the real hazards were plain once anyone asked. A clunky intake system doubled everyone's handling time, and one client escalation always landed on the same two people. So they fixed the intake process (eliminate), spread the escalations across the team (reduce at source), and set a rotation so nobody sat in the hardest queue for more than a fortnight (change exposure). The employee assistance line stayed available as a backstop, the fourth control, not the first.
Six months on, sick leave was down and nobody else had left. Not because people got more resilient. Because the work got less harmful.
Frequently asked questions
What's the difference between eliminating and minimising a psychosocial hazard?
Eliminating means removing the source of harm entirely, like fixing a broken process or redistributing an impossible workload. Minimising means reducing a hazard you can't fully remove, by changing exposure, adding support, or improving how it's managed. The standard is to eliminate first where reasonably practicable, and minimise only what genuinely can't be.
Aren't employee assistance programs and wellbeing sessions worth doing?
Yes, as a backstop. They help people cope with pressures you haven't yet removed, and that's a real benefit. The problem is only when they're used as the main control while the underlying hazard stays untouched. Support sits at the bottom of the hierarchy for a reason: it treats the symptom, not the source.
How do we know if a control actually worked?
You check. A control you install and never review is a guess. Set a review date, watch the same signals that flagged the hazard (turnover, sick leave, feedback, team-level measurement), and see whether they move. There's more on tracking that over time in measuring psychosocial risk.
Does managing hazards this way meet our legal obligations?
Working down the hierarchy of controls and documenting it is the shape regulators expect, but this is general guidance, not legal or WHS advice for your specific situation. Your obligations depend on jurisdiction, size, and facts, so use this to understand the approach and get your own advice for compliance certainty.
If you looked honestly at the last thing you did in response to a stressed team, was it a change to how the work is designed, or just another app?
Keep reading
See it in your organisation
Whyser Work turns everyday people data into the culture and compliance picture leaders can act on.