Psychosocial Safety
How to run a psychosocial risk assessment (with a template)
A step-by-step guide to running a psychosocial risk assessment, plus a hazard-register template you can adapt.
By the Whyser Team · 16 July 2026 · 8 min read

Key takeaways
- A psychosocial risk assessment identifies hazards, rates their likelihood and severity, prioritises them, and controls the ones that matter most. It's the same discipline as a physical safety risk assessment, applied to mental health.
- You don't need a consultant to start. You need a simple hazard register and a habit of updating it.
- Consultation with workers isn't optional. It's part of what makes the assessment legally defensible.
- Controls should target the source of the risk first. Coping supports (EAPs, wellbeing sessions) are a backup, not a substitute.
- Record everything with a date. An assessment that isn't written down is, for legal purposes, close to an assessment that didn't happen.
- Our free psychosocial readiness checklist is the fastest way to see where you actually stand before you build a full register.
A client called us the week before a SafeWork audit and asked, "Do we have a psychosocial risk assessment?" The honest answer was they had an engagement survey from eighteen months ago and a folder of good intentions. That's not an assessment. Here's what one actually looks like, and how to build it.
What a psychosocial risk assessment actually is
It's a structured process for identifying the things at work that could harm someone's mental health, working out how serious that risk is, and doing something about the ones that matter most. It sits inside the broader duty we cover in psychosocial safety at work, and maps to the same four-step cycle regulators expect: identify, assess, control, review.
The word "assessment" makes it sound like a one-time audit. Treat it as one and you'll be back here in twelve months with the same problem. Treat it as an ongoing practice and it starts paying for itself in fewer surprises, not just fewer fines.
Step 1: identify the hazards
Start by working out what's actually happening in your workplace, not what a generic checklist assumes is happening. Common sources worth checking:
- Workload and demands. Are people consistently working beyond capacity, or facing unrealistic deadlines?
- Job control. Do people have a say in how they do their work, or is everything dictated to them?
- Support. Can people actually reach their manager when something's wrong, and do peers back each other up?
- Role clarity. Do people know what's expected of them, or are they guessing?
- Change management. Are changes to structure, systems or roles handled with warning and explanation, or dropped on people?
- Recognition. Does effort get acknowledged, or does good work just get absorbed as the new baseline?
- Exposure to trauma or aggression. Does the role involve difficult customers, distressing material, or physical risk?
- Isolation. Are people working remotely or solo without regular contact?
- Relationships. Is there unresolved conflict, bullying, or harassment anywhere in the business?
For the full breakdown with workplace examples for each, see psychosocial hazards at work. You won't find these in policy documents. You find them in real data: exit interview themes, absenteeism patterns, grievances, and what people say when they trust the answer won't be used against them.
Step 2: assess likelihood and severity
For each hazard you've identified, ask two questions.
How likely is it to cause harm? Is this an occasional issue in one team, or a constant condition across the business? A single tough quarter is different from a role that's been understaffed for two years.
How severe could the harm be if it did occur? A hazard that causes mild frustration is different from one linked to burnout, serious mental ill-health, or people leaving in numbers.
Rate each hazard against both dimensions, even informally with a simple low, medium, high scale. The point isn't precision. It's to stop every hazard getting the same amount of attention, because they don't deserve it.
Step 3: prioritise
Once you've rated your hazards, prioritise by combining likelihood and severity. A high-likelihood, high-severity hazard, say, a team that's been chronically understaffed for a year, goes to the top. A low-likelihood, low-severity issue can wait its turn.
This is also where you look for concentration. Hazards rarely sit alone. A team with high demands, low control and poor support isn't facing three separate small problems. It's facing one compounding one, and it should be treated as the priority it is.
Step 4: control at the source
This is where most assessments quietly fail. It's tempting to respond to a stressed team with an EAP reminder or a resilience workshop. Those things treat the symptom, not the cause.
Controls work best in this order:
- Eliminate the hazard. Can you actually remove the source? Redistribute an unsustainable workload. Fix a broken process causing constant rework.
- Reduce it at the source. Where you can't eliminate it, reduce it. Add headcount. Change a deadline. Improve a system that's generating avoidable friction.
- Change how people are exposed to it. Rotate people out of a high-exposure role periodically. Build in recovery time after a demanding period.
- Support people to cope. EAPs, training and wellbeing supports come last, as a backstop, not a fix.
The regulatory standard is to eliminate psychosocial risk so far as reasonably practicable, and minimise what you can't eliminate. That standard points you at the top of this list, not the bottom.
Step 5: consult your people
Consultation isn't a courtesy. It's part of what makes an assessment legally sound. The people closest to the work usually know exactly what the hazard is and often have a good instinct for the fix. Ask them, and ask in a way that makes it safe to answer honestly.
Step 6: record it, with a date
An assessment that lives in someone's head, or in a slide deck nobody's opened since the workshop, isn't an assessment a regulator will accept as evidence. Write it down. Date it. Keep it somewhere it can be found again in twelve months, and update it when something changes.
A simple hazard-register template
You don't need software to start this. A spreadsheet with these columns will get you further than most businesses currently are:
| Column | What goes in it |
|---|---|
| Hazard | The specific issue, described plainly (e.g. "sustained overtime in the claims team") |
| Where it shows up | Team, role or location |
| Evidence | What told you this was happening (survey data, exit interviews, incident reports, direct feedback) |
| Likelihood | Low / medium / high |
| Severity | Low / medium / high |
| Priority | Combined rating, used to sequence action |
| Control(s) planned | What you're actually going to do, starting with source-level fixes |
| Owner | Who's accountable for the control being actioned |
| Review date | When you'll check whether it worked |
| Status | Open / in progress / reviewed / closed |
Adapt the columns to your business, but keep the discipline: every hazard needs evidence, a rating, a named owner, and a review date. Without those four, it's a list, not a risk assessment.
Where to start, practically
If you're staring at a blank spreadsheet wondering where to begin, start with our free psychosocial readiness checklist. It's an interactive self-assessment that walks you through where your organisation actually stands against the identify, assess, control, review cycle, and it's the fastest way we know to turn "we should probably do this" into a first list of hazards worth registering.
For the ongoing measurement side, once your register exists, see measuring psychosocial risk for how to keep the data current without running a full survey exercise every time.
This is general guidance, not legal advice. It'll get your register started; it doesn't replace your own legal and WHS advice for your specific obligations.
Frequently asked questions
How often should we run a psychosocial risk assessment?
Treat it as ongoing, not annual. A hazard register should be reviewed whenever something material changes, a restructure, a leadership change, a spike in complaints or turnover, and checked periodically even when nothing obvious has shifted. An annual-only cadence tends to miss the problems that build up in the gaps.
Do we need an external consultant to do this?
Not necessarily. Many organisations run a credible first pass internally, especially with a clear template and genuine staff consultation. External expertise earns its place when findings are complex, when trust is too low for an internal assessor to get honest answers, or when a high-risk finding needs independent validation.
What's the difference between a psychosocial risk assessment and an engagement survey?
An engagement survey measures how people feel about work in general. A psychosocial risk assessment specifically identifies hazards, rates the risk they pose, and drives controls. They can share data sources, but a risk assessment has to end in documented action, which most engagement surveys never require.
What counts as good evidence for the likelihood and severity ratings?
Anything real and traceable: survey results, exit interview themes, absenteeism or turnover data in a specific team, incident or grievance records, and direct consultation with the people doing the work. A single manager's impression is a useful input, not sufficient evidence on its own.
Ready to see how a hazard register turns into a live system instead of a shelved spreadsheet? Have a look at Whyser Work's culture module, or book a demo to talk through your first pass.
What would your register say about your riskiest team right now, and when did you last update it?
Keep reading
See it in your organisation
Whyser Work turns everyday people data into the culture and compliance picture leaders can act on.