Psychosocial Safety
Psychosocial risk management: turning a legal duty into a routine
How to turn psychosocial risk management from a one-off project into a repeating identify, assess, control, review cycle embedded in normal management.
By the Whyser Team · 3 August 2026 · 8 min read

Key takeaways
- Psychosocial risk management is a cycle, not a project. Identify, assess, control, review, then round again. A project has an end date; a duty doesn't.
- Anything you run once as a big launch will decay. The organisations that get this right make it small, regular, and part of how they already manage, not a separate initiative bolted on the side.
- The review step is the one everyone skips, and it's the one the Code of Practice specifically expects. A control you never check is a guess you're hoping paid off.
- Ownership needs to sit where the risk lives. A cycle that only turns at board level never reaches the team where the hazard actually is.
- Done as a routine, the cycle produces your evidence as a byproduct. You're not building a compliance file separately from managing risk; the running of the cycle is the record.
In our consulting work last year, someone in HR told us that they'd "done psychosocial risk." They'd run a big assessment, written a report, presented it to the exec, and ticked it off. Six months later, nobody could tell us whether a single thing in that report had changed. It had been treated as a project, and projects finish. The duty didn't get that memo.
That's the shift we want to make here. Psychosocial risk management isn't a thing you complete. It's a thing you run, on repeat, quietly, forever. And once you see it that way, it gets a lot less overwhelming.
Why the project mindset fails
The project mindset is seductive because it promises an end. Do the assessment, write the report, present it, done. But psychosocial risk doesn't hold still long enough for that to work. A team that was fine in the assessment can be overloaded a quarter later because a project blew out, someone left and wasn't replaced, or a manager changed and took the culture with them. The report you filed in March describes a workplace that no longer exists by August.
There's a second failure mode: the big launch that fades. You can kick off with real energy, a workshop, a survey, a flurry of emails, and watch it quietly evaporate because nobody built it into anything ongoing. Energy isn't a system. If it depends on someone caring loudly, it dies the moment they get busy.
The cycle: identify, assess, control, review
Every Australian regulator describes psychosocial risk management, the operating core of psychosocial safety, as the same four-step cycle used for physical safety: identify the hazards, assess the risk, control it, review whether the control worked. Then you go round again.
Identify. Work out what's actually happening in your workplace, not what a generic checklist assumes. Workload, job control, support, role clarity, how change is handled, exposure to trauma or aggression. The full list of psychosocial hazards is the reference; your job is to find which are live for you.
Assess. Rate each hazard for how likely it is to cause harm and how severe that harm could be, so you're not giving every issue equal attention. There's a full walkthrough in how to run a risk assessment.
Control. Do something about the ones that matter, starting at the source. Eliminate where you reasonably can, minimise what you can't. We've written about the controls that actually work.
Review. Check whether the control worked. This is the step almost everyone drops, and it's the one that turns the cycle back into a loop instead of a line: not four steps you do once, but four you keep doing, because the workplace keeps changing.
The step everyone skips: review
If we had to bet on where an organisation's psychosocial risk management is broken, we'd bet on review. Identifying, assessing, and controlling all feel like progress. Reviewing feels like admin, so it gets dropped, and the moment it does, the cycle stops being a cycle.
The Code of Practice is explicit that you're expected to review your controls, not just install them and move on. And there's a hard logic beyond compliance: a control you never check is a guess. You put headcount into the overloaded team, and then what? Did it work, or did it push the strain onto someone else? Without a review step you don't know, and you've quietly gone back to hoping.
Reviewing well doesn't mean re-running the whole assessment every time. It means watching the same signals that flagged the hazard, turnover, sick leave, direct feedback, team-level measurement, and checking whether they've moved, on a sensible cadence, not a twelve-month lag. More on why the timing matters in measuring psychosocial risk.
Making it a routine, not an event
The organisations that manage this well don't have a bigger annual project. They have a smaller, more frequent rhythm, hidden inside routines that already exist.
Attach it to things you already do. A standing item in monthly team reviews. A psychosocial line in the quarterly ops review. If it lives inside existing rhythms, it doesn't need heroic energy to survive.
Keep each turn small. A light, regular read beats an exhausting annual production. Nobody sustains a giant survey-and-workshop cycle, but everyone can sustain a short check that fits into a meeting they're already having.
Give it a named owner at every level. Someone owns the cycle for each team, close to where the risk actually is, with the authority and resourcing to act on what they find.
Connect the steps. The hazard someone identifies has to have somewhere to go: an assessment, a control, a review, a person. Wired together, the cycle turns on its own; left disconnected, it stalls between each step.
That's the shape of continuous management we've built the Culture module at Whyser Work around: not a bigger event, a rhythm that runs at the level where risk lives.
The routine is your evidence
When psychosocial risk management runs as a genuine routine, it produces your evidence for free. Every turn of the cycle leaves a trace: here's the hazard we identified, how we assessed it, the control, the review showing whether it worked. String those together and you have exactly the record a regulator or a court would look for. You didn't build a compliance file on the side; the running of the cycle is the file.
Compare the two answers if you're ever asked whether you took reasonable steps. "We ran an assessment eighteen months ago" is thin. "Here's the cycle turning every quarter, with what we found, what we did, and whether it worked" is genuinely strong. The routine and the evidence are the same thing, which is the practical backbone of the duty of care leaders now carry.
A short example
A professional services firm stopped treating psychosocial safety as an annual event and made it a quarterly rhythm. Every team lead had a standing fifteen-minute slot in their quarterly review: any new hazards, how the existing controls are holding, anything to escalate.
But one quarter a team lead flagged that a client account was quietly burning out two of her people, a load that had crept up since a colleague left. Because the slot existed, it got named early. They redistributed the account and reviewed it the next quarter, by which point the signals had settled.
No crisis, no resignation, no complaint. Just a small problem caught by a routine that was actually turning, instead of a big one discovered by a project that finished months ago.
Frequently asked questions
How often should the psychosocial risk management cycle turn?
There's no single correct cadence; it depends on your size and risk level. The principle is that it should turn often enough to catch a shift before it becomes a resignation, and be small enough each time to be sustainable. A quarterly rhythm with lighter signals in between works for many organisations; an annual-only cycle misses what builds in the gaps.
Isn't running this continuously more work than an annual assessment?
It feels like more because it never fully stops, but each turn is far smaller, and it replaces a lot of reactive cost that lands later: firefighting, exit interviews, and replacement hiring for problems visible months earlier. A steady light routine is usually less total effort than one giant annual production.
Who should own the cycle?
Ownership needs to sit at every level, but especially close to where the risk lives. Officers own making sure the system exists and is resourced; managers own running the cycle for their teams. A cycle owned only at board level never reaches the team where the hazard is.
Does running this cycle mean we've met our legal obligations?
Running a genuine identify, assess, control, review cycle is the approach regulators expect, but this is general guidance, not legal or WHS advice for your specific situation. Your obligations depend on jurisdiction, size, and facts, so use this to build the routine and get your own advice for compliance certainty.
When did your psychosocial risk cycle last turn, honestly, and if it stopped turning tomorrow, would anyone notice?
Keep reading
See it in your organisation
Whyser Work turns everyday people data into the culture and compliance picture leaders can act on.