Since Australian work health and safety law was updated to deal explicitly with psychosocial hazards, a lot of employers have been left with the same question: what does that actually mean we have to do?

Here is the plain-English version. This is general information rather than legal advice, and the detail varies by state, so check your local regulator. But the shape of the obligation is the same across the country.

What a psychosocial hazard actually is

A psychosocial hazard is anything about the way work is designed or managed that can harm someone’s mental health. Safe Work Australia lists common ones, including:

  • High job demands, or very low demands
  • Low job control, where people have little say over how they work
  • Poor support from managers or colleagues
  • Lack of role clarity
  • Poorly managed organisational change
  • Low reward and recognition
  • Poor workplace relationships, including bullying, harassment and conflict
  • Remote or isolated work
  • Exposure to traumatic events

Notice that most of these are not about one difficult person. They are about how work is set up. That is the shift in the law: mental health at work is treated as a safety issue you design for, the same way you would manage a physical hazard.

What the law actually asks of you

You are not expected to eliminate stress or guarantee everyone is happy. You are expected to manage psychosocial risk the same way you manage any other work health and safety risk. In practice that is a four-step cycle:

  • Identify the psychosocial hazards in your workplace.
  • Assess the risk each one creates.
  • Control the risk, so far as is reasonably practicable.
  • Review your controls, and adjust them.

Safe Work Australia’s Code of Practice, Managing psychosocial hazards at work, sets out how to do this, and ISO 45003 is the international guidance many organisations use alongside it.

The gap most employers have

Here is where a lot of organisations quietly fall short. They run an annual engagement survey, get a report, and treat that as their psychosocial risk management.

An annual survey is a snapshot. The law asks you to identify hazards on an ongoing basis, because work changes, teams change, and pressure builds between surveys. If your only source of information about how your people are going is twelve months old, you cannot honestly say you are identifying risk as it arises.

How to identify psychosocial risk regularly

The practical answer is a light, regular check-in that lets people tell you how work is going before it escalates. A few principles make it work:

  • Make it regular. A short monthly or fortnightly pulse beats a long annual survey, because it catches change while you can still do something about it.
  • Keep it anonymous and team-level. The goal is to see where pressure is building, not to monitor individuals. Aggregated, anonymous results protect people and give you a truer picture.
  • Measure the things the law names. Job demands, control, support, clarity. Map your check-in to the actual hazards, not a generic happiness score.
  • Act on it. Identifying a hazard and doing nothing is worse than not looking. The point of measuring is to change something: workloads, rosters, support, a manager conversation.

From measuring to actually reducing risk

Measurement is only the first step. Once a check-in shows you that one team’s job demands are consistently high and their sense of control is low, you have identified a risk. The obligation, and the opportunity, is to do something about it: rebalance the load, give the team more say, or step in with support.

That is also the difference between a compliance exercise and a genuinely mentally healthy workplace. One ticks a box. The other uses what it learns.

Doing it without adding to the load

Any system you put in front of your team has to be light, private and easy, or people will not use it and managers will not act on it. That means a check-in that takes under a minute, results that are anonymous by default, and data that stays where it should.

If you use a platform, ask where the data is stored and how it is secured. iyarn is Australian owned and hosted and ISO 27001 certified, with the detail on our trust and security page.

Where to start

You do not need a full program to begin meeting the obligation. Start by giving one part of the business a regular, anonymous check-in mapped to the common psychosocial hazards, watch what it surfaces, and act on the clearest signal first.

To see how a workplace check-in works, take a look at iyarn for workplaces, or start free today.