Glossary — Standards

What Is ISO 45003?

ISO 45003 is an international standard that gives guidance on managing psychosocial risk and psychological health, safety and wellbeing at work. It is designed to sit alongside the ISO 45001 occupational health and safety management system — and it is guidance, so organizations are not certified against it.

What the standard covers

ISO 45003 was published in 2021 by the International Organization for Standardization under the full title Occupational health and safety management — Psychological health and safety at work — Guidelines for managing psychosocial risks. It is the first international standard devoted specifically to the psychological side of occupational health.

Its content is practical rather than philosophical. It describes the kinds of psychosocial hazards that arise from how work is organized, from social factors at work, and from the work environment; it explains how to identify and assess them; and it sets out how to control them, monitor whether the controls worked, and improve from there. It also covers supporting workers' recovery and return to work, and the role of leadership commitment and worker participation in making any of it credible.

Guidance, not a certifiable requirement

This is the single most misunderstood point about ISO 45003. It is a guidance document. Its clauses are written as recommendations, not as auditable requirements, and organizations are not certified against ISO 45003. Any claim that a company or a product is "ISO 45003 certified" is a misunderstanding of what the standard is.

What an organization can legitimately say is that its psychosocial risk management is aligned with or informed by ISO 45003 — and then show the evidence: the hazards identified, the assessments run, the controls applied, and the review cycle.

How it relates to ISO 45001

ISO 45001 is the certifiable management-system standard for occupational health and safety. ISO 45003 is designed to sit inside it: same plan-do-check-act structure, same clause logic, applied to psychological health. An organization already running an ISO 45001 system does not need a parallel structure for psychosocial risk — it extends the hazard identification, risk assessment, control and review processes it already has to cover organizational and social hazards alongside physical ones.

Organizations without a formal management system can still use ISO 45003 on its own as a well-structured checklist for what a serious psychosocial risk program should contain.

Why US employers use it

There is no US regulation that requires an engagement or psychosocial risk survey. ISO 45003 matters in the US because it supplies a recognized, externally authored framework for a duty that does exist in more general terms.

  • OSHA General Duty Clause. Section 5(a)(1) requires employers to keep the workplace free from recognized hazards. OSHA has acted on conditions including excessive workloads, hostile environments, fatigue and workplace violence risk. Following ISO 45003 with regular monitoring is how employers surface those conditions early and document good-faith due diligence.
  • NIOSH Total Worker Health. The NIOSH framework treats worker wellbeing as inseparable from worker safety and explicitly includes psychological and organizational factors among the conditions employers should assess and manage. Regular anonymous surveys are one of the recognized mechanisms for that assessment.
  • Consistency across borders. For companies operating in both the US and Mexico, ISO 45003 provides one internal framework that also maps cleanly onto the obligations of NOM-035, rather than running two unrelated programs.

What implementing ISO 45003 looks like

  1. Set the commitment. A stated leadership position on psychological health and safety, with a named owner and a channel for worker participation. Without it, the rest reads as an HR exercise.
  2. Identify the hazards. Work through the categories the standard describes — workload, control, role clarity, support, relationships, harassment, work–life interference, job security, change management — for each part of the organization, not for the organization as an average.
  3. Assess the risk. Anonymous self-report is the primary instrument, scored by domain and read by team or site with a minimum group size. Corroborate with objective indicators such as overtime, absence and turnover patterns.
  4. Apply controls at the source. Rebalance workloads, clarify roles, widen autonomy, train managers, enforce anti-harassment policy. Individual support such as an employee assistance programme is a complement, not a control.
  5. Monitor and review. Re-measure on a regular cadence so you can see whether the control changed the score, and feed the result back into the next cycle. Communicating results and actions back to workers is part of the standard, not an optional courtesy.

The review step is where most programs quietly fail. An assessment that is run once, reported, and never repeated cannot show whether anything improved — and improvement is the entire point of the plan-do-check-act loop.

Where a pulse survey program fits

ISO 45003 asks for identification, assessment, control and monitoring on a continuing basis. That is a measurement cadence problem more than a documentation problem, and it is what short recurring surveys are good at.

Bloomder runs ISO 45003-aligned wellbeing templates as regular anonymous pulse surveys, scores psychosocial domains at team level, and logs every send, reminder and response rate automatically — producing a continuous evidence trail rather than a snapshot. Employers with Mexican operations can use the same programme for the formal record; see NOM-035 and ISO 45003 compliance software for how the two map together.

General information, not legal advice. This page describes ISO 45003 in general terms and does not constitute legal, medical or compliance advice. ISO 45003 is guidance; it is not a certifiable requirement, and nothing here should be read as a statement that any organization is certified against it. Consult qualified counsel or an occupational health specialist for decisions about your program.

Common questions

Can a company be certified to ISO 45003?

No. ISO 45003 is a guidance document, not a certifiable requirements standard, so there is no certification against it. Organizations can accurately say their psychosocial risk management is aligned with or informed by ISO 45003, and support that with evidence of hazards identified, assessments run, controls applied and reviews completed. ISO 45001 is the certifiable management-system standard it accompanies.

Is ISO 45003 required in the United States?

No US regulation requires ISO 45003 or a psychosocial risk survey. Employers use it because OSHA's General Duty Clause obliges them to address recognized hazards and the NIOSH Total Worker Health framework treats psychological and organizational factors as conditions to assess. ISO 45003 provides a recognized structure for meeting those broader expectations and documenting due diligence.

How is ISO 45003 different from NOM-035?

ISO 45003 is voluntary international guidance that describes how to manage psychosocial risk. NOM-035-STPS-2018 is a mandatory Mexican standard with defined obligations, headcount tiers, prescribed reference guides and records that STPS inspectors can ask to see. The subject matter overlaps heavily, so one well-designed monitoring programme can serve both.

Build the evidence trail ISO 45003 expects

Aligned templates, anonymous responses, team-level risk scoring and automatic documentation. 14 days free, no credit card.

Start Free Trial →

Or see the compliance workflow.