✦ ISO 45003 & NOM‑035 Compliance

Always-Ready 035 File

The official Guia de Referencia III questionnaire, all 72 items in Spanish, scored and turned into an STPS-ready report with traceability, refreshed every cycle. Audit-ready in 30 days with the 035 Shield Program.

ISO 45003 — the psychosocial safety standard
NOM‑035 mandatory for Mexican workplaces (16+ employees)
The psychosocial‑risk standards

Workplace mental health
is now a recognized psychosocial risk

ISO 45003 (2021) is the international standard for managing psychosocial risk at work, and NIOSH Total Worker Health® provides the US public‑health framework. Neither mandates a specific survey — but both expect employers to identify these risks and document how they act on them. That's exactly what Bloomder produces.

Where OSHA fits in

OSHA does not require psychosocial or engagement surveys. Its General Duty Clause § 5(a)(1) does, however, oblige employers to keep a workplace free from recognized hazards — and OSHA has cited employers over excessive workloads, hostile environments, heat stress, fatigue, and workplace‑violence risk.

Following ISO 45003 with regular pulse surveys is how responsible employers surface those conditions early — and evidence their due‑diligence — before they show up in injury logs or lawsuits.

NIOSH Total Worker Health®

The National Institute for Occupational Safety and Health (NIOSH) treats worker wellbeing as inseparable from worker safety. Their Total Worker Health® framework explicitly includes psychological and organizational factors as conditions the employer should assess and manage.

Regular anonymous surveys are one of the recognized mechanisms for that assessment.

Source: CDC / NIOSH Total Worker Health® program overview.

Mexico · NOM‑035‑STPS‑2018

If you have employees in Mexico,
you're already required to do this

NOM‑035‑STPS‑2018 — the Mexican federal standard on psychosocial risk factors at work — requires employers to identify, analyze, and prevent psychosocial risks, and to document that they have done so. Non‑compliance carries fines and increases exposure in labor disputes.

What NOM‑035 requires

  • Assessment of psychosocial risk factors for all covered employees.
  • Questionnaires at defined cadences, calibrated to company size.
  • Documented action plans when risk levels exceed thresholds.
  • Records available for inspection by STPS auditors.
  • Respectful, confidential handling of individual responses.

Read the full NOM-035 compliance checklist →

How Bloomder maps to it

  • Pre‑built NOM‑035 questionnaires aligned to Guías de Referencia II and III.
  • Automated distribution on the cadence your workforce size requires.
  • Aggregated risk scoring with color‑coded thresholds.
  • Exportable PDF / CSV reports formatted for inspectors.
  • Anonymous‑by‑default responses, with auditable aggregate data.
How Bloomder helps

Four pieces of documentation
every audit will ask for

We designed Bloomder's compliance workflow with one question in mind: "If an OSHA or STPS inspector walked in tomorrow, what would they ask to see?" — and then built the Service to produce exactly that.

Expert‑built templates

ISO 45003-aligned workplace wellness templates and full NOM‑035 questionnaires, written by organizational development specialists — not recycled from a generic engagement tool.

Automated documentation trail

Every survey sent, every reminder, every completion — logged with timestamps. Who was invited, when, and what percentage responded. The audit trail regulators expect is generated automatically.

Real‑time risk signals

AI‑generated summaries surface burnout risk, disengagement, and psychosocial stress patterns at the team and department level — before they become injury or attrition statistics.

Audit‑ready exports

One click and you have PDF / CSV reports formatted for OSHA inspectors or STPS auditors, with aggregated results, trend lines, and timestamps of corrective action plans.

What Bloomder is NOT

We want to be direct about this because compliance shortcuts cause real harm:

  • Bloomder is not legal counsel. We cannot tell you whether your specific program satisfies your specific regulator in your specific jurisdiction. Consult a qualified employment lawyer or compliance advisor.
  • Bloomder does not replace safety training, hazard assessments, ergonomic evaluations, emergency response planning, or any physical inspection that OSHA, STPS, or other regulators require.
  • The employer remains the regulatory duty‑holder. Using Bloomder helps you gather, analyze, and document the psychosocial‑risk side of compliance; it does not transfer responsibility for the underlying obligations.
  • No compliance tool eliminates violations by itself. Tools document action. You still have to take it.

If you have questions about how Bloomder integrates with your overall compliance program, talk to us at [email protected].

For legal & compliance reviewers

The methodology behind "anonymous"

"Anonymous" is a legal claim, not a marketing word — and it's the specific mechanism your legal team will want verified before an STPS or OSHA audit, not just a checkbox. Here is exactly how it works.

1

One-time token issued

Each invite gets a unique, single-use token tied to the employee record — never embedded in the response itself.

2

Secure link delivery

The token resolves to the survey form. It confirms a real invited employee is responding, without re-asking for name or email.

3

Token invalidated on submit

Results for any segment stay hidden until at least 5 different people have answered — a floor that no administrator can lower.

4

Aggregate-only storage

Individual answers are stored without an identity link. Managers only ever see department/team aggregates, never a per-person record.

5

Small-group threshold

Results are only surfaced for groups above a minimum size, so a 3-person team's answers can't be reverse-engineered by elimination.

Why it matters for NOM-035 audits

NOM-035-STPS-2018 §7.1 requires that survey administration guarantee the confidentiality of individual responses. Because Bloomder stores answers without an identity link, it is structurally unable to produce an individual response record — even under an internal data request.

That matters in practice: the most common way a psychosocial-risk program gets challenged in a Mexican labor dispute is an employee alleging retaliation tied to their specific answers. If the individual record never existed, that allegation has nothing to point to.

Why it matters for OSHA

Under the General Duty Clause, employers are expected to identify hazards without creating a chilling effect that suppresses honest reporting. Because Bloomder can't expose who said what, employees have no disincentive to report accurately.

That gives you a documented, good-faith monitoring program — the kind OSHA looks for — without the retaliation-liability exposure that comes from identifiable survey data sitting in a database somewhere.

Get compliant before your next audit

14 days free. ISO 45003 & NOM‑035 templates included from day one. No credit card.

Or talk to our compliance team.