Skip to content
Back to the blog
Psychosocial governance

Psychosocial risk is a governance problem, not a wellness perk

The risk lives in how work is organized — which is why the instrument has to read the organization, not the individual.

Conselho Editorial Eixo4 Aug 13, 2026 5 min read
Summary

Psychosocial risk at work originates in how work is designed, staffed, and led — not in individual resilience. ISO 45003 and the WHO’s 2022 guidelines both direct employers to manage it as an organizational hazard, through the same governance cycle used for any other risk: assess, set policy, act, review. Individual mental-health screening is a poor substitute: it addresses the symptom rather than the cause, and in the United States it also runs into ADA limits on disability-related inquiries and medical examinations of employees.

The spending went up. The exposure did not go down.

Employers have spent a decade adding mental-health benefits: meditation apps, EAP expansions, resilience training, wellness stipends. The spending is real. The exposure it was meant to address is largely unchanged.

The reason is structural. Those programs are addressed to the individual employee, and the risk they are meant to offset is not produced by the individual employee. It is produced by how work is organized — workload and pacing, role clarity, autonomy, schedule predictability, the quality of supervision, how conflict and change are handled, whether people can raise a problem without cost.

An app is a reasonable thing to offer. It is not a control. Offering one and calling the matter handled is the corporate equivalent of issuing earplugs and declaring the noise hazard managed.

What the standards actually ask for

Two reference documents are worth reading directly, because both are more specific than the summaries of them.

ISO 45003 — the international guidance on psychological health and safety at work — treats psychosocial factors as hazards to be identified and managed inside an occupational health and safety management system. Its subject is the work environment: demands, control, support, relationships, role, and organizational change. It is guidance, not a certifiable standard, and it does not ask employers to assess anyone’s mental health.

The WHO’s 2022 guidelines on mental health at work are more direct still. Their strongest recommendations are for organizational interventions — changes to working conditions — and they are explicit that training individuals in coping skills, on its own, is not sufficient. The evidence base points at the job, not the jobholder.

Neither document asks an employer to find out who is struggling. Both ask what in the work is producing the strain.

Why screening individuals is the wrong instrument

There is a tempting shortcut: survey the workforce, score each person, flag the ones who look at risk, route them to support. It sounds proactive. It is the wrong instrument, for two independent reasons.

It answers the wrong question. A list of individuals under strain tells you nothing about what is producing the strain. Two teams with identical distress scores can require opposite interventions — one has a staffing problem, the other a supervision problem. Aggregate readings by team, role, and site identify the mechanism. Individual scores identify people.

In the United States, it also creates legal exposure. The Americans with Disabilities Act restricts when an employer may make disability-related inquiries or require medical examinations of current employees, and the EEOC’s enforcement guidance sets out the job-related-and-consistent-with-business-necessity standard those inquiries must meet. An instrument that produces individual mental-health indicators about identifiable employees is a materially different thing, legally, from one that produces a group-level reading of working conditions — even when the questionnaire looks similar. Anything sitting near that line is worth putting in front of employment counsel before it is fielded, not after.

The engineering consequence is straightforward. If the analytical layer never resolves to an identifiable person, an entire class of legal and ethical exposure is removed at the design stage rather than managed after the fact. That constraint is not a limitation on the method. It is the method.

What governance looks like instead

Managing psychosocial risk as a hazard means running the same loop an organization already runs for any other risk class — assess, interpret, set standards, test, act, review — with named owners and dated evidence at each step.

At Eixo4 that loop is the PENSAR® method: Probe, Examine, Normalize, Simulate, Apply, Review. The letters matter less than the property they enforce: nothing is applied before it is understood, and nothing is considered finished once applied. A cycle that stops at "we ran a survey" produces a slide. A cycle that closes produces a control.

Practically, the artifacts are unremarkable and that is the point:

  • a psychosocial risk assessment covering demands, control, support, relationships, role and change
  • a written policy that says who decides what, and on what evidence
  • defined thresholds that trigger review — set before the data arrives, not after
  • intervention at the level of work design, not only at the level of individual coping
  • a review interval, with the previous cycle’s results on the table

None of this is exotic. It is what a mature safety, quality, or financial control function already looks like. Psychosocial risk is simply the domain where most organizations have not yet built one.

What belongs on the board’s agenda

Two things make this a governance item rather than an HR item.

The first is that working conditions sit inside the employer’s duty of care, and in the US the general duty clause of the OSH Act obliges employers to furnish employment free from recognized hazards likely to cause death or serious physical harm. How far that reaches into psychosocial hazards is unsettled and contested — it should not be described as a settled requirement. But the direction of regulatory attention across jurisdictions is not ambiguous.

The second is disclosure. Since the SEC’s 2020 amendments to Regulation S-K, registrants describe their human capital resources and the measures they use to manage them. An organization that manages psychosocial risk through a documented cycle has something specific to describe. One that manages it through a benefits catalog has a list of vendors.

The distinction worth holding

Psychosocial governance is not a mental-health program with a new name. It does not diagnose, does not treat, and does not track individuals. It works one layer up: on how work is organized, and on the evidence that tells you whether the organization is holding.

Support for individuals still matters, and should be available. But it is downstream. Upstream is the design of the work — and that is a decision the organization makes, whether or not it makes it deliberately.

Sensitive content (health/risk): technically reviewed. Technical review: Conselho Editorial Eixo4 — Núcleo técnico de governança psicossocial. Last reviewed on Aug 13, 2026.

Sources

Frequently asked questions

What is psychosocial risk at work?

Risk arising from how work is organized, designed, and managed — workload, pace, role clarity, autonomy, schedule predictability, supervision quality, and how conflict and change are handled. It is a property of the work environment, not of the individual worker.

Does ISO 45003 require companies to assess employees’ mental health?

No. ISO 45003 is guidance for managing psychosocial hazards within an occupational health and safety management system. Its subject is the work environment — demands, control, support, relationships, role, and organizational change — not the mental health status of individuals.

Can a US employer survey employees about mental health?

It depends on what the instrument produces and how it is used. The ADA restricts disability-related inquiries and medical examinations of current employees, and the EEOC has issued enforcement guidance on the standard those must meet. Instruments producing group-level readings of working conditions sit in a different position from those producing individual mental-health indicators about identifiable people. Any instrument near that line should be reviewed by employment counsel before it is fielded.

How is this different from an employee wellness program?

A wellness program offers resources to individuals. Psychosocial governance changes how work is organized and documents the decisions through a review cycle. The two are not substitutes: the first is downstream support, the second is upstream control.

How to cite Eixo4

Eixo4 (2026). Psychosocial risk is a governance problem, not a wellness perk. Eixo4 Blog. Available at: https://eixo4.com/blog/psychosocial-risk-is-a-governance-problem

Share this article
Núcleo técnico de governança psicossocial
Conselho Editorial Eixo4

Núcleo responsável pela curadoria técnica do conteúdo da Eixo4, alinhando norma (Lei 14.831/2024, NR-1, LGPD) e prática de governança psicossocial corporativa.

Ready to assess your organization’s maturity?

Talk to our team about where your psychosocial governance gaps are — read at group level, never exposing individuals.

Talk to a specialist