How to Build a Psychosocial Risk Register: Templates and Best Practices

How to Build a Psychosocial Risk Register: Templates and Best Practices

Luke Giuseppin

Luke Giuseppin

A psychosocial risk register gives you one place to manage psychosocial hazards the same way you manage any other WHS risk. You capture the hazard, the evidence, the risk rating, the controls, the actions, and the review cycle. Many organisations start with a general spreadsheet risk register because it feels quick and familiar. It often falls over when ownership changes, reviews slip, and evidence ends up scattered across folders.

ReFresh keeps the register alive as a system. ReFresh can act as your incident reporting software, your confidential intake channel, your survey system, your risk register, your control and evidence tracker, and your governance reporting layer. You get one connected workflow instead of six disconnected tools.

Regulatory and duty context across locations

Across Australia, the UK, Canada, and other mature WHS environments, the expectation stays consistent: identify hazards, assess risk, implement controls, consult workers, and keep records that show you did the work.

In Australia, Safe Work Australia states that a PCBU must eliminate psychosocial risks, or if that is not reasonably practicable, minimise them so far as is reasonably practicable.

In the Commonwealth jurisdiction, Comcare describes psychosocial hazards as aspects of work with the potential to cause psychological or physical harm, and points to the Managing Psychosocial Hazards at Work Code of Practice 2024, which identifies 17 psychosocial hazards.

In the UK, HSE states employers have a legal duty to protect workers from stress at work by doing a risk assessment and acting on it.

ISO 45003 provides a global management-system style approach for managing psychosocial risk within an OH&S management system based on ISO 45001.

The register sits at the centre of all of this. When an inspector or auditor asks how you manage psychosocial risk, the register is usually the first document they want to see, because it shows in one place whether you have identified hazards, rated them honestly, controlled them proportionately, and kept the cycle turning.

What counts as a psychosocial hazard

A psychosocial hazard is anything about work that could cause psychological harm. Safe Work Australia lists common hazards including job demands, low job control, poor support, lack of role clarity, poor organisational change management, poor organisational justice, traumatic events or material, remote or isolated work, poor physical environment, violence and aggression, bullying, harassment, and conflict or poor workplace relationships.

Hazards can combine. Workload risk increases when people can't take breaks or can't access help. A team carrying high job demands with strong supervisor support and clear priorities sits in a very different risk position to a team carrying the same demands with an absent manager and shifting expectations. Build that reality into your ratings and controls rather than assessing each hazard in isolation.

What a psychosocial risk register includes

Use a structure that forces evidence, controls, owners, and review: date issue raised, hazard or situation, information sources, harm consequences, harm likelihood, level of risk, controls in place, adequacy of controls, further controls required, actioned by and comments, date completed, monitoring and review method, and review date.

Each column exists for a reason. The information sources column stops entries being based on one person's opinion. The adequacy column forces an honest judgement about whether existing controls actually work, rather than letting their existence stand in for effectiveness. The actioned by and review date columns are what keep the register alive: without a named owner and a date, entries drift into the category of things everyone agrees are important and no one is responsible for.

Step-by-step: build the register

Step 1: Set scope, access, and confidentiality

Choose the level that matches operations: enterprise, site, function, or team. A 60-person professional services firm can run a single register. A multi-site aged care provider probably needs site-level registers rolling up to an enterprise view, because the hazard profile of one facility will differ meaningfully from another.

Decide who can see and edit the register before you populate it, not after. Workers need confidence that raising a hazard won't expose them, and leaders need enough visibility to act. Keep personal case details out of the register entirely. If an entry reads "complaint about the manager of Team X", it belongs in a case management process, not here. The register tracks hazards and system controls: "escalation pathways in Team X are unclear and complaints go unresolved" is a hazard entry; the individual complaint is not.

Step 2: Standardise hazard categories and write hazards in workplace language

Start with the standard hazard categories so your register maps cleanly to the Code of Practice and different teams describe the same problem the same way. Then write each entry in operational terms that someone outside WHS would recognise. "Job demands" becomes "queue time targets plus overtime above 10 hours weekly". "Poor support" becomes "no supervisor coverage on late shift, escalations go unanswered".

The specific version does two things the generic version cannot. It tells you exactly what a control needs to change, and it lets you verify later whether the control worked. You cannot test whether "job demands" improved. You can test whether overtime dropped below 10 hours.

Step 3: Identify hazards using evidence streams

Use at least three sources per entry: consultation outcomes, incident and complaint patterns, surveys and free-text themes, workload data (overtime, backlog, wait times), and HR trends (turnover, absence).

Each stream compensates for the blind spots of the others. Surveys capture what people will say anonymously but not what they'll report formally. Incident data captures what crossed a threshold but misses the chronic, low-grade exposures that never generate a report. Workload data is objective but silent on how the load feels. When three independent streams point at the same team or the same hazard, you have identification evidence a regulator will take seriously, and a rating you can defend.

Step 4: Rate consequence and likelihood consistently

Use your existing risk matrix rather than inventing a new one, so psychosocial risk gets compared against every other risk the organisation carries. The adjustment that matters is aligning the consequence language to psychological harm so different leaders rate the same scenario similarly. If your matrix describes consequences in terms of fractures and lost-time injuries, a site manager has no anchor for rating sustained exposure to aggression, and ratings will scatter.

Calibrate as a group. Take two or three real entries, have the leadership team rate them independently, and compare. The first round almost always produces a spread, and the discussion that closes the gap is where a shared standard actually forms. HSE tells employers to assess stress risk like other work-related health and safety risks and to act on it, and consistent ratings are what make the acting proportionate.

Step 5: Choose controls that reduce exposure and prove they work

Avoid the "training only" trap. Resilience training and EAP access are support measures, not controls, because they leave the hazard itself untouched. Start with work design and system controls: change the rostering that creates the overtime, add the supervisor coverage that closes the support gap, fix the escalation pathway that lets aggression go unanswered. Then add training and support around them. Safe Work Australia frames the duty as eliminating risk where reasonably practicable, otherwise minimising it so far as reasonably practicable, and a control that never touches the source of exposure is hard to defend under either limb.

For every control, record what evidence would show it working. If the control is a workload planning process, the evidence is overtime data trending down and survey scores on demands improving. Deciding the evidence up front is what makes the adequacy review in Step 7 honest instead of hopeful.

Step 6: Turn controls into actions and close them out

A register only works when actions land. Every further control identified in the register needs an owner by name, a due date, and a defined completion state. "Improve escalation pathways" is a wish; "document the after-hours escalation pathway, brief all late-shift staff, confirm via toolbox talk records by 5 March" is an action someone can complete and someone else can verify.

Track completion in the register itself, with dates. Overdue actions on high-rated hazards are precisely what an inspector will look for, because an identified risk with a stalled control demonstrates that the organisation knew and did not act. That is a materially worse position than not having identified the hazard at all, which is why closing the loop matters more than the elegance of the register itself.

Step 7: Review, learn, and improve

Set a standing review cycle, quarterly for most organisations and monthly for high-rated entries, and also review when work changes: restructure, peak season, new systems, incident clusters, survey spikes. Safe Work Australia notes that hazards can interact and combine, which means risk levels can shift quickly. A register reviewed annually describes the workplace as it was, not as it is.

At each review, test three things per entry: is the hazard still present, did the controls produce the evidence you defined in Step 5, and has anything changed that shifts the rating. Downgrade ratings only when the evidence supports it. A register where every entry drifts down to low over time without corresponding data is a register a regulator will read as managed for appearances.

Templates you can copy today

Template A: Psychosocial risk register headings (spreadsheet-ready)

These headings work in any spreadsheet or system. The worked example row shows the level of specificity each field should carry.

Date issue raised

Hazard / situation

Information sources

Harm consequences

Harm likelihood

Level of risk

Controls in place

Adequacy

Further controls

Actioned by

Date completed

Monitor/review

Review date

15/01/2026

High workload and unclear priorities within Customer Support during peak periods

Worker feedback survey, incident reports, absenteeism data, manager observations

Stress, burnout, reduced concentration, increased error rates, psychological injury

Likely

High

Informal workload discussions, EAP access, flexible start times

Partially adequate

Formal workload planning, clarify role priorities, regular check-ins, escalation pathway

HR Manager

05/02/2026

Monthly review using survey results, absenteeism, manager check-ins

30/04/2026

Template B: Control adequacy scale

Use a consistent three-point scale for the adequacy column, so "partially effective" means the same thing across every team and every review.

Rating

Description

Effective

Controls formally documented, implemented as designed, consistently applied, evidence of risk reduction, scheduled monitoring and review.

Partially effective

Documented or implemented but not consistently applied. Evidence of risk reduction limited or reactive. Improvement required.

Not effective

Controls absent, informal, or not implemented. No evidence of risk reduction. Immediate corrective action required.

Template C: Workshop prompts (60 minutes)

Run these prompts with a manager group or an HSR consultation session to surface hazards in operational language. Each answer usually converts directly into a register entry.

  • Where does workload spike, and what triggers it?

  • Where do people lose control over how they do the work?

  • Which roles face aggression, trauma exposure, or conflict?

  • What change landed recently, and where did communication break?

  • Where does role clarity fall apart and rework starts?

Common mistakes to avoid

  • Teams log "culture" instead of hazards. "Poor culture in operations" gives you nothing to control and nothing to measure. Use consistent hazard categories and describe the specific working condition creating the exposure.

  • Teams rely on training as the fix. Training changes what people know; it rarely changes the conditions creating the risk. Force control evidence and effectiveness reviews so support measures cannot masquerade as controls.

  • Teams skip consultation. WHS law requires consulting workers on hazards that affect them, and a register built without worker input tends to miss the hazards workers actually carry. Link consultation records to risk assessments so the register shows the duty was met.

  • Teams lose the trail across tools. Incidents in one system, surveys in another, the register in a spreadsheet, actions in email. When a regulator asks how a hazard was identified and what happened next, the answer becomes an archaeology project. Keep incidents, surveys, risk assessments, controls, evidence, actions, and reviews connected.

The register is the system, not the document

Mental health claims have risen 161% over the past decade, and in NSW the average psychological injury claim now costs $288,542. Those numbers are why regulators keep asking for registers, but they also explain why a static document misses the point. The organisations that manage this risk well treat the register as the visible surface of a working system: evidence flows in, ratings stay current, controls get tested, and actions close. Whether you run that system in a spreadsheet or a platform, the test is the same. If a regulator asked for your psychosocial risk register tomorrow, would it describe your workplace as it is today, and could you show what you did about every high rating in it?

Related reading