ISO 45003 keeps psychosocial risk separate from diagnosis
ISO 45003:2021 is published guidance for managing psychosocial risk within an occupational health and safety management system. It is not a clinical diagnostic standard or a software outcome claim.
Editorial figure by Safety Operations Standard. Source context: ISO — ISO 45003:2021.
Psychosocial risk belongs in the OH&S system
ISO's public abstract places psychosocial risk inside an occupational health and safety management system based on ISO 45001. That makes the operating focus work-related hazards, organizational context, prevention, controls, monitoring, and improvement rather than an attempt to diagnose an individual worker.
For an EHS program, the evidence may include work design, staffing, workload, organizational change, consultation, reported concerns, control ownership, action tracking, and evaluation. Sensitive personal information should not be collected merely because a platform can store it.
Guidance and clinical care have different boundaries
The standard's title and abstract concern psychological health and safety at work and guidelines for managing psychosocial risks. They do not authorize an employer, software provider, survey tool, or publication to diagnose a condition or make an individual treatment decision.
A buyer should separate organizational risk signals from occupational-health cases, employee-assistance services, accommodations, clinical records, and emergency response. Each has different accountable professionals, confidentiality rules, access controls, escalation paths, and evidence limits.
A feature does not establish an effective control
Surveys, anonymous reporting, case intake, action plans, analytics, and connected-worker tools may support parts of a psychosocial-risk program. Provider documentation can establish that a feature is offered; it cannot establish that workers trust it, that hazards were assessed correctly, or that controls reduced work-related harm.
The enterprise test should follow a representative hazard from identification through consultation, assessment, ownership, action, exception, follow-up, and evaluation. It should also test aggregation, anonymity, role-based access, retention, and the boundary between organizational and individual information.
Systematic review is not a new edition
ISO currently shows ISO 45003:2021 as published and also identifies a systematic review that began April 15, 2026. Those two states can coexist: the 2021 edition remains the published record while ISO considers its future disposition.
Organizations should track the review without inventing a revision, transition date, or new requirement. Any later confirmation, revision, or withdrawal needs its own authoritative status record before controlled procedures, mappings, or training materials are changed.
Enterprise buyer test
Translate this change into the exact population, record type, workflow stage, decision owner, effective date, and evidence that could be affected. Ask current or prospective providers to demonstrate the named workflow with representative data and an exception—not a polished feature tour. Record what official documentation establishes, what a provider states, what the team observes, and what remains unresolved.
A defensible review also identifies the dependency outside the product. Authority interpretation, policy configuration, data quality, integrations, human judgment, approval rights, release governance, training, and retained evidence may remain customer or service responsibilities. The evaluation should preserve those boundaries instead of treating a technology claim as the complete operating model.
What we will watch next
Safety Operations Standard will watch the named source and affected market records for later evidence that changes status, scope, availability, implementation timing, workflow consequence, or the limits of the initial report. A later announcement does not silently overwrite this dated account; the change ledger preserves the sequence.