Key takeaways
- Treat the audit as a diagnostic. An HSE psychosocial risk audit checklist shows where wellbeing gaps drain productivity, not just where compliance falls short.
- Start with an HSE internal audit. Map your policies, EAP utilisation, absence data and exit interviews against the six HSE domains before inspectors do it for you.
- Evidence beats intention. Inspectors want documented proof that controls are in place, working and sustained over time.
- Bring leaders the numbers. Workers who want better mental health support lose 49.9 days of productivity a year, which makes psychosocial risk a board conversation.
- Connect support rather than stack it. Integrated wellbeing support can help close the gap for the 20 per cent of workers in the UK who rate their employer's mental health support as poor.
Most HR leaders within UK organisations know psychosocial risk matters. Far fewer can demonstrate they're managing it. That gap now separates organisations that receive an improvement notice from those that present a defensible audit. In 2026, the Health and Safety Executive (HSE) has moved from signalling intent to issuing enforcement action and the consequences of being unprepared are no longer theoretical. A working HSE psychosocial risk audit checklist is now one of the most useful tools an HR team can have.
The stakes go well beyond enforcement. The HSE also reports that stress, depression or anxiety account for 52 per cent of all work-related ill health in Great Britain. An audit failure is rarely just a paperwork problem. It usually points to a workforce health problem.
As enforcement continues, the questions HR leaders responsible for compliance are working through become:
- What are the real consequences of HSE non-compliance?
- What does enforcement action look like in practice?
- How do you prove your controls are working, not just in place?
- Where do you start if your organisation is early in this journey?
The positive aspect is that preparing for an audit isn't about building from zero. It's about taking the infrastructure that likely already exists in your organisation, such as your policies, your data and your employee feedback, and ensuring it's documented, maintained and connected to tangible action.
Three steps to audit readiness
Step 1: Conduct an HSE internal audit against the six domains
You can begin by reviewing all existing policies, procedures and practices against each of the six HSE domains. Employers with five or more workers must carry out a stress risk assessment and document it. Cross-reference your employee assistance programme (EAP) utilisation data, exit interview themes, grievance records and your incident register to map your likely risk profile and identify hazards.
Strong audits combine quantitative data, qualitative engagement and physical observation. Think of this as one of the compliance audit health checks you run before external inspectors arrive. It gives you an evidence-based picture of where your exposure points are before anyone else identifies them for you.
“There are ways of mapping your EAP utilisation to categories of psychosocial hazard to get a picture of what your likely hazard profile looks like.”
- Oliver Brecht, Vice-president, Center for Organizational Effectiveness
This step is diagnostic. You aren't looking for perfection. You're looking for gaps. These are the areas where you have a policy but no evidence it's being used, or where you have data (like absence patterns) but no corresponding investigation.
National data can help you benchmark what you find. For example, according to the TELUS Mental Health Index (MHI) 32 per cent of workers in the UK face high mental health risk, and sub-scores show elevated strain for anxiety and isolation (Q1 2026). If your internal numbers look much healthier than the national picture, assess whether employees feel safe reporting concerns before you celebrate.
For each domain, ask:
- Do we have documented processes in place, such as job design frameworks, escalation procedures and role clarity tools?
- Does evidence exist that these processes are in active use?
- Do surveys and focus groups show whether policy matches lived experience, and do other data points such as EAP utilisation, absence rates and turnover signal a gap between policy and practice or broader hazards?
This HSE internal audit takes time. It gives you a realistic baseline and prevents you from discovering gaps later, under inspection.
Step 2: Build stakeholder understanding before demanding action
The most common mistake at this stage is jumping too quickly to “we need to act now.” Give leaders space to understand what psychosocial risk means for their teams before asking them to commit to action.
Leadership buy-in is more than an intellectual exercise. Senior leaders who lack genuine will to act will stall progress regardless of how well-designed your policies are.
Use your internal audit findings to start a conversation. Show your leadership team:
- Your current risk profile, based on exit interview themes and absence patterns.
- The gap between primary (removing the hazard at source), secondary (policies and systems that reduce risk) and tertiary (support for individuals already affected) controls.
- The legal position and what enforcement now means for your organisation specifically.
Concrete numbers can help move boards faster than principles. According to the MHI, workers who want better mental health support from their employer lose 49.9 days of productivity per year. Framed that way, psychosocial risk stops being a compliance line item and becomes a productivity conversation. Staying close to employee wellbeing trends can give leaders the wider context behind your internal findings.
Help leaders understand that this isn't about creating new programmes. It's about connecting the work you're already doing into a coherent, evidenced, defensible system.
Step 3: Conduct a formal psychosocial risk assessment with employee consultation
Once you have internal data and stakeholder engagement in place, conduct a formal HSE psychosocial risk assessment with employee consultation built in; ISO 45003 provides guidance for managing psychosocial risks within an occupational health and safety management system.
Leaders consistently perceive psychosocial risk differently from how employees experience it. Employee consultation is both a regulatory requirement and the foundation that gives your risk profile legitimacy.
Use validated HSE audit tools, such as structured surveys mapped to the six management standards, to capture both qualitative and quantitative risk data, including through focus groups. The assessment should examine psychosocial hazards and psychosocial factors such as work demands, workload and pace, including tight deadlines, heavy workloads and staffing issues, to help prevent work related stress. Having your infrastructure in place before you run the assessment, such as your incident reporting pathways, your stakeholder engagement and your initial findings, means you can respond to the results far more quickly. The assessment becomes a starting point for action.
The HSE audit preparation framework
For each psychosocial control you have in place, ask three questions and push for documented evidence at each level; in the same way as other safety reviews, control measures should identify risks by matching fixes to the specific psychosocial hazards found in the audit, with existing controls aimed at the source rather than only general resilience support:
- What controls are in place for the hazard identified?
- Is the risk control working?
- Is the measure sustained and meaningful?
Then prioritise identified risks using likelihood, severity and employee exposure.
Where your organisation sits on the mental health and wellbeing continuum
Your HSE psychosocial risk audit checklist does more than confirm compliance. It shows how mature your approach is across workplace culture, work design and psychological safety, supporting psychological health, mental wellbeing and stronger organisational performance.

Audit preparation example: job demands and psychosocial hazards
What controls are in place?
You might demonstrate a workload review process for all teams as a way to assess work demands, identify hazards and spot common psychosocial hazards in job design, work methods and other aspects of how work is organised, such as tight deadlines or staffing pressure. This should be handled as systematically as more familiar physical hazards and other safety risks. You can show the policy, meeting records and the calendar invitations as evidence this happens regularly.
Is the control working?
You can show evidence by demonstrating that overtime hours and workload-related EAP presentations have decreased compared to the same period last year. This will showcase whether controls reduce stress and pressures. Reviewing early signs in absence data or EAP trends can also help assess whether the control is working.
Is the measure sustained and meaningful?
Workload reviews might happen quarterly. If so, the scheduled reviews should be formally logged, the outcomes documented and each follow-up action plan should be tracked with a clear owner, deadline and measure of effectiveness.
The goal is clarity, showing how risks are identified, addressed and measured over time. Continuous monitoring and review keep the process responsive as conditions change.
What happens if an HSE audit finds non-compliance?
If an HSE audit finds your organisation unable to demonstrate adequate psychosocial risk management, there are five possible outcomes.
- Financial penalties: There's no upper limit on fines in the UK. HSE enforcement notices for psychosocial risk failures are also now being issued, with the East of England Ambulance Service receiving a Notice of Contravention in April 2025 under the Management of Health and Safety at Work Regulations 1999.
- Criminal liability: Where a serious incident such as a suicide connects to organisational negligence, directors and managers face personal criminal liability.
- Operational changes: The HSE can mandate changes to the working environment and to how your organisation carries out work. This creates significant financial and operational disruption.
- Reputational damage: The HSE publishes enforcement notices and non-compliance orders publicly. This damages your ability to win contracts and attract and retain talent.
- Insurance consequences: UK employers' liability premiums connect directly to claims history. As mental health claims rise in volume and complexity, and poor management can also contribute to physical ill health, insurers treat psychosocial risk management as a material underwriting factor. Organisations with poor claims records face higher premiums at renewal and potential difficulties securing cover.
Non-compliance often reflects unmanaged psychosocial hazards and broader safety risks, not just missing paperwork.
A closer look at HSE enforcement action
The HSE operates under an Enforcement Management Model that gives inspectors discretion to issue an improvement notice, a prohibition notice or proceed directly to prosecution depending on the severity and circumstances of the breach. There's no guaranteed sequence.
In practice, for organisations with no prior enforcement history and where no serious incident has occurred, an improvement notice requiring remedial action within a defined timeframe is the more common first outcome. But this is inspector discretion, not a right. The cost of investigation, management time and remediation at that stage significantly exceeds the cost of acting before any notice arrives.
What HSE inspectors expect every employer to have ready
In a recent webinar hosted by the Centre for Organisational Effectiveness, experts were asked to name the single most important thing every organisation should have ready. Their answers, taken together, form a complete picture:
“Organisations should be able to answer four basic questions: What are your risks? What controls do you have in place? Do you have a delivery partner supporting these changes? And how are you monitoring whether those controls are working?”
— Leona Thomson, Vice President of Global Learning Operations at The Centre for Organizational Effectiveness
“Leadership needs to move beyond agreement to show clear, visible commitment in action. When leaders demonstrate this consistently, it sets the tone for the wider organisation and enables meaningful progress.”
— David Stace, Director of Clinical Policy at The Centre for Organizational Effectiveness
“Clear, consistent documentation is a critical foundation. Without documentation, it becomes harder to demonstrate what is in place. Applying a ‘prove it’ approach ensures every control can be evidenced in multiple ways.”
— Oliver Brecht, Vice President at The Centre for Organizational Effectiveness
Closing the support gap after your HSE audit
An audit tells you where your gaps are. Closing them is where the value sits. According to the MHI, 20 per cent of workers in the UK rate their employer's mental health support as poor. If your audit shows support that exists on paper but isn't used, that's a signal to connect your EAP, absence data and manager training into one workplace wellbeing strategy rather than adding more siloed programmes.
Integrated employee health and wellbeing solutions make it easier to showcase that support is accessible, used and working. That's exactly what inspectors ask you to prove.
An HSE audit for psychosocial risk isn't a future possibility. For UK organisations, it's a question of timing. The organisations best placed aren't the ones with the most policies. They're the ones that document, evidence and prove three cuts deep that their controls are in place, working and sustained.

Psychosocial Risk Enforcement and Your Legal Obligations
Watch the on-demand webinar to hear directly from Oliver Brecht, David Stace and Leona Thomson on what the HSE is looking for and how to build a defensible audit-ready programme.
Watch the on-demand webinarFrequently asked questions
What is psychosocial risk management?
Psychosocial risk management is about identifying and controlling psychosocial factors in the workplace that affect employee mental health and wellbeing. Psychosocial hazards are aspects of work design, management and social relationships that can harm mental wellbeing and psychological health. This includes workload, role clarity, management support, workplace relationships, bullying and organisational change, as well as pressures such as tight deadlines. The HSE now requires organisations to manage these risks as part of their health and safety obligations.
Do we need to create new programmes to be audit-ready?
No. Audit readiness is about connecting the work you're already doing—your policies, EAP data, absence data and employee feedback—into a coherent, evidenced system. You're documenting and proving what exists, not starting from scratch.
What should an HSE psychosocial risk audit checklist cover?
It should cover the six HSE management standards (demands, control, support, relationships, role and change), evidence that controls exist and are used, employee consultation records, incident reporting pathways and documented responses to every concern raised. A strong checklist also covers leadership commitment, worker consultation and risk identification in the same way as other workplace hazards are assessed. Beyond compliance, it works as a diagnostic that shows where wellbeing gaps are draining productivity.
What HSE audit tools should UK HR leaders use?
Effective HSE audit tools include a risk assessment framework aligned to the six management standards, employee pulse surveys benchmarked, focus groups, grievance records, EAP utilisation mapping and structured exit interview analysis. Data collection should combine quantitative data, qualitative engagement and physical observation, including where flexible working may affect exposure and controls. Run compliance audit health checks quarterly and a full HSE internal audit annually so controls stay current.
What happens if an HSE audit finds non-compliance?
Possible outcomes include financial penalties (with no upper limit in the UK), criminal liability for directors and managers, mandatory operational changes, reputational damage through public enforcement notices and increased insurance premiums due to poor claims history.
How do we prove our controls are working, not just in place?
For each control, gather three types of evidence: 1) what controls exist and are documented, 2) data showing the control is having an effect (such as reduced overtime hours or lower EAP presentations), and 3) evidence the control is sustained over time (such as scheduled reviews and tracked outcomes).




