Key takeaways
- HSE inspections now cover psychosocial risk. Audits can be reactive or proactive, no advance notice is required and enforcement applies to every employer regardless of size or sector.
- The six management standards set the bar. Job demands, job control, support, relationships, role clarity and organisational change management form the legal framework inspectors measure you against.
- Evidence matters more than intent. Inspectors want a current risk assessment, documented actions, live reporting pathways and a recorded response to every concern raised.
- An EAP alone won’t pass an audit. Primary and secondary controls, like redesigning work and building escalation systems, must sit alongside tertiary support.
- Manager readiness is the weak link. UK managers score just 2.9 points above non-managers on the TELUS Mental Health Index, so audit findings only drive change when managers are trained and supported to act.
The Health and Safety Executive (HSE) is taking a more active role in how organisations manage psychosocial risk. While expectations around employer responsibility haven’t fundamentally changed, what’s different now is how closely those expectations are being monitored and enforced. For many HR leaders, preparing for an HSE psychosocial risk audit has become a board-level priority.
The scale of the challenge is clear. According to the TELUS Mental Health Index (MHI), 32 per cent of UK workers have a high mental health risk and 54 per cent work at least one day a week while feeling unwell.
As David Stace, Director of Clinical Policy and Best Practice, Centre for Organizational Intelligence puts it: “The question is whether organisations will act before the crisis actually happens.”
The HSE now focuses on what organisations can evidence in practice, not what they claim to be doing. As enforcement continues, the questions HR leaders are asking become:
- What triggers an HSE audit and could it happen to us?
- What does the inspector want to see?
- Where do most organisations fall short?
The six HSE management standards every UK employer must assess
The HSE’s Management Standards define psychosocial risk across six core domains. These are the legal framework against which organisations are now being inspected. The HSE made this unambiguous in its 2024/25 Annual Report: “In the coming year, our inspections will consider how employers are preventing psychological as well as physical ill health.”
Under the Health and Safety at Work Act 1974 and related work regulations, employers have a legal duty to protect workers’ mental as well as physical health, supported by safety at work regulations under the wider work act. ISO 45003 provides guidelines for managing psychosocial risks as supporting guidance alongside the HSE framework.
The six domains of psychological safety
- Job demands: Workload, working patterns and complexity must be appropriately balanced with the time and resources available. This includes fatigue management and shift spacing.
- Job control: The level of autonomy employees have to apply their expertise, make decisions and manage how they complete their work.
- Support: Manager availability and presence, plus access to the resources employees need to do their jobs, including training, technology and time.
- Relationships: Whether workplace relationships are constructive, conflict is actively managed rather than condoned and space exists for the healthy subject-focused debate that sound decisions require.
- Role clarity: Whether employees clearly understand what is expected of them, what their role is and what outcomes they are accountable for; unclear expectations can raise stress levels when roles and outcomes are not clearly defined.
- Organisational change management: When change happens, whether employees are adequately supported, informed and given what they need to navigate it.
These six domains aren’t aspirational. They’re the minimum framework against which your organisation’s approach will be measured. These management standards help identify common psychosocial hazards that can cause psychological injury, including stress and burnout. Together, they form the psychosocial risk management standards UK employers are now inspected against, with direct implications for mental wellbeing and psychological health in the working environment.
How does an HSE psychosocial risk audit get triggered?
HSE audits for psychosocial risk are triggered in one of two ways: reactively, in response to an incident or complaint, or proactively, as part of planned enforcement activity. Both routes are live and neither requires advance notice.
Reactive triggers
- An employee files a complaint or notification directly to the HSE citing unsafe working conditions, psychosocial hazards, risks and work related stress after a near miss
- A workplace incident occurs and prompts a formal HSE investigation
- A pattern of absence data or near miss reporting can point to stress risk, lost productivity, and closer scrutiny
Proactive triggers
- The HSE can arrive unannounced at any organisation, at any time
- Any proactive inspection, even one that begins with physical hazards, will include a psychosocial risk component; inspections do not stop at physical ones and increasingly examine psychosocial risks too.
- The HSE targets inspections on areas of greatest risk, but its enforcement powers apply to all employers regardless of size or sector.
For HR leaders, the real question is whether your organisation can demonstrate compliance across the full workplace environment when an audit happens.
What inspectors look for in an HSE workplace mental health audit
When the HSE arrives, whether reactively or proactively, inspectors assess four specific things. If you can’t evidence all four, you have a compliance gap.
1. A completed psychosocial risk assessment across all six domains
The assessment must be recent enough to reflect your current organisation. A credible set of stress risk assessments usually draws on anonymous staff surveys and existing organisational data analysis. Many organisations use the HSE Stress Indicator Tool to gather consistent audit data. If you completed an audit and subsequently carried out a major restructure, that assessment may no longer reflect what employees are actually experiencing. Presenting a pre-restructure assessment post-restructure is not a defence. It may actually increase your exposure by demonstrating that the assessment process exists but was not maintained.
2. Documented evidence that the assessment led to tangible action
The HSE needs to see that your assessment transitioned into documented action plans and practical control measures across all three levels of intervention:

Effective action planning should involve employee engagement so interventions are designed collaboratively with employees.
Organisations that can only evidence tertiary measures are demonstrating a reaction to the risk rather than control of it, and they are not doing enough to manage psychosocial risks by tackling root causes instead of relying on one off initiatives.
3. Live reporting pathways feeding into an incident register
Employees must have a clear, accessible route to flag psychosocial concerns, near misses and incidents. Those reports must feed into an active incident register. A spreadsheet that has not been updated in 18 months unfortunately may not hold up under inspection.
4. A documented response to every notification
Every complaint or concern raised must have a corresponding investigation record. Even if a complaint is unfounded, there must be a documented record of the appropriate level of investigation and what the outcome was. This is where most organisations often have a significant gap. Informal responses leave no trace and no trace means no defence.
Where most organisations fall short
The single biggest mistake organisations are making right now is focusing almost entirely on tertiary measures. Employee assistance programmes, individual counselling and wellbeing initiatives are valuable, but they are not a nice-to-have substitute for prevention embedded in everyday risk management. They are like offering a hard hat instead of preventing things from falling on people’s heads.
If your organisation handled chemicals, a regulator would not accept a shower in the corner as the only safety measure. They would want to see resource allocation across prevention measures first, so people are isolated from the hazard and chemical handling practices limit the opportunity for a spill, and only then that a response mechanism exists if something goes wrong.
Psychosocial risk management follows exactly the same logic. Regulators want to see evidence of all three levels. Organisations that skip primary and secondary controls, the changes to how work is actually designed and managed to address underlying factors such as workload and work life balance, are leaving themselves exposed to both enforcement action and the ongoing psychosocial risk they are not actually reducing.
The business cost of psychosocial risk
Getting this wrong is expensive: 8.5 million workers in the UK feel their work environment harms their mental health. TELUS Mental Health Index data shows that more than a quarter of workers in the UK have a mental health score of 50 or lower, and this group loses nearly two and a half times as many workdays through absenteeism, with clear effects on productivity and employee wellbeing, than workers with scores of 80 or higher (Q1 2026).
For a 500-employee organisation with 32 per cent of workers at high risk, that represents a serious drag on output. Regular audits and effective psychosocial risk management can help reduce turnover while improving team collaboration and resilience. Plus, strong psychosocial risk management helps protect both your people and your bottom line. Organisations with a strong psychosocial safety climate can save significant costs annually while still supporting innovation.
Closing the gap between audit findings and manager action
An HSE workplace mental health audit tells you where the stress risk and other psychosocial risks sit, but your managers determine whether anything changes. That’s where many organisations hit a wall. According to the MHI , managers in the UK score 66.4 for mental health, just 2.9 points above non-managers at 63.5. This highlights that the people expected to spot early warning signs and act on audit findings are often under strain themselves.
Here are three steps help close this gap:
- Set clear escalation protocols: Connect specific audit domain flags to standardised responses so managers know exactly what to do when a risk appears.
- Train managers to spot early indicators: Teach them to recognise signs that demands are exceeding control, including signs of work-related stress, such as micro-absences, communication drop-offs and missed deadlines.
- Build continuous feedback loops: Track quarterly shifts in wellbeing metrics after primary and secondary interventions to show what’s working, avoid one-off initiatives and review whether interventions are improving mental wellbeing.
Psychosocial risk management works best when prevention, early intervention and crisis support all connect. Learn how TELUS Health’s employee health and wellbeing solutions can help UK employers build all three levels of control and stay ready for inspection.

The UK HSE 2026 Compliance
Access a one-page reference covering your six required domains, legal obligations and best practice steps under HSWA 1974 and MHSWR 1999.
Access the free checklistFrequently asked questions
What's the difference between a reactive and proactive HSE audit?
A reactive audit is triggered by a specific incident, complaint or pattern of absence data that flags an organisation for scrutiny. A proactive audit is an unannounced inspection the HSE conducts as part of planned enforcement activity. Both routes are live and either can happen to any organisation, at any time, regardless of size or sector.
How often must an HSE psychosocial risk assessment be updated?
Review your assessment at least annually and immediately after any significant operational change, such as a restructure, a major technology rollout or a team consolidation. Presenting an outdated assessment during an inspection may actually increase your exposure by demonstrating that the assessment process exists but wasn’t maintained.
What are the six HSE Management Standards and why do they matter?
The six HSE Management Standards are: job demands, job control, support, relationships, role clarity and organisational change management. These form the legal framework the HSE uses to assess your organisation during inspection. They aren’t aspirational. They’re the minimum standard against which your approach will be measured.
Is an employee assistance programme (EAP) enough to pass an HSE audit?
No. EAPs and individual counselling are tertiary measures that support people after a problem has occurred. The HSE expects to see all three levels of intervention: primary controls that remove or redesign the hazard at source, secondary controls that reduce risk through policies and systems and tertiary controls that support affected individuals. Relying only on an EAP leaves you exposed to enforcement action.
What’s the difference between primary, secondary and tertiary controls?
Primary controls remove or redesign the hazard at source, for example restructuring workloads or clarifying roles. Secondary controls are policies, systems and practices that reduce risk, such as escalation frameworks and realistic deadline setting. Tertiary controls support individuals who have been affected, including EAP access and occupational health referrals. The HSE expects evidence of all three.
How can we prepare for an unannounced HSE inspection?
Keep an up-to-date psychosocial risk assessment covering all six Management Standards. Document the primary and secondary controls you’ve put in place in response to its findings. Maintain active escalation logs showing that every employee concern was formally investigated and resolved. If these three things are in order, an unannounced visit becomes far less daunting.



