ISO 45003 and psychological safety: Where guidance ends and accountability begins
- 7 days ago
- 6 min read
I sat in the middle of a circle at a team event and said what I actually thought. It was an open forum, the kind an organization runs precisely so that people will speak.
The manager listened with a fixed smile, nodded once, and said nothing at all. Over the following months there were quiet maneuvers to move me off that team, and I spent that stretch looking over my shoulder at work and crying about it at home.
I used every channel the company had. Everyone I spoke to listened. Nobody was obligated to do anything, so nothing happened.
When I began building Vanguard Voices, I went looking for what already existed. ISO 45003 came closest to the territory I was trying to address, but the boundary became clear: it manages psychosocial risk. It does not create the organizational response obligation.
What ISO 45003 actually is
ISO 45003:2021 is titled Occupational health and safety management — Psychological health and safety at work — Guidelines for managing psychosocial risks. It was published in 2021 as part of the ISO 45000 family, and it is written to complement ISO 45001, the standard that sets requirements for an occupational health and safety management system.
Its argument is that psychological harm at work is not only an individual matter. How work is organized, how people are managed, how decisions get made and how colleagues treat each other all produce risk, and an organization is expected to identify and control that risk the way it would any other hazard. ISO points to factors including ineffective communication, excessive workload pressure, poor leadership and organizational culture.
The shift is in who owns the problem. An organization working with ISO 45003 stops asking how resilient its people are and starts examining what its own operating design does to them. Those are different questions, and they have different owners.
Psychological safety, psychological health, and psychosocial risk
Three terms get used interchangeably, and they should not be.
Psychological safety is Amy Edmondson's term, from her 1999 study in Administrative Science Quarterly, where she described people's “taken-for-granted beliefs about how others will respond when one puts oneself on the line.” It is a perception, usually held at team level, about what happens to you if you ask the awkward question or admit the mistake.
Psychological health and safety is broader. It covers the conditions at work that affect mental health and wellbeing: workload, organizational change, bullying and harassment, and the way concerns get handled.
Psychosocial risk management is the discipline. Identify those conditions as hazards, assess them, introduce controls, then check whether the controls actually work. ISO 45001 runs on a Plan-Do-Check-Act cycle, and ISO 45003 extends that cycle into psychological territory.
The three stack rather than compete. Edmondson tells you whether people believe it is safe to speak. ISO 45003 tells you how to manage the conditions that shape that belief. Neither one tells you what your organization owes a person once they have actually spoken.
That third question is where I have spent the last few years.
ISO 45003 psychological safety certification: can you actually be certified?
Yes and no, and the confusion here is reasonable.
Search for ISO 45003 certification and you will find certification bodies selling it. BSI's own product page is the clearest illustration of the problem. It offers three routes, one of them labeled Get Certified, leading to what BSI describes as its psychological health and safety at work scheme based on ISO 45003. The same page states that “as ISO 45003 is a guidance standard, your organization cannot be awarded an accreditation in the same way as ISO 45001,” and that “BSI offers unaccredited certification to ISO 45003 to both clients with and without ISO 45001.”
Others word it differently again. Centre for Assessment markets its service under an ISO 45003 certification heading while stating on that same page that the standard “provides ‘guidelines’, not ‘requirements’ and is not therefore certifiable in the same way as other management system standards,” and describing what it offers as recognition of the work an organization has done.
So the accurate answer is that an organization can buy independent third-party assurance against ISO 45003. It cannot obtain accredited certification the way it can against ISO 45001, and a buyer should know which one is on the certificate.
These assessments examine psychosocial risk management as a system. That is different from testing what an organization is obligated to do when one identifiable person raises one specific concern.

The accountability question after “speak up”
Most organizational effort still lands on the person doing the speaking. Be more courageous. Have the conversation nobody wants to have. Those are reasonable things to ask of people, and they put the burden on the party with the least control over the outcome.
The organization runs the investigation. It decides whether a concern is recorded, who owns it, whether the person ever hears back, and how performance and promotion decisions land in the year afterwards. An employee can supply the courage. Everything that determines what that courage costs sits on the other side of the table.
I keep returning to my own case for this reason. Nobody in that chain broke a rule. The policy existed, and so did the forum, and so did the channels, staffed by people who listened carefully and had nothing they were required to do. The system performed exactly as designed. It was designed to receive.
Two organizations that look identical
Consider two companies. Both have a speak-up policy, an annual engagement survey,
manager training, a published set of values and a reporting channel. On any audit of provision, they score the same.
In Company A, a concern is raised, logged somewhere, and acknowledged with a standard message. No named person owns it. No decision is recorded. The employee hears nothing further, and no consequence follows for the manager who let it sit.
In Company B, the same concern creates an obligation. Someone is named as owner. The response is recorded and can be reviewed later. Retaliation against the person who raised it is monitored for a defined period. An unresolved case escalates on a clock, and a repeating pattern reaches a level with the authority to act.
Both organizations can say they support speaking up. Only one can show what its systems require after someone does.
What certification would actually have to test
If a psychological safety standard is going to be certifiable, it cannot rest on declarations, and it cannot rest on asking every employee whether they feel safe. No organization is able to guarantee a feeling.
What an organization can be held to is a set of obligations that operate whether or not a particular leader is having a good week:
concerns can be raised without routing through the person the concern is about
significant concerns are recorded, and the organization can show what happened next
commitments made by leaders are tracked to completion rather than to the end of the meeting
retaliation is actively monitored rather than left to be reported voluntarily
serious or repeated failures reach a level with the authority and the obligation to act
assessment is independent, evidence-based, and repeats on a fixed cycle
certification is withdrawn when the requirements are no longer met
The last one carries most of the weight. Certification means very little if passing once means holding the badge indefinitely.
Vanguard Voices is building a public psychological safety certification, anchored to ISO 45003 and built around a different question: what must happen after someone speaks?
A working group of practitioners and researchers is pulling the first draft apart now. I build it on evenings and weekends from inside a corporate role, and nothing guarantees that a single company steps forward to be measured against v0.1.
Three questions, three layers. Edmondson asks whether people believe it is safe to speak. ISO 45003 asks how an organization manages the conditions that shape that belief. Vanguard Voices asks what the organization owes them afterwards, and whether it can prove what it did.
If you have ever raised something at work and watched every channel operate exactly as designed while nothing changed, you already know why that last question is the one that matters.
— Jessica



