The biggest psychosocial risks are often the ones nobody is looking for.
Most organisations approaching psychosocial risk start in the same place. They look at their controls. They review the policies, the training calendar, the EAP contract, the wellbeing initiatives, and they ask whether it is enough.
It is the wrong starting question.
Before you can control a hazard, someone has to have identified it. Before it can be identified, your systems have to be capable of surfacing it. And that capability is not automatic. It has to be built.
Most organisations do not have a control problem. They have a visibility problem.
Identification is now a separate, enforceable duty
Since 1 December 2025, the Occupational Health and Safety (Psychological Health) Regulations 2025 have been in force in Victoria. They sit alongside the OHS Act 2004 as standalone regulations, and they split the psychosocial duty into three distinct obligations.
Regulation 14 requires employers to identify psychosocial hazards, so far as is reasonably practicable. Regulation 15 requires control of the associated risks, applying a modified hierarchy that puts elimination and work redesign ahead of administrative measures. Regulation 16 requires review of those controls when specific triggers occur, including changes to work, new information, incident reports or complaints, notifiable incidents, and requests from health and safety representatives.
Read that sequence carefully. Identification is not a preliminary step toward the real obligation. It is the first of three obligations, and it is enforceable on its own terms.
There is a second detail in regulation 15 that most organisations have not absorbed. Information, instruction and training cannot be the exclusive control measure unless nothing else is reasonably practicable, and where controls are combined, training cannot be the predominant one.
A psychosocial risk system that relies predominantly on awareness sessions, toolbox talks or EAP referrals should therefore be tested carefully against regulation 15. Attendance alone does not demonstrate that higher-order controls have been considered or implemented.
Which brings the weight back to regulation 14. If your identification process is weak, everything downstream inherits that weakness. You cannot design a higher-order control for a hazard you never surfaced.
The Compliance Code makes this distinction clearly
WorkSafe Victoria's Psychological Health Compliance Code is worth reading closely on this point, because its own structure separates the two activities.
Appendix C is the appendix most people cite. It lists sixteen examples of psychosocial hazards, describes what each might look like in a workplace, and offers sample controls. It sits under Step 3 of the risk management process: control risks.
The identification tool is Appendix B, and it sits under Step 1. It is a prompt list. It points you toward the records you already hold, the patterns those records might contain, the questions leaders should be able to answer, and the workforce characteristics that may increase exposure.
The Code's structure makes an important distinction. The sixteen examples can help you recognise hazards, but identification itself requires inquiry into the work, the workforce and the evidence your organisation holds. The Code also says plainly that its list of examples is not exhaustive, and that where an employer identifies another psychosocial hazard arising in their working environment, the duty to control the associated risk applies to that hazard too.
A list is a prompt. It is not a method.
Consultation is not the same thing as visibility
Good organisations still miss psychosocial hazards. Not because they do not care. Because they cannot see them.
Two organisations can both consult their workforce, both run an annual engagement survey, both hold regular team meetings, and both maintain a suggestion channel. Both can honestly say they consulted. And they can end up with completely different pictures of their own risk, because consultation designed to confirm is a different instrument from consultation designed to reveal.
The test is not whether consultation occurred.
Consultation is not evidence because it happened. It is evidence because it helped your organisation see something it could not previously see.
So the question to put to your own process is not "did we consult?" It is "what did our consultation actually help us see?"
If the honest answer is that it confirmed what leadership already believed, the process has not produced visibility. It has produced reassurance. Those two things feel identical in a board pack and behave very differently under a regulator's questioning.
We look at how to test this properly in How to Test Whether Your Consultation Process Finds Psychosocial Hazards.
Generic consultation produces generic controls
Here is the failure chain, stated plainly.
Generic consultation creates generic visibility. Generic visibility creates generic controls. Generic controls leave real exposure unmanaged.
The uncomfortable part is how normal this looks from the inside. The survey response rate is respectable. The hazard register is populated. The controls are documented, dated and assigned. The compliance box gets ticked.
And the actual exposure remains invisible.
This is not a failure of effort, and it is not a failure of the people in the workplace. It is a design failure. When an organisation concludes that workers "did not report it", the more useful question is what the system did to make reporting possible, safe and worth doing. Locating the failure in the system rather than the worker is not a soft position. It is the only position that produces a fixable problem.
Visibility has to be deliberately designed
Visibility is not something organisations accidentally achieve. It is something they deliberately design.
At Burriin, we organise the broader system around four stages.
Governance. Clear accountability for psychosocial risk, set from the top, so that identification has authority behind it rather than sitting with whoever has capacity.
Visibility. Structured identification, built for this workplace, this workforce and this work design, rather than a template applied to a list.
Action. Controls, responsibilities and evidence built from the hazards actually identified, not from a generic action plan that could belong to any organisation.
Impact. Evidence of what changed, fed back into governance, so the system improves rather than resetting every year.
Within the visibility and action stages sits a more fundamental risk-management sequence:
Visibility → Identification → Control → Evidence → Improvement.
The four stages are the operating framework. The five-step sequence is the risk logic running inside it. Both run in one direction, and neither skips a step. Break the first link and everything after it is running on assumption.
Five questions worth asking before your next review
These are the questions we find separate an organisation with a defensible system from one with a well-documented assumption.
- How do you know your identification process surfaced all the hazards present, rather than the ones easiest to name?
- What did your last consultation round reveal that leadership did not already believe?
- Which hazards on your register were identified through inquiry, and which were copied from a list?
- If a control measure is predominantly training or awareness, what made higher-order controls not reasonably practicable?
- If an inspector asked you to demonstrate how you identified hazards specific to this workplace, what would you show them?
If those questions are difficult to answer, the gap is not in your controls. It is upstream of them.
Where the gap is widest
Every consultation framework has blind spots. Some workplace experiences make those blind spots easier to see.
Mainstream psychosocial frameworks identify hazards that can affect workers broadly. They do not necessarily surface workplace exposures that arise specifically from First Nations identity, cultural responsibility, community relationships or culturally unsafe systems.
That does not make the existing frameworks wrong. It means the quality of identification still depends on whether the inquiry is capable of seeing those exposures. And the Regulations do not limit the duty to hazards a template anticipated.
This is why Burriin assesses twenty-one hazards rather than sixteen: the full Compliance Code set, plus five First Nations-specific psychosocial hazards that standard identification processes may not surface. You can read the full model, including the evidence base behind those five, on the 16+5 Model page.
The broader principle holds regardless of workforce. Identification is only as good as the inquiry that produced it.
Test your own process
We have built a short self-assessment for exactly this. It walks through whether your consultation process is identifying the full range of psychosocial hazards, or only the ones that were easiest to see.
Download: Are You Covered? A Practical Psychosocial Risk Self-Assessment
No form. No email required.
Need to test your current approach against regulation 14? Book a conversation with Burriin.
