Psychosocial & people risk
Workload, role clarity, support, conflict, change fatigue and burnout — the human side of risk.
One live risk register across WHS, psychosocial, operational and compliance risk. ISO 31000 aligned workflows, controls that are actually tested, and board-ready evidence that's time-stamped as the work happens — because looking after your people properly should never need reconstructing after an incident.
Risk domains
Aligned
Audit trail

One source of truth
Every risk, control and treatment action — owned, dated and defensible.
Australian risk software backed by industry recognition












What it is
Enterprise risk management software gives an organisation one system to identify, assess, treat, monitor and report risk — replacing disconnected spreadsheets with a live register that leadership, WHS, HR, operations and the board all read from.
Flourish360 adds the part most ERM platforms miss: the people. Australian WHS law now treats psychosocial hazards with the same seriousness as physical ones, yet most registers still score people risk from an annual survey. We measure it continuously and gently, as people grow and lead better day to day, and feed that straight into the enterprise register alongside every other risk domain.
Your people grow. Your risk becomes evidence, not opinion.
Live register
Always current
ISO 31000
Lifecycle by design
Board-ready
Export on demand
Register snapshot
Workload & fatigue — night shift
Owner: Ops Manager
Contractor induction currency
Owner: WHS Lead
Role clarity after restructure
Owner: People & Culture
Chemical handling competency
Owner: Site Supervisor
Bullying & conduct signals
Owner: Exec Sponsor
Illustrative view. Ratings, owners and appetite bands are configured to your framework.
Boards are now asked what they knew, when they knew it, and what they did about the people affected. A register that only updates before a quarterly meeting can't answer that — and regulators, insurers and courts increasingly assume that what wasn't recorded didn't happen.
Maximum WHS Category 1 penalty per offence under the model WHS Act
Source: Model WHS Act
Annual cost of work-related injury and illness to the Australian economy
Source: Safe Work Australia
Mental health related workers' compensation claims are work-pressure or harassment driven
Source: Safe Work Australia
Median time lost for a psychological injury claim versus a physical injury claim
Source: Safe Work Australia
The enterprise gap: most organisations manage physical risk in a system and people risk in a once-a-year survey. The hazards that generate the longest claims, and cause the most human harm, sit in the second category — psychosocial hazards.
Risk domains
Enterprise risk is only useful when it's enterprise-wide. Flourish360 holds safety, people, operational and compliance risk in the same taxonomy, scored on the same matrix — so no one falls through the gap between systems.
Workload, role clarity, support, conflict, change fatigue and burnout — the human side of risk.
Physical hazards, incidents, near misses, contractor and site risk.
Process failure, capacity, supply chain, business continuity and key-person risk.
WHS duties, training currency, privacy obligations and industry-specific rules.
Skill gaps, expired certifications and training that was completed but never really landed.
Conduct, grievance patterns, leadership signals and how people feel about coming to work.
The workflows risk, WHS and people leaders actually run — without the six-month implementation that legacy GRC suites demand.
One register across WHS, psychosocial, operational, compliance and people risk — with owners, ratings, appetite thresholds and a full, honest change history.
Likelihood and consequence scales, inherent versus residual scoring and appetite bands configured to your framework, not a vendor default.
Every control has an owner, a test cadence and an effectiveness rating — so 'we have a control' becomes 'the control works, for our people'.
Continuous, private signals from your people surface emerging risk before it turns into an incident, a claim, or someone quietly leaving.
Assign, track and escalate treatment plans with due dates, reminders and automatic escalation, so nothing that matters gets left behind.
Heatmaps, top-risk movement, control coverage and trend packs export on demand for executive, board and audit committee reporting.
How it works
01
Configure your matrix, appetite bands and risk taxonomy so scoring reflects how your organisation actually makes decisions.
02
Import existing registers and layer continuous, private signals from your people so hazards surface from real life, not just workshops.
03
Assign controls and treatment actions with owners, dates and effectiveness tests — escalating automatically when they slip.
04
Live heatmaps, appetite breach alerts and board-ready packs, with every change time-stamped for audit.
Why Australian organisations are retiring the register spreadsheet and the annual survey in the same move — and giving their people a better experience along the way.
Risk register
Spreadsheet updated before board meetings
Live register with full audit trail
Psychosocial risk
Annual engagement survey
Continuous, private leading indicators
Controls
Listed, rarely tested
Owned, tested and rated for effectiveness
Escalation
Depends on someone noticing
Automatic on overdue or appetite breach
Board reporting
Rebuilt manually each quarter
Exported on demand, always current
Evidence at audit
Reconstructed after the event
Time-stamped as work happens
Buyer questions
Straight, honest answers to the questions Australian risk, WHS, HR and executive teams ask before choosing an ERM platform.
Enterprise risk management software (ERM software) is a single system for identifying, assessing, treating, monitoring and reporting risk across an entire organisation. Instead of separate spreadsheets for WHS, psychosocial, operational, compliance and people risk, an ERM platform holds one live risk register with owners, controls, treatment plans, due dates and an audit trail — so leadership and the board see the same honest picture, at the same time.
A spreadsheet records risk at a point in time and depends on someone remembering to update it. Enterprise risk management software keeps the register live: controls have owners and review dates, signals from your people feed ratings automatically, overdue actions escalate, and every change is time-stamped. When a regulator, insurer or auditor asks what you knew and when, the system answers instead of your inbox.
Five things: alignment to ISO 31000 and the model WHS Act (including psychosocial duties), a configurable risk matrix that matches your appetite, control effectiveness testing rather than tick-box controls, leading indicators that surface risk before it reaches someone, and board-ready reporting you can export without rebuilding it in slides.
It must. Since the model WHS Regulations were amended, psychosocial hazards carry the same duty to identify, assess, control and review as physical hazards. Most legacy ERM tools were never designed with people in mind. Flourish360 treats psychosocial hazards as first-class risk objects — workload, role clarity, support, bullying, change management — measured continuously, with care, and pushed straight into the enterprise register.
ISO 31000 asks for a structured, repeatable process: establish context, identify risk, analyse, evaluate, treat, monitor and communicate. Flourish360 builds that lifecycle into the everyday workflow, so evidence of good practice becomes a natural by-product of the work — not a scramble before an audit.
Risk and compliance leads maintain the register and controls; WHS and HR care for psychosocial and people risk; operations and site managers close out treatment actions; executives and the board see heatmaps, appetite breaches and trend reporting. Role-based access means each group sees what it needs, while people's individual data stays private.
Most Australian mid-market organisations are live on a first register within weeks, not quarters — importing existing registers, mapping your matrix and appetite, and configuring escalation rules. Psychosocial measurement typically starts in the same window because it runs on short, private pulse cycles that people actually want to complete, rather than a long annual survey.
It cannot remove exposure, but it changes what you can prove. Demonstrated hazard identification, dated controls, evidence of review and documented treatment are exactly what regulators, insurers and courts look for when assessing whether an organisation took reasonably practicable steps to look after its people. Undocumented diligence looks identical to no diligence.
See the live enterprise risk register, control effectiveness testing and psychosocial leading indicators in a 30-minute walkthrough.
See the risk register live
30 min · ISO 31000 aligned