
Working note, not a pitch
Where PsychProof fits.
Two layers either side of detection: assessing a planned change before it creates a hazard, and running the loop after one is flagged. Both on one continuous record. What follows is what it is, the problem it solves, how a pilot runs, the evidence behind the method, how it adapts to you, and what is underneath it. Written to be forwarded.
1. What PsychProof is
Restructures, new systems, AI rollouts, survey results that need acting on: every organisation has them. PsychProof is how you get through them without leaving a psychosocial liability behind. Run the change well, and the compliance record you would need in front of a board or a regulator builds itself along the way.
Most tools finish at measurement: a survey, a heat map, a report. PsychProof is what runs the loop after a hazard is flagged. Who owns it, what control was chosen, whether it was reviewed, and a timestamped record of all of it that stands on its own if a board, an inspector or a claim asks.

2. Where it sits, alongside what you already run
Two additional layers either side of what you already have, writing into one continuous record rather than a separate reconstruction exercise.
Before the change: PsychProof
Plan a Change maps a planned organisational change to its foreseeable psychosocial hazards and requires controls before rollout. Some of what would reach detection later is addressed at the design stage instead.
Detection and assessment: yours
Your survey tool, your health check, your ISO 45003 assurance and reporting. PsychProof does not touch this layer and has no ambition to.
After the flag: PsychProof
Ownership and due dates, controls tagged to the hierarchy, a monitoring cadence and effectiveness signals, escalation into a formal case. Run on the same evidentiary standard the detection layer already holds.
3. The problem, in dated facts
17,600
serious mental-health claims in 2023-24, 12% of all serious claims
+161%
growth in those claims over a decade; +14.7% in the last year alone
$67,400
median compensation per claim, against $16,300 across all serious claims
35.7 wks
median working time lost per claim
Source: Safe Work Australia, Key Work Health and Safety Statistics Australia 2025.
1 Dec 2025
Victoria's psychological health regulations commence. Training or information cannot be the main control. A change to work triggers a review.
18 Feb 2026
NSW passes the Digital Work Systems Act: work allocated by an algorithm, AI, automation or platform must not put health and safety at risk. Commencement by proclamation.
1 Jul 2026
In NSW, complying with the Code of Practice becomes a standalone enforceable duty.
23 Jul 2026
Safe Work Australia publishes AI and digital technologies guidance: intensification, surveillance and unfair decisions by systems are WHS hazards, managed the ordinary way, in every state.
2 Oct 2026
People at Work, the free survey over 5,000 organisations used, closes. Its own review cited limited guidance on what to do with the results.
4. How we help, step by step
The loop after detection. Without it, a hazard is marked actioned and the next survey cycle re-flags it a year later.
Assign
A named owner and a due date, not a queue. Owners report progress through a single emailed link, without a login.
Implement
A control chosen from a cited library, tagged to its level in the hierarchy. Training or communication alone is not accepted as the only control.
Monitor
Verification measures on a defined cadence, monthly or quarterly, against the pre-control baseline.
Verify
At review, each owner is asked whether the control was implemented and whether it worked. The measure returns a signal of effectiveness, or of failure.
Escalate
Still failing, it becomes a formal case with its own loop. Working, it closes out. Either way it is on the record, and the next survey cycle does not simply re-flag it a year later.

Three ways a pilot starts
A change is coming
A restructure, a new rostering system, an AI tool landing in a team. The Change Planner maps the hazards, seeds the controls, asks the digital work system questions if AI is involved, and shows the gaps against the Code, your state's regulation, ISO 45003 and the digital duties before the change lands.
A People at Work report with no next step
Upload it. Findings surface by team and hazard, prioritised, checked against what is already in your register so nothing logs twice. The ones you accept become cases with owners, and follow through to controls and review.
Hazards identified, controls needed
Design controls from the cited library with the hierarchy enforced, assign owners, and let the 90-day review actually happen. This is where most paper plans quietly fall over, and where a pilot proves itself.
A worked example: an AI tool landing in a team
An AI assistant is being rolled out to triage work in one team. Before rollout, the Change Planner maps the foreseeable hazards for that change type, among them high job demands, low job control, low role clarity, poor organisational justice, job insecurity and intrusive surveillance. Each carries its source: the Code of Practice, ISO 45003:2021 or a WHS Act section. Australian regulators flag AI implementation as high risk largely because workers read it as a precursor to redundancy even where none is planned.
Three controls are selected, one of them structural: worker consultation on the design of the tool itself, rather than a training session about it. What was discussed and what was agreed is logged against the plan. Because the tool allocates and scores work, the four digital work system questions are answered and a named system owner is recorded. The coverage report then shows, row by row, what is covered and what is still missing, while there is time to act.
The 90-day review closes the same loop as the five steps above. Plan a Change and the after-the-flag loop are two entry points into one evidence record, not two systems.
Every pilot starts with a 20-minute conversation and ends with a board-ready, timestamped record you keep either way. Six months, one business unit, fees credited against rollout. Full step-by-step at psychproof.com.au/psychosocial-risk-pilot.
5. Methodology and evidence basis
Built on the instruments that apply
The Safe Work Australia model Code of Practice and its 17 named hazards, each state's regulation, ISO 45003:2021 and ISO 45001:2018, and, for AI and digital systems, the Safe Work Australia AI guidance, the NSW digital work system duty and the Voluntary AI Safety Standard guardrails. Every hazard and control cites its source and an evidence tier.
Grounded in the research
The job demand-control-support model, the most replicated finding in occupational health psychology and the basis of ISO 45003 itself, and organisational justice research on why a fair process matters as much as a fair outcome. The AI and digital questions map onto the same four risks the regulator names: workload, metrics, surveillance, discrimination.
Coverage, not a questionnaire
A change plan is checked against 41 requirements drawn from those instruments. The result is derived from what the plan actually records, never from a self-assessment checkbox. Each row shows covered, weak, out of order or missing, with a recommended fix.
Control effectiveness as a structured signal
Every verification measure carries a signal of effectiveness and a signal of failure, against a pre-control baseline on a defined cadence, so "did the control work" is answered from data on a schedule rather than from a manager's recollection at the next review. The hierarchy of controls is enforced: a plan cannot be finalised on training or communication alone, because the Code does not accept that either. Victoria's modified hierarchy is applied where it applies.
6. How it adapts to your organisation
Your state
A single jurisdiction engine resolves every Australian jurisdiction, all eight states and territories plus the Commonwealth, to the exact regulatory instrument that applies. Citations change with your state; the process does not.
Your sector
Industry risk libraries for aged care, healthcare, mining, construction, manufacturing, logistics, government, education and professional services, with sector-specific hazards on top of the Code's 17.
Your scope
A pilot runs in one business unit, site or team of up to 50 people with up to ten manager accounts. Governance tiers extend the same process organisation-wide.
Your existing data
People at Work reports, COPSOQ surveys, and existing risk assessments import directly. You are not asked to start from zero.
Your capability
No specialist on staff is the normal case. The engine confirms rather than invents. For a major piece of work, independent WHS consultants in our network use the platform with their clients, with their own client view.
Your other systems
HR, incident and survey systems stay. PsychProof sits either side of them and produces the record none of them is built for. It does not duplicate intake.
7. Technology and security: the record underneath
Every step in the loop writes to one record of exactly what was done, when, and by whom. That record cannot be altered afterwards. "Did we manage this properly" and "can we prove it" come out of the same record, so nothing is reconstructed for a regulator or an insurer after the fact. Everything below is stated on our public Trust and Security pages, including what is not yet done.
Where your data lives
Stored and processed in Australia, AWS ap-southeast-2 (Sydney), via Supabase. Never offshore.
Encryption
TLS 1.3 for data in transit. AES-256-GCM for records at rest, with hardware security module key management.
Tenant isolation
Row-level security enforced at the database kernel, not in application code. Every query is checked by the database itself.
Record integrity
Every record is hashed with SHA-256 and chained to the one before it, so a single changed character is detectable. Sealed records are timestamped by an independent RFC 3161 authority (FreeTSA), which receives only the hash, never the content.
AI inputs
Free text is scrubbed server-side before any call to a language model. Names and identifying detail are never sent as typed. Every AI recommendation accepted or overridden is logged.
Emailed links
Single-use, expiring, and only ever sent to an address on your own organisation's email domain. Your admin can set a verification phrase that appears in every genuine email, so a spoofed one is easy to spot.
Certification
Built on independently certified infrastructure: Supabase (SOC 2 Type II) and AWS (ISO 27001, SOC 2). PsychProof itself is not yet SOC 2 or ISO 27001 certified. A formal engagement is planned once customer volume justifies it. We say so rather than imply otherwise.
Not yet done, stated plainly
Multi-factor authentication is in development and not yet enforceable. Independent penetration testing is not yet complete; our public position is a formal engagement within 90 days of first enterprise deployment. Full detail on the Security page.
Your exit
You may export your complete record set at any time, in open formats. Encrypted backups are kept in Australia.
8. How we work
A documented gap beats a clean-looking plan.
The coverage report shows what is missing and what was done about it, including a consultation that happened after the decision. That record is more defensible than one nobody checked.
We say what is not built.
MFA, penetration testing, certifications: where something is pending, the site says so in plain words, with the timeline. You will not find a claim here the product cannot back.
Not HR software, and not a survey.
Surveys finish at measurement. PsychProof is what runs the loop after a hazard is flagged: owner, control, review, evidence. That is the part a regulator asks about.
Workers get a voice on the record.
Workers can add their own perspective to any record. Consultation is measured by whether they could influence the outcome, not by whether a survey went out.
No jurisdiction is oversold.
The NSW digital work system duty is NSW-only and not yet in force. The general duty to manage psychosocial risk from AI and digital systems applies in every state. We keep those two distinct, because your board will ask.
9. Next step
Happy to walk one live case through the loop together.
Mostly we would like your read on whether the sequence above matches what you actually see day to day, and where it does not. It starts with a 20-minute conversation. Tell us which of the three situations is yours, and we will tell you honestly whether a pilot fits.
Book a conversation
calendly.com/martin-psychproof/psychproof
Pricing and the pilot
psychproof.com.au/pricing
psychproof.com.au/psychosocial-risk-pilot

