Assess. Control. Respond.

How much documentation is enough? Building a defensible psychosocial risk record

A plain-English guide for Australian employers on how much psychosocial documentation is actually enough to be defensible, what a defensible risk register and evidence pack look like, and how to tell a real record from a paperwork pile.

Resona HQ · 4 June 2026 · 10 min read

Most employers asking this question are really asking two things at once. How much paperwork do I need before I can stop worrying, and what does the paperwork actually have to contain to hold up if someone asks to see it. Both are fair questions, and the honest answer is that there is no fixed page count and no certificate that makes the worry go away. What there is, instead, is a standard you can aim at: a record that shows you identified the psychosocial hazards in your workplace, made reasonable decisions about them, consulted your workers, acted, and kept reviewing. If your documentation tells that story clearly and stays current, you are in a far stronger position to show you took reasonable steps. If it is a folder of policies nobody has looked at since they were written, that story is much harder to tell, and the thickness of the folder will do little for you. Whether any specific record would satisfy a regulator or withstand a particular claim depends on the full facts, which is why current, reasoned documentation supports your position rather than settles it.

This guide explains what “defensible” really means for a psychosocial risk record, what a defensible risk register and evidence pack actually look like, how much is enough, and how to tell a genuine record from a pile of paper. It is written for an employer learning the terms, not for a safety professional, and it is general information rather than legal advice.

What “defensible” actually means

There is no Australian law that says “keep twelve documents and you are safe”. The duty under work health and safety law is to manage psychosocial hazards so far as is reasonably practicable, and to be able to show you did. Your documentation is the showing. So a defensible record is not defined by volume. It is defined by whether it demonstrates a genuine, reasonable, recorded response to the hazards that actually apply to your workplace.

Four qualities separate a defensible record from a decorative one. It is contemporaneous, meaning the decisions were written down at the time, not reconstructed afterwards. It is reasoned, meaning it shows why you chose what you chose, not just what you chose. It is consultative, meaning it captures that you involved workers, because consultation is a legal duty in its own right and one of the records inspectors most often want to see. And it is current, meaning it has been reviewed and updated, because the duty runs as a continuous loop (identify, assess, control, consult, review) rather than a one-off project. A record that has all four reads as a working process. A record missing any one of them reads as a gap.

How much is enough? Proportionality is the answer

The amount of documentation that is enough scales with the risk, not with your appetite for paperwork. The legal standard, reasonably practicable, is itself a proportionality test: you weigh the level of risk against what it would take to address it. The same logic applies to the record. A small employer with low-risk office work does not need the documentation depth of a large organisation running high-demand frontline shift work with exposure to aggression or traumatic content. Enough means enough to match the hazards you genuinely have.

In practice that means depth where the risk is real and brevity where it is not. For a serious, likely hazard, you would expect a clear assessment, a considered control with a named owner, evidence you consulted workers, and a review. For a low-level concern, a short note that you identified it, rated it low, and why, is often a proportionate record on its own. Documenting every minor item to the depth of your top risks is not more defensible; it buries the decisions that matter and reads as box-ticking. Aim for a record an outsider could read in twenty minutes and come away understanding what your real risks are and what you did about them.

What a defensible risk register looks like

The risk register is the spine of the whole record, so it is worth being specific about what a good one contains. A defensible register is a structured, dated list where each row is a named hazard you can actually act on, rather than a raw survey export or a wall of free-text comments.

For each hazard, a defensible register carries:

  1. The hazard, named against the recognised psychosocial categories (things like unreasonable workload, low job control, poor support, bullying or harassment, role conflict, poor change management, and exposure to aggression or traumatic content) rather than a vague label.
  2. A short description of what you found and where it shows up in the work.
  3. A risk rating: how likely the harm is and how serious it would be, so your priorities are visible.
  4. The control or controls you have chosen, with a note on why they are reasonable.
  5. An owner, a due date, and a status, so each entry is a tracked action rather than an intention.
  6. A review date, so the register shows the duty is being kept current rather than frozen at the moment it was written.

The register’s job is to convert a survey or a walkthrough into named, rated, owned hazards. If your register does that and stays dated and current, it carries most of the defensibility weight on its own.

What an evidence pack looks like

If the register is the spine, the evidence pack is the body of supporting records the register points to. The test for an evidence pack is simple: could an inspector, an insurer, or a board member pick it up cold and follow what you did, without you in the room to narrate it. A defensible pack holds together as one continuous record rather than scattered files in different inboxes.

A sound evidence pack typically gathers:

  1. The risk register itself, as above.
  2. The controls decision record, showing what you chose and why it was reasonable, including any higher-order controls (the ones that change how the work is designed and managed, which regulators expect you to look at first rather than relying on an Employee Assistance Program or a wellbeing app to do a job that work redesign should be doing).
  3. A consultation log: dates, who was consulted, in what forum, what was raised, and how it changed the plan. This is the record that is hardest to fake after the fact, which is exactly why it carries weight.
  4. An action tracker showing status over time, not just a one-off plan, with completion evidence against each control.
  5. Dated review notes showing you checked whether controls worked and adjusted where they did not.
  6. A leadership-reporting summary, because officers such as directors carry a personal due-diligence duty separate from the organisation’s own duty, and the pack should show the matter reached the people accountable for it.

None of this requires a clinical assessment or a legal opinion to start. It requires that the decisions, the consultation, and the follow-through are written down, kept current, and linked so they read as one story.

The two failure modes: too little and the wrong kind

Employers tend to fail defensibility in one of two ways, and they are opposites. The first is too little: a policy, an EAP, and some training, with nothing that addresses the design of the work itself and no record of decisions, consultation, or review. That is the most common gap regulators and advisers point to. The second is a large volume of the wrong kind of documentation: reams of generic policies, a survey nobody acted on, a plan with no owners or dates, a thick folder that has not been opened since it was filed. Volume is not defensibility. A short, current, reasoned record beats a thick, stale one every time.

Be wary, too, of the idea that a particular technology makes a record defensible by itself. Some providers market features like tamper-evident or cryptographic proof of when a document existed. Knowing when a file was created can be useful, but it does not answer the question that matters, which is whether the content shows a reasonable, consulted, reviewed response to your real hazards. Defensibility lives in the substance of the decisions, not in the timestamp on the file.

A note on contested questions

This guide describes what a defensible record generally looks like. It does not, and cannot, tell you whether your specific record would withstand a specific regulator’s view or a specific claim, because that depends on your circumstances, the facts, and the rules in your state. Genuinely contested or higher-stakes questions warrant your own qualified adviser. Where a board, an insurer, or an officer wants external assurance on a record, you can engage your own suitably qualified adviser to add an outside name to the file. The point of building the record well is not to guarantee an outcome. It is to make sure that if you are ever asked, you can show your working rather than a gap.

Where PsychSecure fits

PsychSecure is a managed service that supports employers to implement and maintain their psychosocial risk-management workflow and to create defensible documentation aligned with applicable WHS guidance. In plain terms, it is built to produce exactly the record this guide describes: it helps you map the recognised hazards against your own evidence, grade your existing controls as adequate, partial, or absent, build a prioritised plan with named owners and review points, and keep the register, the consultation records, the action tracking, the leadership reporting, and the evidence pack in one maintained record designed to drop into your due-diligence file. Its eyebrow says it simply: assess, control, respond.

To be clear about what it is and is not. PsychSecure is decision-support and workflow automation. It is not legal advice, it is not a clinical diagnostic tool, and it does not by itself make your organisation compliant. The primary duty stays with you. What the service is designed to do is help you build a record that is proportionate, current, and readable by an outsider, and to keep it that way after the initial enthusiasm fades, which is the part most organisations cannot sustain on their own.

A note on what this is and is not

This guide is general information to help Australian employers understand what a defensible psychosocial risk record looks like and how much documentation tends to be enough. It is not legal, clinical, or WHS advice, and it does not guarantee any compliance or regulatory outcome. How the duty applies, and what would be enough in a given case, depends on your own circumstances and the rules in your state. Genuinely contested or higher-stakes questions warrant your own qualified adviser. Material here is aligned with applicable WHS guidance as we understand it; confirm anything that matters for your business against the current rules that apply to you.

A next step, if it is useful

If you are looking at your own folder and genuinely cannot tell whether it would hold up, you are welcome to a short call, usually 15 to 20 minutes. We will walk through what a proportionate, defensible record looks like for an organisation like yours, show you a sample register and evidence pack, and answer your questions, with no pressure either way. If you were simply trying to work out how much is enough, the short version is this: enough to show a reasonable, consulted, reviewed response to the hazards you actually have, kept current. Not the thickest folder. The clearest one.

If it would help to talk through what this looks like for an organisation like yours, a short call, usually 15 to 20 minutes, is an easy place to start.