FROID NR-1/ISO-45003 — anchored in ISO 45003:2021

Assessing psychosocial risk is the easy half. Proving the fix worked is the half that fails.

Most tools survey your workforce and hand back a score. The harder obligation — showing that a preventive measure actually reduced exposure — needs a baseline, a second cycle, and the discipline to report no improvement when the evidence does not support one. FROID measures that, and refuses to claim success when the confidence interval will not carry it.

ISO 45003
the 2021 international guideline for psychological health and safety at work, and the reference our instrument is anchored to.
15 / 10
minimum responses per campaign and per breakdown. Absolute floors, enforced in the database, not on the screen.
24 of 26
breakdowns our engine returned as no change in a validation run — including four that looked like improvement at the midpoint.
26 May 2026
the date Brazil made psychosocial risk assessment explicit and enforceable. That regime is where this product was hardened.

The obligation

It is already an employer duty in most safety regimes

Not always as a named rule about "psychosocial risk" — more often as the general duty to identify and control every hazard arising from work, which psychosocial factors have never been exempt from.

International

ISO 45003:2021

The reference guideline for managing psychological health and safety within an occupational health and safety management system. It is guidance rather than a certifiable standard — which is precisely why buyers should ask a supplier what method it actually implements, and against what evidence.

European Union

The general duty already covers it

The Framework Directive obliges employers to evaluate all risks to workers' safety and health. Several member states have since issued specific guidance on work-related stress and organisational factors. The exposure is rarely a missing rule — it is a missing assessment.

Brazil

Made explicit, and enforceable

Brazil wrote psychosocial factors expressly into the risk inventory, with a start date and an enforcement date. That produced something unusual: a jurisdiction where the method had to survive inspection. It is the regime this platform was built and tested against.

Presented as context, not legal advice. Obligations differ by country and by sector, and your own counsel is better placed than we are to say what applies to you. What we can state precisely is what the platform does, and that is the rest of this page.

The method

Two gates, and they are not interchangeable

Both are checked before any result is released, and both are enforced inside the database rather than in the interface — because a rule in the interface is a rule someone can route around.

Gate 1

Anonymity

Fifteen substantive responses in a campaign, ten in any breakdown. These are absolute counts, and they protect the person: below them, knowing a group's average is close to knowing what each member answered.

No amount of extra participation fixes this one — the floor looks at how big the group is, not at how many replied. A team of six will never publish its own breakdown, and any supplier promising otherwise is promising something the arithmetic forbids.

Gate 2

Representativeness

The responding cohort has to be able to speak for the declared headcount: a sample for a proportion with finite population correction, at 95% confidence and a 5-point margin.

This one participation does fix, and the dashboard shows exactly how many responses are still missing. The two gates therefore call for opposite remedies — which is why a report that fails to say which one blocked it sends you down the wrong road for a whole cycle.

The sample requirement flattens as the organisation grows. Ninety-eight people need seventy-nine responses; three thousand people need three hundred and forty-one. Below roughly a hundred, the required sample reaches the entire workforce and the exercise becomes a census.

Said before the contract rather than after the collection window closes — it is the promise that most often breaks at the end of a cycle, with the money already spent.

The differentiator

Proving the measure worked

Almost every supplier asserts effectiveness in a report. Very few can demonstrate it, and the difference is the whole argument in front of an auditor or an expert witness.

How

Each unit against itself

The comparison is always a unit against its own baseline, on the same instrument, before and after the measure — never against a market average or a generic population, which is what makes a comparison contestable.

With what rigour

The interval decides, not the midpoint

We compute the standardised difference between the two moments and its margin of error, which depends on how many people answered. Classification uses the conservative bound of the interval: only the magnitude the whole interval supports gets asserted.

The uncomfortable part

And when it did not work

The measure is recorded as ineffective, the risk is not marked down on paper, and it goes on the list of what has to be corrected. A supplier that only ever reports improvement is not measuring — it is confirming what it already wanted to say.

Three lines that summarise the method

Real engine output on demonstration data. The first two are assertions; the third is the refusal to make one.

Dimension and unitBefore → afterEffectVerdict
Excessive demands · Support4.39 → 2.94+3.05 ±0.51effective
Harassment · Support1.85 → 3.17−2.86 ±0.49worsened
Harassment · Logistics2.50 → 2.14+0.60 ±0.60no change

The third line is the one that matters. The average fell, the effect is positive — and the system refuses to say it improved, because with twenty-two responses the margin of error reaches zero. That is the difference between measuring and asserting.

What no one else delivers

When the data is not enough, you still get a document

Participation that fell short, a team too small, a site with twenty people: ordinary situations, and the market's usual answer is a blank page.

An empty panel is not neutral. Anyone who opens a report and sees nothing concludes there is no risk there — and that is the one conclusion the absence of data never authorises. A document that shows three units and says nothing about the fourth asserts, by silence, that the fourth is fine.

Suppressing is concealing. Declaring insufficiency is documenting.

A breakdown that fails a gate does not disappear from the report. It enters the same inventory — never an appendix, never omitted — as a declared-insufficient line, naming which gate blocked it, what the remedy is, and stating explicitly that this does not mean there is no risk.

Why this is a database constraint, not an editorial choice

An inventory line either carries all four numbers — cohort, mean, severity and likelihood — and no gate, or it carries a gate and an escalation note with those four left null. There is no in-between state: the database refuses it. A half-filled line is exactly what an auditor reads as low risk, and that is the mistake the design makes impossible.

The boundary

The employer never reads an individual answer

This is not an access setting someone can loosen. It is how the database is built, and we will demonstrate it live in thirty seconds.

In the database

No read policy exists

The individual-response tables carry no read policy at all, and the role the system runs under has no permission over them. The only way data leaves the database is an aggregation function that has already applied the minimum group floors.

No names

There is no field for a name

This is not a retention policy — the column does not exist. You provide a payroll number; the system stores a cryptographic pseudonym of it and a digest of the invitation link, never the pair between the two. Who received which link is known only to your own HR.

Why it protects you

A frightened workforce gives you a false picture

Someone who suspects the answers are readable replies with what is safe, not with what is true — and then the organisation pays for a portrait that does not match it. The guarantee protects the employer at least as much as the worker.

Scope

What this is, and what it is not

FROID is an instrument for characterising and documenting exposure to psychosocial risk factors, built to produce the aggregate evidence that a risk assessment requires, together with a measured comparison of effectiveness between cycles.

FROID is not a surveillance tool, does not diagnose individuals, does not score or rank people, and does not replace your occupational health service, your safety committee, your occupational physician or your legal counsel. Engaging us does not transfer your legal responsibility for managing occupational risk.

A questionnaire on its own does not constitute risk management, and we say so before you ask. The instrument characterises exposure; observation of real work and dialogue with workers are done by people, and are quoted separately.

On local compliance documents, read this carefully. The generated documents — risk inventory, action plan, criteria record — follow the structure Brazilian regulation requires. Outside Brazil, what transfers is the instrument, the gates, the effectiveness engine and the evidence trail; mapping the output onto your jurisdiction's required paperwork is scoped per engagement, and we would rather say that now than discover it together later.

Pricing

How much it costs

FROID NR-1/ISO-45003 assesses working conditions, anonymously and in aggregate. It does not assess individuals, does not produce a diagnosis and does not hand clinical data to the employer.

ComponentAmount
Platform base, per establishmentR$ 200 / month
Band 1 — from 1 to 100 workersR$ 15.00 / worker / month
Band 2 — from 101 to 300R$ 12.50 / worker / month
Band 3 — from 301 to 1,000R$ 9.30 / worker / month
Band 4 — above 1,000R$ 6.55 / worker / month

Bands are cumulative and apply to the company's total headcount: with 300 workers you pay R$ 15 for the first 100 and R$ 12.50 for the next 200. The base is per establishment — not per department: a company with five departments at the same address has one base, not five. Amounts are in Brazilian reais. The proposal simulator computes the figure for your headcount.

Simulate your company's amount

The calculation comes from FROID's pricing engine, not from this page: the amount carries the version and the fingerprint of the commercial table that produced it.

Estimate based on the table in force. The contracted amount is the one in the Commercial Proposal.

Conducting the assessment is the client's responsibility

Observation of the real activity, dialogue with workers and the execution of prevention measures belong to the contracting company. FROID does not conduct field assessment, does not perform an AET and does not implement any measure — neither with its own team nor through third parties.

What FROID delivers is the instrument: the measurement, the record of each piece of evidence with its declared method, and the verification of the effectiveness of the actions the company decides and carries out, in the form the rule requires.

The reason is technical, not commercial. The company is the one that knows the activity, the organisation of work and the concrete conditions — and it is to the company that the rule assigns the decision on measures, their implementation and the signing of the documents. A supplier that proposed and executed its own measures would be measuring the result of its own work.

Unlimited campaigns. Each establishment opens as many assessment campaigns as it needs, in any sector, with no charge per campaign or per sector. The monthly amount is the one in the table above, and measuring again never costs more — the opposite of the incentive of whoever charges per survey.
No result is published below the floors. A campaign releases results from 15 completed answers, and every breakdown requires at least 10 — and only after collection closes. Below 98 people in the establishment the required sample becomes a census. These floors are enforced in the database, not in the application.

Next step

Start with one establishment

A single site, criteria documented from the first day, and exposure characterised in a form your assessment can absorb. If the method holds up there, it scales; if it does not, you found out cheaply.