Skip to content
See all cases
Sistema Cuidar logo

The psychosocial risk report left Google Forms and now comes out with AI writing inside the methodology

Brazil's NR-1 standard now requires companies to identify and manage psychosocial risk. Doing that properly means hearing employees under guaranteed anonymity, classifying risk factor by factor and delivering a technical report that holds up in the company's risk-management programme. Epicora built Sistema Cuidar: its own collection layer — the previous one, on Google Forms, was rejected by the assessed companies —, sector-level reading, a 13-factor risk matrix and a 15-section report, five of them written by AI that cannot invent a number or fabricate a reference.

Client
Sistema Cuidar — organisational psychology consultancy (Brazil)
What we did
End-to-end psychosocial assessment platform — anonymous collection, sector analysis, risk matrix and an AI-generated NR-1 report
Platform
Responsive web (React 19 · NestJS · MongoDB · AWS) · AI: Claude via AWS Bedrock
23
assessment programmes run on the platform
370
responses collected anonymously
13
factors in the matrix, computed without AI
15
report sections — 5 written by AI
01

The starting point

NR-1 put psychosocial risk on the same footing as physical, chemical and ergonomic risk: it has to be identified, assessed, classified and managed inside the company's risk-management programme. That created demand which organisational psychology already knew how to meet in method — but not at scale. The assessment requires hearing dozens or hundreds of workers under real anonymity, reading the result by sector, classifying risk factor by factor and delivering a report that survives an audit.

The bottleneck was double. In collection: the instrument ran on Google Forms, and the assessed companies simply would not accept it — identifiable psychosocial data about workers travelling through a generic form, with no access control and no guarantee of anonymity, gets past nobody's legal team. In analysis: each report consumed two to three days of manual work, compiling the spreadsheet, crossing factor with sector and writing the technical text by hand. One report at a time, one company at a time.

  • Collection on Google Forms was blocked by the companies — no access control, no guaranteed anonymity, no audit trail.
  • Two to three days of manual work per report, which caps any growth.
  • Sensitive worker mental-health data in a shared spreadsheet — direct exposure under Brazil's data-protection law.
  • The open-ended question, where the nuance lives, required reading and summarising everything by hand.
  • No standardisation: two reports from the same consultancy could come out with different structures.
Before: the collection the company would not accept
The AI writes; it does not calculate
02

The turning point

Epicora treated the problem as two chained systems, not as a text generator. The first is collection: each programme has its own questionnaire built in a form builder — the current standard is DRPS 50, 50 questions plus two for identification, with direct and reverse scoring —, answered through a public link, with no individual identification, aggregated only collectively. That is the difference between a generic form and an instrument: the sector identification question is what later allows risk to be read by area of the company instead of an average that says nothing.

The second is the report. The DRPS spreadsheet comes in one per sector, with all-or-nothing import — if any spreadsheet is off-standard, none is imported. The system extracts the 13 risk factors and builds the risk matrix, which is a table rendered from the data, with no AI at all. Only then does the AI come in, to write the five sections that require technical interpretation.

And the writing is not a single call. It is five independent calls to Claude, via AWS Bedrock, run in parallel — technical analysis, action plan, conclusion, monitoring recommendations and methodological notes —, each returning its own structured JSON. A failure in one does not invalidate the others, and each section can be regenerated on its own. All of them start from the same input: the 13 extracted factors, the reference material and a few-shot sample of the consultancy's standard report.

The decision that unlocked it

Separating what is calculation from what is writing. The risk matrix, the per-factor classification and the charts come out of the data, deterministically — the AI never touches them. The AI writes the five interpretive sections, and the system prompt explicitly forbids it from inventing numeric data, creating a new factor or citing an author that is not in the reference material. That is what makes the report signable by a technical lead: no number in the document came from a language model.

03

What we delivered

Collection the company's legal team accepts

A questionnaire built per programme in a form builder with sections and question types, answered through a public link without login, with no individual identification, and with an opening text telling the employee that the analysis is collective and feeds the preventive measures of the risk-management programme. The consent term and the signed document stay attached to the programme itself.

Reading by sector, not a blind average

Every question becomes a consolidated chart, with response and option counts, and every chart is exportable. Because the instrument identifies sector, role and shift — without identifying the person — risk can be read by area: that is what turns "the company has high risk on overload" into "these sectors do, these do not".

The 13-factor matrix — computed, not written

The 13 DRPS 50 factors — from harassment and low support to overload, underload, low autonomy, organisational injustice and isolated work — go into a single seven-column table, with severity, probability and final classification per factor, rendered straight from the extracted data. Zero AI in this section: it is arithmetic and rules, auditable line by line.

The 15-section report, five of them written by AI

Cover, presentation, introduction, objective, methodology, sample characterisation and assessed dimensions come from a versioned template. The matrix is computed. Technical analysis, action plan, conclusion, monitoring recommendations and methodological notes are AI-generated — in five parallel calls — and land in an editor where the technical lead reviews before exporting. The action plan comes out with one line per factor, always all 13, ordered by criticality.

04

How we made it safe

The AI is required to stay inside the methodology

The system prompt shared by the five calls sets the bar: technical-forensic language in Brazilian Portuguese, focus on the organisation of work rather than the individual, and grounding aligned with NR-1, the Brazilian risk-management programme, ISO 45003, COPSOQ, the HSE Management Standards, the Psychodynamics of Work and the Demand-Control-Support model. It requires traceable coherence — finding, interpretation, matrix, classification, action plan, monitoring, conclusion — with no section contradicting another. And it mandates acknowledging under-reporting and defensive adaptation: low declared perception of risk is not absence of risk.

An explicit list of what the AI may not write

This is the detail that separates a technical report from motivational text. The prompt forbids shallow HR vocabulary — "bad climate", "toxic leadership" without operationalisation, "lack of resilience", "healthy environment" without evidence — and imposes the auditable occupational terminology that takes its place: "centralising management practices", "low predictability of demands", "role ambiguity", "imbalance between demands and resources", "interference of work demands in psychophysiological recovery time". The report reads like an expert assessment because the bar lives in the code, not in the review.

Sensitive data treated as sensitive data

An employee's answer is health data. Collection is anonymous by design — the system never asks for individual identification and only aggregates —, platform access is authenticated by role, and programme files (signed term, spreadsheets, report) sit in private storage with signed access. The report identifies the assessed organisation, never the person: the AI is instructed to refer to "the assessed organisation", "the organisational environment", "the Programme".

05

The result

What used to take two to three days of compiling and writing by hand now comes out of the collected data itself: the matrix is computed, the five interpretive sections are generated in parallel, and the psychologist steps in where her value actually is — reviewing and signing, not typing. The collection layer, previously blocked by the companies for running on a generic form, is now an instrument with anonymity by design.

And scale showed up the way that matters: 23 programmes run, including a network that applied the assessment unit by unit across three states, and an industrial operation with 189 respondents in a single programme — each with its own matrix, its per-factor action plan and its report.

The report comes out of the data

Related solutions

Related cases

Do you need AI on top of data that leaves no room for error?

Epicora builds AI that stays inside the method: what is calculation remains calculation, and the model writes only where interpretation is the product — with the bar in the code, not in the review.

Contact

Let's talk about your project

Tell us what you need to solve. We reply fast, with people who understand both technology and business.

Prefer to talk directly?

Pick the channel you prefer. We reply fast, during business hours.

From the first conversation to go-live: efficiency, security and innovation.