NOM-035-STPS-2018 ("NOM-035") is Mexico's federal standard for identifying, analyzing, and preventing psychosocial risk factors in the workplace. It became mandatory for all companies with more than 50 employees in October 2019 and for smaller organizations in October 2020.

Despite being in effect for several years, compliance remains inconsistent. Many HR departments complete the initial assessment but then let it sit — unactioned and undocumented — until the next inspection cycle. This guide walks through what the standard actually requires, where organizations most commonly fall short, and how a well-designed pulse survey program can handle the heavy lifting automatically.

Disclaimer: This article is for informational purposes. It does not constitute legal advice. Consult your legal counsel or occupational health specialist for compliance decisions specific to your organization.

What NOM-035 actually requires

The standard has four main obligations, organized by the size of your workforce:

For all employers (1+ employees)

For employers with 16–50 workers

For employers with 50+ workers

The 9 domains NOM-035 measures

The standard defines psychosocial risk factors across nine categories:

  1. Conditions in the work environment — physical risk factors, inadequate or unsafe conditions.
  2. Workload — excessive demands, time pressure, emotional demands.
  3. Lack of control over work — inability to influence pace, methods, or schedules.
  4. Working hours — extended hours, rotating shifts, insufficient recovery time.
  5. Interference between work and personal life — inability to balance responsibilities.
  6. Deficient leadership — lack of support, poor communication, inconsistent management.
  7. Workplace relationships — conflict, lack of cooperation, violence or harassment.
  8. Violence — psychological violence, discrimination, or abuse from any source.
  9. Inadequate recognition of work performance — lack of feedback, unfair evaluation, poor compensation perception.

NOM-035 compliance checklist

Use this checklist to audit your current compliance posture:

Phase 1 — Policy & Communication

Foundation requirements applicable to all organizations regardless of size.

Phase 2 — Evaluation

For 16–50 employees: Reference Guide I. For 50+ employees: Reference Guide II or III.

Phase 3 — Action

Required when any domain scores at medium, high, or very high risk level.

Phase 4 — Records & Re-evaluation

Documentation and continuous measurement requirements.

Where organizations most commonly fail

Completing the evaluation but taking no action

This is by far the most common failure mode. Organizations complete the Reference Guide, calculate scores, file the document — and then do nothing. Under NOM-035, the evaluation is not the end state; it is the starting point. An organization that documents high workload scores and does nothing about them is technically out of compliance, even if the survey was administered correctly.

Treating it as an annual checkbox rather than a living program

NOM-035 requires re-evaluation every two years, but the intent of the standard is continuous improvement. Organizations that run a formal evaluation every two years with no monitoring in between are meeting the letter but not the spirit of the law — and are also at higher risk of missing significant deterioration in working conditions between cycles.

Inadequate anonymity protections

The standard requires that individual responses remain confidential. In small teams (fewer than 10 people), even aggregate results can effectively identify individuals. Organizations working with small groups must either combine groups for reporting purposes or use specialized suppression rules to protect respondent identity.

Failing to document the feedback loop

NOM-035 requires communicating results and actions back to employees. This is frequently skipped. In an IMSS or STPS inspection, the inspector will ask not only for the evaluation records but also for evidence that results were shared — typically in the form of meeting minutes, email notifications, or an internal posting.

How Bloomder automates NOM-035 compliance

Bloomder's survey templates include a NOM-035–aligned question bank built around the nine risk factor domains. Instead of administering a formal 72-item or 120-item instrument once every two years, Bloomder distributes these questions across regular pulse cycles — so you maintain continuous monitoring of psychosocial risk indicators while also generating the documentation required for formal compliance reporting.

The platform automatically generates compliance-ready reports that map your pulse data to the NOM-035 domain structure, with risk level classifications and trend lines. When a domain approaches or exceeds the medium-risk threshold, the system alerts the designated HR owner — giving you weeks to act before the problem is formally reportable.

For organizations approaching their re-evaluation deadline, Bloomder can administer the full Reference Guide II or III as a one-time survey and incorporate the results into the ongoing compliance record, satisfying the formal evaluation requirement without a separate vendor engagement.

To understand how Bloomder structures the compliance documentation trail for STPS auditors, see how Bloomder covers NOM-035 & ISO 45003 compliance.

Automate your NOM-035 compliance

Launch continuous psychosocial risk monitoring and generate compliance-ready reports — in under 10 minutes.

Start Free Trial →