Australia eSafety Commissioner - Online Safety Expectations for Industry
Evidence request list. 18 controls, 18 carrying auditor artefact guidance. Generated from the compliance knowledge graph on 11 September 2026. Published by The Art of Service.
Accessibility and Transparency
The provider will ensure information about the service's terms of use, policies and procedures, standards of conduct, and complaints mechanisms is accessible to end-users.
- Accessible publication of terms, policies and complaint info
- Plain-language availability
- Terms/policies not accessible
- Information not in plain language
The provider will provide end-users with updates about changes to the service's terms of use, policies and procedures, and standards of conduct.
- Change-notification process
- Records of updates communicated
- Changes not communicated
- No update mechanism
Information Requests and Contact
The provider will comply with requests from the Commissioner to provide information about the service, including in response to reporting notices.
- Process to respond to Commissioner information requests
- Records of information provided
- Requests not actioned
- No process to respond to notices
The provider will have a designated contact point for the purposes of the Commissioner's dealings with the provider.
- Named designated contact
- Up-to-date contact details with the Commissioner
- No designated contact
- Contact details out of date
Record Keeping
The provider will keep records relating to specified matters, including reports and complaints and steps taken, for the period required.
- Record set covering reports/complaints and steps taken
- Retention meeting required period
- Records not kept
- Retention period not met
Reports and Complaints
The provider will ensure the service has clear and accessible mechanisms to report, and make complaints about, class 1 material and certain unlawful or harmful material.
- Reporting/complaint mechanism for harmful material
- Triage and response process
- Records of reports handled
- No reporting mechanism
- Reports not actioned
- Mechanism hard to find/use
The provider will ensure the service has terms of use, policies and procedures, and standards of conduct, and will enforce them.
- Published terms of use and standards of conduct
- Enforcement records
- No terms of use/standards
- Terms not enforced
The provider will ensure the service has mechanisms to report and make complaints about breaches of the service's terms of use.
- Mechanism for terms-of-use breach complaints
- Handling and outcome records
- No breach-complaint mechanism
- Breach complaints not handled
The provider will make accessible to end-users information on how to make complaints to the eSafety Commissioner.
- Accessible information pointing users to the Commissioner
- Placement in help/complaints flows
- No information on Commissioner complaints
- Information hard to find
Safe Use Expectations
The provider will consult and cooperate with other service providers to promote the ability of end-users to use all services in a safe manner.
- Evidence of cross-provider cooperation
- Participation in industry safety initiatives
- No cooperation with other providers
- Safety gaps at service boundaries
The provider will take reasonable steps to minimise the extent to which the service provides class 1 material and certain unlawful or harmful material.
- Proactive detection/removal measures
- Metrics on prevalence of prohibited material
- No measures to minimise class 1 material
- Harmful material proliferates unchecked
The provider will take reasonable steps to prevent access by children to class 2 material provided on the service.
- Age assurance / access controls for class 2 material
- Evidence children are prevented from access
- No age assurance for class 2 material
- Children able to access class 2 material
The provider of the service will take reasonable steps to ensure that end-users are able to use the service in a safe manner.
- Documented safe-use measures and risk controls
- Evidence of reasonable steps proportionate to risk
- Review of safety measures
- No safe-use measures
- Steps not proportionate to the service's risk
- Measures undocumented
The provider will consult and have regard to the Commissioner's guidance when determining reasonable steps to ensure safe use.
- Evidence guidance was considered
- Records of consultation with the Commissioner
- Commissioner guidance ignored
- No consultation where expected
Where the service uses encryption, the provider will take reasonable steps to develop and implement processes to detect and address unlawful or harmful material.
- Processes to detect/address harmful material on encrypted services
- Evidence reasonable steps taken despite encryption
- No safety processes for encrypted services
- Encryption used to avoid safety obligations
Where the service uses or provides generative AI capabilities, the provider will take reasonable steps to consider and address safety risks arising from those capabilities.
- Assessment of safety risks from generative AI features
- Mitigations for AI-generated harmful material
- GenAI features unassessed for safety
- No mitigation for AI-generated harm
Where the service uses recommender systems, the provider will take reasonable steps to consider and address safety risks arising from them.
- Assessment of recommender-system safety risks
- Controls limiting amplification of harmful material
- Recommender risks unassessed
- Amplification of harmful content unaddressed
The provider will take reasonable steps to prevent anonymous accounts being used to deal with material, or activity, that is or may be unlawful or harmful.
- Controls on misuse of anonymous accounts
- Identity/verification or detection measures where appropriate
- Anonymous accounts misused without controls
- No detection of anonymous-account harm
Assembled from the framework’s own control set, so this list is regenerated rather than written and stays current as the graph does. See the Australia eSafety Commissioner - Online Safety Expectations for Industry framework page.