Skip to content

Evidence request lists

Australia eSafety Commissioner - Online Safety Expectations for Industry

Evidence request list. 18 controls, 18 carrying auditor artefact guidance. Generated from the compliance knowledge graph on 11 September 2026. Published by The Art of Service.

Accessibility and Transparency

BOSE-S17
Additional expectation - terms of use, policies and complaints information accessible

The provider will ensure information about the service's terms of use, policies and procedures, standards of conduct, and complaints mechanisms is accessible to end-users.

Artefacts an auditor will ask for
  • Accessible publication of terms, policies and complaint info
  • Plain-language availability
Where this commonly fails
  • Terms/policies not accessible
  • Information not in plain language
BOSE-S18
Additional expectation - provide updates about changes in policies and terms

The provider will provide end-users with updates about changes to the service's terms of use, policies and procedures, and standards of conduct.

Artefacts an auditor will ask for
  • Change-notification process
  • Records of updates communicated
Where this commonly fails
  • Changes not communicated
  • No update mechanism

Information Requests and Contact

BOSE-S20
Expectation - provide requested information to the Commissioner

The provider will comply with requests from the Commissioner to provide information about the service, including in response to reporting notices.

Artefacts an auditor will ask for
  • Process to respond to Commissioner information requests
  • Records of information provided
Where this commonly fails
  • Requests not actioned
  • No process to respond to notices
BOSE-S21
Additional expectation - designated contact point

The provider will have a designated contact point for the purposes of the Commissioner's dealings with the provider.

Artefacts an auditor will ask for
  • Named designated contact
  • Up-to-date contact details with the Commissioner
Where this commonly fails
  • No designated contact
  • Contact details out of date

Record Keeping

BOSE-S19
Additional expectation - keep records regarding certain matters

The provider will keep records relating to specified matters, including reports and complaints and steps taken, for the period required.

Artefacts an auditor will ask for
  • Record set covering reports/complaints and steps taken
  • Retention meeting required period
Where this commonly fails
  • Records not kept
  • Retention period not met

Reports and Complaints

BOSE-S13
Mechanisms to report and make complaints about certain material

The provider will ensure the service has clear and accessible mechanisms to report, and make complaints about, class 1 material and certain unlawful or harmful material.

Artefacts an auditor will ask for
  • Reporting/complaint mechanism for harmful material
  • Triage and response process
  • Records of reports handled
Where this commonly fails
  • No reporting mechanism
  • Reports not actioned
  • Mechanism hard to find/use
BOSE-S14
Additional expectation - terms of use, policies and standards of conduct

The provider will ensure the service has terms of use, policies and procedures, and standards of conduct, and will enforce them.

Artefacts an auditor will ask for
  • Published terms of use and standards of conduct
  • Enforcement records
Where this commonly fails
  • No terms of use/standards
  • Terms not enforced
BOSE-S15
Mechanisms to report and make complaints about breaches of terms of use

The provider will ensure the service has mechanisms to report and make complaints about breaches of the service's terms of use.

Artefacts an auditor will ask for
  • Mechanism for terms-of-use breach complaints
  • Handling and outcome records
Where this commonly fails
  • No breach-complaint mechanism
  • Breach complaints not handled
BOSE-S16
Additional expectation - accessible information on how to complain to the Commissioner

The provider will make accessible to end-users information on how to make complaints to the eSafety Commissioner.

Artefacts an auditor will ask for
  • Accessible information pointing users to the Commissioner
  • Placement in help/complaints flows
Where this commonly fails
  • No information on Commissioner complaints
  • Information hard to find

Safe Use Expectations

BOSE-S10
Additional expectation - consult and cooperate with other service providers

The provider will consult and cooperate with other service providers to promote the ability of end-users to use all services in a safe manner.

Artefacts an auditor will ask for
  • Evidence of cross-provider cooperation
  • Participation in industry safety initiatives
Where this commonly fails
  • No cooperation with other providers
  • Safety gaps at service boundaries
BOSE-S11
Core expectation - reasonable steps to minimise provision of certain material

The provider will take reasonable steps to minimise the extent to which the service provides class 1 material and certain unlawful or harmful material.

Artefacts an auditor will ask for
  • Proactive detection/removal measures
  • Metrics on prevalence of prohibited material
Where this commonly fails
  • No measures to minimise class 1 material
  • Harmful material proliferates unchecked
BOSE-S12
Core expectation - reasonable steps to prevent children accessing class 2 material

The provider will take reasonable steps to prevent access by children to class 2 material provided on the service.

Artefacts an auditor will ask for
  • Age assurance / access controls for class 2 material
  • Evidence children are prevented from access
Where this commonly fails
  • No age assurance for class 2 material
  • Children able to access class 2 material
BOSE-S6
Core expectation - reasonable steps to ensure safe use

The provider of the service will take reasonable steps to ensure that end-users are able to use the service in a safe manner.

Artefacts an auditor will ask for
  • Documented safe-use measures and risk controls
  • Evidence of reasonable steps proportionate to risk
  • Review of safety measures
Where this commonly fails
  • No safe-use measures
  • Steps not proportionate to the service's risk
  • Measures undocumented
BOSE-S7
Expectation - consult Commissioner and refer to guidance in determining reasonable steps

The provider will consult and have regard to the Commissioner's guidance when determining reasonable steps to ensure safe use.

Artefacts an auditor will ask for
  • Evidence guidance was considered
  • Records of consultation with the Commissioner
Where this commonly fails
  • Commissioner guidance ignored
  • No consultation where expected
BOSE-S8
Additional expectation - reasonable steps regarding encrypted services

Where the service uses encryption, the provider will take reasonable steps to develop and implement processes to detect and address unlawful or harmful material.

Artefacts an auditor will ask for
  • Processes to detect/address harmful material on encrypted services
  • Evidence reasonable steps taken despite encryption
Where this commonly fails
  • No safety processes for encrypted services
  • Encryption used to avoid safety obligations
BOSE-S8A
Additional expectation - reasonable steps regarding generative AI capabilities

Where the service uses or provides generative AI capabilities, the provider will take reasonable steps to consider and address safety risks arising from those capabilities.

Artefacts an auditor will ask for
  • Assessment of safety risks from generative AI features
  • Mitigations for AI-generated harmful material
Where this commonly fails
  • GenAI features unassessed for safety
  • No mitigation for AI-generated harm
BOSE-S8B
Additional expectation - reasonable steps regarding recommender systems

Where the service uses recommender systems, the provider will take reasonable steps to consider and address safety risks arising from them.

Artefacts an auditor will ask for
  • Assessment of recommender-system safety risks
  • Controls limiting amplification of harmful material
Where this commonly fails
  • Recommender risks unassessed
  • Amplification of harmful content unaddressed
BOSE-S9
Additional expectation - reasonable steps regarding anonymous accounts

The provider will take reasonable steps to prevent anonymous accounts being used to deal with material, or activity, that is or may be unlawful or harmful.

Artefacts an auditor will ask for
  • Controls on misuse of anonymous accounts
  • Identity/verification or detection measures where appropriate
Where this commonly fails
  • Anonymous accounts misused without controls
  • No detection of anonymous-account harm
Assembled from the framework's own control set. Every line traces to a control in the graph, so this pack is regenerated rather than written, and stays current as the graph does.

Assembled from the framework’s own control set, so this list is regenerated rather than written and stays current as the graph does. See the Australia eSafety Commissioner - Online Safety Expectations for Industry framework page.