Skip to content

Evidence request lists

Kids Online Safety Act (KOSA)

Evidence request list. 8 controls, 8 carrying auditor artefact guidance. Generated from the compliance knowledge graph on 12 September 2026. Published by The Art of Service.

KOSA Age Verification + Inference

KOSA-Age-Verification-Inference-Section2-Knowledge-Standard-Reasonable-Steps-Age-Inference-Methods-Privacy-Preserving
KOSA Age Verification + Inference + Section 2 Knowledge Standard + Reasonable Steps + Age Inference Methods + Privacy-Preserving + Cohort Estimation + Facial Age Estimation + ID-Based + Parental Confirmation + Avoid Over-Verification

Section 2 of KOSA establishes the knowledge + inference standard for identifying minor users while balancing privacy and over-verification concerns. (1) Section 2 Knowledge Standard: (a) Covered platform must take reasonable steps to know or reasonably infer user age; (b) Higher standard than COPPA actual knowledge; (c) Lower standard than affirmative age verification; (d) Privacy-preserving inference encouraged; (e) Industry self-regulation per Section 9 Council guidance. (2) Section 2 Reasonable Steps Factors: (a) Risk of platform being accessed by minors; (b) Available technical capabilities; (c) Cost burden vs benefit; (d) User experience impact; (e) Privacy implications of verification method; (f) Accuracy vs over-reach trade-off. (3) Age Inference Methods - Knowledge Based: (a) User-provided age at registration (self-declaration); (b) Educational verification (student email); (c) A

Artefacts an auditor will ask for
  • Age inference + Section 2 + records + per touchpoint + per method
  • Reasonable steps + documentation + records + per risk + per technical capability
  • Privacy-preserving + records + per method + PETs + audit
  • Ageing up + transitions + records + per account + 13/16/17/18 + settings cascade
  • Multi-jurisdiction + records + per region + harmonization strategy
Where this commonly fails
  • Age inference solely self-declaration (no reasonable steps)
  • Privacy not preserved (excessive PII collected)
  • Ageing up not implemented (settings stuck at registration age)
  • Over-verification (ID required for all users)
  • Multi-jurisdiction not coordinated

KOSA Default Safeguards

KOSA-Default-Safeguards-Minors-Section4-Strong-Privacy-Time-Limits-Content-Filters-Restricted-Contact-Geographic-Location
KOSA Default Safeguards for Minors + Section 4 + Strong Privacy Settings + Time Management + Content Filtering + Restricted Contact + Geographic Location Default Off + Personalized Recommendations Opt-Out + Direct Messaging Restrictions + Minor Account Designation

Section 4 of KOSA establishes mandatory default safeguards for known or reasonably inferred minor users. (1) Section 4(a) Mandatory Default Safeguards: All covered platforms must establish the following safeguards as DEFAULT for known minors and provide ability for parents to control: (a) Strong privacy settings - private account default + limit access to minor profile + no public discoverability; (b) Time management tools - default limits + notifications + parent controls; (c) Content filtering controls - inappropriate content blocking + reporting; (d) Restricted contact from unknown adults - default blocking + parent override; (e) Opt-out of personalized recommendations - non-personalized default + opt-in for personalization; (f) Geographic location default OFF - no precise location tracking + parent override; (g) Direct messaging restrictions - default disabled from non-followers + no

Artefacts an auditor will ask for
  • Default safeguards + Section 4 + records + per setting + per minor account
  • Strong privacy default + records + per account + re-default + annual + audit
  • Personalization opt-out + records + per choice + persistent + cross-device
  • Geographic location default off + records + per service + override only with consent
  • Dark patterns + prohibition + records + per UI + per UX + audit ready
Where this commonly fails
  • Default safeguards not implemented (defaults remain permissive)
  • Strong privacy not default (opt-in required)
  • Personalization opt-out broken (persistent settings lost)
  • Geographic location default ON
  • Dark patterns persist in cancellation flows

KOSA Duty of Care

KOSA-Duty-of-Care-Section3-Covered-Platforms-Mental-Health-Substance-Use-Suicide-Eating-Disorders-Sexual-Exploitation
KOSA Duty of Care + Section 3 + Covered Platforms + Mental Health + Substance Use + Suicide + Eating Disorders + Sexual Exploitation + Online Bullying + Physical Violence + Predatory Marketing + Compulsive Use + Covered Harms Enumerated

Section 3 of the Kids Online Safety Act establishes the foundational duty of care for covered platforms. (1) S.1409 Kids Online Safety and Privacy Act (KOSPA) introduced 16 February 2022 by Senator Richard Blumenthal (D-CT) and Senator Marsha Blackburn (R-TN) + bipartisan + reintroduced 2 May 2023 for 118th Congress + passed Senate 30 July 2024 by 91-3 vote + did not advance from House before session end + originated from 2021 Facebook leak by data scientist Frances Haugen via Wall Street Journal exposing Instagram negative effects on minors. (2) Section 2 Covered Platform Definition: (a) Online platform connecting users; (b) Including websites + mobile apps + games + messaging services; (c) Reasonably likely to be accessed by minors; (d) Knowledge or reasonable inference standard for age; (e) Excludes - common carriers + educational institutions + general internet services + email provi

Artefacts an auditor will ask for
  • Duty of care + Section 3 + records + per harm category + reasonable measures
  • Risk assessment + 9 harms + records + annual + systemic risk + foreseeable
  • Reasonable care + documentation + records + per design + per decision
  • Best interests of minor + records + per policy + balanced
  • First Amendment + Section 230 + records + per decision + counsel
Where this commonly fails
  • Duty of care not implemented (default settings unchanged)
  • Risk assessment perfunctory (no per-harm analysis)
  • Reasonable care undocumented
  • Best interests standard not applied
  • First Amendment defense unprepared

KOSA Enforcement + FTC + State AG

KOSA-Enforcement-FTC-Section10-State-AG-Sole-Civil-Penalty-43792-Per-Violation-No-Private-Right-of-Action
KOSA Enforcement + Section 10 + FTC Sole Federal Authority + State AG Concurrent + NO Private Right of Action + Civil Penalty up to USD 43,792 Per Violation + Injunctive Relief + State AG Notice to FTC + Multi-State Coordination + Cure Period for Smaller Platforms

Section 10 of KOSA establishes the enforcement framework limiting authority to FTC and State Attorneys General. (1) Section 10(a) FTC Federal Enforcement: (a) FTC has sole federal authority; (b) Treated as unfair or deceptive acts or practices per FTC Act Section 5; (c) Civil penalty authority; (d) Injunctive relief; (e) Restitution + disgorgement; (f) Cease and desist orders; (g) Compliance monitoring + reporting. (2) Section 10(b) State Attorney General Enforcement: (a) State AGs have concurrent enforcement authority; (b) Standing to bring action in federal court; (c) State court action also possible; (d) Civil penalty authority - amount per state law or KOSA cap; (e) Injunctive relief; (f) Restitution to state residents; (g) State AGs MUST provide notice to FTC of intent to bring action. (3) Section 10(c) Civil Penalty Framework: (a) UP TO USD 43,792 per violation (adjusted for inflat

Artefacts an auditor will ask for
  • FTC + State AG cooperation + records + per inquiry + cure period awareness
  • Cure period procedure + records + per notice + sub-threshold consideration
  • Internal compliance + records + per quarter + Board reporting + Chief Trust Safety Officer
  • Multi-state AG coordination + records + per investigation + counsel coordinated
  • Compliance officer + Trust Safety Lead + records + designation + Board access
Where this commonly fails
  • FTC + State AG cooperation reactive (no proactive engagement)
  • Cure period not utilised when available
  • Internal compliance program absent or pro forma
  • Multi-state AG coordination uncoordinated
  • No designated KOSA officer or Trust Safety Lead

KOSA Independent Audit

KOSA-Independent-Audit-Section8-Annual-Third-Party-FTC-Approved-Auditor-Compliance-Verification-Public-Summary
KOSA Independent Audit + Section 8 + Annual + Third-Party + FTC-Approved Auditor + Compliance Verification + Public Summary + Multi-Layer Audit + Risk Assessment Verification + Safeguard Effectiveness + Algorithmic System Audit

Section 8 of KOSA mandates annual independent audits of covered platforms by qualified third-party auditors. (1) Section 8(a) Annual Independent Audit: (a) Covered platform must commission annual third-party audit; (b) Audit fiscal year + calendar year alignment options; (c) First audit within 18 months of effective date; (d) Subsequent audits annually; (e) Material change re-audit (significant feature launch + acquisition + policy change). (2) Section 8(b) FTC-Approved Auditor Requirements: (a) FTC publishes list of approved audit firms + criteria; (b) Independent from covered platform - no conflicts of interest; (c) Demonstrated expertise in minor online safety + algorithm audit + privacy + content moderation; (d) Reasonable engagement standards; (e) Diversity of qualified firms; (f) Regular review + recertification of auditors. (3) Section 8(c) Audit Scope: (a) Section 3 Duty of Care

Artefacts an auditor will ask for
  • Annual independent audit + Section 8 + records + per year + audit ready
  • FTC-approved auditor + independence + records + per engagement + no conflicts
  • Audit scope + Sections 3-9 + records + comprehensive + methodology
  • Public summary + records + annual + compliance status + redacted appropriate
  • Remediation + findings response + records + per finding + timeline + verification
Where this commonly fails
  • Annual audit missing or delayed
  • Auditor independence compromised (consultation services)
  • Audit scope superficial (excludes algorithms)
  • Public summary excessively redacted
  • Remediation tracking absent

KOSA Parental Tools

KOSA-Parental-Tools-Section5-Notification-Control-Account-Privacy-Time-Spending-Limits-Minor-Account-Identification
KOSA Parental Tools + Section 5 + Notification + Control + Account Privacy + Time + Spending Limits + Minor Account Identification + Parental Override + Confirmation + Linked Accounts + Reasonable Tools

Section 5 of KOSA mandates that covered platforms provide parental tools enabling parents and guardians to support minor users. (1) Section 5(a) Required Parental Tools: (a) Account Privacy Controls - parent ability to view and modify minor account privacy settings; (b) Time Management Controls - parent ability to set time limits + bedtime restrictions + view usage; (c) Spending Limits - parent ability to set or block in-app purchases + monitor spending; (d) Notification Settings - parent notification of minor account activities + content reports + safety alerts; (e) Account Privacy Override - parent ability to enable/disable certain features; (f) Linked Accounts Mechanism - secure linking of parent and minor accounts; (g) Education and Awareness Resources - parental guides + safety tips + reporting instructions. (2) Section 5(b) Minor Account Identification: (a) Platform must clearly id

Artefacts an auditor will ask for
  • Parental tools + Section 5 + records + per tool + account linkage
  • Linked accounts + verification + records + per linkage + COPPA-equivalent
  • Parental dashboard + records + per parent + cross-platform consideration
  • Minor privacy + balance + records + notification of parent access + autonomy progressive
  • Multi-caregiver + family + records + per scenario + custody coordination
Where this commonly fails
  • Parental tools fragmented (no unified dashboard)
  • Verification weak (false parental claim accepted)
  • Minor privacy not preserved (parent surveillance excessive)
  • Older minor autonomy ignored
  • Multi-caregiver scenarios unsupported

KOSA Researcher Access

KOSA-Researcher-Access-Section7-Qualified-Researchers-Public-Interest-Research-Approval-Process-Data-Sharing-Protections
KOSA Researcher Access + Section 7 + Qualified Researchers + Public Interest Research + Approval Process + Data Sharing + Privacy Protections + Methodology Standards + Public Reporting + Academic + Civil Society + Government Researchers

Section 7 of KOSA establishes a framework for qualified researcher access to covered platform data for public interest research. (1) Section 7(a) Qualified Researcher Definition: (a) Affiliated with accredited higher education institution + non-profit research organisation + government entity; (b) Demonstrated expertise in subject area (e.g. minor online safety + adolescent mental health + algorithm research); (c) Compliance with research ethics including IRB Institutional Review Board approval; (d) Conflict of interest disclosure; (e) Privacy + security training. (2) Section 7(b) Public Interest Research Scope: (a) Research advancing understanding of minor safety + welfare online; (b) Research on platform design impacts; (c) Research on algorithmic effects; (d) Research on content moderation effectiveness; (e) Research on parental tool effectiveness; (f) Research on demographic disparit

Artefacts an auditor will ask for
  • Researcher approval + Section 7 + records + per application + Council guidance
  • Data sharing + PETs + records + per engagement + per method
  • Privacy protection + sandbox + records + per access + audit trail
  • Research output + records + per engagement + published + cited
  • DSA Article 40 + international + records + per jurisdiction + harmonization
Where this commonly fails
  • Researcher access program absent (no application channel)
  • Data sharing limited to commercial researchers (academic excluded)
  • Privacy protection weak (re-identification possible)
  • Research output not tracked
  • International coordination absent

KOSA Transparency Reporting

KOSA-Transparency-Reporting-Section6-Annual-Disclosure-Risk-Assessment-Independent-Audit-Researcher-Access-Public-Report
KOSA Transparency Reporting + Section 6 + Annual Public Disclosure + Risk Assessment Findings + Independent Audit Results + Researcher Access Reports + Public Report + Reporting Mechanism Statistics + Content Moderation Metrics + Algorithmic Disclosure

Section 6 of KOSA mandates comprehensive transparency reporting by covered platforms. (1) Section 6(a) Annual Public Transparency Report: (a) Covered platform must publish annual report on safety practices; (b) Submitted to FTC + State AGs + made publicly available; (c) Plain English language; (d) Multi-language for non-English markets; (e) Accessibility compliance per ADA; (f) Searchable + downloadable. (2) Section 6(b) Report Content - Risk Assessment Findings: (a) Annual systemic risk assessment per Section 3; (b) Per-harm category assessment - mental health + substance use + suicide + eating disorders + sexual exploitation + bullying + addictive design + predatory marketing + violence; (c) Methodology disclosure; (d) Affected populations analysis; (e) Mitigation actions identified + implemented; (f) Outstanding risks. (3) Section 6(c) Report Content - Reporting Mechanism Statistics:

Artefacts an auditor will ask for
  • Annual transparency report + Section 6 + records + per year + public + FTC + State AG
  • Risk assessment findings + per harm + records + per category + methodology
  • Content moderation metrics + records + per quarter + per platform
  • Independent audit summary + Section 8 + records + per audit + remediation
  • Researcher access reports + Section 7 + records + per engagement + output references
Where this commonly fails
  • Annual report missing or perfunctory
  • Risk assessment findings aggregated (no per-harm breakdown)
  • Content moderation metrics absent or selective
  • Audit summary brief or redacted excessively
  • Researcher access not reported
Assembled from the framework's own control set. Every line traces to a control in the graph, so this pack is regenerated rather than written, and stays current as the graph does.

Assembled from the framework’s own control set, so this list is regenerated rather than written and stays current as the graph does. See the Kids Online Safety Act (KOSA) framework page.