Skip to content

Evidence request lists

UK Online Safety Act 2023

Evidence request list. 19 controls, 19 carrying auditor artefact guidance. Generated from the compliance knowledge graph on 12 September 2026. Published by The Art of Service.

Online Safety Act: Communications Offences and Child Protection

UKOSA-OFF-01
False Communications Offence

Criminal offence to send a message that is knowingly false and intended to cause non-trivial psychological or physical harm.

Artefacts an auditor will ask for
  • Documented procedure addressing false communications offence
  • Evidence of executive or risk owner approval
  • Operational records demonstrating execution
  • Independent assurance or review report
Where this commonly fails
  • Procedure exists but execution inconsistent
  • Owner accountability not codified
  • Review cadence missed or undocumented
  • Coverage gaps for in scope entities or systems
UKOSA-OFF-02
Threatening Communications Offence

Criminal offence to send communications conveying threats of serious harm including death, serious injury, rape, or serious financial loss.

Artefacts an auditor will ask for
  • Threat intelligence platform configuration
  • STIX TAXII feed subscriptions and producers list
  • Indicator quality scoring records
  • Correlation rules and tuning evidence
Where this commonly fails
  • Indicators ingested but not actioned
  • Producer trust scoring absent
  • Feed overlap creating noise
  • Sharing community participation passive
UKOSA-OFF-03
Intimate Image Abuse Offence

Criminal offence to share intimate images without consent (including deepfakes). Includes both sharing with intent to cause distress and sharing without reasonable belief in consent.

Artefacts an auditor will ask for
  • Documented procedure addressing intimate image abuse offence
  • Evidence of executive or risk owner approval
  • Operational records demonstrating execution
  • Independent assurance or review report
Where this commonly fails
  • Procedure exists but execution inconsistent
  • Owner accountability not codified
  • Review cadence missed or undocumented
  • Coverage gaps for in scope entities or systems
UKOSA-OFF-04
CSAM Reporting to NCA

Service providers must report child sexual abuse material (CSAM) to the National Crime Agency (NCA). Specific requirements for detection, reporting, and preservation of evidence.

Artefacts an auditor will ask for
  • Content moderation policy referencing illegal content
  • Hash matching deployment records
  • NCMEC or NCA reporting workflow evidence
  • Reviewer wellbeing and rotation plan
Where this commonly fails
  • Hash database refresh cadence unclear
  • Reporting clock starts after triage rather than detection
  • Reviewer welfare programme thin
  • Appeals process omitted for false positives
UKOSA-OFF-05
Age Verification Requirements

Services hosting content harmful to children must implement age verification or age estimation technologies to prevent children from accessing such content.

Artefacts an auditor will ask for
  • Age assurance method selection rationale
  • Vendor assessment for age estimation tooling
  • Accuracy testing and bias evaluation reports
  • User journey records for assurance steps
Where this commonly fails
  • Self declaration relied upon for high risk content
  • Bias not tested across demographic groups
  • Fallback path lacks equivalent rigour
  • Records retention exceeds regulatory minimum

Online Safety Act: Duties of Care

UKOSA-DC-01
Illegal Content Risk Assessment

Service providers must carry out and record risk assessments identifying the likelihood and severity of illegal content appearing on their service, and the steps to mitigate risks.

Artefacts an auditor will ask for
  • Risk assessment report covering illegal content risk assessment scope
  • Risk register entries with owner, likelihood, and impact
  • Treatment plan linked to identified risks
  • Evidence of management review and acceptance
Where this commonly fails
  • Risk register not refreshed after material change
  • Treatment owners undefined or unaccountable
  • Residual risk acceptance lacks executive sign-off
  • Inherent versus residual scoring not clearly distinguished
UKOSA-DC-02
Illegal Content Safety Duties

Service providers must take proportionate steps to prevent individuals from encountering priority illegal content including CSAM, terrorism, fraud, and hate speech.

Artefacts an auditor will ask for
  • Content moderation policy referencing illegal content
  • Hash matching deployment records
  • NCMEC or NCA reporting workflow evidence
  • Reviewer wellbeing and rotation plan
Where this commonly fails
  • Hash database refresh cadence unclear
  • Reporting clock starts after triage rather than detection
  • Reviewer welfare programme thin
  • Appeals process omitted for false positives
UKOSA-DC-03
Children's Risk Assessment

Category 1 and 2A services likely to be accessed by children must assess risks from content harmful to children including pornography, suicide/self-harm, eating disorders, and bullying.

Artefacts an auditor will ask for
  • Risk assessment report covering children's risk assessment scope
  • Risk register entries with owner, likelihood, and impact
  • Treatment plan linked to identified risks
  • Evidence of management review and acceptance
Where this commonly fails
  • Risk register not refreshed after material change
  • Treatment owners undefined or unaccountable
  • Residual risk acceptance lacks executive sign-off
  • Inherent versus residual scoring not clearly distinguished
UKOSA-DC-04
Children's Safety Duties

Categorised services must take proportionate steps to protect children from harmful content, including age verification or estimation for content not suitable for children.

Artefacts an auditor will ask for
  • Content moderation policy referencing illegal content
  • Hash matching deployment records
  • NCMEC or NCA reporting workflow evidence
  • Reviewer wellbeing and rotation plan
Where this commonly fails
  • Hash database refresh cadence unclear
  • Reporting clock starts after triage rather than detection
  • Reviewer welfare programme thin
  • Appeals process omitted for false positives
UKOSA-DC-05
User Empowerment Duties

Category 1 services must provide adult users with tools to control the content they see, including filtering content types and blocking other users.

Artefacts an auditor will ask for
  • Documented procedure addressing user empowerment duties
  • Evidence of executive or risk owner approval
  • Operational records demonstrating execution
  • Independent assurance or review report
Where this commonly fails
  • Procedure exists but execution inconsistent
  • Owner accountability not codified
  • Review cadence missed or undocumented
  • Coverage gaps for in scope entities or systems
UKOSA-DC-06
Content Reporting Mechanisms

Service providers must establish accessible mechanisms for users to report illegal content and content harmful to children. Must acknowledge reports and inform of outcomes.

Artefacts an auditor will ask for
  • Documented procedure addressing content reporting mechanisms
  • Evidence of executive or risk owner approval
  • Operational records demonstrating execution
  • Independent assurance or review report
Where this commonly fails
  • Procedure exists but execution inconsistent
  • Owner accountability not codified
  • Review cadence missed or undocumented
  • Coverage gaps for in scope entities or systems

Online Safety Act: Ofcom Codes and Enforcement

UKOSA-REG-01
Codes of Practice

Ofcom must prepare and publish codes of practice for each duty of care, setting out recommended steps for compliance.

Artefacts an auditor will ask for
  • Documented procedure addressing codes of practice
  • Evidence of executive or risk owner approval
  • Operational records demonstrating execution
  • Independent assurance or review report
Where this commonly fails
  • Procedure exists but execution inconsistent
  • Owner accountability not codified
  • Review cadence missed or undocumented
  • Coverage gaps for in scope entities or systems
UKOSA-REG-02
Information Gathering Powers

Ofcom may require service providers to provide information about their services, users, content moderation, and compliance measures.

Artefacts an auditor will ask for
  • Documented procedure addressing information gathering powers
  • Evidence of executive or risk owner approval
  • Operational records demonstrating execution
  • Independent assurance or review report
Where this commonly fails
  • Procedure exists but execution inconsistent
  • Owner accountability not codified
  • Review cadence missed or undocumented
  • Coverage gaps for in scope entities or systems
UKOSA-REG-03
Enforcement Notices

Ofcom may issue enforcement notices requiring service providers to take specific steps to comply with their duties. Non-compliance may lead to further enforcement.

Artefacts an auditor will ask for
  • Privacy or transparency notice with version history
  • Layered notice design records
  • Just in time notice deployment evidence
  • Plain language readability assessment
Where this commonly fails
  • Notice not aligned to actual processing
  • Children friendly version absent where required
  • Translation gaps for in-scope jurisdictions
  • Change log not surfaced to data subjects
UKOSA-REG-04
Financial Penalties

Ofcom may impose financial penalties up to £18 million or 10% of qualifying worldwide revenue, whichever is greater, for non-compliance.

Artefacts an auditor will ask for
  • Legal register tracking enforcement risk
  • Counsel opinion on liability exposure
  • Self disclosure decision records
  • Insurance coverage evidence
Where this commonly fails
  • Legal register not refreshed for new enforcement actions
  • Director and officer awareness thin
  • Self disclosure protocols undefined
  • Cooperation credit strategy absent
UKOSA-REG-05
Business Disruption Measures

As a last resort, Ofcom may apply to court for orders requiring ISPs to block or restrict access to non-compliant services.

Artefacts an auditor will ask for
  • Documented procedure addressing business disruption measures
  • Evidence of executive or risk owner approval
  • Operational records demonstrating execution
  • Independent assurance or review report
Where this commonly fails
  • Procedure exists but execution inconsistent
  • Owner accountability not codified
  • Review cadence missed or undocumented
  • Coverage gaps for in scope entities or systems

Online Safety Act: Transparency Reporting

UKOSA-TR-01
Annual Transparency Reports

Category 1, 2A, and 2B services must publish annual transparency reports containing information specified by Ofcom about how they comply with their duties.

Artefacts an auditor will ask for
  • Privacy or transparency notice with version history
  • Layered notice design records
  • Just in time notice deployment evidence
  • Plain language readability assessment
Where this commonly fails
  • Notice not aligned to actual processing
  • Children friendly version absent where required
  • Translation gaps for in-scope jurisdictions
  • Change log not surfaced to data subjects
UKOSA-TR-02
Content Moderation Information

Transparency reports must include information about content moderation systems, volumes of content removed, appeals processes, and outcomes.

Artefacts an auditor will ask for
  • Documented procedure addressing content moderation information
  • Evidence of executive or risk owner approval
  • Operational records demonstrating execution
  • Independent assurance or review report
Where this commonly fails
  • Procedure exists but execution inconsistent
  • Owner accountability not codified
  • Review cadence missed or undocumented
  • Coverage gaps for in scope entities or systems
UKOSA-TR-03
Algorithmic Transparency

Information about how recommender systems and algorithms operate and their potential impact on content exposure, particularly for children.

Artefacts an auditor will ask for
  • Privacy or transparency notice with version history
  • Layered notice design records
  • Just in time notice deployment evidence
  • Plain language readability assessment
Where this commonly fails
  • Notice not aligned to actual processing
  • Children friendly version absent where required
  • Translation gaps for in-scope jurisdictions
  • Change log not surfaced to data subjects
Assembled from the framework's own control set. Every line traces to a control in the graph, so this pack is regenerated rather than written, and stays current as the graph does.

Assembled from the framework’s own control set, so this list is regenerated rather than written and stays current as the graph does. See the UK Online Safety Act 2023 framework page.