UK Online Safety Act 2023
Evidence request list. 19 controls, 19 carrying auditor artefact guidance. Generated from the compliance knowledge graph on 12 September 2026. Published by The Art of Service.
Online Safety Act: Communications Offences and Child Protection
Criminal offence to send a message that is knowingly false and intended to cause non-trivial psychological or physical harm.
- Documented procedure addressing false communications offence
- Evidence of executive or risk owner approval
- Operational records demonstrating execution
- Independent assurance or review report
- Procedure exists but execution inconsistent
- Owner accountability not codified
- Review cadence missed or undocumented
- Coverage gaps for in scope entities or systems
Criminal offence to send communications conveying threats of serious harm including death, serious injury, rape, or serious financial loss.
- Threat intelligence platform configuration
- STIX TAXII feed subscriptions and producers list
- Indicator quality scoring records
- Correlation rules and tuning evidence
- Indicators ingested but not actioned
- Producer trust scoring absent
- Feed overlap creating noise
- Sharing community participation passive
Criminal offence to share intimate images without consent (including deepfakes). Includes both sharing with intent to cause distress and sharing without reasonable belief in consent.
- Documented procedure addressing intimate image abuse offence
- Evidence of executive or risk owner approval
- Operational records demonstrating execution
- Independent assurance or review report
- Procedure exists but execution inconsistent
- Owner accountability not codified
- Review cadence missed or undocumented
- Coverage gaps for in scope entities or systems
Service providers must report child sexual abuse material (CSAM) to the National Crime Agency (NCA). Specific requirements for detection, reporting, and preservation of evidence.
- Content moderation policy referencing illegal content
- Hash matching deployment records
- NCMEC or NCA reporting workflow evidence
- Reviewer wellbeing and rotation plan
- Hash database refresh cadence unclear
- Reporting clock starts after triage rather than detection
- Reviewer welfare programme thin
- Appeals process omitted for false positives
Services hosting content harmful to children must implement age verification or age estimation technologies to prevent children from accessing such content.
- Age assurance method selection rationale
- Vendor assessment for age estimation tooling
- Accuracy testing and bias evaluation reports
- User journey records for assurance steps
- Self declaration relied upon for high risk content
- Bias not tested across demographic groups
- Fallback path lacks equivalent rigour
- Records retention exceeds regulatory minimum
Online Safety Act: Duties of Care
Service providers must carry out and record risk assessments identifying the likelihood and severity of illegal content appearing on their service, and the steps to mitigate risks.
- Risk assessment report covering illegal content risk assessment scope
- Risk register entries with owner, likelihood, and impact
- Treatment plan linked to identified risks
- Evidence of management review and acceptance
- Risk register not refreshed after material change
- Treatment owners undefined or unaccountable
- Residual risk acceptance lacks executive sign-off
- Inherent versus residual scoring not clearly distinguished
Service providers must take proportionate steps to prevent individuals from encountering priority illegal content including CSAM, terrorism, fraud, and hate speech.
- Content moderation policy referencing illegal content
- Hash matching deployment records
- NCMEC or NCA reporting workflow evidence
- Reviewer wellbeing and rotation plan
- Hash database refresh cadence unclear
- Reporting clock starts after triage rather than detection
- Reviewer welfare programme thin
- Appeals process omitted for false positives
Category 1 and 2A services likely to be accessed by children must assess risks from content harmful to children including pornography, suicide/self-harm, eating disorders, and bullying.
- Risk assessment report covering children's risk assessment scope
- Risk register entries with owner, likelihood, and impact
- Treatment plan linked to identified risks
- Evidence of management review and acceptance
- Risk register not refreshed after material change
- Treatment owners undefined or unaccountable
- Residual risk acceptance lacks executive sign-off
- Inherent versus residual scoring not clearly distinguished
Categorised services must take proportionate steps to protect children from harmful content, including age verification or estimation for content not suitable for children.
- Content moderation policy referencing illegal content
- Hash matching deployment records
- NCMEC or NCA reporting workflow evidence
- Reviewer wellbeing and rotation plan
- Hash database refresh cadence unclear
- Reporting clock starts after triage rather than detection
- Reviewer welfare programme thin
- Appeals process omitted for false positives
Category 1 services must provide adult users with tools to control the content they see, including filtering content types and blocking other users.
- Documented procedure addressing user empowerment duties
- Evidence of executive or risk owner approval
- Operational records demonstrating execution
- Independent assurance or review report
- Procedure exists but execution inconsistent
- Owner accountability not codified
- Review cadence missed or undocumented
- Coverage gaps for in scope entities or systems
Service providers must establish accessible mechanisms for users to report illegal content and content harmful to children. Must acknowledge reports and inform of outcomes.
- Documented procedure addressing content reporting mechanisms
- Evidence of executive or risk owner approval
- Operational records demonstrating execution
- Independent assurance or review report
- Procedure exists but execution inconsistent
- Owner accountability not codified
- Review cadence missed or undocumented
- Coverage gaps for in scope entities or systems
Online Safety Act: Ofcom Codes and Enforcement
Ofcom must prepare and publish codes of practice for each duty of care, setting out recommended steps for compliance.
- Documented procedure addressing codes of practice
- Evidence of executive or risk owner approval
- Operational records demonstrating execution
- Independent assurance or review report
- Procedure exists but execution inconsistent
- Owner accountability not codified
- Review cadence missed or undocumented
- Coverage gaps for in scope entities or systems
Ofcom may require service providers to provide information about their services, users, content moderation, and compliance measures.
- Documented procedure addressing information gathering powers
- Evidence of executive or risk owner approval
- Operational records demonstrating execution
- Independent assurance or review report
- Procedure exists but execution inconsistent
- Owner accountability not codified
- Review cadence missed or undocumented
- Coverage gaps for in scope entities or systems
Ofcom may issue enforcement notices requiring service providers to take specific steps to comply with their duties. Non-compliance may lead to further enforcement.
- Privacy or transparency notice with version history
- Layered notice design records
- Just in time notice deployment evidence
- Plain language readability assessment
- Notice not aligned to actual processing
- Children friendly version absent where required
- Translation gaps for in-scope jurisdictions
- Change log not surfaced to data subjects
Ofcom may impose financial penalties up to £18 million or 10% of qualifying worldwide revenue, whichever is greater, for non-compliance.
- Legal register tracking enforcement risk
- Counsel opinion on liability exposure
- Self disclosure decision records
- Insurance coverage evidence
- Legal register not refreshed for new enforcement actions
- Director and officer awareness thin
- Self disclosure protocols undefined
- Cooperation credit strategy absent
As a last resort, Ofcom may apply to court for orders requiring ISPs to block or restrict access to non-compliant services.
- Documented procedure addressing business disruption measures
- Evidence of executive or risk owner approval
- Operational records demonstrating execution
- Independent assurance or review report
- Procedure exists but execution inconsistent
- Owner accountability not codified
- Review cadence missed or undocumented
- Coverage gaps for in scope entities or systems
Online Safety Act: Transparency Reporting
Category 1, 2A, and 2B services must publish annual transparency reports containing information specified by Ofcom about how they comply with their duties.
- Privacy or transparency notice with version history
- Layered notice design records
- Just in time notice deployment evidence
- Plain language readability assessment
- Notice not aligned to actual processing
- Children friendly version absent where required
- Translation gaps for in-scope jurisdictions
- Change log not surfaced to data subjects
Transparency reports must include information about content moderation systems, volumes of content removed, appeals processes, and outcomes.
- Documented procedure addressing content moderation information
- Evidence of executive or risk owner approval
- Operational records demonstrating execution
- Independent assurance or review report
- Procedure exists but execution inconsistent
- Owner accountability not codified
- Review cadence missed or undocumented
- Coverage gaps for in scope entities or systems
Information about how recommender systems and algorithms operate and their potential impact on content exposure, particularly for children.
- Privacy or transparency notice with version history
- Layered notice design records
- Just in time notice deployment evidence
- Plain language readability assessment
- Notice not aligned to actual processing
- Children friendly version absent where required
- Translation gaps for in-scope jurisdictions
- Change log not surfaced to data subjects
Assembled from the framework’s own control set, so this list is regenerated rather than written and stays current as the graph does. See the UK Online Safety Act 2023 framework page.