UK Online Safety Act Age Assurance Selection Workflow
Start with the legal purpose and required assurance level, then compare methods against effectiveness, privacy, accessibility, bias, and evasion risk.
The selected method must work for the service, user journey, content risk, and affected age threshold. A vendor label or nominal accuracy score is not enough.
Choose age assurance only after identifying the duty it must satisfy. Part 5 services that publish or display their own pornographic content have had highly effective age-assurance duties since 17 January 2025. Part 3 user-to-user and search services may need to prevent children from encountering pornography or to support a children's-access conclusion. Test candidate methods in the real user journey and record why the selected combination meets the applicable duty without collecting more personal data than necessary.
1
Section 1
How should an age assurance selection workflow run?
Step 1 - identify the duty and threshold. Record whether the service or relevant part is governed by Part 3 or Part 5, the content or feature being controlled, the age boundary, and the harm caused by a false-adult or false-child result. Under section 230, verifies a user's exact age, while estimates a user's age or age range. The applicable duty may permit either method or both, but the complete process must satisfy the legal standard for that duty.
Step 2 - screen methods against the current Ofcom code and guidance for the duty. Do not infer that a method is highly effective from its name or a supplier's general accuracy figure. Record the evidence source, threshold, test population, known limitations, fallback, and access restriction for the deployed process.
Step 3 - assess privacy and inclusion before procurement. Map every data item, processor, retention period, deletion event, fallback route, and human-review step. A method can support online-safety compliance while still creating UK GDPR or equality risks. Provide an accessible route for users who lack a particular identity document, device, payment method, biometric capability, or credit history.
Step 4 - pilot the full system, not only the vendor component. Test enrolment, retries, the decision boundary where estimation is used, fallback paths, parental or guardian flows where appropriate, account recovery, appeals, and downstream access controls. Test foreseeable circumvention, repeat attempts, account sharing, VPN use, synthetic media, and spoofing where relevant. Approve the method only when evidence shows that the complete journey produces the required outcome.
Trigger: a new service, content surface, age threshold, material design change, new method, or evidence that the current control can be bypassed.
Owners: product defines the journey; safety and legal identify the duty; privacy assesses processing; security tests evasion; accessibility and equality specialists test exclusion; an accountable decision-maker accepts residual risk.
Evidence: legal-purpose statement, children's access assessment, method comparison, vendor evidence, independent or internal test results, data-protection assessment, accessibility findings, decision record, rollout controls, and review date.
Outcome: approve for the named duty and service paths, approve with compensating controls, run a limited pilot, reject, or escalate because the evidence does not support the required assurance level. Approval for one duty or implementation does not establish that the same method is sufficient elsewhere.
What fields should the Age Assurance Selection Workflow template capture?
The decision record should let a later reviewer reconstruct the choice. Record the exact age threshold and protected content, the required level of assurance, candidate methods, test population, error rates around the threshold, demographic performance, attack tests, fallback route, data fields, retention, processors, accessibility barriers, complaints route, and the person who approved the residual risk.
Separate vendor claims from results observed in your implementation and keep the test protocol with the result.
Record false-adult and false-child outcomes separately; an average accuracy figure can hide the error that matters for the duty.
Document how a user who cannot or will not use the primary method can reach an equivalent, accessible alternative.
Set measurable monitoring thresholds for bypass, abandonment, complaints, demographic disparity, and unexpected data retention.
How should teams review and improve the Age Assurance Selection Workflow?
Review the method when Ofcom changes its guidance or codes, the service or threshold changes, the supplier changes its model or data flow, monitoring shows material error or circumvention, complaints identify exclusion, or the children's access or risk assessment changes. A scheduled review does not replace an immediate review after evidence that the control may no longer be effective.
Re-test with current users and current attack techniques rather than carrying forward an earlier certification or benchmark.
Check that the result still controls every relevant route, including logged-out access, embedded content, alternate clients, account recovery, and new features.
Investigate changes in error, bypass, abandonment, and complaint rates by relevant user group.
Record the decision to retain, change, layer, or withdraw the method and update linked risk and privacy assessments.
Which legal sources and final checks control the selection workflow?
Section 230 of the Online Safety Act supplies the binding definitions of and . The applicable duty and start date depend on the service and content. Current Ofcom codes and guidance explain the regulator's effectiveness expectations, while ICO guidance and the joint Ofcom and ICO statement explain the separate data-protection duties.
Confirm the current Ofcom code and guidance for the service and duty before approving a method. Keep the version and date reviewed with the decision record.
The workflow must assess the deployed method and user journey instead of relying on a generic approval list. Record the performance test, decision threshold, uncertainty handling, bypass testing, privacy and security controls, accessibility checks, and evidence supporting the final choice.
Turn UK Online Safety Act Age Assurance Selection Workflow into assigned work
This UK Online Safety Act guide helps turn Age Assurance Selection Workflow into owners, evidence requests, review checkpoints, and reusable operating records in Sorena.
Supports age-assurance method selection with Ofcom's official summary of highly effective age assurance and Online Safety Act implementation milestones.
"The Online Safety Act has introduced new rules on robust age checks that services must follow to protect children."