Artifact GuideUKChildren's Access Assessment

UK Online Safety Act Children's Access Assessment

Assess whether a significant number of children use the service or whether the service is likely to attract a significant number of children.

A stated minimum age does not settle the test if children can still access the service. Assess each materially different part and retain the evidence.

Author
Sorena AI
Published
May 9, 2026
Updated
Jul 25, 2026
Sections
4

Structured answer sets in this page tree.

Primary sources
8

Cited legal and guidance references.

Publication metadata
Sorena AI
Published May 9, 2026
Updated Jul 25, 2026
Overview

A under sections 35 to 37 decides whether a Part 3 user-to-user or search service, or a materially different part of it, is likely to be accessed by under-18s. Existing services had to complete the first assessment by 16 April 2025. If the answer is yes, the provider must complete the applicable children's risk assessment and follow the child-safety duty route. If the answer is no, keep the evidence and repeat the assessment within 12 months or sooner when a statutory or Ofcom trigger applies.

Section 1

How should a children's access assessment work under the UK Online Safety Act?

The duty applies to the provider of every regulated with links to the United Kingdom, including a provider established elsewhere. Confirm that the product is a regulated user-to-user service, search service, or combined service and test the Schedule 1 exemptions before applying the access assessment. Category status does not decide whether this gateway duty applies.

Stage 1 asks whether means children are not normally able to access the service or part. If not, Stage 2 applies the : children are likely to access the service when a significant number of children use it, or the service is of a kind likely to attract a significant number of child users. Significant is contextual and does not require children to form a majority of users.

Use evidence about actual and expected access: reliable age data, registration and usage data, audience research, app-store and marketing choices, content and feature appeal, complaints, support contacts, search queries, school or parent reports, and evidence of circumvention. Do not rely on terms that set a minimum age when the access control is not effective.

A provider can end the assessment at Stage 1 only when the resulting access control is highly effective so that children are not normally able to access the service. A minimum-age term, self-declaration, or weak gate is not enough. Analyse logged-out views, embedded content, alternate clients, account sharing, recovery paths, and each separable service part.

If children are likely to access the service or a part of it, record that result and open the applicable children's risk assessment and safety duties. For a new service that is , Ofcom states that the children's risk assessment is due within three months; it must also be completed before a significant change. If children are not likely to access the service, keep the Stage 1 or Stage 2 evidence and the events that trigger a fresh assessment.

  • Scope decision: identify the provider, service type, UK links, exemptions, and every materially different service part before recording the access result.
  • Outcome: , not likely to be accessed by children because Stage 1 establishes that children cannot normally access the service or Stage 2 establishes that the is not met, or insufficient evidence pending a stated protective interim position.
  • Evidence: service map, child-user data, attraction analysis, access-control tests, bypass tests, assumptions, data gaps, reviewer, and approval.
  • Part-by-part result: explain why materially different public, logged-in, search, messaging, or content areas share or do not share the same conclusion.
  • Review trigger: new feature, audience or marketing change, evidence of child use, control bypass, method change, Ofcom update, or reason to suspect the assessment is inaccurate.
Section 2

What fields should the Children's Access Assessment template capture?

Record the provider, service and part assessed, user and feature map, assessment date, actual child-use evidence, attraction evidence, stated age, access-control design and test, circumvention evidence, data limitations, result, reviewer, approval, linked children's risk-assessment action, and review triggers.

  • Separate actual-use evidence from evidence that the service is likely to attract children.
  • State the measurement period, age-data quality, sample coverage, and users or access paths the data does not cover.
  • Record each materially different service part and the reason it shares or does not share the overall conclusion.
  • If evidence is insufficient, record an interim protective position and the work needed to resolve the gap.
Section 3

How should teams review and improve the Children's Access Assessment workflow?

Review the assessment when there is reason to suspect it is no longer accurate and after changes that could affect child use or access prevention. Relevant events include new content or social functions, marketing or audience changes, logged-out access, a new market, an age-assurance change, bypass evidence, complaints, or a material change in child-user data.

Treat the Act as the binding source for who must assess, the likely-access test, and the reassessment triggers. Ofcom's guidance explains the regulator's two-stage method and evidence expectations; it does not replace the statutory test. Record which conclusion comes from the Act, which method comes from guidance, and any judgment the provider made where the evidence was incomplete.

  • Re-run access-control and circumvention tests across web, app, embedded, recovery, and alternate-client routes.
  • Compare observed child use with the forecast and explain material differences.
  • Open or update the children's risk assessment when the result changes to likely accessed.
  • Keep the prior version, new evidence, changed conclusion, approval, and effective date.
Section 4

Which sources control the assessment, and what should happen next?

Sections 35 to 37 of the Online Safety Act control the scope, test, timing, and reassessment duties. Ofcom's guidance explains the operating sequence and evidence expectations. UK Government and ICO material provides policy and data-protection context but does not replace the Act or Ofcom's statutory guidance.

This page gives a general decision method, not a service-specific legal conclusion. Confirm the provider, UK links, exemptions, service parts, current Ofcom publications, and the deployed age-assurance evidence before relying on a negative assessment. Keep the source version and review date with the assessment record.

  • Binding law: Online Safety Act sections 35 to 37 set the assessment duty, likely-access test, timing framework, and reassessment events.
  • Regulator guidance: Ofcom explains the two-stage method, evidence expectations, highly effective age-assurance branch, and operational deadlines.
  • Related law: UK data-protection duties continue to apply when age assurance or child-user analysis processes personal data.
  • Next action: approve a part-by-part result, preserve the evidence, and open the children's risk assessment immediately for every part .
Primary sources

References and citations

ico.org.uk
Referenced sections
  • Review support for Children's Access Assessment.
"The OSA places requirements for age assurance on organisations that fall in scope."
legislation.gov.uk
Referenced sections
  • Primary legislation for the meaning of a Part 3 service being likely to be accessed by children.
"Meaning of ‘likely to be accessed by children’"
legislation.gov.uk
Referenced sections
  • Binding law for children's access assessments, the assessment periods, provider duties, and the meaning of likely access.
gov.uk
Referenced sections
  • Review support for Children's Access Assessment.
"The Online Safety Act 2023 (the Act) is a new set of laws that protects children and adults online."
Related guides

Explore more topics

Does the UK Online Safety Act apply to this service?
A practical scope test for user-to-user, search, and provider-pornography services under the UK Online Safety Act, including UK links and exemptions.
How Ofcom and ICO duties overlap for online services
How the UK Online Safety Act, UK GDPR, Data Protection Act 2018, and Children's Code apply together to safety technologies and children's data.
How Ofcom enforces the UK Online Safety Act
Ofcom information notices, investigations, representations, confirmation decisions, penalties, remediation, and court-based service restrictions.
How to complete a children's access assessment
The two-stage UK Online Safety Act children's access assessment, evidence, timing, reassessment triggers, and next duties.
How to complete an illegal content risk assessment
UK Online Safety Act illegal content risk assessment scope, required elements, deadlines, review triggers, records, and resulting safety measures.
Is This a User-to-user or Search Service Under the UK Online Safety Act?
Classify user-to-user, search, and combined services under the UK Online Safety Act, apply the UK-links and exemption tests, and identify the next duties.
Ofcom Transparency Reporting FAQ
Who receives Ofcom transparency notices, what Schedule 8 can require, the 2026 notice process, first-report timing, and evidence controls.
Online Safety Act Complaints Handling Workflow
Route and decide Online Safety Act complaints, record the required response, and distinguish an internal review from an Ofcom complaint or super-complaint.
Online Safety Act Illegal Content Risk Assessment
Assess illegal-content risks by offence kind, likelihood, severity, affected users, service design, controls, evidence, and review triggers.
Online Safety Act moderation, reporting, and complaints
How UK Online Safety Act duties shape content moderation, user reporting, complaints, reinstatement, terms, records, and human oversight.
Online Safety Act: User-to-user and Search Service Scope
Decide whether an online service is a regulated user-to-user service, search service, combined service, or exempt service under the UK Online Safety Act.
UK Online Safety Act Age Assurance Options
Compare age verification and age estimation methods by assurance, privacy, accessibility, bias, evasion risk, and operational evidence.
UK Online Safety Act Age Assurance Requirements
When Online Safety Act services need age assurance, what highly effective age assurance means, and how safety duties interact with data protection.
UK Online Safety Act Age Assurance Selection Workflow
Choose an age-assurance method for an Online Safety Act duty by testing effectiveness, privacy, accessibility, evasion risk, and the consequence of error.
UK Online Safety Act Applicability Test Guide
Test whether a service is covered by the UK Online Safety Act by checking service functionality, UK links, exemptions, and the duties that follow.
UK Online Safety Act categories: thresholds and duties
How Category 1, 2A, and 2B thresholds work, how Ofcom categorises services, and what the July 2026 register means.
UK Online Safety Act Categorisation Guide
Apply the UK Online Safety Act Category 1, 2A, and 2B thresholds, calculate active UK users, and use Ofcom's register published in June 2026 and updated in July.
UK Online Safety Act Checklist
Verify UK Online Safety Act scope, assessments, controls, reporting, complaints, records, child safety, and category-specific work.
UK Online Safety Act Children's Safety Duties Guide
Apply the UK Online Safety Act children's access, risk-assessment, safety, age-assurance, reporting, complaints, and record-keeping duties.
UK Online Safety Act Compliance Guide
Build a UK Online Safety Act compliance program from service scope through assessments, controls, evidence, review, and Ofcom response.
UK Online Safety Act Content Moderation and Appeals Guide
Design UK Online Safety Act moderation, content-reporting, complaints, and review processes for illegal content and content harmful to children.
UK Online Safety Act Deadlines and Compliance Calendar Guide
UK Online Safety Act compliance dates for risk assessments, child safety, categorised services, fees, and event-based deadlines.
UK Online Safety Act Enforcement and Penalties Guide
How Ofcom investigates Online Safety Act breaches, issues decisions, requires remedies, imposes penalties, and seeks court orders.
UK Online Safety Act FAQ: scope, duties, and deadlines
Standalone answers and decision paths for UK Online Safety Act scope, risk assessments, child protection, age assurance, categories, reporting, and enforcement.
UK Online Safety Act ICO Overlap Guide
Apply the Online Safety Act and UK data protection law together for age assurance, moderation, profiling, recommender systems, and safety-data sharing.
UK Online Safety Act Illegal Content Duties Explained
Understand the illegal-content risk assessment, safety, reporting, complaints, record-keeping, and review duties for regulated user-to-user and search services.
UK Online Safety Act Moderation, Complaints and Appeals
Build moderation, content-reporting, and complaints procedures for regulated services, and understand where the Online Safety Act does and does not require an appeal.
UK Online Safety Act Ofcom Enforcement Guide
How Ofcom assesses Online Safety Act concerns, gathers information, investigates suspected breaches, and reaches enforcement decisions.
UK Online Safety Act Penalties and Fines Guide
The Online Safety Act penalty ceiling, qualifying worldwide revenue, daily penalties, penalty factors, and payment consequences.
UK Online Safety Act Regulated Service Scope Guide
Understand which user-to-user, search, combined, and provider-pornography services the UK Online Safety Act regulates and which exemptions narrow scope.
UK Online Safety Act Requirements Guide
See which UK Online Safety Act requirements apply to Part 3 services, child-accessible services, provider pornography, and categorised services.
UK Online Safety Act Risk Assessment Template
A field-by-field template for recording service facts, statutory risks, evidence, controls, residual risk, approval, and reassessment triggers.
UK Online Safety Act Risk Assessment Workflow
Run illegal-content and children's risk assessments in the right order, with evidence for risks, controls, governance, and reassessment triggers.
UK Online Safety Act Risk Assessments Playbook
Organise recurring Online Safety Act risk assessments across product, safety, data, engineering, legal, and governance teams.
UK Online Safety Act Senior Manager Liability Explained
Understand when a named senior manager or corporate officer can face personal liability for Online Safety Act information offences and how to control the risk.
UK Online Safety Act Service Classification Workflow
Decide whether a service is regulated, whether it is user-to-user or search, which exemptions apply, and whether Ofcom categorisation adds duties.
UK Online Safety Act Service Scope and Categorization Guide
Move from UK Online Safety Act service scope to Category 1, 2A, or 2B threshold analysis without confusing categorisation with basic coverage.
UK Online Safety Act Transparency Reporting
Understand who must publish an Online Safety Act transparency report, what an Ofcom notice controls, and how to prepare traceable reporting data.
UK Online Safety Act vs DSA: scope and duties
Compare UK Online Safety Act and EU DSA scope, service classes, child-safety and platform duties, dates, evidence, exemptions, and enforcement.
When Are Senior Managers Liable Under the UK Online Safety Act?
When section 110 can make a named senior manager liable for an Online Safety Act information offence, the available defences, and the controls to keep.
When is age assurance required under the UK Online Safety Act?
When UK Online Safety Act services need highly effective age assurance, what Ofcom expects, and how UK data protection law applies.