- Review support for Children's Access Assessment.
"The OSA places requirements for age assurance on organisations that fall in scope."
Assess whether a significant number of children use the service or whether the service is likely to attract a significant number of children.
A stated minimum age does not settle the test if children can still access the service. Assess each materially different part and retain the evidence.
Structured answer sets in this page tree.
Cited legal and guidance references.
A under sections 35 to 37 decides whether a Part 3 user-to-user or search service, or a materially different part of it, is likely to be accessed by under-18s. Existing services had to complete the first assessment by 16 April 2025. If the answer is yes, the provider must complete the applicable children's risk assessment and follow the child-safety duty route. If the answer is no, keep the evidence and repeat the assessment within 12 months or sooner when a statutory or Ofcom trigger applies.
The duty applies to the provider of every regulated with links to the United Kingdom, including a provider established elsewhere. Confirm that the product is a regulated user-to-user service, search service, or combined service and test the Schedule 1 exemptions before applying the access assessment. Category status does not decide whether this gateway duty applies.
Stage 1 asks whether means children are not normally able to access the service or part. If not, Stage 2 applies the : children are likely to access the service when a significant number of children use it, or the service is of a kind likely to attract a significant number of child users. Significant is contextual and does not require children to form a majority of users.
Use evidence about actual and expected access: reliable age data, registration and usage data, audience research, app-store and marketing choices, content and feature appeal, complaints, support contacts, search queries, school or parent reports, and evidence of circumvention. Do not rely on terms that set a minimum age when the access control is not effective.
A provider can end the assessment at Stage 1 only when the resulting access control is highly effective so that children are not normally able to access the service. A minimum-age term, self-declaration, or weak gate is not enough. Analyse logged-out views, embedded content, alternate clients, account sharing, recovery paths, and each separable service part.
If children are likely to access the service or a part of it, record that result and open the applicable children's risk assessment and safety duties. For a new service that is , Ofcom states that the children's risk assessment is due within three months; it must also be completed before a significant change. If children are not likely to access the service, keep the Stage 1 or Stage 2 evidence and the events that trigger a fresh assessment.
Record the provider, service and part assessed, user and feature map, assessment date, actual child-use evidence, attraction evidence, stated age, access-control design and test, circumvention evidence, data limitations, result, reviewer, approval, linked children's risk-assessment action, and review triggers.
Review the assessment when there is reason to suspect it is no longer accurate and after changes that could affect child use or access prevention. Relevant events include new content or social functions, marketing or audience changes, logged-out access, a new market, an age-assurance change, bypass evidence, complaints, or a material change in child-user data.
Treat the Act as the binding source for who must assess, the likely-access test, and the reassessment triggers. Ofcom's guidance explains the regulator's two-stage method and evidence expectations; it does not replace the statutory test. Record which conclusion comes from the Act, which method comes from guidance, and any judgment the provider made where the evidence was incomplete.
Sections 35 to 37 of the Online Safety Act control the scope, test, timing, and reassessment duties. Ofcom's guidance explains the operating sequence and evidence expectations. UK Government and ICO material provides policy and data-protection context but does not replace the Act or Ofcom's statutory guidance.
This page gives a general decision method, not a service-specific legal conclusion. Confirm the provider, UK links, exemptions, service parts, current Ofcom publications, and the deployed age-assurance evidence before relying on a negative assessment. Keep the source version and review date with the assessment record.
This UK Online Safety Act guide helps turn Children's Access Assessment into owners, evidence requests, review checkpoints, and reusable operating records in Sorena.
Turn Children's Access Assessment into scoped questions, evidence fields, and review tasks.
Use Research Copilot to answer follow-up questions with cited source material.
Review scope, evidence, owners, and the next compliance actions with Sorena.
"The OSA places requirements for age assurance on organisations that fall in scope."
"Meaning of ‘likely to be accessed by children’"
"Online Safety Act"
"The Online Safety Act 2023 (the Act) is a new set of laws that protects children and adults online."
"Providers must use risk and evidence-based approaches to ensure there is no room for illegal content and activity on their platforms."