Artifact GuideUKCompliance

UK Online Safety Act Compliance

This implementation guide helps translate the UK Online Safety Act duties into owned controls, evidence, review checkpoints, and escalation paths.

Compliance is service-specific and ongoing. The provider must connect each legal duty to current risk evidence, an implemented measure, a named owner, and a review trigger.

Author
Sorena AI
Published
May 9, 2026
Updated
Jul 24, 2026
Sections
4

Structured answer sets in this page tree.

Primary sources
9

Cited legal and guidance references.

Publication metadata
Sorena AI
Published May 9, 2026
Updated Jul 24, 2026
Overview

Run the program in dependency order: approve service scope, complete the illegal-content assessment, implement core safety and user processes, assess child access, complete child-safety work where triggered, map Part 5 pornography duties, then add formal category duties. Treat each issued as a statutory compliance route, while keeping the underlying duty and any alternative-measure rationale visible. Keep the records current and ready for Ofcom information requests.

Section 1

How should teams structure a UK Online Safety Act Compliance plan?

Create a scope record for each regulated user-to-user part, public search engine, and provider-pornography service. Identify the provider entity, UK link, exemptions, users, content flows, and features that affect risk.

Complete separate illegal-content and, where triggered, children's risk assessments. Consult the current Ofcom risk profiles and guidance, record all aspects of the assessment in an understandable form, and complete a new assessment before a .

Translate each risk into a measure, owner, evidence, monitoring signal, and review date. Map issued Ofcom code measures or explain how an satisfies the underlying duty. Maintain content-reporting, complaints, terms, privacy, and freedom-of-expression controls alongside moderation and product measures.

Add Part 5 age-verification or age-estimation work for provider pornographic content and category-specific work only where those legal triggers apply. Ofcom's register, first published on 30 June 2026 and updated on 10 July 2026, is the source for formal , 2A, and 2B status.

Sequence timing from the actual trigger. The first illegal-content and child-access deadlines for existing services passed in March and April 2025, and the first children's risk-assessment deadline passed on 24 July 2025. A later launch, a service coming into scope, or a can create a new assessment deadline; preserve the trigger date and calculation instead of copying the historic calendar.

  • Use one controlled register linking duty, service part, risk, measure, owner, evidence, legal source, status, and review trigger.
  • Treat completed 2025 deadlines as historical evidence and use event-based timing for new or materially changed services.
  • Keep drafts, guidance, issued codes, binding provisions, and Ofcom notices clearly labelled by legal status.
  • Escalate gaps where the team cannot show the service facts, risk evidence, control operation, or decision rationale.
Section 2

Who should own the UK Online Safety Act compliance, and what evidence should prove the decision?

As an operating control, assign an accountable program owner with authority to resolve gaps across product, engineering, trust and safety, data, privacy, legal, support, and communications. Give each control and assessment an operational owner and a named reviewer.

Keep signed or approved scope and risk records, code mappings, control specifications, test results, moderation and complaint evidence, age-assurance decisions, terms versions, incident reviews, category records, review logs, and regulator correspondence.

  • Give owners authority to change the feature or process that creates the risk, not only to write a policy.
  • Use evidence dates and service versions so a record proves the current control rather than a retired design.
  • Track open assumptions, accepted residual risks, overdue actions, control failures, and the decision-maker for each.
  • Prepare a response protocol for accurate, complete, and timely Ofcom information-notice handling.
Section 3

Which edge cases should teams check before relying on a UK Online Safety Act compliance decision?

A policy or completed assessment does not prove compliance if the service has not implemented and maintained the measures. Code measures are not the only route, but an alternative requires a defensible connection to the underlying duty.

Do not merge different legal tests into one risk score. Scope, illegal-content risk, child access, child harm, provider pornography, and category thresholds each require their own conclusion.

Ofcom can investigate, require information, and enforce the Act. For a breach, the maximum penalty can be the greater of £18 million or 10% of qualifying worldwide revenue. The Act also provides court-based service-restriction and access-restriction routes in specified serious cases. The available response depends on the breached duty, notice, and facts.

  • Check feature launches before release; a post-launch review may be too late for the significant-change assessment duty.
  • Check outsourced moderation and age assurance against the provider's own duties, evidence access, testing, and incident response.
  • Check that safety processing also meets data-protection requirements and that privacy controls do not silently disable required safety measures.
  • Check whether the formal category register or an Ofcom notice changes reporting, fee, risk-record, or additional-duty work.
Section 4

How should teams run and review the compliance program?

Use stage gates: no duty mapping without an approved service boundary; no final control plan without completed risk assessments; no without the required pre-change assessment; and no closure without implementation and test evidence.

Review on a scheduled cadence and after changes in service design, user base, risk evidence, incidents, complaints, control performance, formal category, or official codes and guidance. Record whether each change requires a new statutory assessment, a control retest, an updated record, or all three.

  • Report status by service and duty, not only by project completion percentage.
  • Keep a dated log of control decisions, exceptions, approvals, tests, and corrective actions.
  • Use complaints, moderation errors, incidents, and user research as inputs to the next assessment and review.
  • For and 2A services, update and prepare current illegal-content risk-assessment records for Ofcom's October 2026 expectation.
Primary sources

References and citations

ofcom.org.uk
Referenced sections
  • Formal register published on 30 June 2026 and updated on 10 July 2026, with the service boundaries used to assign additional work.
legislation.gov.uk
Referenced sections
  • Primary source for the provider duties, records, reviews, codes, information powers, categories, and enforcement framework.
legislation.gov.uk
Referenced sections
  • Binding source for Ofcom's enforcement powers, penalties, and the statutory service-restriction and access-restriction order framework.
Related guides

Explore more topics

Does the UK Online Safety Act apply to this service?
A practical scope test for user-to-user, search, and provider-pornography services under the UK Online Safety Act, including UK links and exemptions.
How Ofcom and ICO duties overlap for online services
How the UK Online Safety Act, UK GDPR, Data Protection Act 2018, and Children's Code apply together to safety technologies and children's data.
How Ofcom enforces the UK Online Safety Act
Ofcom information notices, investigations, representations, confirmation decisions, penalties, remediation, and court-based service restrictions.
How to complete a children's access assessment
The two-stage UK Online Safety Act children's access assessment, evidence, timing, reassessment triggers, and next duties.
How to complete an illegal content risk assessment
UK Online Safety Act illegal content risk assessment scope, required elements, deadlines, review triggers, records, and resulting safety measures.
Is This a User-to-user or Search Service Under the UK Online Safety Act?
Classify user-to-user, search, and combined services under the UK Online Safety Act, apply the UK-links and exemption tests, and identify the next duties.
Ofcom Transparency Reporting FAQ
Who receives Ofcom transparency notices, what Schedule 8 can require, the 2026 notice process, first-report timing, and evidence controls.
Online Safety Act Children's Access Assessment
Decide whether children are likely to access a regulated service or part of it, document the evidence, and identify when a children's risk assessment follows.
Online Safety Act Complaints Handling Workflow
Route and decide Online Safety Act complaints, record the required response, and distinguish an internal review from an Ofcom complaint or super-complaint.
Online Safety Act Illegal Content Risk Assessment
Assess illegal-content risks by offence kind, likelihood, severity, affected users, service design, controls, evidence, and review triggers.
Online Safety Act moderation, reporting, and complaints
How UK Online Safety Act duties shape content moderation, user reporting, complaints, reinstatement, terms, records, and human oversight.
Online Safety Act: User-to-user and Search Service Scope
Decide whether an online service is a regulated user-to-user service, search service, combined service, or exempt service under the UK Online Safety Act.
UK Online Safety Act Age Assurance Options
Compare age verification and age estimation methods by assurance, privacy, accessibility, bias, evasion risk, and operational evidence.
UK Online Safety Act Age Assurance Requirements
When Online Safety Act services need age assurance, what highly effective age assurance means, and how safety duties interact with data protection.
UK Online Safety Act Age Assurance Selection Workflow
Choose an age-assurance method for an Online Safety Act duty by testing effectiveness, privacy, accessibility, evasion risk, and the consequence of error.
UK Online Safety Act Applicability Test Guide
Test whether a service is covered by the UK Online Safety Act by checking service functionality, UK links, exemptions, and the duties that follow.
UK Online Safety Act categories: thresholds and duties
How Category 1, 2A, and 2B thresholds work, how Ofcom categorises services, and what the July 2026 register means.
UK Online Safety Act Categorisation Guide
Apply the UK Online Safety Act Category 1, 2A, and 2B thresholds, calculate active UK users, and use Ofcom's register published in June 2026 and updated in July.
UK Online Safety Act Checklist
Verify UK Online Safety Act scope, assessments, controls, reporting, complaints, records, child safety, and category-specific work.
UK Online Safety Act Children's Safety Duties Guide
Apply the UK Online Safety Act children's access, risk-assessment, safety, age-assurance, reporting, complaints, and record-keeping duties.
UK Online Safety Act Content Moderation and Appeals Guide
Design UK Online Safety Act moderation, content-reporting, complaints, and review processes for illegal content and content harmful to children.
UK Online Safety Act Deadlines and Compliance Calendar Guide
UK Online Safety Act compliance dates for risk assessments, child safety, categorised services, fees, and event-based deadlines.
UK Online Safety Act Enforcement and Penalties Guide
How Ofcom investigates Online Safety Act breaches, issues decisions, requires remedies, imposes penalties, and seeks court orders.
UK Online Safety Act FAQ: scope, duties, and deadlines
Standalone answers and decision paths for UK Online Safety Act scope, risk assessments, child protection, age assurance, categories, reporting, and enforcement.
UK Online Safety Act ICO Overlap Guide
Apply the Online Safety Act and UK data protection law together for age assurance, moderation, profiling, recommender systems, and safety-data sharing.
UK Online Safety Act Illegal Content Duties Explained
Understand the illegal-content risk assessment, safety, reporting, complaints, record-keeping, and review duties for regulated user-to-user and search services.
UK Online Safety Act Moderation, Complaints and Appeals
Build moderation, content-reporting, and complaints procedures for regulated services, and understand where the Online Safety Act does and does not require an appeal.
UK Online Safety Act Ofcom Enforcement Guide
How Ofcom assesses Online Safety Act concerns, gathers information, investigates suspected breaches, and reaches enforcement decisions.
UK Online Safety Act Penalties and Fines Guide
The Online Safety Act penalty ceiling, qualifying worldwide revenue, daily penalties, penalty factors, and payment consequences.
UK Online Safety Act Regulated Service Scope Guide
Understand which user-to-user, search, combined, and provider-pornography services the UK Online Safety Act regulates and which exemptions narrow scope.
UK Online Safety Act Requirements Guide
See which UK Online Safety Act requirements apply to Part 3 services, child-accessible services, provider pornography, and categorised services.
UK Online Safety Act Risk Assessment Template
A field-by-field template for recording service facts, statutory risks, evidence, controls, residual risk, approval, and reassessment triggers.
UK Online Safety Act Risk Assessment Workflow
Run illegal-content and children's risk assessments in the right order, with evidence for risks, controls, governance, and reassessment triggers.
UK Online Safety Act Risk Assessments Playbook
Organise recurring Online Safety Act risk assessments across product, safety, data, engineering, legal, and governance teams.
UK Online Safety Act Senior Manager Liability Explained
Understand when a named senior manager or corporate officer can face personal liability for Online Safety Act information offences and how to control the risk.
UK Online Safety Act Service Classification Workflow
Decide whether a service is regulated, whether it is user-to-user or search, which exemptions apply, and whether Ofcom categorisation adds duties.
UK Online Safety Act Service Scope and Categorization Guide
Move from UK Online Safety Act service scope to Category 1, 2A, or 2B threshold analysis without confusing categorisation with basic coverage.
UK Online Safety Act Transparency Reporting
Understand who must publish an Online Safety Act transparency report, what an Ofcom notice controls, and how to prepare traceable reporting data.
UK Online Safety Act vs DSA: scope and duties
Compare UK Online Safety Act and EU DSA scope, service classes, child-safety and platform duties, dates, evidence, exemptions, and enforcement.
When Are Senior Managers Liable Under the UK Online Safety Act?
When section 110 can make a named senior manager liable for an Online Safety Act information offence, the available defences, and the controls to keep.
When is age assurance required under the UK Online Safety Act?
When UK Online Safety Act services need highly effective age assurance, what Ofcom expects, and how UK data protection law applies.