What must the assessment cover?
User-to-user providers assess the risk of users encountering each kind of and other illegal content, and the risk of the service being used to commit or facilitate a priority offence. Search providers assess the risk of users encountering priority illegal content and other illegal content in or via search results. Sections 9 and 26 set the detailed elements for each service type.
The assessment must consider the service's user base, functionalities, algorithmic systems, business model, governance, proactive technology, user tools, intended and unintended uses, and how easily, quickly, and widely content may spread. It must also consider Ofcom's current risk profiles. Rate likelihood and impact using evidence that reflects the actual service.
- Define each assessed service and part, provider entity, user groups, languages, geography, features, algorithms, and revenue model.
- Assess every statutory kind of ; do not limit the work to content already found on the service.
- Record evidence, assumptions, risk level, existing controls, gaps, owner, and the proportionate measure chosen for each material risk.
Sets the illegal content risk assessment duties and required elements for regulated user-to-user services.
Sets the corresponding duties and required elements for regulated search services.
Explains the suitable-and-sufficient standard, required inputs, and relationship between findings and safety measures.