Every Part 3 user-to-user and search service must complete and record a suitable and sufficient . Existing services had to complete the first assessment by 16 March 2025; a new or newly in-scope service generally has three months. Keep the assessment up to date and assess a significant design or operational change before making it. Use the findings to choose proportionate safety measures, owners, tests, and monitoring.
1
Section 1
How should an illegal content risk assessment run?
Sections 9 and 26 require providers of regulated user-to-user and search services to carry out a suitable and sufficient illegal-content risk assessment. Assess each of the 18 kinds of separately and assess other illegal content that users may encounter. A user-to-user service must also assess the risk that it is used to commit or facilitate a priority offence. Ofcom's risk profiles are mandatory inputs, not substitutes for the service's own assessment.
Define how each offence or content kind can arise in the service: creation, upload, sharing, messaging, recommendation, search, indexing, monetisation, contact, or off-platform coordination. Consider the user base; likelihood and severity of harm; the number and characteristics of people affected; functionalities and algorithmic systems; the business model; intended and unintended use; and how the service's design, operation, and existing controls increase or reduce risk.
Evidence should combine Ofcom risk profiles with internal data such as prevalence and reach, user reports, complaints, moderation and search samples, recommender tests, enforcement outcomes, threat intelligence, user research, and known blind spots. Low reporting can reflect poor detection or inaccessible reporting, so record uncertainty.
Map every material risk to proportionate design and operational measures, the relevant in-force Ofcom code measure or a documented effective alternative, an owner, test evidence, residual risk, and monitoring threshold. Ofcom guidance recommends a review at least every 12 months, while the Act requires the assessment to remain up to date and requires a further assessment before a .
Scope: provider, service boundary, user-to-user or search function, UK link, users, features, business model, and assessment version.
Risk row: content or offence kind, pathway, likelihood, impact, affected groups, design contribution, existing controls, evidence, and uncertainty.
Decision row: residual risk, code measure or alternative, action, owner, due date, interim restriction, approver, and acceptance reason.
What fields should the Illegal Content Risk Assessment template capture?
Record the provider, service boundary, assessment type and version, content or offence kind, encounter or dissemination pathway, affected groups, likelihood and impact evidence, design contribution, data limitations, existing controls, control test, residual risk, code measure or alternative, action, owner, due date, approval, and review trigger.
Keep and other illegal content identifiable by kind and pathway.
Record both inherent risk and residual risk so the claimed effect of existing controls is visible.
Label estimates, sampling, detection limits, missing markets or features, and other uncertainty beside the conclusion affected.
Do not count a planned mitigation as an operating control; give it an owner, deadline, interim control, and completion test.
How should teams review and improve the Illegal Content Risk Assessment workflow?
Review when there is reason to suspect the assessment is inaccurate and before a significant service change. Triggers include new messaging or group features, a recommender or search change, monetisation, generative-AI functions, a new market, a material user-base shift, a control failure, new offence evidence, or a significant Ofcom risk-profile change. Category 1 and 2A providers must also reflect their registered service boundary and provide Ofcom with the record as soon as reasonably practicable after making or revising it. Following publication of the categorised-services register on 30 June 2026, Ofcom said providers should supply their latest records by October 2026, or confirm where Ofcom already holds an up-to-date record.
Re-run prevalence, reach, search, recommender, reporting, and moderation tests affected by the change.
Compare incidents and complaints with the risks and control assumptions in the approved assessment.
Escalate high-severity plausible harms when evidence is missing rather than assigning a low likelihood by default.
Version the changed evidence, conclusion, mitigation, residual risk, approval, and effective date.
Turn UK Online Safety Act Illegal Content Risk Assessment into assigned work
This UK Online Safety Act guide helps turn Illegal Content Risk Assessment into owners, evidence requests, review checkpoints, and reusable operating records in Sorena.
Explains that code measures vary with the illegal-harm risks identified and that providers using alternatives must keep a record of how they meet the duties.