- ICO source for age-assurance and data-protection fields in the Online Safety risk assessment template.
"age assurance can form part of an appropriate and proportionate approach"
Use this template to record the assessment boundary, evidence, risk pathway, affected users, design contribution, controls, residual risk, and accountable approval.
It is a working record, not an official Ofcom form. Adapt it to the separate illegal-content or children's risk-assessment duty that applies.
Structured answer sets in this page tree.
Cited legal and guidance references.
Use one controlled record for each applicable Part 3 Online Safety Act risk assessment. The template is a Sorena working aid, not an Ofcom form. It records the service boundary, statutory assessment type, evidence, risk pathways, current controls, residual risk, accountable approval, and review triggers so a later reviewer can reconstruct the decision.
Use a separate controlled record for each illegal-content or children's risk assessment and keep the identifiable as its own decision. Existing services had first-assessment deadlines of 16 March 2025 for illegal content, 16 April 2025 for children's access, and 24 July 2025 for children's risk where triggered. For a new or newly in-scope service, record the applicable three-month period; for a significant change, approve the relevant assessment before release.
For each material risk, record the content or harm kind separately, the encounter or dissemination pathway, affected users and characteristics, likelihood evidence, severity evidence, service-design contribution, existing controls, control test, residual risk, in-force Ofcom code measure or documented effective alternative, action, owner, deadline, and monitoring trigger. For illegal-content assessments, include each priority-illegal-content kind, other illegal content, and, for user-to-user services, commission or facilitation of priority offences.
The evidence index should state the source system, date range, query or test method, version, limitations, retention location, and the conclusion supported. A score without a written rationale and retrievable evidence does not let a later reviewer reconstruct the decision.
Finish with unresolved assumptions, rejected controls and reasons, dependencies, interim restrictions, approval conditions, any required public summary, and event-driven review triggers. Planned work is an action, not an operating control.
Keep each field decision-relevant. Service facts establish scope; evidence fields establish what is known; risk rows show the statutory analysis; control rows show what operates now; action rows show work still due; approval and review fields show who accepted the result and when it must be reopened.
Review the template when a completed assessment cannot be reproduced, a required statutory factor has nowhere to be recorded, actions are mistaken for operating controls, or reviewers cannot tell which evidence supports a conclusion. Reopen the assessment itself whenever the applicable accuracy or significant-change trigger is met.
Use the template to assign evidence requests, control owners, approvals, review checkpoints, and reassessment triggers.
Turn Online Safety Risk Assessment Template into scoped questions, evidence fields, and review tasks.
Use Research Copilot to answer follow-up questions with cited source material.
Review scope, evidence, owners, and the next compliance actions with Sorena.
"age assurance can form part of an appropriate and proportionate approach"
"Children's code"
"providers can take alternative measures and must keep a record of the measures"
"Online Safety Act"
"The Online Safety Act 2023 (the Act) is a new set of laws that protects children and adults online."