- ICO source for age-assurance and children-code privacy context that can affect user-group and child-access fields.
"UK GDPR and the DPA 2018"
Confirm scope, complete the children's access assessment, run each applicable risk assessment, choose proportionate controls, and retain the reasoning.
Illegal-content and children's risk assessments are separate statutory duties. One register can support both, but it must preserve their different hazards, factors, and conclusions.
Structured answer sets in this page tree.
Cited legal and guidance references.
Use this workflow for a Part 3 user-to-user or search service. Complete and record an illegal-content risk assessment for every regulated service. Complete a children's access assessment separately; if children are likely to access the service or part of it, complete the applicable children's risk assessment. New or newly in-scope services generally have three months for the first assessment, while a to the service's design or operation requires the relevant risk assessment before release.
Step 1 - define the assessed service and scope boundary. Record the provider, service type, UK link, user and search functions, excluded or exempt parts, launch status, user base, business model, and dependencies. A group-wide assessment works only if it shows how the conclusions apply to each regulated service.
Step 2 - collect evidence before scoring. Use Ofcom's risk profiles, internal prevalence and reach data, complaints, reports, enforcement data, user research, threat intelligence, recommender and search testing, and evidence about children. Record missing data; absence of reports does not establish absence of risk.
Step 3 - assess each statutory risk in the form required for the service. Illegal-content assessments separate each priority-illegal-content kind and other illegal content; user-to-user assessments also cover commission or facilitation of priority offences. Children's assessments separate each kind of primary-priority and priority content harmful to children and consider age groups. Consider likelihood, severity, affected users and their characteristics, design and operation, intended and unintended use, and how content is encountered or disseminated.
Step 4 - map conclusions to proportionate measures, owners, and evidence. Compare proposed design and operational controls with the applicable in-force Ofcom code. A provider may use effective alternative measures, but it remains responsible for meeting the binding duty and should retain the evidence and rationale for the alternative.
Step 5 - approve, disclose where required, and monitor assumptions. An accountable owner should accept residual risk, fund actions, set deadlines, and define reassessment evidence. Category 1 and 2A services on Ofcom's July 2026 register have additional illegal-content risk-assessment record and summary duties; those duties do not apply to every Part 3 service.
Record the assessment version, service facts, responsible people, applicable duty, Ofcom risk-profile reference, hazard, affected users, evidence, likelihood and impact rationale, design contribution, existing controls, residual risk, code measure or alternative, action, owner, due date, approval, and review trigger. Each score needs a written rationale and linked evidence.
Review the workflow after Ofcom code or significant risk-profile updates, feature changes, algorithm changes, user-base changes, incident trends, complaints, enforcement notices, or transparency-report cycles. Ofcom recommends reviewing risk assessments at least every 12 months, but event-driven duties can require earlier action. Decide whether current controls still reduce the identified risk, whether the evidence is sufficient, and whether the item should stay open, be escalated, or be closed.
Assign the assessment boundary, evidence inputs, risk decisions, controls, approvals, monitoring thresholds, and reassessment triggers.
Turn Risk Assessment Workflow into scoped questions, evidence fields, and review tasks.
Use Research Copilot to answer follow-up questions with cited source material.
Review scope, evidence, owners, and the next compliance actions with Sorena.
"UK GDPR and the DPA 2018"
"Children's code"
"Ofcom must keep the codes of practice under review."
"Section 47(1) of the OSA require Ofcom to keep under review each code of practice."