Artifact GuideUKRisk Assessment Workflow

UK Online Safety Act Risk Assessment Workflow

Risk Assessment Workflow decisions under the UK Online Safety Act should be written in operational language: who is in scope, what must happen, what evidence proves it, and when escalation is needed.

Use this guide to turn official requirements into scope, evidence, owner, and review decisions. This guidance is practical, source-linked, and should be validated against current legal and policy requirements before implementation.

Author
Sorena AI
Published
May 9, 2026
Updated
May 9, 2026
Sections
3

Structured answer sets in this page tree.

Primary sources
4

Cited legal and guidance references.

Publication metadata
Sorena AI
Published May 9, 2026
Updated May 9, 2026
Overview

This page helps you determine when UK Online Safety Act obligations apply, who owns each action, the required evidence, and the review path before escalation.

Section 1

How should a Risk Assessment Workflow run under the UK Online Safety Act?

Run the workflow as online-safety triage: first confirm whether the service is in scope, then check whether children are likely to access it, identify the relevant duty or risk type, decide the mitigation or control, record evidence, assign an owner, and set the next review date. If the service is not in scope, close the item; if it is in scope and the risk is unresolved, escalate before implementation.

  • Check whether the service is a user-to-user service or search service and whether the issue relates to child safety or illegal content.
  • Confirm the source-linked rule that applies, then choose the required action: close, mitigate, escalate, or send for review.
  • Record the decision, the owner, the reviewer, the evidence location, and the next review date.
  • Keep the outcome plain and practical so support, product, legal, security, and compliance teams can use it.
Section 2

What fields should the Risk Assessment Workflow template capture?

A useful template captures service type, user group, risk type, child-access result, code measure, mitigation owner, evidence, review date, and unresolved assumptions. Each field should support a decision, not just store a label.

  • Link to the source URL and include the source quote that supports the decision.
  • Identify the entity, product, service, system, data category, and user group involved.
  • Capture the decision result, control action, owner, reviewer, due date, and escalation reason.
  • Attach the evidence, approval note, exception note, and review cadence used to reach the decision.
Section 3

How should teams review and improve the Risk Assessment Workflow?

Review the workflow after Ofcom code updates, feature changes, algorithm changes, user-base changes, incident trends, complaints, enforcement notices, or transparency-report cycles. Use each review to decide whether the current controls still reduce the identified risk, whether the evidence is sufficient, and whether the item should stay open, be escalated, or be closed.

  • Track recurring exception categories and update intake questions.
  • Remove fields that never affect the decision.
  • Add fields when reviews show missing source evidence or unclear ownership.
  • Confirm the public page and working template include the same visible source-linked guidance.
Primary sources

References and citations

ico.org.uk
Referenced sections
  • ICO source for age-assurance and children-code privacy context that can affect user-group and child-access fields.
"It explains how UK GDPR and the DPA 2018 apply, and how the Children's code and the Online"
ico.org.uk
Referenced sections
  • ICO source for practical review observations that support improving risk-assessment fields after service or evidence reviews.
"This document is described as an interim impact review of the Children's code"
Related guides

Explore more topics

How should teams decide whether UK Online Safety Act applies?
UK Online Safety Act guidance for Regulated Service Scope, with practical decisions, evidence, edge cases, and external source citations.
UK Online Safety Act Age Assurance Guide
UK Online Safety Act guidance for Age Assurance, with practical decisions, evidence, edge cases, and external source citations.
UK Online Safety Act Age Assurance Options Guide
UK Online Safety Act guidance for Age Assurance Options, with practical decisions, evidence, edge cases, and external source citations.
UK Online Safety Act Age Assurance Selection Workflow Guide
UK Online Safety Act guidance for Age Assurance Selection Workflow, with practical decisions, evidence, edge cases, and external source citations.
UK Online Safety Act Applicability Test Guide
Practical guidance for the UK Online Safety Act applicability test, with practical decisions, evidence, edge cases, and external source citations.
UK Online Safety Act Categorisation Guide
UK Online Safety Act guidance for Categorisation, with practical decisions, evidence, edge cases, and external source citations.
UK Online Safety Act Checklist
Practical guidance for the UK Online Safety Act checklist, with practical decisions, evidence, edge cases, and external source citations.
UK Online Safety Act Children's Access Assessment Guide
UK Online Safety Act guidance for Children's Access Assessment, with practical decisions, evidence, edge cases, and external source citations.
UK Online Safety Act Children's Safety Duties Guide
UK Online Safety Act guidance for Children's Safety Duties, with practical decisions, evidence, edge cases, and external source citations.
UK Online Safety Act Complaint And Appeal Handling Workflow Guide
UK Online Safety Act guidance for Complaint And Appeal Handling Workflow, with practical decisions, evidence, edge cases, and external source citations.
UK Online Safety Act Compliance Guide
Practical guidance for the UK Online Safety Act compliance, with practical decisions, evidence, edge cases, and external source citations.
UK Online Safety Act Content Moderation And Appeals Guide
UK Online Safety Act guidance for Content Moderation And Appeals, with practical decisions, evidence, edge cases, and external source citations.
UK Online Safety Act Deadlines and Compliance Calendar Guide
UK Online Safety Act guidance for Deadlines and Compliance Calendar, with practical decisions, evidence, edge cases, and external source citations.
UK Online Safety Act Enforcement And Penalties Guide
UK Online Safety Act guidance for Enforcement And Penalties, with practical decisions, evidence, edge cases, and external source citations.
UK Online Safety Act FAQ
Practical guidance for the UK Online Safety Act FAQ, with practical decisions, evidence, edge cases, and external source citations.
UK Online Safety Act ICO Overlap Guide
UK Online Safety Act guidance for ICO Overlap, with practical decisions, evidence, edge cases, and external source citations.
UK Online Safety Act Illegal Content Duties Explained Guide
UK Online Safety Act guidance for Illegal Content Duties Explained, with practical decisions, evidence, edge cases, and external source citations.
UK Online Safety Act Illegal Content Risk Assessment Guide
UK Online Safety Act guidance for Illegal Content Risk Assessment, with practical decisions, evidence, edge cases, and external source citations.
UK Online Safety Act Moderation And Appeals Guide
UK Online Safety Act guidance for Moderation And Appeals, with practical decisions, evidence, edge cases, and external source citations.
UK Online Safety Act Ofcom Enforcement Guide
UK Online Safety Act guidance for Ofcom Enforcement, with practical decisions, evidence, edge cases, and external source citations.
UK Online Safety Act Ofcom enforcement: penalty tiers, investigations, and senior manager liability
UK Online Safety Act guidance for Ofcom Enforcement, with practical decisions, evidence, edge cases, and external source citations.
UK Online Safety Act Online Safety Risk Assessment Template Guide
UK Online Safety Act guidance for Online Safety Risk Assessment Template, with practical decisions, evidence, edge cases, and external source citations.
UK Online Safety Act penalties and fines Guide
UK Online Safety Act guidance for penalties and fines, with practical decisions, evidence, edge cases, and external source citations.
UK Online Safety Act Regulated Service Scope Guide
UK Online Safety Act guidance for Regulated Service Scope, with practical decisions, evidence, edge cases, and external source citations.
UK Online Safety Act Requirements Guide
Practical guidance for the UK Online Safety Act requirements, with practical decisions, evidence, edge cases, and external source citations.
UK Online Safety Act Risk Assessments Playbook Guide
UK Online Safety Act guidance for Risk Assessments Playbook, with practical decisions, evidence, edge cases, and external source citations.
UK Online Safety Act Senior Manager Liability Guide
UK Online Safety Act guidance for Senior Manager Liability, with practical decisions, evidence, edge cases, and external source citations.
UK Online Safety Act Service Classification Workflow Guide
UK Online Safety Act guidance for Service Classification Workflow, with practical decisions, evidence, edge cases, and external source citations.
UK Online Safety Act Service Scope and Categorization Guide
UK Online Safety Act guidance for Service Scope and Categorization, with practical decisions, evidence, edge cases, and external source citations.
UK Online Safety Act Transparency Reporting Guide
UK Online Safety Act guidance for Transparency Reporting, with practical decisions, evidence, edge cases, and external source citations.
UK Online Safety Act User-to-user And Search Services Guide
UK Online Safety Act guidance for User-to-user And Search Services, with practical decisions, evidence, edge cases, and external source citations.
UK Online Safety Act vs Dsa Guide
UK Online Safety Act guidance for Online Safety Act vs Dsa, with practical decisions, evidence, edge cases, and external source citations.
What should teams do about Age Assurance under the UK Online Safety Act?
UK Online Safety Act guidance for Age Assurance, with practical decisions, evidence, edge cases, and external source citations.
What should teams do about Categorisation under the UK Online Safety Act?
UK Online Safety Act guidance for Categorisation, with practical decisions, evidence, edge cases, and external source citations.
What should teams do about Children's Access Assessment under the UK Online Safety Act?
UK Online Safety Act guidance for Children's Access Assessment, with practical decisions, evidence, edge cases, and external source citations.
What should teams do about Ico Overlap under the UK Online Safety Act?
UK Online Safety Act guidance for Ico Overlap, with practical decisions, evidence, edge cases, and external source citations.
What should teams do about Illegal Content Risk Assessment under the UK Online Safety Act?
UK Online Safety Act guidance for Illegal Content Risk Assessment, with practical decisions, evidence, edge cases, and external source citations.
What should teams do about Moderation And Appeals under the UK Online Safety Act?
UK Online Safety Act guidance for Moderation And Appeals, with practical decisions, evidence, edge cases, and external source citations.
What should teams do about Senior Manager Liability under the UK Online Safety Act?
UK Online Safety Act guidance for Senior Manager Liability, with practical decisions, evidence, edge cases, and external source citations.
What should teams do about Transparency Reporting under the UK Online Safety Act?
UK Online Safety Act guidance for Transparency Reporting, with practical decisions, evidence, edge cases, and external source citations.
What should teams do about User-to-user And Search Services under the UK Online Safety Act?
UK Online Safety Act guidance for User-to-user And Search Services, with practical decisions, evidence, edge cases, and external source citations.