OFCOM’s guidance about children’s risk assessments
Children’s Risk Assessment Guidance and Children’s Risk Profiles
Published 24 April 2025
Contents¶
Part 1: Duties and carrying out a children’s risk assessment¶
1. Introduction ........................................................................................................................ 4
2. Children’s risk assessment duties....................................................................................... 6
Part 2: How to carry out a children's risk assessment¶
1. Overview of the four-step risk assessment process ........................................................ 18
2. Detailed explanation of the four steps............................................................................. 21
Part 3: Supporting information¶
1. Children’s Risk Profiles ..................................................................................................... 38
2. Non-designated content .................................................................................................. 56
3. Evidence inputs ................................................................................................................ 58
4. Risk Level Table for content harmful to children ............................................................. 68
5. Making a significant change to your service .................................................................... 72
Annex¶
1. Appendix A: Examples of how to use the Risk Level Table .............................................. 76
6. Appendix B: Comparison of children’s and illegal content risk assessment duties ......... 64
Part 1: Duties and carrying out a children’s risk assessment¶
Section 1 Introduction¶
Box 1: Assessing the risk of harm to children To meet the requirements of the children’s risk assessment duties set out in the Act, you should assess the risk of harm to children presented by content that is harmful to children. Content harmful to children includes primary priority content, priority content, and non-designated content that is harmful to children. You must give separate consideration to children in different age groups and also assess how the design and use of your service affects the level of risk of harm to children.
1 Section 11 for user-to-user services and section 28 for search services in the Act. 2 Section 7(4) of the Act. For illegal content risk assessment duties, see section 9 for user-to-user services and section 26 for search services in the Act.
c) Part 3 includes supporting information for completing each step in the four-step methodology. d) Appendix A provides examples of how to use the Risk Level Table. e) Appendix B contains a comparison of the children’s and illegal content risk assessment duties.
Section 2 Children’s risk assessment duties¶
What are the children’s risk assessment duties?¶
3 Sections 7(4), 11(1), 24(4) and 28(1) of the Act. 4 The legal definition of content harmful to children is included in section 60 of the Act.
5 Sections 11 and 24 of the Act. 6 Children’s risk assessment duties are set out in Section 11 of the Act (for user-to-user service providers), and section 28 of the Act (for search service providers). 7 Section 11(6) and 28(5) of the Act. 8 Section 11(6) and 28(5) of the Act. 9 Section 11(2) and 28(2) of the Act. 10 Sections 11(3) and 28(3) of the Act.
• You must carry out a further children’s risk assessment before making any significant change to any aspect of your service’s design or operation, relating to that proposed change;11 • You need to keep a record of each children’s risk assessment you carry out.12 We have published separate Record-Keeping and Review Guidance to help you with this.
What is a ‘suitable and sufficient’ children’s risk assessment?¶
11 Sections 11(4) and 28(4) of the Act. We explain what a significant change may involve in the sub-section ‘Making a significant change to your service’.
12 Sections 23(2) and 34(2) of the Act. 13 The Children’s Register is our assessment of the causes and impacts of harms to children online based on the evidence that we have gathered over the past four years. 14 Section 11(6) for user-to-user services and section 28(5) for search services. 15 These are set out in Part 3, sub-section 1 and include a list of risk factors (such as features and functionalities) with an explanation of how they could increase the risk of particular content harmful to children covered by the Act.
Record-keeping duties¶
Additional duties for categorised service providers¶
16 Providers of large services, or those who identify several specific risk factors for a kind of content harmful to children should consider using enhanced inputs to achieve a suitable and sufficient assessment. 17 Section 95(10) of the Act.
must include the findings of the most recent children’s risk assessment of a service (including as to levels of risk and as to nature, and severity, of potential harm to children);18 and
b) Provide Ofcom with a copy of their children’s risk assessment record as soon as reasonably practicable.19
What happens if you do not carry out a suitable and sufficient risk assessment?¶
When do you need to complete the first children’s risk assessment?¶
18 Section 12(14) of the Act (user-to-user service providers) and Section 29(9) of the Act (search service providers). 19 Section 23(10) of the Act (user-to-user service providers) and Section 34(9) of the Act (search service providers). 20 Section 131 of the Act. 21 Section 143 of the Act and schedule 13 to the Act. 22 See Section 5 of the Children’s Access Assessments Guidance
What content harmful to children do you need to assess?¶
Table 1: List of content harmful to children to assess¶
23 Sections 60-62 of the Act.
What to assess about each kind of content harmful to children¶
24 Content is not to be regarded as non-designated content where the risk of harm flows from the content’s potential financial impact; the safety or quality of goods featured in the content; or the way in which a service featured in the content may be performed. 25 See the Children’s Register for our evidence on these types of non-designated content. 26 If you have identified those kinds of non-designated content as present on your service, you will have an additional duty to notify Ofcom of the presence and incidence of that content: see Step 4. 27 See the Children’s Register.
Harm¶
Assessing the risk of harm¶
28 Section 234 of the Act. 29 Children’s Register of Risks. 30 Section 234 of the Act.
Using Children’s Risk Profiles and the Risk Level Table in your children’s risk assessment¶
Keeping your children’s risk assessment up to date¶
31 Search content is defined in section 57 of the Act. 32 Sections 11(6) and 28(5) of the Act. 33 Section 98(5) and (7) of the Act.
b) A duty to update your children’s risk assessment if Ofcom makes any significant change to a Children’s Risk Profile that relates to your service; and c) Before making any significant change to any aspect of your service’s design or operation, a duty to carry out a further suitable and sufficient children’s risk assessment relating to the impacts of that proposed change.
Review and update at least every 12 months¶
34 Sections 11(3) and (4), and 28(3) and (4) of the Act.
Review and update if Ofcom makes a change to Children’s Risk Profiles¶
Relevance of the illegal content risk assessment¶
35 Section 98(8) of the Act. 36 Sections 11(3) and 28(3) of the Act. 37 Section 59(2) of the Act. 38 If a service provider believes content could count as illegal content, they should apply the illegal content duties and take note of the children’s safety duties.
Part 2: How to carry out a children’s risk assessment¶
Section 3 Overview of the four-step risk assessment process¶
Step 1: Understand content harmful to children that needs to be assessed¶
Step 1 will help you to understand the content harmful to children to assess and will prepare you to make accurate judgements about your risk to children.
Sequence of activities and outcomes¶
• Identify the content harmful to children that needs to be separately assessed, including each kind of primary priority content, each kind of priority content, and any kind(s) of non-designated content that may be relevant to your service. • Consult Ofcom’s Children’s Risk Profiles and identify the key risk factors relevant to your service for each kind of primary priority content, priority content, and the kind(s) of non-designated content identified by Ofcom.
Essential records¶
• Confirmation that you have consulted Ofcom’s Children’s Risk Profiles and recorded any risk factors relevant to your service. • A record of the kind(s) of non-designated content that will be assessed, and how you have considered the risk of children encountering non-designated content by means of the service.
Step 2: Assess the risk of harm to children¶
Step 2 will help you use evidence to assess and assign a risk level to the risk of harm to children presented by each of the four kinds of primary priority content, each of the eight kinds of priority content, and any kind(s) of non-designated content you have identified for assessment. When assigning these risk levels, you must also consider the impact of your service’s design and use on the risk of harm.
Sequence of activities and outcomes¶
• Separately assess the likelihood and impact of children encountering the content harmful to children you have identified at Step 1 for assessment on your service, using all relevant evidence. • As part of your assessment of likelihood and impact: o Consider the different ways in which the service is used, including ways which are unintended. Identify whether there are any additional characteristics or functionalities of the service’s design or operation, not in the Children’s Risk Profiles, which could increase the risk to children. This includes functionalities that present higher levels of risk such as recommender systems, or those that enable adults to
search and/or contact children, predictive search functionalities, and features and functionalities which affect how much children use the service.
o Consider the effectiveness of any existing control measures which could impact the level of risk of harm to children.
• Consult the Risk Level Table to assign a risk level for each of the four kinds of primary priority content, each of the eight kinds of priority content, and any kind(s) of non-designated content you have identified for assessment. This risk level should reflect risk as it exists on the service at the time of assessment, having had regard to the efficacy of any existing control measures you have in place. • Conclude the assessment of all the risks relating to content harmful to children, including the design and use of the service, to mitigate in Step 3.
Essential records¶
• Where applicable, a list of any additional characteristics (including user base, business models, functionalities, governance, and systems and processes) considered alongside the risk factors identified in Ofcom’s Children’s Risk Profiles. This should include how you have identified and assessed those functionalities that present higher levels of risk such as recommender systems, functionalities which enable adults to search for and/or contact children and predictive search functionalities, as well as features and functionalities which affect how much children use the service. • If you have considered the role of any existing controls already in operation on your service at the time of this risk assessment, you should record what these controls are, what risks they are intended to mitigate and how they do this, and how the consideration of the existing controls has impacted the risk level you have assigned to a kind of content harmful to children. • A list of the evidence and summary of the reasoning that has informed the assessment of likelihood and impact of each kind primary priority content, each kind of priority content, and any kind(s) non-designated content that you have identified for assessment. This should include relevant evidence about the design and use of the service, and how different age groups of children have been considered. • The level of risk assigned to each of the four kinds of primary priority content, each of the eight kinds of priority content, and for any kind(s) of non-designated content that you have identified for assessment on the service, and an evidence-based explanation of the decision. This level should reflect risk as it exists on the service at the time of assessment.
Step 3: Decide measures, implement and record¶
Step 3 will help you identify any relevant measures to implement to address risk to children, record any measures you have taken, and make a record of your assessment.
Sequence of activities and outcomes¶
• Consult Ofcom’s Protection of Children Codes for user-to-user services and search services , check which measures are recommended for your service, and decide whether to implement applicable measures to reduce the risk of harm to child users, or use alternative measures.
• Identify any additional measures that may be appropriate for your service. • Implement all relevant measures. • Record the outcomes of the children’s risk assessment.
Essential records¶
• A complete record of the findings of the children’s risk assessment. • All measures from Ofcom’s Protection of Children Codes that have been, or are planned to be, implemented. • Any applicable measures from Ofcom’s Protection of Children Codes that are not planned to be implemented, and the alternative measures that have been or are planned to be implemented instead, with information that demonstrates how these alternative measures meet the relevant duties.
Step 4: Report, review and update¶
Step 4 will help you to understand how to keep your children’s risk assessment up to date and put in place appropriate steps to review your assessment.
Sequence of activities and outcomes¶
• Report on the children’s risk assessment and measures through appropriate governance and accountability channels. • Providers of user-to-user services to notify Ofcom of the kinds and incidence of any non-designated content you have identified as present on your service through your children’s risk assessment. • Providers of Category 1 and 2A services to supply Ofcom with a copy of their children’s risk assessment record. • Providers of Category 1/2A services to summarise the findings of their most recent children’s risk assessment in their terms of service/a publicly available statement (as applicable). • Monitor the effectiveness of safety measures at reducing the risk of harm to users. • Monitor developing risks and the level of risk exposure after appropriate measures are implemented (also known as residual risk). • Review and/or update the children’s risk assessment when appropriate, including before making any significant change to any aspect of the service’s design or operation.
Essential records¶
• A written record of the annual review cycle for the children’s risk assessment, and the named person responsible who has been appointed for this process. • Confirmation that the findings of the children’s risk assessment have been reported, and recorded, through appropriate governance and accountability channels.
Section 4 Detailed explanation of the four steps¶
This sub-section explains in detail the activities and outcomes for each step of your children’s risk assessment.
Step 1: Understand content harmful to children that needs to be assessed¶
Sequence of activities and outcomes for Step 1¶
Identify content harmful to children you need to assess¶
Table 2: List of content harmful to children to assess¶
39 These types of content are set out in sections 60-62 of the Act. 40 You can find more detail on identifying non-designated content in the sub-section ‘Non-designated content’ in Part 3 of this guidance document.
What to assess about each kind of content harmful to children¶
41 Content is not to be regarded as non-designated content where the risk of harm flows from the content’s potential financial impact; the safety or quality of goods featured in the content, or the way in which a service featured in the content may be performed. 42 Please see the Children’s Register for our evidence on these types of non-designated content. 43 If you have identified those kinds of non-designated content as present on your service, you will have an additional duty to notify Ofcom of the presence and incidence of that content: see Step 4.
Identify non-designated content for assessment¶
Consult Ofcom’s Children’s Risk Profiles¶
Essential records for Step 1¶
44 Children’s Register of Risks and Guidance on Content Harmful to Children 45 Section 60(2)(c) of the Act.
46 These are: content that discriminates against or otherwise stigmatises body types or body parts; and content that romanticises depression and depressive thinking. 47 Note that the separate Illegal Content Risk Assessment Guidance includes different Ofcom Risk Profiles to help meet your illegal content risk assessment duty. 48 The Children’s Risk Profiles have grouped different content harmful to children in line with the Children’s Register. Regardless of this, service providers have a duty to separately assess the risk of children encountering each kind of primary priority content, each kind of priority content, and non-designated content.
Step 2: Assess the risk of harm to children¶
Sequence of activities and outcomes for Step 2¶
• Consider if there are any additional characteristics of your service which are not present in Ofcom’s Children’s Risk Profiles, but which might increase risk of harm to children. • Consider if there are any existing controls on your service which affect the level of risk of content harmful to children on your service. If so, you should consider how and to what extent these controls affect the risk of harm to children. • Identify and use evidence relating to your service to complete your children’s risk assessment. The level of risk of content harmful to children can be influenced by various elements, including how your service’s functionalities, user base (including the different age groups of children), business model, and systems and processes in combination can serve to increase or decrease risks to children.
49 Aside from kinds of non-designated content that you have identified beyond the types from Ofcom’s Children’s Register, which are not associated with Children’s Risk Profiles.
Identifying relevant evidence¶
Table 3: Summary of relevant types of evidence¶
50 See ‘Risk Level Table for content harmful to children’ in Part 3 of this guidance. 51 Section 11(e)-(h) of the Act.
Evaluate likelihood and impact by assigning a risk level to content harmful to children¶
52 A service provider can consult the Children’s Register to better understand different kinds of content that is harmful to children, for instance, those which they identify risk factors for when consulting Children’s Risk Profiles. 53 This could include insights from content moderation systems – as a core input, we expect service providers to consider high level outputs, for example, the volume of content harmful to children identified through a complaints-based content moderation system.
54 This could also include results of previous interventions to reduce online safety risk. 55 As an enhanced input, we expect service providers to consider more granular or in-depth analysis such as evidence which relates to the effectiveness of content moderation systems. 56 ICO, UK GDPR guidance and resources; ICO, Age appropriate design: a code of practice for online services; ICO, ‘Likely to be accessed’ by children guidance.
content you have identified for assessment. We have included additional guidance on assessing non-designated content in Part 3.
Assessing the likelihood of children encountering harmful content¶
Table 3: What to consider when assessing likelihood of children encountering content harmful to children Guiding questions when assessing likelihood • If your service is a user-to-user service, do your service’s risk factors identified in Step 1 indicate that children are likely to encounter this kind of content on your service?57 If so, how many risk factors do you have? Ordinarily, the larger the number of risk factors for a given kind of content, the higher the likelihood of that kind of content. If your service is a search service, does the Children’s Register section58 on search indicate evidence that children are likely to encounter this kind of content on your service? Is there evidence to indicate that children are likely to encounter any of the kind(s) of non-designated content you have identified for assessment on your service? If so, what is the incidence of such kinds? • Are there any additional characteristics of your service (including functionalities, child user base, business model and governance, systems and processes) that may make it more likely that children encounter this kind of content? For example, you may consider: > (For user-to-user services) Are adults able to search for children or contact children through your service? > (For search services) Do you provide a functionality that makes suggestions relating to child users’ search requests? > Does your service use recommender algorithms or functionalities which allow users to share content widely? > Do you have any features or functionalities which affect how much children use your service, such as a feature that enables content to play automatically?
Evaluating the likelihood will depend on your understanding of the evidence about your own service. • Is there any evidence from your core inputs that content harmful to children is likely to occur on your service? You should consider:
57 If you have identified additional kinds of non-designated content for assessment outside of those that Ofcom has identified, you should consider whether any risk factors you have identified for other content harmful to children are relevant to assess likelihood. 58 Section 12 of the Children’s Register.
> Evidence of this kind of content being encountered by children, including children with certain characteristics, based on user complaints and reports. For example, significant volumes of reports in relation to a particular kind of content could indicate a higher likelihood of that kind of content occurring; and > Any other relevant evidence and data which suggests there is a risk of this kind of content occurring on your service.
• If you have consulted core inputs and are still unsure about the likelihood of children encountering this kind of content, consider any additional evidence from enhanced inputs. For example, you may consider: > Evidence from independent experts or externally commissioned research that highlights the potential for children to encounter this kind of content; > Evidence based on results of product testing of the potential for children to encounter this kind of content; and > Evidence based on results of content moderation of this kind of content.
• Are there measures already in place that reduce the risk of children encountering this kind of content on your service? Can you demonstrate that these are effective in decreasing the risk of children encountering this kind of content? For example, you could consider: > Do you prohibit this kind of content on your service and do you have effective controls to identify and remove this content from the service? > Have you implemented highly effective age assurance to prevent/protect children from encountering this content? > Do you have measures to promote users’ media literacy and safe use of the service? It is possible that such measures could reduce the likelihood of content harmful to children being encountered.
Source: Ofcom analysis
Assessing the impact of children encountering harmful content¶
Table 4: What to consider when assessing the impact of children encountering content harmful to children Guiding questions when assessing impact • To make judgements on the nature and severity of content harmful to children, you need to consider: > If children on your service have had a materially harmful experience, for example, due to the nature of this kind of content and how children may encounter it on the service. > If harm is suffered indirectly by children who are not users of the service, for example, violent content that normalises the carrying of weapons, by which other children are impacted.59 If so, how severe is the impact likely to be?
59 See Section 7 of Children’s Register.
> What the potential reach of this kind of content on your service could be, and the number of children that could be impacted. > How children might be affected by experiencing this kind of content cumulatively over time on your service?
• To make judgements on impact on the children affected, you need to consider: > How many children are on your service, either confirmed or estimated with your best available information?60 > What does child user data that you have available tell you about your user base demographics (including age, sex and any vulnerable groups)? > How many of your child users are particularly likely to be affected by the kind of content in question due to their characteristics, such as age, or belonging to vulnerable groups. > How are children who are not users of your service affected?
• To make judgements about the design and use of your service, you need to consider: > How does your service’s revenue model and commercial profile influence the way this kind of content is experienced on your service? Consider the information provided in the Children’s Risk Profiles and your own evidence. > Are there any other characteristics that apply to your service (including functionalities, user-base, business model and governance, and systems and processes) that you have identified may increase the impact of this kind of content? > Whether the way this kind of content is shared and disseminated, including through recommender systems and other algorithmic systems, could increase the number of children encountering this kind of content over a period. > Whether you have any features or functionalities which affect how much children will use the service. The more time a child spends on a service the greater the impact of encountering this kind of content may be.
Evaluating the impact will depend on your understanding of the evidence about your own service.
• Is there any evidence from core inputs about the experience of this kind of content and its impact? For example: > What user complaints and reports regarding this kind of content tells you about impact on child users and other children. > The potential reach of this kind of content measured by the number of child users (if you have this evidence available) who could be affected.
• If you have consulted core inputs and are still unsure about the impact of the content, then consider any additional evidence based on the information from enhanced inputs. For example, you may consider: > What user research, including with children (including children in different age groups, or children belonging to vulnerable groups) shows about impact on child users and other children;
60 Please see the ‘Assessing the user base’ sub-section in this guidance document.
> What independent experts (e.g., child behavioural experts) or research tells you about the impact of this kind of content on a service of your type; > Identifying metrics regarding the virality of this kind of content (including its potential reach and speed of spread); and > Evidence about how this kind of content may affect third parties beyond your service.
• For the avoidance of doubt, where evidence shows the potential for severe harm in relation to a kind of content, we expect that this may lead to an assessment of medium or high impact, even if the number of children potentially impacted is relatively small or smaller than the indicative values provided in the Risk Level Table (Risk Level Table included in Part 3 of this guidance). Source: Ofcom analysis
Assessing the user base¶
Essential records for Step 2¶
Step 3: Decide measures, implement and record¶
Sequence of activities and outcomes for Step 3¶
Decide what measures you should take to reduce the risk of harm¶
Alternative measures to consider¶
61 Volume 4: ‘What should services do to mitigate the risks of online harms to children?’ 62 Section 10: ‘Framework for Codes’. 63 Section 49 of the Act.
service. If you do take alternative measures, you must keep a record of what you have done and explain how the relevant children’s safety duties have been met. In doing so, you must consider the importance of protecting users’ rights to freedom of expression and of protecting child users from breaches of relevant privacy laws.
Additional measures to consider¶
Implement all measures to mitigate and manage risk¶
Changes to measures and controls¶
Essential records for Step 3¶
Record the outcomes of the children’s risk assessment¶
• The applicable measures that are not planned to be implemented; • The alternative measures that have been or are planned to be implemented instead; • Information that demonstrates how these measures achieve compliance with the safety duties.
Box 2: Information to include in the record of your children’s risk assessment • The service to which the children’s risk assessment relates; • The date the children’s risk assessment was completed; • If applicable, the date the children’s risk assessment was reviewed or updated; • Who completed the children’s risk assessment, and the named person responsible for the children’s risk assessment; • Who approved the children’s risk assessment; • Confirmation that you have consulted Ofcom’s Children’s Risk Profiles. You may do this by recording the outcomes of the Children’s Risk Profiles questionnaire, see Part 3. • A record of any risk factors from Ofcom’s Children’s Risk Profiles which are relevant to your service; • A record of the kind(s) of non-designated content that you have identified for assessment, and how you have considered the risk of children encountering non-designated content by means of your service; • Where applicable, a list of any additional characteristics (including user base, business models, functionalities, governance, and systems and processes) considered alongside the risk factors identified in Ofcom’s Children’s Risk Profiles in Step 1. This should include how you have identified and assessed those functionalities that present higher levels of risk, such as recommender systems, functionalities which enable adults to search for and/or contact children and predicting search functionalities, as well as features and functionalities which affect how much children use the service; • If you have considered the role of any existing controls already in operation on your service at the time of this risk assessment, you should record what these controls are, what risks they are intended to mitigate and how they do this, and how the consideration of the existing controls has impacted the risk level you have assigned to a kind of content harmful to children; • A list of the evidence and summary of the reasoning that has informed the assessment of likelihood and impact of each kind of primary priority content, each kind of priority content, and each kind of non-designated content. This should include relevant evidence about the design and use of the service, and how different age groups of children have been considered; • The level of risk assigned to each of the four kinds of primary priority content, each of the eight kinds of priority content, and for any kind(s) of non-designated content you have assessed on your service, and an evidence-based explanation of the decision; • Confirmation that the findings of the children’s risk assessment have been reported, and recorded, through appropriate governance and accountability channels (this is explained in Step 4); and
• Information regarding how your service takes appropriate steps to keep the children’s risk assessment up to date (e.g., a written policy) (this is explained in Step 4).
Record all relevant measures and how the safety duties have been met¶
Step 4: Report, review and update¶
Sequence of activities and outcomes for Step 4¶
Report on the children’s risk assessment and measures via relevant governance and accountability channels¶
64 PCU/PCS A1-A7.
of the findings of their children’s risk assessment in their terms of service, and Category 2A service providers must include a summary of the findings of their children’s risk assessment in a publicly available statement.
Notify Ofcom of the kinds and incidence of non-designated content¶
Monitor the effectiveness of your safety measures¶
Review your children’s risk assessment¶
65 Whether this is non-designated content which Ofcom has identified in the Children’s Register, or any other kinds of non-designated content which Ofcom has not identified in the Children’s Register. 66 Governance and Accountability measure PCU A4 in the Code for user-to-user services/PCS A4 in the Code for search services complements this. This measure recommends that providers of all large user-to-user services and all large search services likely to be accessed by children that are multi-risk for content harmful to children should have an internal monitoring and assurance function to independently assess, on an ongoing basis, the effectiveness of measures to mitigate and manage risks of harm to children identified in the children’s risk assessment.
67 Governance and Accountability measure PCU A1 in the Code for user-to-user services/PCS A1 in the Code for search services complements this. The measure says that a provider’s most senior governance body in relation to the service should carry out and record an annual review of risk management activities having to do with content that is harmful to children in the UK, including in relation to risk that is remaining after the implementation of appropriate Codes measures. 68 This could include deciding to change any existing measures, or measures which are additional to those set out in the Codes.
Essential records for Step 4¶
69 Service providers should identify the relevant Governance and Accountability measures in the Protection of Children Codes of Practice that may apply to them.
Part 3: Supporting documents¶
Section 1 Children’s Risk Profiles¶
70 The key kinds of content harmful to children associated with a risk factor are those where our evidence indicated the strongest link. There may be other kinds of content harmful to children which may be relevant. For further information, see Section 1 of the Children’s Register. 71 Table 1.1 and 1.2 in Section 1 of the Children’s Register. 72 For further information on how we see these dynamics play out in our evidence base, see Section 1 and Section 16 of the Children’s Register.
Children’s User-to-User Risk Profile¶
73 If your service offers multiple versions – for example, mobile and web – you should select ‘Y’ if any version of the service has the relevant characteristic(s). However, this only applies where versions are similar enough to be treated as a single service. 74 If, after consulting Section 18 of the Children’s Register, you are still unsure if the risk factor applies to you, we would suggest you read the corresponding information provided about that risk factor in Table 7 and consider if this information is relevant to your service. You may also wish to consult the Children’s Register for more detailed information on the corresponding risk factor or kind of content harmful to children.
Figure 1. Questions for identifying your risk factors
75 A service may consider more than one service type to apply. 76 We describe ‘user connections’ as a user-to-user service functionality that allows users to follow or subscribe to other users. Users must sometimes be connected to view all or some of the content that each user shares. Further information on risk factors is available in Section 18 of the Children’s Register.
Table 5. Children’s User-to-User Risk Profile77¶
77 We have listed the key kinds of content harmful to children associated with each specific risk factor in alphabetical order.
78 We describe ‘anonymous user profiles’ as a user-to-user service functionality allowing users to create a user profile where their identity is unknown to an extent. This includes instances where a user’s identity (an individual’s formal or officially recognised identity) is unknown to other users, for example, through the use of aliases (‘pseudonymity’). It also includes where a user’s identity may be unknown to a service, for example, services that do not require users to register by creating an account. Further information on risk factors is available in Section 18 of the Children’s Register.
79 These spaces are likely to be community moderated.
80 We describe ‘bots’ as an umbrella term that refers to a software application or automated tool that has been programmed by a person to carry out a specific or predefined task without any human intervention. Further information on risk factors is available in Section 18 of the Children’s Register.
81 We recognise that service providers will likely have different levels of understanding, evidence and data about the age of users on their services. See ‘Assessing the user base’ sub-section of the Children’s Risk Assessment Guidance for more detail. However, we still expect them to consider the risk of harm to children in different age groups that they have reason to believe may be accessing the service, regardless of whether or not they intend all those age groups to do so.
82 Where users pay services to give prominence to their content. 83 For instance, display advertisements. While paid-for advertisements are not typically in scope of the Act themselves (unless they also amount to user-generated content), they are considered here by virtue of being a vector to user-generated content harmful to children.
84 We describe ‘growth strategy’ as how the service plans to expand its business, for example, through the adoption of emerging technologies. Further information on risk factors is available in Section 18 of the Children’s Register. 85 We use ‘commercial profile’ to refer to the size of the service in terms of capacity, the stage of service maturity, and the rate of growth in relation to users and/or revenue. Further information on risk factors is available in Section 18 of the Children’s Register.
Table 6. Summary of specific risk factors in the Children’s User-to-User Risk Profile associated with each kind of content harmful to children
Children’s Search Risk Profile¶
86 If your service offers multiple versions – for example, mobile and web – you should select ‘Y’ if any version of the service has the relevant characteristic(s). However, this only applies where versions are similar enough to be treated as a single service. 87 If, after consulting Section 18 of Children’s Register, you are still unsure if the risk factor applies to you, we would suggest you read the corresponding information provided about that risk factor in Table 9 and consider if this information is relevant to your service. You may also wish to consult Section 12 of the Children’s Register for more detailed information on the corresponding risk factor or kind of content harmful to children.
includes any specific risk factors you have selected alongside all four of the general risk factors.
Figure 2. Questions for identifying your risk factors
Table 7. Children’s Search Risk Profile¶
88 For the purposes of the Children’s Search Risk Profile and our recommended measures, a downstream general search service is still a ‘general search service’. The unique business models of downstream general search services do not change the type of search service that is offered to users. That being said, it will be relevant when determining who the ‘provider’ of the downstream general search service is. We consider it is for the entities involved in the downstream arrangement to determine how many distinct search services are being offered to users, and who the ‘provider’ is for each of these services. If entities involved in a downstream general search service arrangement fail to agree on who the ‘provider’ of the service is and make arrangements to ensure compliance with the Act, each risks being the entity that we determine to be the ‘provider’.
89 We recognise that service providers will likely have different levels of understanding, evidence and data about the age of their users. See ‘Assessing the user base’ sub-section of the Children’s Risk Assessment Guidance for more detail. However, we still expect services to consider the risk of harm to children in different age groups that they have reason to believe may be accessing the service, regardless of whether or not they intend all those age groups to do so.
90 While general search services typically generate revenue using an advertising-based model and there is a risk that advertising could be used to promote content harmful to children, there is very limited evidence demonstrating any direct link between different revenue models and the presence of content that is harmful to children in search results. We nevertheless encourage search services to consider any links between their revenue model and increased risks for children.
91 In terms of number of employees or revenues. See Section 18 of the Children’s Register. 92 Search services that are start-ups or at an early growth stage. See Section 18 of the Children’s Register.
Section 2 Non-designated content¶
In this sub-section we provide guidance to service providers to help them fulfil their duties to assess the risk presented to children by non-designated content harmful to children, and (for user-to-user services) to notify Ofcom where a children’s risk assessment identifies presence of non-designated content.
What is non-designated content?¶
Identify non-designated content for assessment¶
93 Section 60(2)(c) of the Act.
94 Content is not to be regarded as non-designated content where the risk of harm flows from the content’s potential financial impact; the safety or quality of goods featured in the content; or the way in which a service featured in the content may be performed. 95 These are: Content that shames or otherwise stigmatises body types or physical features (‘body stigma content’); and Content that promotes depression, hopelessness and despair (‘depression content’). 96 For example, if you are aware of a new or emerging kind of content on a service that is similar to the one you provide.
Assess non-designated content¶
Notify Ofcom of non-designated content¶
97 This means where you have assessed the level of risk from a kind of non-designated content as low, medium or high, but not negligible. 98 Section 11(5) of the Act.
Section 3 Evidence inputs¶
This sub-section of the guidance focuses on the different types of evidence that service providers should consider when assessing risk of harm to children.
Why is evidence important?¶
How should you decide what evidence is relevant?¶
99 ICO, UK GDPR guidance and resources; ICO, Age appropriate design: a code of practice for online services; ICO, ‘Likely to be accessed’ by children guidance.
your analysis, you should consider whether you have sufficient information to reach accurate conclusions on the level of risk for that particular kind of content. If not, you should consider gathering additional evidence from the list of enhanced inputs.
Evidence on child age¶
What is a core input?¶
100 ICO, UK GDPR guidance and resources; ICO, Age appropriate design: a code of practice for online services; ICO, ‘Likely to be accessed’ by children guidance. 101 See Section 17 of the Children’s Register: ‘Age Groups’.
Table 8: Core evidence inputs¶
102 ICO, UK GDPR guidance and resources; ICO, Age appropriate design: a code of practice for online services; ICO, ‘Likely to be accessed’ by children guidance.
What is an enhanced input?¶
Profiles will typically need to include some or many enhanced inputs to ensure their children’s risk assessments are suitable and sufficient.
Box 3: Illustrative examples of how to decide on evidence inputs
Table 9: Enhanced evidence inputs
Enhanced inputs Explanation
103 When we use the word ‘product’ we are using it as an all-encompassing term that includes any functionality, feature, tool or policy that you provide to users for them to interact with through your service. This includes but is not limited to terms and conditions, content feeds, react buttons or privacy settings. By ‘testing’ we mean services should be considering any potential risks of technical and design choices, and testing the components used as part of their products before the final product is developed. We recognise that services, depending on their size, could have different employees responsible for different products and that these products are designed separately from one another.
104 By ‘on-platform testing of recommender algorithms’ we mean the process of testing two or more variants of recommender system before proceeding with the design change. This could include but is not limited to A/B/x Testing or Multi Arm Bandit (‘MAB’) Testing.
Section 4 Risk Level Table for content harmful to children¶
Table 10: Risk Level Table¶
105 When assessing a kind of non-designated content that is not identified in Ofcom’s Children’s Register of Risks and Children’s Risk Profiles, you should form your own assessment of what the relevant risk factors are likely to be and how many apply to your service. 106 Hereafter ‘content’, referring to each kind of primary priority content, each kind of priority content, and any kinds of non-designated content you have identified for assessment.
107 We consider ‘many’ to be a large number of risk factors in proportion to the total number of specific risk factors for a particular kind of content harmful to children in the Children’s Risk Profiles. The number of risk factors we have identified for different kinds of content harmful to children in the Children’s Risk Profiles varies in line with the evidence available and the way harm manifests. A kind of content harmful to children which involves many different offences, pathways and behaviours may have more evidence available, and in turn more risk factors associated with it than one which has fewer. Therefore, for a kind of content harmful to children with a small total number of risk factors, even a few may be considered ‘many’. Similar considerations apply to ‘several’ and ‘few’ for the risk levels in the rest of the table. 108 For example, children who are indirectly affected. One example could be violent content, where links have been found between this kind of content and specific acts of violence. See Section 7 of the Children’s Register.
109 As calculated in accordance with the methodology set out in the Protection of Children Codes of Practice from paragraph [XX]. 110 This condition sets a substantially higher bar than the bar set to describe a service “of a kind likely to attract a significant number of users who are children” in the Children’s Access Assessment Guidance (i.e., a service meeting the child user condition in Stage 2 of the assessment). In the latter case, a service may meet the child user condition even if it does not actively target children, for several reasons (e.g., the service has the potential to benefit children).
111 This is intended as an overall guide, but rather than focusing purely on the number of risk factors, you should consider the combined effect of the risk factors to make an overall judgement about the level of risk on your service.
Source: Ofcom
Section 5 Making a significant change to your service¶
Carry out a new risk assessment before making a significant change to your service¶
Table 11: Guidance on significant change¶
recommender. It may also include a complete replacement of the existing content recommender.
> Introduction of a new machine-learning model within the existing recommender system: A service could implement a new machine-learning model to enhance the predictions that are made by a recommender system (e.g., updating any kind of modelling with regards to user age, including inferred or estimated ages of child users). These new or enhanced predictions would, in turn, alter the types of content that children are recommended in different age groups.112 > Changing the ‘goal criteria’ of recommender systems: Changing the overall aims that the service has in mind for those systems, for instance, to maximise the average viewing time, or to promote a certain kind of content to be presented to children (e.g., educational content). > New insights from on-platform testing: Indications that a change to a recommender system, for example, the addition of a child-specific feature or focus, may have a significant impact on the risk of harm arising from content harmful to children.
• Adding or removing functionalities: The children’s risk assessment must assess the impact of functionalities on the risk of harm to children, so adding or removing functionalities – such as sharing content, direct messaging, end-to-end encryption or livestreaming, and especially those that might appeal strongly to children, such as generative artificial intelligence, or autoplay features – must be accounted for in the children’s risk assessment. • Changes to platform content rules or content prioritisation: These may alter the types of content that children encounter and subsequently alter the site’s child user base. This could include, for instance, the decision to alter a threshold around what violent content is prohibited on a service. • Updates to the design of user facing functionalities and features: This could include changing the location or prominence of the reporting function or changing the layout, formatting or wording113 of a safety notification which could impact how children engage with safety measures. • Introducing the use of prompts: Such prompts could alert or remind children about options to change content control settings; the timing and language used in these prompts could impact the choices children make and go on to impact the risk of encountering content harmful to children. • Any acquisition that may change the core product offered to child users: This could include integrating functionality from another service following a product acquisition, and child user migration. • Changes in ownership or investment: These may influence how the service operates (a new owner may have different views on how the service should operate). • Changes in the revenue models: Examples that may affect level of risk include new streams of revenue, a significant change in the factors or key performance indicators
112 This is relevant even where a service provider may not be using age assurance approaches to understand the age of children. 113 In particular, if the comprehensibility of written information is changed, based on the likely reading age of the youngest person permitted to use the service without the consent of a parent or guardian. See our Protection of Children Codes for further detail on the accessibility of such features.
that the service maximises to achieve its revenue goals, or changes in sources of revenue that have a significant impact on the design choices of the service.
• Changes in the service’s growth strategy: For example, changes in growth strategy could affect service design choices or the speed of growth of your child user base, or the number of children in different age groups. • Change in capacity (in terms of number of employees): This could include capacity changes that may affect the number and quality of technical resources to assess and mitigate risk to children on your service.
A1 Appendix A: Examples of how to use the Risk Level Table¶
Boxes 4-9: Risk Level Table theoretical examples
114 ICO, UK GDPR guidance and resources; ICO, Age appropriate design: a code of practice for online services; ICO, ‘Likely to be accessed’ by children guidance.
A2 Appendix B: Comparison of children’s and illegal content risk assessment duties¶
Table 12: Comparison of the illegal content risk assessment duties and the children’s risk assessment duties – user-to-user services
Illegal content risk assessment duties Children’s risk assessment duties Section 9 (User-to-user services) Section 11 (User-to-user services)
(2) A duty to carry out a suitable and sufficient (2) A duty to carry out a suitable and sufficient illegal content risk assessment at a time set out children’s risk assessment at a time set out in, in, or as provided by, schedule 3. or as provided by, schedule 3.
(4) Before making any significant change to any (4) Before making any significant change to any aspect of a service’s design or operation, a duty aspect of a service’s design or operation, a duty to carry out a further suitable and sufficient to carry out a further suitable and sufficient illegal content risk assessment relating to the children’s risk assessment relating to the impacts of that proposed change. impacts of that proposed change.
Illegal content risk assessment duties Children’s risk assessment duties Section 9 (User-to-user services) Section 11 (User-to-user services)
(5) An ‘illegal content risk assessment’ of a service of a particular kind means an (6) A ‘children’s risk assessment’ of a service of
assessment of the following matters, taking a particular kind means an assessment of the
into account the risk profile that relates to following matters, taking into account the risk profile that relates to services of that kind – services of that kind –
(a) the user base; (a) the user base, including the number of users who are children in different age groups; (b) the level of risk of children who are users of the service encountering the following by means of the service – (i) each kind of primary (b) the level of risk of individuals who are users priority content that is harmful to children of the service encountering the following by (with each kind separately assessed), (ii) each means of the service – (i) each kind of priority kind of priority content that is harmful to illegal content (with each kind separately children (with each kind separately assessed), assessed), and (ii) other illegal content, taking and (iii) non-designated content that is harmful into account (in particular) algorithms used by to children, giving separate consideration to the service, and how easily, quickly and widely content may be disseminated by means of the children in different age groups, and taking into
service; account (in particular) algorithms used by the service and how easily, quickly and widely content may be disseminated by means of the service; (d) the level of risk of harm to children (d) the level of risk of harm to individuals presented by illegal content of different kinds presented by content that is harmful to
or by the use of the service for the commission children which particularly affects individuals
or facilitation of a priority offence; with a certain characteristic or members of a certain group;
Illegal content risk assessment duties Children’s risk assessment duties Section 9 (User-to-user services) Section 11 (User-to-user services) (f) the different ways in which the service is used, including functionalities or other features (f) the different ways in which the service is of the service that affect how much children used, and the impact of such use on the level of use the service (e.g., a feature that enables risk of harm that might be suffered by individuals; content to play automatically), and the impact of such use on the level of risk of harm that might be suffered by children;
(h) how the design and operation of the service (h) how the design and operation of the service (including the business model, governance, use (including the business model, governance, use of proactive technology, measures to promote of proactive technology, measures to promote users’ media literacy and safe use of the users’ media literacy and safe use of the service, and other systems and processes) may service, and other systems and processes) may reduce or increase the risks identified. reduce or increase the risks identified.
(7) See also – (a) section 23(2) and (10) (records (8) See also – (a) section 23(2) and (10) (records of risk assessments), and (b) schedule 3 (timing of risk assessments), and (b) schedule 3 (timing of providers’ assessments). of providers’ assessments).
Table 13: Comparison of the illegal content risk assessment duties and the children’s risk assessment duties – search services
Illegal content risk assessment duties Children’s risk assessment duties Section 26 (Search services) Section 28 (Search services)
(2) A duty to carry out a suitable and sufficient (2) A duty to carry out a suitable and sufficient illegal content risk assessment at a time set out children’s risk assessment at a time set out in, in, or as provided by, schedule 3. or as provided by, schedule 3.
(4) Before making any significant change to any (4) Before making any significant change to any aspect of a service’s design or operation, a duty aspect of a service’s design or operation, a duty to carry out a further suitable and sufficient to carry out a further suitable and sufficient illegal content risk assessment relating to the children’s risk assessment relating to the impacts of that proposed change. impacts of that proposed change.
Illegal content risk assessment duties Children’s risk assessment duties Section 26 (Search services) Section 28 (Search services) (a) the level of risk of children who are users of the service encountering search content of the following kinds – (i) each kind of primary (a) the level of risk of individuals who are users priority content that is harmful to children of the service encountering search content of the following kinds – (i) each kind of priority (with each kind separately assessed), (ii) each
illegal content (with each kind separately kind of priority content that is harmful to
assessed), and (ii) other illegal content, taking children (with each kind separately assessed),
into account (in particular) risks presented by and (iii) non-designated content that is harmful
algorithms used by the service, and the way to children, giving separate consideration to children in different age groups, and taking into that the service indexes, organises and presents account (in particular) risks presented by search results; algorithms used by the service and the way that the service indexes, organises and presents search results; (c) the extent to which the design of the service, in particular its functionalities, affects (c) the nature, and severity, of the harm that the level of risk of harm that might be suffered might be suffered by individuals from the by children, identifying and assessing those matters identified in accordance with functionalities that present higher levels of risk, paragraphs (a) and (b); including a functionality that makes suggestions relating to users’ search requests (predictive search functionality); (e) the nature, and severity, of the harm that might be suffered by children from the matters identified in accordance with paragraphs (a) to (d), giving separate consideration to children in different age groups;
Illegal content risk assessment duties Children’s risk assessment duties Section 26 (Search services) Section 28 (Search services)
(6) In this section references to risk profiles are (6) In this section references to risk profiles are to the risk profiles for the time being published to the risk profiles for the time being published under section 98 which relate to the risk of under section 98 which relate to the risk of harm to individuals presented by illegal harm to children presented by content that is content. harmful to children.