OFCOM's guidance about record-keeping and review duties
Record-Keeping and Review Guidance
V3.0 Published 25 June 2026
Contents¶
Section¶
1. Introduction ..................................................................................................................... 3
2. Guidance on written records ........................................................................................... 6
3. Making and keeping written records of risk assessments ............................................... 7
4. Records of measures taken in compliance with a relevant duty which are recommended in Ofcom’s Code of Practice .................................................................................................. 12
5. Records of alternative measures taken to comply with a relevant duty ........................ 14
6. Reviewing compliance ................................................................................................... 16
Section 1 Introduction¶
Who does this guidance apply to?¶
What does this guidance cover?¶
b) the ‘review duties’, namely the duties to:
1 This guidance does not cover the record-keeping duties that apply to providers which provide an online service on which pornographic content is published or displayed by or on behalf of that provider (‘Part 5 providers’). Guidance on those duties is included in our Guidance on highly effective age assurance and other Part 5 duties. This guidance also does not cover guidance on written records for children’s access assessments (conducted under section 36). This is covered in our Children’s Access Assessments Guidance. 2 See section 9 or section 26 (as applicable) for illegal content risk assessment duties. 3 All providers of regulated U2U and search services are required to carry out children’s access assessments, under section 36 of the Act. If a service is likely to be accessed by children, the provider must conduct a children’s risk assessment; see section 11 or section 28 (as applicable) for children’s risk assessment duties. We have produced guidance on children’s access assessments and children’s risk assessments. 4 A ‘relevant duty’ for regulated U2U services means the duties set out in: section 10 (illegal content); section 12 (children’s online safety); section 15 (user empowerment); section 17 (content of democratic importance); section 19 (journalistic content); section 20 (content reporting); and section 21 (complaints procedures). A ‘relevant duty’ for regulated search services means the duties set out in: section 27 (illegal content); section 29 (children’s online safety); section 31 (content reporting); and section 32 (complaints procedures).
5 For regulated U2U services, these are the duties set out in: section 10 (illegal content); section 12 (children’s online safety); section 15 (user empowerment); section 17 (content of democratic importance); section 18 (news publisher content); section 19 (journalistic content); section 20 (content reporting); section 21 (complaints procedures); section 71 and section 72 (terms of service); and section 75 (disclosure of information about use of service by deceased child users). For regulated search services, these are the duties set out in: section 27 (illegal content); section 29 (children’s online safety); section 31 (content reporting);
ii) review compliance with the relevant online safety duties as soon as practicable after making a significant change to the design or operation of the service.
Why is this guidance important?¶
Failure to keep records or review compliance¶
This guidance was originally published on 16 December 2024. An updated version was published on 24 April 2025. We added a section on guidance specific to record-keeping of children’s risk assessments and updated the ‘what does this guidance cover?’ section to reflect this. We aligned the guidance with our Children’s Risk Assessment Guidance. This
section 32 (complaints procedures); and section 75 (disclosure of information about use of service by deceased child users). 6 Section 23(10) and section 34(9) respectively of the Act. Category 1 U2U services and Category 2A search services are services that Ofcom considers meet the applicable threshold conditions set out in regulations to be made by the Secretary of State under Schedule 11 of the Act and that are entered in a public register to be kept by Ofcom under section 95 of the Act.
7 See our regulatory documents: Illegal Content Codes of Practice for U2U services; Illegal Content Codes of Practice for search services; and Risk Assessment Guidance and Risk Profiles. 8 See our regulatory documents: Protection of Children Code of Practice for user-to-user services; Protection of Children Code of Practice for search services; and Children’s Risk Assessment Guidance and Risk Profiles. 9 Online Safety Enforcement Guidance.
version was published 25 June 2026 to reflect the new priority offences. We replaced references to ’17 kinds of priority illegal content’ with ’18 kinds of illegal content’.
Section 2 Guidance on written records¶
Durability and accessibility¶
Easy to understand¶
Up to date¶
10 See paragraphs 6.1 to 6.8 for guidance on the service provider’s duty to conduct a review of a measure when there has been a significant change to any aspect of the design or operation of a regulated service. 11 We set out in paragraphs 3.9, 3.18, 4.5, and 5.6 when the respective written records should be made.
Section 3 Making and keeping written records of risk assessments¶
Illegal content risk assessments¶
What must all service providers do?¶
What should the illegal content risk assessment record include?¶
12 Categorised services are services that Ofcom considers meet the applicable threshold conditions set out in regulations to be made by the Secretary of State under Schedule 11 of the Act and that are entered in a public register to be kept by Ofcom under section 95 of the Act. 13 See section 9 or section 26 of the Act (as applicable). 14 All providers must take account of the relevant Risk Profiles for their service when conducting the risk assessment. There is a separate set of risks for U2U services and for search services. The Risk Profiles are available in our Risk Assessment Guidance and Risk Profiles published document.
e) who approved the risk assessment.
When should the illegal content risk assessment record be made?¶
15 Risk Assessment Guidance and Risk Profiles. 16 Risk Assessment Guidance and Risk Profiles.
Children’s risk assessments¶
What must all service providers do?¶
What should the children’s risk assessment record include?¶
17 See our guidance on children’s access assessments for more detail on the duty and how to conduct such an assessment. Record-keeping in relation to children’s access assessments is covered in that guidance.
18 Section 37 of the Act explains the meaning of “likely to be accessed by children”. 19 Section 11 or section 28 of the Act (as applicable). 20 All providers must take account of the relevant Children’s Risk Profiles for their service when conducting the risk assessment. There is a separate set of risks for U2U services and for search services. The Children’s Risk Profiles are available in our Children’s Risk Assessment Guidance and Risk Profiles document. 21 Children’s Risk Assessment Guidance and Risk Profiles.
b) a record of any risk factors from Ofcom’s Children’s Risk Profiles that are relevant to the regulated provider’s service; c) a record of the kind(s) of non-designated content that the service provider has identified for assessment, and how the provider has considered the risk of children encountering non-designated content by means of their service;22 d) where applicable, a list of any additional characteristics (including user base, business models, functionalities, governance, and systems and processes) that the regulated provider has considered alongside the risk factors identified in Ofcom’s Children’s Risk Profiles. This should include how the provider has identified and assessed those functionalities that present higher levels of risk, such as recommender systems, functionalities which enable adults to search for and/or contact children, and predicting search functionalities, as well as features and functionalities which affect how much children use the service; e) if a service provider has considered the role of any existing controls already in operation on their service at the time of the risk assessment, what these controls are, what risks they are intended to mitigate and how they do this, and how the consideration of the existing controls has impacted the risk level assigned by the provider to a kind of content harmful to children; f) a list of the evidence, and summary of the reasoning, that has informed the assessment of likelihood and impact of each kind of primary priority content, each kind of priority content, and each kind of non-designated content. This should include relevant evidence about the design and use of the service, and how different age groups of children have been considered; g) the level of risk assigned to each of the four kinds of primary priority content, each of the eight kinds of priority content, and for any kind(s) of non-designated content the provider has assessed on the service, and an evidence-based explanation of the decision;23 h) confirmation that the findings of the children’s risk assessment have been reported, and recorded, through appropriate governance and accountability channels; and i) information regarding how the service provider takes appropriate steps to keep the children’s risk assessment up to date (for example, a written policy).
When should the children’s risk assessment record be made?¶
22 Section 60 sets out what constitutes “non-designated content”. See also: ‘Table 1: list of content harmful to children to assess’ in our Children’s Risk Assessment Guidance. 23 Section 61 sets out what constitutes “primary priority content”. Section 62 sets out what constitutes “priority content”. ‘Table 1: list of content harmful to children to assess’ in our Children’s Risk Assessment Guidance also explains what primary priority content, priority content, and non-designated content is. 24 Children’s Risk Assessment Guidance and Risk Profiles.
Category 1 U2U services and Category 2A search services¶
Duty to provide risk assessments to Ofcom¶
Duty to publicly summarise the findings of the most recent risk assessment¶
25 Categorised services are services that Ofcom considers meet the applicable threshold conditions set out in regulations to be made by the Secretary of State under Schedule 11 of the Act and that are entered in a public register to be kept by Ofcom under section 95 of the Act. 26 Section 23(10) and section 34(9) of the Act respectively. 27 Section 10(9) or section 12(14) of the Act (as applicable). 28 Section 27(9) or 29(9) of the Act (as applicable).
Section 4 Records of measures taken in compliance with a relevant duty which are recommended in Ofcom’s Code of Practice¶
What must service providers do?¶
Table 1: relevant duties for service providers:¶
What should the record include?¶
in question (or a copy) should be kept and maintained as part of the record made for the purposes of the record-keeping duty under section 23(3) or section 34(3).29
When should the record of a Code measure be made?¶
29 Such document or information should be durable, accessible, easy to understand, and up to date, in line with this guidance.
Section 5 Records of alternative measures taken to comply with a relevant duty¶
What must service providers do?¶
What should the record of an alternative measure include?¶
30 These are measures set out by Ofcom in a Code of Practice which apply to the relevant service provider.
31 There is no obligation on a service provider to keep a written record of a measure (from the Code of Practice) that does not apply to it (for example, where particular measures only apply to a subset of services based on size or risk of a particular harm). 32 Specifically, the duties in section 10(2) and (3) for U2U services and section 27(2) and (3) for search services in relation to safety duties about illegal content; and the duties in section 12(2) and (3) for U2U services and section 29(2) and (3) for search services in relation to safety duties protecting children. 33 See section 23(5) and section 34(5) of the Act for what must be recorded in relation to alternative measures.
Table 2: areas in which alternative measures can be taken:¶
When should the written record of alternative measures be made?¶
Section 6 Reviewing compliance¶
What must service providers do?¶
Table 3: a service provider must review its compliance with the following online safety duties:¶
When should a review be carried out?¶
service; the findings of the provider’s most recent illegal content and, where applicable, children’s risk assessment; and the outcome of the provider’s last compliance review.
34 See ‘Part 1: Duties and carrying out an illegal content risk assessment’ in Risk Assessment Guidance and Risk Profiles, specifically the section titled ‘Review and update at least every 12 months’; and ‘Part 1: Duties and carrying out a children’s risk assessment’ in Children’s Risk Assessment and Risk Profiles, specifically the section titled ‘Review and update at least every 12 months’. Additionally, service providers required to complete a Children’s Access Assessment must re-do these at least every 12 months (see section 36(3) of the Act).