This is the document the whole Online Safety Act regime hangs off. Ofcom does not assess whether your platform is safe in the abstract. It assesses whether you identified the risks on your service and put proportionate measures against them, and the risk assessment is where you prove you did.
Part of our UK Online Safety Act guides. Not legal advice.
- What the assessment is
- Ofcom's four steps
- The priority offence categories
- Evidence Ofcom expects
- Where detection evidence fits
- Frequently asked questions
What the assessment actually is
An illegal content risk assessment is a written judgement about the likelihood that each kind of priority illegal content appears on your service, the harm it would cause UK users if it did, and what you are doing about it. It is not a security questionnaire and it is not a policy statement. Ofcom's guidance frames it as an evidence-led exercise tied to your specific functionalities.
The practical consequence is that generic answers fail. "We have a moderation team" is not an assessment. "Our direct messaging feature allows adults to contact under-18s without a prior connection, which our risk profile flags as a grooming vector, and we mitigate it with behavioural detection on first-contact conversations plus a restriction on unsolicited adult-to-minor messaging" is.
The duty to complete the assessment is separate from the duty to act on illegal content. A service can be in breach for having no suitable assessment even in a period where no harmful content was found.
Understand the harms
Work through the kinds of illegal content Ofcom lists in its register of risks, and establish which are relevant to your service. Ofcom's risk profiles group services by type and functionality so you can start from a baseline rather than a blank page.
Assess the risk of harm
For each relevant kind of illegal content, judge the likelihood and impact on UK users, taking account of your functionalities, user base, business model and any incident history. Record why you reached each judgement, not just the rating.
Decide measures and record outcomes
Identify the safety measures you will operate. Following the measures in Ofcom's codes of practice is the route that gives you the clearest position; departing from them means demonstrating your alternative achieves the same outcome.
Report, review and update
Sign the assessment off through your governance, and keep it current. Ofcom expects a fresh assessment before you make a significant change to your service, and periodic review regardless.
Ofcom's register of risks groups priority illegal content into categories your assessment has to work through. These are the ones most platforms with under-18 users find relevant:
Child sexual exploitation and abuse
Includes grooming, CSAM, and image-based abuse. Ofcom treats this as a priority offence for every service type.
Encouraging or assisting suicide and self-harm
Priority illegal content with its own dedicated duties.
Harassment, stalking and threats
Covers coordinated abuse and coercive patterns, not only individual messages.
Fraud and financial offences
Romance scams, social engineering, money mule recruitment.
Terrorism and extremism
Radicalisation pathways as well as prohibited material.
Drugs, weapons and human trafficking
Supply and facilitation offences carried out through the service.
This is a summary, not the full register. Ofcom's published register of risks is the authoritative list and includes offences not shown here.
Evidence Ofcom expects behind it
If Ofcom issues an information notice, the assessment document alone rarely satisfies it. What tends to be asked for is proof the measures you described are actually running:
- The completed assessment document, with reasoning recorded against each kind of illegal content
- The date it was carried out and the governance sign-off behind it
- The measures you decided to operate, and the rationale where you departed from a code measure
- Operational data showing the measures actually run: detection volumes, moderation outcomes, response times
- A record of review triggers, including significant service changes
The gap most teams hit is step four: they can describe their measures, but not evidence them over time. Tuteliq's incident records carry the detection rationale, confidence score, modality, and the full moderator audit trail, including who reviewed a case, what they decided, and when. Decisions carry signed receipts, so an exported report is cryptographically tied to the decisions it describes.
For services that operate a Trust Center, that operational record can also be surfaced publicly without exposing case content, which is useful when partners or parents ask the same questions Ofcom does.
Related reading: the Protection of Children Codes and how Ofcom enforces.
Who has to complete an illegal harms risk assessment?
Every in-scope user-to-user and search service with links to the UK, regardless of size or where the company is based. Ofcom's proportionality principle changes what measures are expected of you, not whether the assessment itself is required.
What happens if we never completed one?
Failing to carry out a suitable and sufficient risk assessment is a breach of a duty in its own right, separate from any harm that occurs on the service. Ofcom can open an investigation and issue an information notice requiring you to produce the assessment. Completing one late is materially better than not having one when the notice arrives.
How often does it need updating?
Before you make a significant change to the design or operation of your service, and on a periodic basis in any case. Launching a new functionality such as direct messaging, live voice, or user-generated video is the kind of change that normally warrants a fresh assessment.
Can a vendor complete the assessment for us?
No. The assessment is your organisation's work product and your governance has to own it. What a vendor can supply is the operational evidence layer underneath it: what your detection systems catch, at what confidence, and what your moderators did about it.
Does Tuteliq cover every priority offence category?
Tuteliq's detection covers child sexual exploitation and grooming, suicide and self-harm, bullying and harassment, coercive control, image-based abuse, radicalisation, and several fraud typologies across text, voice, image and video. It does not cover every offence in the register, and no single system does. Your assessment should be explicit about which risks are addressed by tooling and which by policy, staffing or design.