How to audit for online safety act 2023 compliance
Ensuring your platform is safe for users isn't just a moral duty; it is a legal requirement that protects your business from massive fines and keeps your community healthy.
If your software facilitates user-to-user interaction or allows users to post their own content, you have a legal obligation under the Online Safety Act 2023 to proactively identify and mitigate risks of harm. To comply, you must perform a thorough risk assessment, implement systems to remove illegal content, and, if your platform is accessible to minors, deploy robust age-verification and protection measures. Failure to do so can result in Ofcom issuing fines of up to £18 million or 10% of your global annual turnover.
Does this apply to your business?
The Act primarily targets "user-to-user services." This means if your SaaS allows users to share text, images, videos, or even send private messages to one another, you are likely in scope. Common examples include forums, social networks, messaging apps, and collaborative tools with public or semi-public sharing features. If your software is purely a back-office tool with no user-generated content or interaction, your obligations are minimal, but you should still document why you believe the Act does not apply to you.
Step 1: Conduct a risk assessment
The first step is to identify where the "harm" could happen on your platform. You should create a document that explores the following areas:
- Illegal Content: How could users use your platform to share illegal material (e.g., terrorism, child sexual abuse material, or extreme violence)?
- Harmful Content to Children: If children use your service, what is the risk of them seeing content related to bullying, self-harm, or eating disorders?
- User Profiles: Can users hide behind anonymous profiles to harass others?
Step 2: Implement safety measures
Once you have identified the risks, you must put "safety by design" features in place. This is not a one-size-fits-all requirement; the measures should be proportionate to your size and risk level.
| Feature Type | Action Required |
| Reporting Tools | Provide a clear, easy-to-use button for users to report illegal or harmful content. |
| Moderation | Use automated filters or human moderators to review flagged content quickly. |
| Takedown Procedures | Establish a clear internal process for removing illegal content as soon as you become aware of it. |
| Appeals | Create a way for users to challenge a decision if their content was removed. |
Step 3: Protect children (if applicable)
If your service is "likely to be accessed by children," the bar is much higher. You must prevent children from accessing "highest-risk" content. This might involve:
- Age Verification: Using third-party tools to confirm a user's age before they can access certain features.
- Default Settings: Ensuring the highest privacy settings are turned on by default for users under 18.
- Geolocation: Turning off location sharing for minors by default.
Step 4: Update your terms and documentation
Your Terms of Service must clearly state what is and isn't allowed on your platform. You should be transparent about how you moderate content and what technologies you use to keep users safe. Under the Act, Ofcom expects you to be able to explain your safety processes at any time, so keep a log of all risk assessments and moderation actions taken.
Relatable Example: Imagine you’ve built a project management tool. If users can only talk to colleagues within their own company, your risk is low. However, if you add a "Public Template Gallery" where anyone can upload files and comment on them, you have moved into a higher-risk category and must audit that gallery for potential abuse.
Best practices for startups
- Proportionate Response: You don't need the multi-million pound moderation budget of a global social media giant, but you do need a system that works for your specific user base.
- Stay Informed: Ofcom is the regulator for this Act. Regularly check their website for updated "Codes of Practice" which provide the exact steps they expect small businesses to take.
- Document Everything: In the eyes of a regulator, if it isn't documented, it didn't happen. Keep a folder of your safety audits and version-controlled policy documents.
Created by hatch. • Updated on April 29, 2026