Guides

Online Safety Act annual review requirement

Your risk assessment is not a one-off. You are expected to keep it up to date and review it — in particular before you make a significant change to your service, and when something happens that could change your risk. Many small operators treat this as a regular, roughly annual check-in as well.

The review is meant to be light: confirm the assessment still reflects reality, update what has changed, and record that you looked.

When a review is really needed

The clearest trigger is a material change — a new feature that changes how users interact, a big shift in your user base, or a new kind of problem content appearing. At those points you should revisit the assessment before, not after, the change lands.

Beyond that, a periodic check (an annual review is a sensible default for a small service) keeps the records current and shows ongoing diligence.

Keeping the review proportionate

A review does not mean starting from scratch. Re-read the assessment, note anything that has changed, adjust the measures if needed, and date the update. Keep the previous version so the history is visible — that is part of record-keeping.

Not sure if this applies to you?

Run the free scope checker — seven questions, about three minutes, a cited verdict at the end.

Frequently asked

Is an annual review legally required by a fixed date?
The Act ties review to keeping the assessment up to date and to significant changes, rather than to one fixed calendar date. An annual cadence is a practical way to stay current; check Ofcom guidance for what applies to your service.
What should a review actually produce?
A dated, updated risk assessment (or a note confirming nothing material changed), plus any adjusted safety measures. Keep the prior version so the change history is clear.

Sources

General guidance to help you prepare records — not legal advice, and following it does not make you “compliant”.

More guides

Want a tool that walks you through these duties when we build it?