Online Safety Act record-keeping requirements
Record-keeping is the duty that turns everything else into something you can actually demonstrate. In practice it means writing down your risk assessment and the safety measures you take, and keeping those records so your position is clear over time.
It is less work than it sounds — the records are mostly by-products of doing the other duties properly.
What to keep
Keep your illegal-content risk assessment, any children’s access assessment, and a record of the measures you have in place — moderation, reporting tools, terms, and how you act on complaints. If you make a material change, record the updated position rather than overwriting the old one.
The aim is that, if asked, you can show what you assessed, what you decided, and when.
How long and in what form
There is no need for a special system. A dated set of documents — a shared drive folder is fine — that you review when your service changes materially will usually do for a small operator. Keep it current and keep the history.
Ofcom’s guidance is the authority on form and retention, and it is written to be proportionate: what a two-person forum is expected to hold is not what a large platform is expected to hold. Read the record-keeping guidance linked below against your own service rather than assuming the heaviest reading applies to you.
What this looks like in practice
For most small services the whole record is four or five documents in one folder: the illegal-content risk assessment, the children’s access assessment if you did one, a short description of the safety measures actually in place, your terms, and a running log of complaints and what you did about them.
Two habits do most of the work. Date every document and never overwrite one — save a new version alongside the old, so the folder shows how your thinking changed and when. And write down the reasoning, not just the conclusion: “we considered X and decided Y because Z” is the part that demonstrates you assessed something, and it is the part people leave out.
When to update it
The trigger is material change, not the calendar. Adding direct messaging, opening registration to the public, introducing user uploads, or removing a moderation control all change what your risk assessment concluded, so each is a reason to revisit the record and save a new dated version.
A periodic look-over on top of that keeps the record from quietly going stale between changes — see the annual review guide below for how to keep that light.
Not sure if this applies to you?
Run the free scope checker — seven questions, about three minutes, a cited verdict at the end.
Frequently asked
- Do I need special software to keep OSA records?
- No. Dated documents you can produce on request are enough. What matters is that the records are genuine, current, and cover your risk assessment and safety measures.
- What happens if I never wrote anything down?
- Then you cannot demonstrate you met the duties, which is the risk record-keeping exists to remove. The fix is straightforward: do the assessment now and start keeping the record.
- Does record-keeping still apply if my service is tiny?
- If your service is in scope, the duties apply regardless of size — but what is expected of you is proportionate to your service. A small service is not expected to produce what a large platform produces; it is expected to have genuinely assessed its own risks and to be able to show that.
- Do I need to record every individual moderation decision?
- A small operator generally needs to show the system rather than every instance: what your measures are, how complaints are handled, and a log of complaints and outcomes. Keeping notes on decisions that were difficult or that changed your approach is worth doing, because those are the ones you will want to explain later.
- Can I keep the records wherever I like?
- The location matters less than being able to produce them. A shared drive folder is fine. What causes problems is records spread across personal inboxes and chat threads, where nobody can reconstruct what was decided or when.
Sources
- Ofcom — Illegal harms: record-keeping & review duties
- Ofcom — Illegal harms: risk assessment guidance & Codes of Practice
- Ofcom — Online safety
General guidance to help you prepare records — not legal advice, and following it does not make you “compliant”.
More guides
Want a tool that walks you through these duties when we build it?