Regulatory performance framework shaping age-assurance procurement and implementation
Ofcom highly effective age assurance framework
Ofcom's highly effective age assurance framework defines how covered services should assess age-checking processes under the UK Online Safety Act. Its January 2025 decision uses four technical criteria—accuracy, robustness, reliability and fairness—alongside implementation requirements for the whole process.
Criteria and accepted evidence
Ofcom declined proposed fixed 95% and 99% thresholds in the initial guidance, citing inadequate comparable testing evidence and innovation considerations. It also declined mandatory independent certification: providers may rely on their own, vendor or independent tests. The children's code recommends assurance for specified access and content controls, with alternative compliant measures available under section 49. The September 2026 resource retained the distinction between certification evidence and compliance; the framework does not require identification across the entire internet.
Ofcom → Ofcom highly effective age assurance framework
allows certification as evidence without making it mandatory or sufficient for
Decision of 16 January 2025; FOI response of 26 August 2025; resource of 2 September 2026.
Paragraphs 3.350 to 3.353 decline the request from Yoti for mandatory independent certification. Providers can use their own, vendor or independent tests as evidence. Trust framework certification does not automatically establish compliance. The September 2026 vendor resource maintains this distinction.
Issued UK Protection of Children user-to-user Code → Ofcom highly effective age assurance framework
recommends for specified access and content controls
In force 25 July 2025.
PCU B2 and B3 concern service-wide adult access; B4 to B7 concern conditional content or feed protections. B4 to B7 permit restrictions for users who do not seek adult access. Section 49 allows alternative compliant measures. The code does not mandate identification across the internet.
Ofcom → Ofcom highly effective age assurance framework
declined proposed fixed numerical thresholds in initial guidance for
Decision of 16 January 2025; currentness checked against the 2 September 2026 resource.
Paragraphs 3.251 to 3.259 retain a criteria-based approach despite proposed 95% and 99% thresholds, citing inadequate comparable evidence and testing, and innovation considerations. Future thresholds remain possible; the September 2026 resource does not itself impose one.
Ofcom → Ofcom highly effective age assurance framework
publishes and applies
16 January 2025; Part 3 updated 24 April 2025; current page updated 2 September 2026.
The January 2025 decision sets technical accuracy, robustness, reliability and fairness criteria, with final Part 3 and Part 5 guidance. The whole process must meet the criteria. Not all services must use age assurance.
16 January 2025; Part 3 updated 24 April 2025; current page updated 2 September 2026.
The January 2025 decision sets technical accuracy, robustness, reliability and fairness criteria, with final Part 3 and Part 5 guidance. The whole process must meet the criteria. Not all services must use age assurance.
PCU B2 and B3 concern service-wide adult access; B4 to B7 concern conditional content or feed protections. B4 to B7 permit restrictions for users who do not seek adult access. Section 49 allows alternative compliant measures. The code does not mandate identification across the internet.
Decision of 16 January 2025; currentness checked against the 2 September 2026 resource.
Paragraphs 3.251 to 3.259 retain a criteria-based approach despite proposed 95% and 99% thresholds, citing inadequate comparable evidence and testing, and innovation considerations. Future thresholds remain possible; the September 2026 resource does not itself impose one.
Decision of 16 January 2025; FOI response of 26 August 2025; resource of 2 September 2026.
Paragraphs 3.350 to 3.353 decline the request from Yoti for mandatory independent certification. Providers can use their own, vendor or independent tests as evidence. Trust framework certification does not automatically establish compliance. The September 2026 vendor resource maintains this distinction.