Summary
- Ofcom has published a vendor due-diligence framework covering testing, circumvention, appeals, standards, technical safeguards, and performance monitoring.
- Regulated services remain responsible for ensuring the entire age-assurance process is highly effective even when a specialist supplier provides the technology.
- The guidance turns age assurance into an ongoing technology-governance and procurement issue rather than a one-off product selection.
Online platforms using specialist suppliers to keep children away from restricted content remain responsible when those systems underperform, with Ofcom now setting out the questions companies should keep asking vendors rather than treating an age-checking contract as evidence of compliance.
Ofcom has published a due-diligence resource for services using third-party age-assurance technology, covering how products are tested, whether children can circumvent them, what happens when a user appeals a decision, and how performance problems are reported back to customers.
The allocation of responsibility is explicit: even where another company supplies the technology, the regulated online service must ensure that its age-assurance process as a whole meets the Online Safety Act’s requirement to be highly effective. Due diligence is therefore expected to continue after selection rather than end once a supplier has passed procurement.
That turns age assurance into a supplier-governance problem as well as a technical one. Platforms can buy facial-age estimation, document checks, credit-card checks, or other approaches from specialist companies, but the legal duty remains attached to the service whose users encounter the resulting gate.
Ofcom’s questions ask vendors what metrics they use to demonstrate performance against the regulator’s criteria, how frequently systems are tested, and how problems are communicated. Services are also encouraged to establish which methods children can use to circumvent a product and what evidence shows that countermeasures are working.
Appeals form another part of the framework because age-assurance systems inevitably make some incorrect decisions. Ofcom wants services to understand how users challenge a result, how quickly appeals are handled, what proportion succeed, and how vendors monitor the accuracy of those decisions.
A certificate does not settle compliance
Standards and certifications can form part of that assessment, but Ofcom warns against treating them as automatic evidence that a service has met its duties. Its suggested questions include whether a product meets schemes such as the UK Digital Verification Services Trust Framework or ISO/IEC 27566-1:2025, while stressing that certification alone does not establish whether the overall process satisfies the highly effective age-assurance criteria.
Some requirements also depend on the method being used. Where a supplier relies on age estimation, Ofcom expects services to examine whether the product uses an appropriate challenge-age mechanism or an equally effective alternative to reduce the risk that children are incorrectly classified as adults.
For facial-age estimation or systems matching a person against photographic identification, the regulator asks whether liveness detection is deployed. That control is intended to make it harder to defeat a check with a static image or similarly simple circumvention technique rather than a live person completing the process.
The detail reflects shortcomings Ofcom has already identified in how services use age assurance. Its updated guidance says organisations should follow the regulator’s effectiveness requirements in full, conduct appropriate due diligence, monitor vendor performance using suitable metrics, and make improvements where weaknesses emerge.
Procurement teams therefore cannot judge a supplier solely on integration effort, conversion rates, or unit price. The purchasing decision increasingly needs technical evidence about false classifications, resilience against circumvention, appeals, privacy, monitoring, and the way a vendor communicates degradation or material changes to its service.
Outsourcing technology does not outsource responsibility
The structure resembles other areas of technology regulation in which responsibility stays with the organisation using an external service even when another company supplies the relevant control. Cloud hosting, identity verification, payment processing, cyber monitoring, and outsourced data processing have all forced businesses to develop supplier-governance processes around systems they do not operate directly.
Age assurance adds a particularly awkward balance because services are trying to distinguish children from adults while limiting unnecessary collection of identity and personal data. Ofcom’s guidance therefore points companies back to UK data-protection requirements alongside the Online Safety Act, requiring technical effectiveness to be considered together with accountability around the information used.
The procurement question is becoming more important as age checks spread across regulated services. Previous Ofcom evidence has already shown that compliant services can lose traffic while users move towards sites with weaker controls, leaving enforcement and consistent implementation as part of whether the regime works in practice.
Against that background, an age-assurance vendor sits inside a wider system involving product design, policy, data protection, enforcement, and user behaviour. A technically accurate model can still produce a weak compliance process if it is implemented with inappropriate thresholds, easily bypassed, poorly monitored, or left unchanged as users discover new ways around it.
Regular due diligence also changes what suppliers need to provide. Vendors selling into regulated services will increasingly be expected to produce performance evidence that can survive internal governance and regulatory scrutiny, rather than relying on general claims that their technology is compliant.
That could favour suppliers with mature testing and reporting systems, although it may also increase procurement costs for smaller services without specialist technical or regulatory teams. Ofcom’s framework makes the conversation more structured, but a checklist cannot remove the work required to judge whether a vendor’s answers are adequate.
The guidance therefore moves age assurance further away from being treated as a plug-in installed to meet a deadline. Services using third-party technology are expected to understand what they bought, monitor how it behaves, revisit its performance, and remain accountable for the result — an increasingly familiar pattern as digital regulation reaches deeper into enterprise technology procurement.












