If you use a third-party age assurance vendor, Ofcom expects you to conduct regular due diligence on them. Ultimately it is your responsibility as the service provider to ensure that your age assurance process as a whole is highly effective.
To support your due diligence conversations with vendors, we have created this non-exhaustive list of questions primarily based on the areas for improvement identified in our Report on the use of age assurance (PDF, 1.51 MB).
This resource is also available as a PDF with space for responses and comments: Vet your vendor (PDF, 123 KB).
Questions to support due diligence of an age assurance vendor
Testing
Questions to understand what tests have been conducted and what metrics are used to measure results.
- Which metrics do you collect and measure against to evidence that your solution meets each of Ofcom’s highly effective age assurance (HEAA) criteria?
- Explain how you test and evaluate your solution’s performance, and how often this testing is conducted.
- How do you communicate the outcomes of your testing and flag any issues to me (the regulated service)?
Circumvention by children
Questions to help you ensure that risks of circumvention by children have been considered, and appropriate steps taken.
- What methods of circumvention to your solution have you identified that are easily accessible to children?
- What steps have you taken to address identified circumvention risks and what evidence do you have that this is mitigating the risks?
Appeals
Questions to explore if the vendor has a robust appeals process, and how they monitor appeal metrics.
- How are users able to appeal the result of an age check?
- How do you monitor relevant metrics about appeals? This may include appeal rates, appeals upheld, time taken to make appeal determinations, and accuracy of decision making.
- How do you communicate these appeal metrics and flag any issues to me (the regulated service)?
Standards and certifications
Question to explore whether the vendor has achieved certification against relevant schemes or standards. While this is not an automatic means of compliance, it may help to demonstrate regard to Ofcom’s HEAA criteria.
- Is your method certified against or does it conform to/meet a particular standard or scheme, such as the UK Digital Verification Services Trust Framework or ISO/IEC 27566-1:2025?
Method-specific questions
If the vendor offers age estimation, ensure a challenge age approach or equally effective alternative is used.
- Does your solution include a challenge age approach? If not, can you demonstrate an alternative mechanism that is equally as effective as a challenge age at reducing the likelihood of false positives (children incorrectly classified as adults)?
- What information on the limits of the technical accuracy of your method can you share to help me to choose an appropriate challenge age?
If the vendor offers facial age estimation and/or photo-ID matching, ensure liveness detection is deployed.
- Does your solution include liveness detection?
Further guidance
See our Part 3 Guidance on highly effective age assurance (PDF, 394.54 KB) and Guidance on highly effective age assurance and other Part 5 duties (PDF, 775.13 KB), which explains relevant terms and is designed to assist you in meeting your obligations when implementing HEAA.
You must implement HEAA in a way which complies with data protection law. This includes ensuring appropriate accountability and governance arrangements are in place. For more information, see the ICO’s guidance on UK GDPR, including on controllers and processors.