If you have highly effective age assurance in place on your service, you will need to carry out a new children’s access assessment in response to evidence about reduced effectiveness of your age assurance and access control methods on your service.
This would mean that your age assurance and access control methods are no longer highly effective at correctly determining whether or not a particular user is a child and therefore preventing children from being able to normally access your service.
How to consider whether effectiveness is reduced
Evidence of reduced effectiveness could come from user reports, post-signup age checks, media reports, independent research, and vendor updates/warnings, as well as other sources not listed here.
Effectiveness in the context of the children’s access assessment should be considered in relation to the technical accuracy, robustness, reliability and/or fairness of the age assurance methods.
- Technical accuracy: children (or some children, for example those with a particular protected characteristic) are inaccurately being identified as adults
- Robustness: children are circumventing age assurance or access controls
- Reliability: children are able to access a service that they previously could not gain access to, while using the same information
- Fairness: age assurance methods or processes are discriminating against a particular protected characteristic. For example, an AI model that is systematically biased against a particular protected characteristic
Evidence of a reduction in technical accuracy, robustness, reliability and/or fairness may therefore trigger a new children’s access assessment.
Relevant evidence
Not all changes will necessarily mean the service needs to carry out a new children’s access assessment. This is because not all evidence will be considered as relevant. For example, one-off technical failures that do not relate to children that result in a decline in accuracy.