KCSIE isn't guidance your school can ignore — it's statutory. Our audits verify your filtering, monitoring, online safety, and digital governance against the requirements, and show you exactly what's missing.
There are three frameworks every UK school must be able to evidence. Our audit platform is built around all three — and the obligations they place on your technology.
Statutory
Keeping Children Safe in Education obliges schools to have appropriate filtering and monitoring, to review them regularly, and to keep a designated safeguarding lead accountable. Your IT is part of your safeguarding duty — if the controls aren't real, your safeguarding isn't real.
Expected
The DfE's digital technology standards cover broadband, network resilience, and device security. Schools are expected to meet them and to appoint a digital lead. Most schools aren't sure where they stand — that's the gap we close.
Obligation
Schools process more sensitive data than most organisations. We check data protection practices — access controls, backups, retention, and breach readiness — against UK GDPR expectations.
We verify that web filtering is genuinely deployed, monitored, and effective — inside and outside the school network. We check that content is age-appropriate and that concerns are surfaced to the DSL. Regular review is a KCSIE requirement; we show you what "appropriate and effective" means in practice.
Technology alone isn't compliance. We check who is accountable, whether the DSL receives the KCSIE requirements, and whether there's an effective online safety strategy behind the tools.
Unmanaged devices are a safeguarding and security risk. We check whether school devices are centrally managed, patched, encrypted, and protected — and whether personal devices are appropriately controlled.
Pupil records, assessment data, and safeguarding files must be held securely and shared safely. We review access controls, backup integrity, and how data leaves the school.
Every school must have a digital lead and a clear technology strategy. We assess whether decisions are documented, understood, and evidenced — not just assumed.
Safeguarding is only as strong as the people. We check induction, online safety training, and whether staff actually know the reporting routes and filtering expectations.
The difference between "we think we're fine" and "we can prove we're compliant" is evidence. Our audits produce it.
We test the controls actually present, not the claims on a policy document. If it isn't real, it doesn't count as compliant in your report.
Every finding is tied to the specific KCSIE clause or DfE standard it relates to — so inspectors and governors see the link instantly.
Your report doubles as evidence for Ofsted and accreditation visits. Inspectors ask about filtering, monitoring, and online safety — you'll have the answer documented.
Findings are ranked. Safeguarding-critical gaps come first, with clear, achievable actions your team can follow.
| Requirement | Typical finding | Status |
|---|---|---|
| KCSIE filtering & monitoring, regularly reviewed | Filtering in place, no formal review log | Partial |
| DfE device security standard | Out-of-life devices still on network | Gap |
| Digital lead appointed | No named digital lead on record | Gap |
| Cyber Essentials baseline controls | Controls mostly present, patching gaps | Partial |
| Data protection & access controls | Appropriate controls evidenced | Met |
Representative example only. Every school receives its own genuine assessment.
Filtering and monitoring gaps expose pupils to inappropriate content and online harm. This is the non-negotiable core of your duty.
Ofsted, and international bodies like COBIS and CIS, ask questions your safeguarding record must answer. Vague answers cost you credibility.
An unpatched device or a misconfigured firewall can become a breach — a financial, reputational, and safeguarding event for the school.