ComplyChat Start free

Guide · Schools

Filtering and monitoring in schools

Schools and colleges in England have a statutory responsibility to keep children safe online, which includes having appropriate filtering and monitoring systems, and should review them at least once every academic year, under paragraph 173 of Keeping children safe in education 2026 and the Department for Education’s four filtering and monitoring standards, with a named senior leader and governor responsible and a written record of the review and of every check.

By ComplyChatPublished 12 minute read

An IT technician and the designated safeguarding lead sit side by side on a low sofa in a secondary school’s sixth-form study centre late in the afternoon, testing a pupil laptop together while sixth-formers work at study carrels beyond

This guide covers the roles, the review, the log of checks and the records they create. The wider online safety policy, the 4Cs and the curriculum are covered in our online safety policy guide; this one is about running and evidencing the systems.

01

The rule: KCSIE 2026 paragraphs 173 to 177 and the DfE standards

Governing bodies and proprietors of schools and colleges in England “should ensure their school or college has appropriate filtering and monitoring systems in place and ensure that a review of their effectiveness is carried out at least once every academic year”, in the words of paragraph 173 of Keeping children safe in education 2026 (KCSIE), the statutory guidance in force from 1 September 2026. The 2026 edition adds who does it and what is kept: “Reviews should be carried out by the SLT member responsible for filtering and monitoring, with the support of the school’s designated safeguarding lead and IT support. They should include checks that filtering is working appropriately on all internet-connected devices in all relevant locations, and a record should be kept of these checks.”

Paragraph 175 points to the Department for Education’s filtering and monitoring standards, part of its digital and technology standards for schools and colleges, which say schools and colleges should:

  1. identify and assign roles and responsibilities to manage filtering and monitoring systems,
  2. review filtering and monitoring provision at least annually,
  3. block harmful and inappropriate content without unreasonably impacting teaching and learning, and
  4. have effective monitoring strategies in place that meet their safeguarding needs.

Of each standard the Department says: “You should already be meeting this standard.”

The standards define the two terms precisely. “Filtering is preventative”: it protects users from accessing illegal, inappropriate and potentially harmful content by blocking specific web links and digital content, including AI-generated content. “Monitoring is reactive”: it reviews what users are doing on devices and generates reports or alerts, and “monitoring solutions do not block users from seeing or doing anything”. What is appropriate is “a matter for individual schools and colleges”, informed in part by the school’s Prevent duty risk assessment (paragraph 174).

02

Who is responsible for filtering and monitoring

The first standard is about names, because filtering and monitoring are safeguarding responsibilities shared between people who rarely sit in the same office. Governing bodies and proprietors “have overall strategic responsibility for filtering and monitoring and need assurance that the standards are being met”, and should identify and assign “a member of the SLT and a governor, to be responsible for ensuring these standards are met”, plus the roles of staff and third parties such as contracted IT support. The roles may sit inside wider jobs, “however, it must be clear who is responsible and it must be possible to make prompt changes to your provision.”

  • The senior leadership team is responsible for scoping the school’s needs, “including use of generative AI”, buying the systems, “documenting decisions on what is blocked or allowed and why”, governance of the systems, reviewing the effectiveness of the provision and overseeing reports, and for making sure all staff understand their role, are trained, follow the procedures and act on reports and concerns.
  • The designated safeguarding lead leads on safeguarding and online safety, including “checking relevant reports”, “responding to safeguarding concerns identified by filtering and monitoring” and “providing governors with assurance that filtering and monitoring systems are working effectively and reviewed regularly”. KCSIE paragraph 127 says this includes “understanding the filtering and monitoring systems and processes in place”.
  • IT support, in-house or a third-party provider, has technical responsibility for maintaining the systems, providing reports and “completing actions following concerns or system checks”, and works with the senior leader and DSL to buy systems, identify risk and carry out reviews and checks.
  • The responsible governor takes part in the annual review and, with the senior leader, is responsible for ensuring the standards are met. The UK Council for Internet Safety’s Online safety in schools and colleges: questions from the governing board is a practical set of questions for that role.
  • All school staff receive safeguarding training at induction that includes “an understanding of the expectations, applicable roles and responsibilities in relation to filtering and monitoring” (KCSIE paragraph 153), with updates at least annually (paragraph 154). The standards add that all staff “should conduct a level of in-person monitoring if they are in a room with students on devices, as part of wider classroom supervision”.
03

The annual filtering and monitoring review

The review happens “at least once every academic year” and “can be part of a wider online safety review”. The standard says who and what is kept: “The yearly review should be conducted by members of the senior leadership team, the designated safeguarding lead and IT support. It should also involve the responsible governor. You should record the results of the review and document any actions taken. This record should be available to anyone who is entitled to inspect that information.”

It is also due outside the annual cycle when “a safeguarding risk is identified”, when “there is a change in working practice, like remote access or BYOD”, when “new technology is introduced, such as new devices or generative-AI tools”, when “major software updates occur” or when the technical configuration of the network and devices changes.

The standard lists what the review needs to understand, which makes a usable agenda:

  • the pupils’ risk profile, considering age, special educational needs and disabilities and English as an additional language;
  • what the filtering system currently blocks or allows;
  • how the school uses technology, including any bring your own device policy for pupils and staff;
  • how and where generative AI web and in-application products are used;
  • technical limitations, such as whether the system can filter and monitor real-time, dynamic, personalised or AI-generated content;
  • outside safeguarding influences, such as county lines;
  • relevant safeguarding reports or serious incidents;
  • the digital resilience of pupils;
  • teaching requirements, such as the RSHE and PSHE curriculum;
  • the related safeguarding and technology policies, “including approval processes for temporary exceptions from filtering and monitoring systems”;
  • what checks are currently taking place and how resulting actions are handled; and
  • technical set-up recommendations, including automatic updates.

The review should then inform the related policies, roles, staff training, the curriculum, “how often and what is checked”, monitoring strategies and procurement; a record listing those headings, each with a finding and an owner, is what “record the results of the review and document any actions taken” looks like in practice. The Department’s Plan technology for your school service lets schools self-assess against the standards and receive recommendations (KCSIE paragraph 176), and its output is useful evidence for the same record.

04

The checks, and what the log must show

Between reviews the school checks that the system still works. How often is for the school: frequency “should be based on your school or college context, the risks highlighted in your filtering and monitoring review, and any other risk assessments”, and “checks should be made from both a safeguarding and IT perspective”. The checks make sure “the system setup has not changed or been deactivated”, across:

  • school-owned devices and services – every internet-connected device the school manages, “even if they are taken home”, including laptops, tablets and audio-visual equipment;
  • every location, where there are buildings or schools on different premises; and
  • every user group – that accounts filter the correct content for pupils, staff and guests.

The standard asks for “a log of your checks so they can be reviewed”, recording:

  1. when the check took place,
  2. who did the check,
  3. what they tested or checked, and
  4. resulting actions.

As a minimum, testing tools such as the one provided by the South West Grid for Learning, Test Filtering, can confirm that the system blocks access to “illegal child abuse material”, “unlawful terrorist content” and “adult content”. The school should also make sure that systems work on new devices and services “before distributing them”, and that the content it chooses to block is reviewed as guidance and risks change.

A useful entry names the device or account, the site, the user profile, the test, the result and the action that followed; “filtering checked – OK” meets only the first heading.

A school governor and the designated safeguarding lead go through a printed annual review at a bench in an empty secondary school science laboratory, stools upturned on the benches around them and late afternoon sun through the windows
05

What the review tests: filtering, monitoring and the records they create

Filtering. “No filtering system can be 100% effective”, so the school needs to understand its system’s coverage and limitations. The filtering should not have “a blanket filtering profile for all users. As a minimum, student and staff profiles should be in place.” Schools “must make sure” the Internet Watch Foundation and Counter-Terrorism Internet Referral Unit blocklists are implemented, and the solution must be designed so that those blocklists “cannot be disabled, overridden, or altered by any user” at any level, including system administrators. Filtering should cover managed devices taken off-site, bring-your-own devices and guests on the school internet, and block ways round it “such as VPNs, proxy services and end-to-end encryption methods”. KCSIE paragraph 163 sets the counterweight: governing bodies should be careful that “over blocking” does not lead to unreasonable restrictions on what children can be taught.

Exceptions. If a temporary exception is needed, for example for a system update, “the member of the senior leadership team (SLT) responsible for filtering and monitoring must approve and document it. The designated safeguarding lead (DSL) should assess any safeguarding implications.” Each exception is therefore a record: what was opened, for whom, why, who approved it, the DSL’s view and when it closed.

Identification. As a minimum the system should identify the “device name or ID, IP address, and where possible, the individual”, “the time and date of attempted access” and “the search term or content being blocked”.

Monitoring. The monitoring plan may combine device monitoring, in-person supervision and network monitoring of log files. “As a minimum, your monitoring plan should include weekly monitoring reports highlighting incidents. It should also include immediate reports when an incident is classed as high-risk.” Everyone using the network should know filtering and monitoring are in place, and technical systems should tell users so, for example in a message at log-in. The DSL “is responsible for any safeguarding and child protection matters that are identified through monitoring”, and “there should be a documented process for recording incidents that includes what action was taken and the outcomes”. An incident that becomes a safeguarding concern goes into the child’s record like any other, as our guide to what KCSIE requires you to record explains.

Data protection. Both filtering and technical monitoring process personal data about pupils and staff, so the standards say schools “will need to conduct their own data protection impact assessments (DPIAs) and review the privacy notices of third-party providers”, and that monitoring procedures should be reflected in the acceptable use policy and privacy notices. The Data (Use and Access) Act 2025 amends the UK GDPR and the Data Protection Act 2018 in stages, so check the date on any ICO guidance you rely on.

06

The unblock request and the alert that travel by text

The filtering system keeps an exact record of itself: every blocked attempt with a device, a time and a search term. The decisions about it are another matter.

A history teacher messages the IT technician at five past eight: can the documentary site be unblocked for Year 10 in period two? It is done by quarter past. That was a temporary exception, which the standard says the responsible senior leader must approve and document and the DSL should assess; the only record is a thread on two personal phones. On a Friday evening the monitoring provider’s high-risk alert reaches the contracted technician, who forwards a screenshot with a pupil’s name in it to the DSL’s own messaging app. The DSL replies that she will pick it up first thing Monday. That exchange is the immediate report the standard requires and the first entry of a safeguarding response, and it now sits outside every system the school controls, with personal data about a child on a phone the school does not manage.

None of this is bad practice in intent; it is how a small team keeps teaching going. But the annual review asks “what checks are currently taking place and how resulting actions are handled”, the governor is asked for assurance, and the honest evidence for the exceptions granted and the speed of the response is in conversations nobody can produce.

A question for the next governors’ meeting: if the responsible governor asked for every filtering exception approved this term, and the time each high-risk alert reached the designated safeguarding lead, could the school produce both from records it holds?

07

Questions people ask

What is filtering and monitoring in safeguarding in schools?

Filtering and monitoring are the two technical safeguards Keeping children safe in education 2026 expects every school and college in England to have on its devices and networks: filtering blocks access to illegal, inappropriate and potentially harmful content, and monitoring reviews what users do on devices so concerns can be picked up and acted on. The Department for Education’s standards describe filtering as “preventative” and monitoring as “reactive”.

What are the DfE web filtering standards for schools?

The DfE’s filtering and monitoring standards say schools and colleges should assign roles and responsibilities, review provision at least annually, block harmful and inappropriate content without unreasonably affecting teaching and learning, and have effective monitoring strategies. They sit in the Department’s digital and technology standards for schools and colleges, and KCSIE 2026 paragraph 175 points to them.

How often should filtering and monitoring systems be reviewed?

Filtering and monitoring provision should be reviewed at least once every academic year under KCSIE 2026 paragraph 173 and the DfE standards, and again whenever a safeguarding risk is identified, working practice changes, new technology or generative AI tools arrive, major software updates occur or the network configuration changes. Checks in between are set by the school’s own risk assessment and recorded in a log.

Can my school see my search history on my laptop?

On a laptop the school manages, usually yes for blocked searches: the DfE standards expect the filtering system to identify the device, the time and date of attempted access and the search term or content blocked, including on school devices taken home. Technical monitoring systems should tell users the device is covered, for example in a message at log-in, and the school’s acceptable use policy and privacy notice should explain what is collected.

08

Official guidance and your next step

The primary sources are Keeping children safe in education 2026, paragraphs 153 to 154, 163 and 173 to 177, and the Department for Education’s filtering and monitoring standards, whose page showed an update dated 16 September 2026 when this guide was written; the standards change between KCSIE editions, so check the date. The UK Safer Internet Centre’s guidance on appropriate filtering and monitoring explains what to ask a provider.

This guide is a practical summary for schools and colleges in England, not legal advice. Schools in Wales, Scotland and Northern Ireland follow their own guidance.

KCSIE paragraph 177 also lists resources from the UK Safer Internet Centre, the South West Grid for Learning and the Department’s buying guidance. Then do one thing: ask IT support for the last three entries in the log of checks and read them against the four headings – when, who, what was tested and what happened next. If any heading is blank, that is the first item for this year’s review.

Why we publish this

ComplyChat is not a filtering or monitoring product and does nothing on pupils’ devices. We build a work messaging channel for the conversations around duties like this one – the exception requested before a lesson, the alert passed to the designated safeguarding lead on a Friday – where everyone added is told the channel is on the record. On paid plans, once the school’s Microsoft 365 tenant is connected, the lasting record files there under the school’s own retention rules.

Explore Free · How it works · Compare plans

Sources

Every document this guide quotes or links to, in the order it first cites them.

  1. Keeping children safe in education 2026 gov.uk
  2. Filtering and monitoring standards gov.uk
  3. Online safety in schools and colleges: questions from the governing board gov.uk
  4. Test Filtering testfiltering.com
  5. UK Safer Internet Centre’s guidance on appropriate filtering and monitoring saferinternet.org.uk