Here is the honest situation. Here is the honest situation. The Digital Services Act does not ask a designated platform or search engine to simply remove illegal posts, it asks you to identify the systemic risks your service creates or amplifies, assess them diligently at least once a year and before any critical functionality change, mitigate them proportionately, and prove all of it to an independent auditor under Article 37. Doing that well means an assessment across all four Article 34 categories, illegal content dissemination, fundamental rights, civic discourse and elections, and minors, gender-based violence and well-being, each tied to the design factors Article 34(2) names. It means mitigations selected from the full Article 35 range, not just more moderators, with the proportionality and fundamental-rights reasoning written down at the time of the decision. It means measuring whether a measure actually reduced the risk, not merely that it shipped. Where teams fall short is predictable: diligent moderation offered as the answer to a risk-management obligation, a conclusory report with no traceable line from evidence to conclusion, and an evidence package assembled the week the auditor arrives.
This Kit removes the guesswork. It is DSA systemic risk assessment and mitigation written as adopt-ready controls you personalize in a weekend, with the evidence an independent auditor examines.
What you get, the moment you buy
Grounded in the DSA text and current supervisory practice. Editable Word and Excel files.
What one control looks like
This is the opening control, where the programme begins. All 18 are built to this depth.
Why this is not another template pack
- The evidence is the point. A control you cannot evidence is a gap waiting to be found. This tells you what an independent auditor examines and where teams fall short, for every control.
- The DSA specifics built in. The four Article 34 categories, the Article 34(2) influencing factors, the full Article 35 mitigation range, proportionality and fundamental-rights reasoning, and the Article 37 evidence package are written into the controls, not left generic.
- Built on real practice, not one person's opinion, grounded in how systemic risk programmes actually hold up and where they actually fail.
- It compounds. This work shares its shape with data protection, AI governance and enterprise risk frameworks, so it feeds your wider programme.
Who buys this
Compliance, legal, trust and safety and risk leads who carry the systemic risk obligation on an EU-facing platform or search service, and the product and engineering owners of the recommender, advertising and moderation systems around them. Whether this is your first assessment cycle or a maturity uplift, you save weeks and walk in with your scope, assessment, mitigation, effectiveness and audit controls structured.
Common questions
Is it really editable? Yes. Word and Excel files you own and adapt. No portal, no subscription.
Does it cover all four Article 34 risk categories? Yes. Illegal content dissemination, fundamental rights, civic discourse and electoral processes, and minors, gender-based violence and well-being each have their own control with its own evidence.
Does it cover the Article 37 audit? Yes. The standing evidence package, the traceable decision trail, and closing out operational recommendations from a non-positive opinion are all built as controls.
What if it is not for me? A 30-day money-back guarantee.
Instant digital download · 30-day money-back guarantee · The Art of Service Pty Ltd, GPO Box 2673, Brisbane QLD 4001 · support@theartofservice.com