Part 4 of 13 in Meeting the DfE digital and technology standards.

Five of the six core standards give schools until 2030. This one does not. Filtering and monitoring is a safeguarding duty first and a technology standard second, and the DfE's wording reflects that.

In short: The DfE's filtering and monitoring standard is the one core standard schools and colleges "should be meeting now". It rests on Keeping children safe in education and has four requirements: assign clear roles, including an SLT member, a responsible governor, the DSL and IT support; review provision at least once every academic year; run a filtering system with separate staff and student profiles and IWF and CTIRU blocklists that no administrator can override; and monitor effectively, with weekly reports and immediate reports for high-risk incidents. IT support builds and evidences the systems. The designated safeguarding lead owns the response.

Why this standard is different from the other five

Every other core standard says you "should be working towards meeting it by 2030". The filtering and monitoring page says: "You should be meeting this standard now and working towards meeting all 6 core standards by 2030."

The reason is the legal footing. The DfE states that "Schools and colleges have a statutory responsibility to keep children and young people safe online as well as offline", and that governing bodies and proprietors should make sure appropriate systems are in place "as detailed in the statutory guidance, keeping children safe in education".

The same duty appears inside the broadband standard, which asks for "a content filtering system in place which meets the requirements outlined in the online safety section of keeping children safe in education, paragraphs 123-135", with a firewall as part of the internet and network system.

What does the standard actually ask for?

Four requirements, in the DfE's order:

  • "Identify and assign roles and responsibilities to manage your filtering and monitoring systems". An SLT member, a responsible governor, the DSL and IT support, with responsibilities written down.
  • "Review your filtering and monitoring provision at least annually". Once every academic year at minimum, recorded, and sooner when practice or technology changes.
  • "Filtering systems should block harmful and inappropriate content without unreasonably impacting teaching and learning". Separate staff and student profiles, the IWF and CTIRU blocklists, and coverage of every device and every internet feed.
  • "Have effective monitoring strategies that meet the safeguarding needs of your school or college". Weekly reports, immediate high-risk reports, and trained people reading them.

The full text is on the GOV.UK filtering and monitoring core standard page. Our DfE standards guide sets it in context.

Who holds which responsibility?

"Governing bodies and proprietors have overall strategic responsibility for filtering and monitoring and need assurance that the standards are being met." Then:

  • A member of SLT scopes needs, including generative AI use, buys the systems, is responsible for "Documenting decisions on what is blocked or allowed and why", reviews effectiveness, oversees reports and arranges staff training.
  • A responsible governor is assigned and takes part in the annual review.
  • The designated safeguarding lead leads on safeguarding and online safety, checks reports, responds to concerns and assures governors. The DfE says the DSL "is responsible for any safeguarding and child protection matters that are identified through monitoring".
  • IT support, in-house or third-party, maintains the systems, provides the reports and completes actions.
  • All staff "should conduct a level of in-person monitoring if they are in a room with students on devices".

The DfE accepts that "There may not be full-time staff for each of these roles", but "it must be clear who is responsible and it must be possible to make prompt changes to your provision". Its summary: "Day-to-day management of filtering and monitoring systems requires the specialist knowledge of both safeguarding and IT support to be effective."

Four tiles reading: Now, not 2030; 2 profiles, staff and student; Weekly, monitoring reports; Yearly, full review
The four facts about the filtering and monitoring standard that a governor is most likely to ask about.

What the filtering system has to do

The DfE opens with a warning: "No filtering system can be 100% effective." You need to understand its coverage and limitations, and mitigate them to meet your statutory duties under Keeping children safe in education and the Prevent duty guidance. Then:

  • Two profiles at minimum. "Your filtering system should not have a blanket filtering profile for all users. As a minimum, student and staff profiles should be in place to provide differing levels of access to online content."
  • Blocklists that nobody can switch off. The Internet Watch Foundation (IWF) and Counter-Terrorism Internet Referral Unit (CTIRU) publish lists of illegal websites. "Schools and colleges must make sure these blocklists are implemented with their filtering solutions", and solutions "must be designed so that these blocklists cannot be disabled, overridden, or altered by any user in a school, college, multi-academy trust (MAT), local authority or any other responsible body, including system administrators, at any level."
  • A provider that qualifies. The DfE asks that your filtering provider is "A member of IWF", "Signed up to CTIRU" and regularly updating its blocklists.
  • Every device, every feed. Managed devices including off-site, BYOD and guests. "Devices that are not school or college-managed should be on a separate virtual network." Filtering should cover all internet feeds, "including backup connections and portable wifi".
  • No way round it. "Block technologies and techniques that allow users to get around the filtering, such as VPNs, proxy services and end-to-end encryption methods." Safe search locked on, extra browsers and plugins blocked.
  • Logs that identify. Device or IP address and the individual, the time and date, and the search term or content, with alerts when content is blocked.
  • A DPIA. Schools "will need to conduct their own data protection impact assessments (DPIAs)" and review providers' privacy notices. The ICO provides a template.

Temporary exceptions are allowed, approved and documented by the responsible SLT member, with the DSL assessing the safeguarding implications.

What effective monitoring looks like

Filtering decides what cannot be reached. Monitoring tells you what people tried to reach. The DfE describes a plan that may combine device monitoring software, in-person monitoring and network monitoring of logs, and sets a floor for reporting:

  • "As a minimum, your monitoring plan should include weekly monitoring reports highlighting incidents. It should also include immediate reports when an incident is classed as high-risk", for example incidents of a malicious, technical or safeguarding nature.
  • Everyone using the network should know monitoring is in place, and technical systems "should also notify users that the device is being monitored".
  • Users should be identifiable, including guest accounts where possible, with a documented process for recording incidents.
  • Monitoring staff should be trained in safeguarding and in reporting to the DSL, and the provision should alert on behaviours linked to the "4 areas of risk" in the online safety section of Keeping children safe in education.
  • Monitoring should be reflected in the acceptable use policy, safeguarding policies and privacy notices, with a DPIA for technical monitoring systems.

"IT can build the filter and deliver the report. Only the safeguarding lead can decide what the report means."

The DfE draws the boundary plainly: "Technical monitoring systems do not stop unsafe activities on a device or online." Supervision does.

The annual review, and how to evidence it

The review should happen "as a minimum, once every academic year" or sooner when a safeguarding risk is identified, working practice changes such as remote access or BYOD, new technology arrives such as new devices or generative AI tools, major software updates occur, or the network and device configuration changes.

The DfE says the review "should be conducted by members of the senior leadership team, the designated safeguarding lead and IT support" and "should also involve the responsible governor". The evidence expected is specific:

  • "You should record the results of the review and document any actions taken. This record should be available to anyone who is entitled to inspect that information."
  • Checks on all school-owned devices, including those taken home and AV equipment, across all sites and user groups, with a log of when, who, what was tested and the actions taken.
  • A test using a tool such as the one from South West Grid for Learning (SWGfL), to confirm that "as a minimum, your filtering system is blocking access to illegal child abuse material, unlawful terrorist content and adult content".

Where schools usually fall short

The pattern we see in most organisations is that filtering gets bought and monitoring gets ignored: alerts go to a mailbox nobody owns. The gaps:

  • One blanket profile for everyone.
  • Guest Wi-Fi, the backup 4G connection or a visitor's portable hotspot bypassing the filter entirely.
  • Unmanaged and personal devices on the same network as school devices rather than a separate virtual network.
  • VPN and proxy apps that work, because nobody tested them.
  • Weekly reports generated but not read, and no record of who reads them.
  • An annual review that happened in conversation and was never recorded.
  • No DPIA, and no named IT responsibility in the support contract.

None of these need new software. They need configuration, a separate network for unmanaged devices, a firewall that blocks circumvention, and a reporting route that ends at the DSL. The DfE names cyber security and broadband as dependencies for good reason.

Where Systech fits

We do not provide filtering or monitoring software ourselves, and we do not make safeguarding decisions. We do the technical half the DfE assigns to IT support: configure your chosen filtering platform with proper staff and student profiles, put unmanaged devices on a separate virtual network through our networking work, block VPNs and proxies at the managed firewall, and make sure backup connections are filtered too.

We also route the weekly and high-risk reports to the DSL, and keep the test log and review record that inspectors can ask for. We work with schools, colleges and trusts as well as businesses, and schedule disruptive work into the holidays.

If you want to know whether your provision would stand up to the annual review, our free 60-minute DfE standards baseline includes this standard, and the written findings are yours whether or not you work with us.

Frequently asked

Do schools have to meet the DfE filtering and monitoring standard now?

Yes. The DfE's filtering and monitoring standard is the only one of the six core standards where the wording is not about 2030. The page says you should be meeting this standard now and working towards meeting all six core standards by 2030. The DfE also states that schools and colleges have a statutory responsibility to keep children and young people safe online as well as offline, and that governing bodies and proprietors should make sure their school or college has appropriate filtering and monitoring systems in place, as detailed in the statutory guidance, Keeping children safe in education. Each of the four requirements within the standard says you should already be meeting it.

Who is responsible for filtering and monitoring in a school?

The DfE standard sets out layered responsibilities. Governing bodies and proprietors have overall strategic responsibility and need assurance that the standards are being met. They identify and assign a member of the senior leadership team and a governor responsible for ensuring the standards are met. The SLT member scopes needs, buys systems, documents what is blocked or allowed and why, reviews effectiveness and oversees reports. The designated safeguarding lead leads on safeguarding and online safety, checks reports, responds to concerns and gives assurance to governors. IT support, in-house or third-party, maintains the systems, provides the reports and completes actions. The DfE says it must be clear who is responsible, even where these sit within wider roles.

How often should a school review its filtering and monitoring?

At least once every academic year, according to the DfE standard, and sooner when specific triggers occur: a safeguarding risk is identified, there is a change in working practice such as remote access or BYOD, new technology is introduced such as new devices or generative AI tools, major software updates occur, or there are changes to the technical configuration of the network and devices. The review should be conducted by members of the senior leadership team, the designated safeguarding lead and IT support, and involve the responsible governor. The DfE says you should record the results and any actions taken, and that this record should be available to anyone entitled to inspect it. The SWGfL testing tool can be used to check the minimum blocking.

SC
Systech Cloud Team

The Systech IT Solutions cloud team, helping UK businesses get more from their Microsoft investment.