Join our Newsletter — 33% off our NHI Course

What are the signs that a reporting process for harmful images is creating avoidable barriers for children and young people?

Warning signs include high drop-off before submission, repeated requests for identity documents, user concern about who will see the data, and reluctance to report without using a real name. If the process feels intrusive, people may stop short of completing it. A child-centred workflow should feel simple, discreet, and supportive from start to finish.

What the warning signs look like in practice

The clearest signs are behavioural, not technical. If children and young people are dropping off before the final step, repeatedly abandoning the form, or hesitating when they see identity checks, the process is asking for more friction than the report justifies. A good child-centred flow should reduce uncertainty, not add it.

When a reporting route asks for repeated identity documents, shows unclear steps, or creates confusion about who will see the information, it starts to feel like a gatekeeping process rather than a safeguarding one. The more a user has to pause and interpret the process, the more likely they are to stop or withhold details.

Reluctance to give a real name, concern about being traced, or a need to ask a trusted adult to finish the report are strong signals that the design is undermining trust. For a young audience, the reporting experience has to feel discreet, proportionate, and safe enough to continue without feeling exposed.

Why these barriers matter for safeguarding

Reporting harmful images is only effective if the person can complete the pathway with confidence. If the process feels intrusive, young people may decide the personal cost is higher than the value of reporting, which leaves harmful content in circulation for longer and reduces the chance of timely intervention. NIST Cybersecurity Framework 2.0 is useful here because the issue is not just collection, but whether the workflow is trustworthy enough to support the intended outcome.

Barrier-heavy reporting also creates a visibility problem for safeguarding teams. A process that looks available on paper but is abandoned in practice can give a false sense of coverage, especially if teams only measure submissions that were completed. The operational risk is that the organisation believes it has a reporting channel, while the users who most need it are not using it.

From a control perspective, the weakness is usually not a single broken field. It is the accumulation of small trust failures, too many questions, unclear purpose, over-collection, and fear about data handling, that together make the process feel unsafe. That combination can suppress reporting even when the underlying harm is serious.

How to tell whether the process is too hard for the audience

Look for evidence at each step of the journey, not just at the point of submission. A steep fall in completion rate, repeated help requests, or comments that the form is “too much” are practical signals that the workflow is not age-appropriate. If users consistently need reassurance before they continue, the design is probably working against disclosure.

It also helps to test whether the process can be completed with the minimum information needed to act. A reporting route that demands more identity data than the case requires will often create hesitation without improving the safeguarding outcome. For image-reporting workflows, simplicity is usually a security and trust control, not just a usability preference.

For teams designing or reviewing the flow, NIST Privacy Framework is relevant because the same questions apply: what data is truly necessary, what expectations does the user have, and how do you reduce perceived intrusion while still enabling action.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

NIST CSF 2.0 and NIST SP 800-53 Rev 5 set the technical controls, while ISO/IEC 27001:2022 defines the regulatory obligations.

Framework Control / Reference Relevance
NIST CSF 2.0 PR.AA-05 — Identity Management, Authentication and Access Control Trustworthy reporting flows depend on proportionate identity handling and access control.
Recommendation — Minimise identity friction and collect only the access data needed to complete the report.
NIST SP 800-53 Rev 5 AU-3 — Content of Audit Records Abandonment and drop-off are operational signals that the process is not working as intended.
PT-2 — Authority to Process Personally Identifiable Information The process asks for sensitive user data, so collection authority and necessity matter.
AC-6 — Least Privilege Who sees the report data is a central trust concern in the reporting workflow.
Recommendation — Log step-by-step funnel abandonment to identify where users stop reporting. Limit collection to data that is necessary for safeguarding and disclose why it is needed. Restrict report visibility to the smallest set of staff who need it to act.
ISO/IEC 27001:2022 A.5.15 — Access control The question turns on whether users trust who can access their report data.
Recommendation — Define and enforce who can access report submissions and supporting details.

Practitioner Guidance

What to prioritise: Treat completion rate, abandonment points, and requests for extra reassurance as the main signals, not just the number of reports received. If young users are backing out early, the process is probably too demanding for the harm it is meant to capture.

What to verify: Check whether every mandatory field has a clear operational purpose and whether the workflow can be completed without unnecessary identity disclosure. If a field does not change the safeguarding decision, it is a candidate for removal or deferral.

Common mistake: Teams often mistake “more information” for “better reporting.” In child-facing processes, more friction can mean less disclosure, less trust, and slower intervention.

Practitioner takeaway: The best reporting processes for young people feel low-pressure enough to finish, while still collecting only the information needed to act safely and quickly.