Child rights impact assessment has moved from a public-policy technique used by a handful of governments to something regulators, funders and procurement teams now name directly. The European Commission's guidelines on protecting minors online point platforms towards child rights impact assessment tools. UNICEF has published a dedicated toolbox for digital products and AI. Scotland and Wales use them in government decision-making. For many organisations the first question is simply what the term means, and whether they need one.
What is a Child Rights Impact Assessment?
A Child Rights Impact Assessment (CRIA) is a structured process for predicting how a proposed law, policy, budget, product or service will affect children's rights under the UN Convention on the Rights of the Child, before the decision is taken. It weighs positive and negative impacts, involves children, recommends changes and plans monitoring.
Where the idea comes from
The CRIA is rooted in Article 3(1) of the Convention: the best interests of the child must be a primary consideration in all actions concerning children. The UN Committee on the Rights of the Child turned that principle into a working method in a series of General Comments.
- General Comment No. 5 (2003), on general measures of implementation, says respecting the Convention across government "demands a continuous process of child impact assessment", predicting the impact of any proposed law, policy or budgetary allocation, followed by evaluation of the actual impact.
- General Comment No. 16 (2013), on the business sector, calls on States to require child-rights due diligence from companies and describes child-rights impact assessments as a way of considering the impact of a business or sector on all affected children, including particular groups of children.
- General Comment No. 25 (2021), on the digital environment, says States should mandate the use of child rights impact assessments for legislation, budgets and administrative decisions relating to the digital environment, and promote their use among public bodies and businesses.
Around that core, practical tools have followed. The Children's Rights and Business Principles, launched on 12 March 2012 by UNICEF, the UN Global Compact and Save the Children, set out ten principles for companies. In 2013 UNICEF and the Danish Institute for Human Rights published Children's Rights in Impact Assessments, a guide for companies built on those principles. In 2025 UNICEF released the D-CRIA Toolbox, developed with BSR, for companies developing, deploying or using digital technologies, including artificial intelligence.
How governments and regulators use it
The Council of Europe's 2018 Recommendation on the rights of the child in the digital environment says digital laws and policies should be assessed at drafting stage for their impact on children, and that States should require businesses to carry out regular child-rights risk assessments of their digital products and services.
In Wales, children's rights impact assessments are how Welsh Ministers show they have met the duty in the Rights of Children and Young Persons (Wales) Measure 2011 to have due regard to the Convention. Scotland, which incorporated the Convention into Scots law through the UNCRC (Incorporation) (Scotland) Act 2024, uses a Child Rights and Wellbeing Impact Assessment (CRWIA) for bills, certain regulations and strategic decisions affecting children.
The most commercially significant development is in EU platform regulation. The Commission's guidelines under Article 28 of the Digital Services Act, published on 14 July 2025, ask platforms accessible to minors to carry out a risk review at least annually or whenever they make significant changes. The review should consider the positive and negative effects of measures on children's rights, treat the best interests of the child as a primary consideration and include the perspectives of children. The guidelines note that existing child rights impact assessment tools, including those from UNICEF and the Dutch Ministry of the Interior and Kingdom Relations, can support providers.
Who needs one
- Governments and public bodies drafting laws, strategies, budgets or digital programmes that affect children, particularly where a domestic duty or a Committee recommendation applies.
- Online platforms and app providers whose services children use, whether or not children are the intended audience. A CRIA gives the rights-based analysis that EU risk reviews expect and that supports the risk assessments other regimes require.
- AI developers and deployers. The EU AI Act requires providers of high-risk systems to consider whether a system is likely to have an adverse impact on people under 18. A CRIA is the natural way to do that work for a child-facing AI system, including chatbots and educational tools.
- NGOs and UN agencies introducing digital tools, data collection or new programme models that reach children, and wanting evidence for donors that rights were considered before launch.
- Corporates whose products, marketing, supply chains or workplace policies affect children, as part of human rights due diligence.
The typical steps
Methods vary, but a sound CRIA usually follows the same sequence.
- Screening. Decide whether the proposal affects children enough to need a full assessment, and record the reasoning either way.
- Scoping. Define what is being assessed, which children are affected (by age, disability, gender, location and other circumstances) and which Convention rights are engaged.
- Evidence gathering. Collect data, research, complaints, product analytics, incident records and expert input.
- Consulting children. Hear directly from children and young people, and from parents, carers and the professionals who work with them.
- Assessing impact. Weigh likely positive and negative effects on each relevant right, including where rights pull in different directions, such as protection against privacy or access to information.
- Recommendations. Propose changes, safeguards or alternatives, and state which recommendations were accepted by the decision-maker.
- Monitoring and review. Set indicators and a date to check what actually happened.
- Publication. Share the findings, ideally with a child-friendly summary.
What a CRIA is not
- It is not a Data Protection Impact Assessment. A DPIA looks at risks arising from processing personal data. Standard 2 of the UK Information Commissioner's Age Appropriate Design Code requires a DPIA that addresses risks to the rights and freedoms of children, and the ICO has published a best interests self-assessment grounded in the Convention. A CRIA is wider: it covers rights that have nothing to do with data, such as play, education, freedom from violence and the right to be heard. A good CRIA can feed a DPIA; it does not replace one.
- It is not a children's risk assessment under the Online Safety Act. Ofcom requires in-scope services likely to be accessed by children to assess the risk of specified harmful content and to apply its codes. That is a statutory compliance exercise focused on harm. A CRIA also considers the benefits of a service and the rights that safety measures may restrict, which is useful when deciding how far to go with measures such as age assurance. The two are complementary, as the comparison of the UK and EU regimes shows.
- It is not a safeguarding audit. A safeguarding audit tests whether an organisation's own arrangements, such as vetting, reporting and governance, protect children from harm by people connected to it. A CRIA looks outward at a specific decision, product or policy and its effect on children's rights in general.
What you get at the end
The outputs of a well-run CRIA are practical rather than academic:
- a written assessment mapping impacts against the relevant Convention rights, with the evidence behind each finding;
- a summary of what children and other stakeholders said and how it was taken into account;
- a prioritised set of recommendations or a roadmap, with owners;
- a monitoring plan with indicators and a review date;
- where appropriate, a public or child-friendly summary.
For platforms and AI developers, this record doubles as evidence for regulators and business partners. For public bodies and NGOs, it often informs a wider safeguarding and child rights policy framework.
How long it takes
Duration depends on scope rather than method. A focused assessment of a single product feature, programme or policy can typically be completed in a matter of weeks. A national strategy, a platform operating across several jurisdictions or an AI system with many use cases can take several months, largely because evidence gathering and meaningful consultation with children take time. The most common mistake is starting too late: a CRIA done after launch becomes a review of decisions that can no longer easily change.
How to involve children
Article 12 of the Convention gives children the right to express their views freely in matters affecting them, and to have those views given due weight according to their age and maturity. A CRIA that does not hear from children is incomplete, and both UNICEF's toolbox and the Commission's guidelines expect their perspectives to be included.
- Go to where children already are: schools, youth groups, existing user panels and advisory boards, rather than building an event from scratch.
- Include the children most likely to be affected, including younger children, disabled children and children who are rarely consulted.
- Make it safe. Obtain informed consent and assent, have safeguarding arrangements in place for disclosures, and protect children's data.
- Close the loop. Tell children what changed because of what they said, and what did not change and why.
Where direct consultation is not proportionate, record why and draw on existing research with children.
What this means for organisations deciding whether to commission one
If your product, policy or programme affects children and you cannot yet explain, in writing, which of their rights it touches and what you did about it, a CRIA is the most direct way to get there. Regulators in the UK and EU are asking for risk assessments that consider children; a CRIA gives those assessments a rights-based foundation that holds up across jurisdictions. Organisations with an online safety compliance programme already under way can use a CRIA to connect the separate assessments they have into one coherent account.
Frequently asked questions
Is a Child Rights Impact Assessment a legal requirement? It depends on who you are and where. Some governments must carry out CRIAs or equivalent assessments under domestic law, as in Wales and Scotland. For most companies it is not mandated by name, but EU guidance under the Digital Services Act points to CRIA tools for the required risk review.
Is it the same as a Children's Rights Impact Assessment? Yes. Child rights impact assessment and children's rights impact assessment are used interchangeably. Scotland's version adds wellbeing and is called a CRWIA; UNICEF's digital version is the D-CRIA.
Can a CRIA replace our DPIA or our Ofcom children's risk assessment? No. Each has its own legal basis and required content. A CRIA can inform both and reduce duplication, but the statutory assessments must still be completed in the form the regulator expects.
When should a CRIA be done? As early as possible, while the design, policy or budget can still change, and again when significant changes are made. The Commission's guidelines ask platforms to review at least annually.
Who should carry it out? Someone with child rights expertise and enough independence to challenge the product or policy team, working with the people who understand the system being assessed.
Regulatory details cited here are accurate as of September 2026 and should be checked against the UN Committee on the Rights of the Child, UNICEF, the European Commission, Ofcom and the ICO before being relied on in a compliance decision.