The race is on to meet the EU’s Digital Services Act (DSA) regulation, as a number of platforms near the threshold for being classified as Very Large Online Platforms (VLOPs). Upon designation by the European Commission (EC), organisations have only four months to navigate an expanded set of regulatory obligations.
The challenge lies not just in achieving compliance but maintaining it amidst real-time regulatory scrutiny and a continuously evolving regulatory landscape.
KPMG Digital Regulation specialists Patrick Farrell and Hermes Peraza outline the risks of delay, what “minimum viable” compliance looks like, the top six areas for emerging VLOPs to get right.
For platforms approaching VLOP thresholds, the biggest risk is waiting too long to act. Once designated as a VLOP, firms have only four months to comply with a significantly expanded set of obligations, including the need to:
The priority for platforms approaching this threshold is simple: build a minimum viable regulatory framework early, then refine and scale.
“For emerging VLOPs, readiness cannot start at designation. Organisations that manage scrutiny best are those that build evidence, accountability and control effectiveness into their operating model before the four-month clock begins. Those that wait until designation is confirmed risk trying to evidence compliance while the regulatory examination is already underway” said Hermes Peraza, Director in Risk and Regulatory Consulting at KPMG.
The EC demands demonstrable, evidence-based proof that controls to keep online users safe are effective. “Minimum viable” readiness in practice means:
Regulators are specifically looking for practical governance and oversight arrangements that support effective supervision, including the EC’s ability to interrogate decisions, request information, and trace accountability to senior management and the Board. They want to see evidence that the platform has a firm grasp on key risks and can consistently explain and demonstrate control effectiveness and mitigations.
Compliance claims must be supported by verifiable evidence, including auditability, transparency reporting, and the ability to substantiate how DSA obligations are met in practice, with evidence, rather than merely being documented in policies and procedures. Overall, regulators want to see that online users are being kept safe, and that platforms have the ability to identify, prevent and minimise the risks online users are exposed to.
In two years, online platforms have reversed around 50 million decisions affecting users’ content or accounts, helping users exercise their Digital Services Act (DSA) rights online in the EU.
Newly designated VLOPs face intense regulatory scrutiny, with direct supervision by the EC since late 2023.
The enforcement risk is real: where a DSA breach is confirmed, the Commission can impose fines of up to 6% of global turnover, alongside enhanced supervision and corrective measures with a set deadline. We are already seeing some of those measures take place, commented Patrick Farrell, Partner and Head of Advisory Markets at KPMG.
As of July 2026, the EC issued around 75 Requests for Information (RFIs) across 23 VLOPSEs and initiated formal proceedings against 12 platforms, reflecting a supervisory focus on practical compliance. This involves testing the credibility of compliance claims, governance, oversight, and mitigation measures. VLOPs are assessed beyond policy frameworks, requiring meaningful internal and external data and systems access to withstand sustained supervision.
1. Systemic Risk and Control Assessments (SRAs) – Establish procedures to identify, analyse, and assess systemic risks stemming from the design or functioning of the service and its related systems, including algorithmic systems, as well as from the use made of those services.
2. Establish an independent Compliance Function with a direct reporting line to the Board – An independent compliance function, framework and operating model is required to perform compliance oversight activities and processes. Consideration should be given to establishing a central compliance team, rather than operating in silos, particularly for global firms.
3. Crisis response, communication and learning – A crisis is deemed to have occurred where extraordinary circumstances lead to a serious threat to public security or public health in the EU. Online platforms should identify, assess, and implement measures to prevent or eliminate serious threats; develop crisis protocols for addressing crisis situations; and report to the Commission at regular intervals on the implementation and qualitative and quantitative impact of measures taken to mitigate those threats.
4. Transparency Reporting, Data and MI – Transparency reporting frequency will increase to twice a year. Accuracy of data will be critical, alongside consistency of messaging across disclosures. Information disclosed through systemic risk assessments, independent audits, transparency reports, and responses to regulatory information requests should be internally consistent and evidence-based.
5. Assurance and Remediation: Arrange an independent audit at least annually and implement any required remediation measures. Readiness requires clear ownership for engagement with the independent auditor and defined accountability across the Compliance Function, legal, product, integrity, and engineering teams. Organisations must be prepared for the volume and intensity of audit activity, including control walkthroughs, evidence production, and detailed review cycles.
6. Direct European Commission supervision – Under the DSA, the Commission has powers to request information, conduct inspections, open formal investigations, and assess compliance with the DSA. Where necessary, it may also adopt enforcement measures to address non-compliance.
KPMG offers deep technical expertise across all areas related to the DSA. The team specialises in readiness and assurance, risk assessment, control design and documentation, implementation of key processes, and regulatory engagement and reporting. With KPMG’s support, navigating the complexities of DSA compliance becomes a streamlined and effective process.
Markel Insurance, the insurance operation within Markel Group Inc., has announced its partnership with Verodat,…
Nearly half (45%) of Irish festival goers are likely to buy a new smartphone ahead…
BPFI welcomes the launch of Ireland’s first National Anti-Money Laundering, Countering Financing of Terrorism and…
The Digital and Techworker Alliance branch of the Communications Workers’ Union (DATA-CWU) has announced plans to…
The Artificial Intelligence Collaboration Centre (AICC) at Ulster University, in partnership with AI for Collective…
Guest Post by Crystel Robbins Rynne, CEO, HRLocker Across most organisations, AI adoption hasn’t followed…
Irish Tech News are Ireland’s No. 1 Online Tech Publication and often Ireland’s No.1 Tech Podcast too.
You can find hundreds of fantastic previous episodes and subscribe using whatever platform you like via our Anchor.fm page here: https://anchor.fm/irish-tech-news
If you’d like to be featured in an upcoming Podcast email us at Simon@IrishTechNews.ie now to discuss.
Irish Tech News have a range of services available to help promote your business. Why not drop us a line at Info@IrishTechNews.ie now to find out more about how we can help you reach our audience.
You can also find and follow us on Twitter, LinkedIn, Facebook, Instagram, TikTok and Snapchat.