Search

Four steps to upgrade Digital Services Act compliance

 

Executive summary

 

Three years into the Digital Services Act (DSA), many of the affected online platforms and search engines have moved beyond initial implementation to ongoing compliance. Their current challenge is building a sustainable operating model that reduces risk, supports innovation and withstands regulatory scrutiny over time. Organizations need to shift from treating DSA compliance as a standalone initiative, to create a model with four key elements: It must rationalize controls, streamline evidence creation, improve efficiency with technology and treat DSA as an ongoing and evolving business capability.

 
 

Compliance as an operational capability

 
 

When the Digital Services Act (DSA) first took effect, many organizations approached compliance as a new regulatory obligation that required rapid implementation.

 

Regulatory expectations were evolving, guidance was limited and many organizations used external frameworks to establish their initial compliance programs. Some of these frameworks used controls, processes and documentation practices designed for speed rather than integration or sustainability.

 

Three years later

 

The environment is different now, three years later. Recent legal settlements have brought the DSA to the forefront of awareness for executives and risk management teams. Compliance has become an organizational business imperative.

 

In addition, organizations have gained an understanding of foundational DSA requirements, established practical experience operating under the regulation and developed a clearer view of how compliance affects their platform operations. Teams now understand how controls support business objectives and user trust.

 

In this environment, leaders increasingly view DSA compliance as an ongoing business process rather than a special initiative. To develop an ongoing compliance model, organizations can take four important steps:

  • Rationalize controls
  • Streamline evidence creation
  • Improve efficiency
  • Keep evolving a model that treats DSA as an ongoing business capability

These steps are part of a shift that views compliance as an operational capability, and they start with better controls.

 
 

1. Rationalize controls

 
 

New regulatory programs can experience a period of overengineering, where organizations implement extensive documentation, processes and controls to address uncertainty and demonstrate good-faith compliance.

 

Now that DSA compliance leaders have a clearer understanding of regulatory requirements, they can reassess existing controls and determine whether they are still aligned with regulatory objectives. Mature programs eliminate unnecessary complexity while ensuring their current processes:

  • support identifiable regulatory objectives
  • provide meaningful risk reduction
  • produce useful evidence
  • integrate naturally with business operations
  • remain cost-effective over time

This exercise can reveal opportunities to simplify documentation, eliminate duplicative processes and better align controls with operational realities. While the exercise might not reduce the number of controls, it will make controls easier to operate consistently and demonstrate during regulatory reviews.

 

How we can help you

 
 

 

Ready to talk? We’re ready to listen.

 

Request a meeting -->

 
 

2. Streamline evidence creation

 
 

The most effective DSA compliance programs are integrated with existing business processes. When controls are layered on top of existing processes, instead of becoming integrated, these standalone compliance activities create additional work for engineering, safety, legal and operational teams.

 

Product development lifecycles, operational workflows and existing governance structures can generate compliance evidence as a natural byproduct of normal operations. This streamlined approach reduces the burden on operational teams while also creating more reliable evidence, improving consistency and helping organizations respond to new requirements more effectively.

 

Most importantly, streamlined evidence creation builds a stronger connection between risk management and platform operations. Engineering teams often have the deepest understanding of system behavior, platform risk and implementation realities. When organizations bring that perspective directly into compliance program design, they create controls that are both effective and practical.

 
 

3. Improve efficiency

 
 

Many organizations continue to rely heavily on manual processes to perform controls, collect evidence and support testing activities. As compliance programs mature, those approaches become increasingly difficult to sustain.

 

Manual processes consume significant operational time and often require support from engineering, legal, risk and compliance teams. The cumulative burden can become much larger than external audit or assurance costs alone.

 

Technology-enabled compliance programs can automate evidence collection, improve control execution and enhance monitoring capabilities. Advances in analytics and AI-supported testing can evaluate larger populations of data and activities than traditional sampling approaches allow. These capabilities do not eliminate the need for human oversight, so programs must still maintain appropriate governance and review processes. Technology serves as an enabler that helps organizations perform controls more efficiently and consistently while allowing human attention to focus on higher-risk areas.

 

When compliance activities become more automated, engineering and operational staff can spend less time responding to evidence requests and more time focused on platform improvement and innovation.

 
 
 

4. Keep evolving

 
 

The first years of DSA compliance focused on implementation. The next phase is about optimization.

 

To control compliance costs, complexity and operational burden, organizations need to embed compliance into current business operations and plan to keep evolving their programs in the years ahead.

 

Mature DSA programs must continue evaluating and maintaining the capabilities that support trust, transparency, risk management and operational resilience. As the regulatory environment continues to evolve, those capabilities offer agile adaptation that can become an advantage.

 
 

Contacts:

 
 

Orange County, California

Industries

  • Construction & Real Estate
  • Manufacturing
  • Technology
  • Not-for-profit & Higher Education
  • Asset Management

Service Experience

  • Advisory Services
 
 

Content disclaimer

This Grant Thornton Advisors LLC content provides information and comments on current issues and developments. It is not a comprehensive analysis of the subject matter covered. It is not, and should not be construed as, accounting, legal, tax, or professional advice provided by Grant Thornton Advisors LLC. All relevant facts and circumstances, including the pertinent authoritative literature, need to be considered to arrive at conclusions that comply with matters addressed in this content.

Grant Thornton Advisors LLC and its subsidiary entities are not licensed CPA firms.

For additional information on topics covered in this content, contact a Grant Thornton Advisors LLC professional.

 

Ready to talk? We’re ready to listen.

 

Request a meeting and a member of our team will be in touch to see what we can do to meet your needs.

 

Want to submit an RFP? Please submit your request through our RFP submission page.

 
 
 

Trending topics