Section 8 of KOSA mandates annual independent audits of covered platforms by qualified third-party auditors. (1) Section 8(a) Annual Independent Audit: (a) Covered platform must commission annual third-party audit; (b) Audit fiscal year + calendar year alignment options; (c) First audit within 18 months of effective date; (d) Subsequent audits annually; (e) Material change re-audit (significant feature launch + acquisition + policy change). (2) Section 8(b) FTC-Approved Auditor Requirements: (a) FTC publishes list of approved audit firms + criteria; (b) Independent from covered platform - no conflicts of interest; (c) Demonstrated expertise in minor online safety + algorithm audit + privacy + content moderation; (d) Reasonable engagement standards; (e) Diversity of qualified firms; (f) Regular review + recertification of auditors. (3) Section 8(c) Audit Scope: (a) Section 3 Duty of Care compliance; (b) Section 4 Default Safeguards effectiveness; (c) Section 5 Parental Tools availability + usability; (d) Section 6 Transparency Reporting accuracy + completeness; (e) Section 7 Researcher Access process effectiveness; (f) Section 9 Council Engagement; (g) Risk Assessment methodology + execution; (h) Algorithmic system review; (i) Reporting mechanism effectiveness; (j) Content moderation review. (4) Section 8(d) Audit Methodology: (a) Document review; (b) Stakeholder interviews - employees + parents + minors + experts; (c) Technical assessment - platform inspection + algorithm review where feasible; (d) Statistical sampling of content moderation decisions + reports; (e) Mystery shopping + simulated minor accounts; (f) Comparison to industry baselines + best practices; (g) Section 9 Council guidance integration. (5) Section 8(e) Audit Report Components: (a) Executive Summary; (b) Findings per Section; (c) Compliance status (Compliant + Partially Compliant + Non-Compliant + Not Applicable); (d) Risk severity assessment; (e) Recommendations for improvement; (f) Remediation timelines; (g) Auditor methodology + scope + limitations; (h) Confidentiality protections balanced with transparency. (6) Section 8(f) Audit Independence Safeguards: (a) Auditor cannot have business relationship with platform beyond audit engagement; (b) Auditor rotation - same lead auditor maximum 5 consecutive years; (c) Audit firm rotation considerations; (d) No consultation services to audited platform during audit period; (e) Whistleblower protection for audit team. (7) Section 8(g) Public Summary Report: (a) Redacted version of audit report publicly available; (b) Trade secret + confidential business information protected per FOIA exemption 4; (c) Aggregate findings + key recommendations published; (d) Compliance status disclosed; (e) Available on platform website + FTC + State AG. (8) Section 8(h) Audit Findings Response: (a) Platform response to findings within reasonable time; (b) Remediation plan with timelines; (c) Outstanding issues escalation; (d) Follow-up audit verification; (e) Material findings notification to FTC + State AGs. (9) Section 8(i) FTC + State AG Use of Audit: (a) FTC + State AGs may request full audit report; (b) Audit findings inform enforcement priorities; (c) Compliance program assessment input; (d) Industry trend analysis; (e) Confidentiality maintained except for material non-compliance. (10) Section 8(j) Council Coordination: (a) Section 9 Kids Online Safety Council audit framework development; (b) Best Practices for audit methodology; (c) Industry standards harmonization; (d) Auditor certification considerations. (11) Industry Implementation Considerations: (a) Audit firms - Big 4 (Deloitte + EY + KPMG + PwC) + specialised firms (BSI + DNV + Lloyd's Register) + emerging auditors; (b) Audit cost considerations - typically USD 500K-5M for major platforms; (c) Audit duration - typically 6-9 months; (d) Coordination with privacy + cybersecurity audits (SOC 2 + ISO 27001 + ISO 27701); (e) Multi-jurisdiction audit coordination (DSA Article 37 audit). (12) Enforcement of Section 8: (a) FTC + State AG enforcement; (b) Civil penalty up to USD 43,792 per violation; (c) Failure to conduct audit; (d) Failure to remediate audit findings; (e) Auditor non-compliance + sanctions. Coordinates with EU DSA Article 37 Independent Audits + UK Online Safety Act audits + AICPA Trust Services Criteria + SOC 2 + ISO/IEC 27001 + 27701 + ISO/IEC 19011 Audit Standards + Section 9 Kids Online Safety Council + Big 4 + specialised audit firms + FTC + State AG audit coordination + DSA VLOP audit framework. KOSA Independent Audit + Section 8 applies.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.