Skip to content
Friday, October 2, 2026
3G TIMESFINTECH LAW · LEGAL TECH · COMPLIANCE
Digital

Four Steps to Upgrade Digital Services Act Compliance: What the Framework Actually Asks

Grant Thornton's four-part model treats DSA compliance as an operating capability, not a one-time build.

Naomi Bergman · October 2, 2026 · 6 min read
ShareXFacebookLinkedInTelegramEmail
Four Steps to Upgrade Digital Services Act Compliance: What the Framework Actually Asks
Four Steps to Upgrade Digital Services Act Compliance: What the Framework Actually Asks

Three years into the Digital Services Act, the compliance question for online platforms and search engines has changed. The initial build phase is largely done. The new problem, according to Grant Thornton, is constructing a sustainable operating model that reduces risk, supports innovation and withstands regulatory scrutiny over time.

The advisory firm's answer is a four-step upgrade: rationalize controls, streamline evidence creation, improve efficiency with technology, and keep evolving the program as an ongoing business capability. The framing matters for officers because it treats DSA work the way firms treat financial controls — a permanent function with an owner, a budget and a lifecycle, not a project with an end date. This article unpacks each step and the background a newcomer needs to follow the debate. It is general information, not legal advice; organizations with specific DSA obligations should work with qualified counsel.

First, some context. When the DSA first took effect, many organizations treated it as a new regulatory obligation requiring rapid implementation. Guidance was limited and regulatory expectations were still moving, so firms leaned on external frameworks to stand up initial programs. Grant Thornton's assessment is that some of those frameworks used controls, processes and documentation practices designed for speed rather than integration or sustainability. That speed-first design is precisely what the four steps are meant to correct. Readers tracking how evidence and audit trails are built for other regimes may find the Consent Receipts and Audit Logs coverage a useful parallel on exam-ready evidence. This connects to our earlier piece, Consent Receipts and Audit Logs: Designing Exam-Ready Evidence for Open-Banking Authorization.

Why is DSA compliance changing now?

Because the environment around the regulation has shifted. Grant Thornton notes that recent legal settlements have brought the DSA to the forefront of awareness for executives and risk management teams, moving compliance from a specialist concern to an organizational business imperative. The firm also observes that organizations now have practical experience operating under the regulation and a clearer view of how compliance affects platform operations. Teams understand how controls support business objectives and user trust. In that setting, leaders increasingly view DSA compliance as an ongoing business process rather than a special initiative — which is the premise the four steps build on.

Step one: rationalize controls

New regulatory programs often overengineer. Organizations implement extensive documentation, processes and controls to handle uncertainty and demonstrate good-faith compliance. Now that DSA compliance leaders understand the requirements better, Grant Thornton argues they can reassess existing controls and check whether they still align with regulatory objectives.

The firm's test for a mature control set is concrete. Current processes should:

The exercise can reveal opportunities to simplify documentation and eliminate duplicative processes. Notably, Grant Thornton cautions that rationalization might not reduce the number of controls at all. The goal is controls that are easier to operate consistently and easier to demonstrate during regulatory reviews — an outcome a compliance officer can defend to a board without promising headcount savings.

Step two: streamline evidence creation

The second step targets how compliance work actually lands on teams. When controls are layered on top of existing processes instead of integrated into them, the standalone compliance activities create additional work for engineering, safety, legal and operational teams. Grant Thornton's alternative is to let product development lifecycles, operational workflows and existing governance structures generate compliance evidence as a natural byproduct of normal operations.

The claimed benefits are threefold: less burden on operational teams, more reliable and consistent evidence, and faster response to new requirements. The firm adds a structural point that goes beyond efficiency. Engineering teams often have the deepest understanding of system behavior, platform risk and implementation realities. Bringing that perspective directly into compliance program design, the argument runs, produces controls that are both effective and practical — a stronger connection between risk management and platform operations.

Step three: improve efficiency with technology

Many organizations still run DSA controls manually, collecting evidence and supporting testing by hand. As programs mature, Grant Thornton finds those approaches increasingly difficult to sustain. Manual processes consume significant operational time and often require support from engineering, legal, risk and compliance teams. The firm's pointed observation: the cumulative burden can become much larger than external audit or assurance costs alone.

Technology-enabled programs can automate evidence collection, improve control execution and enhance monitoring. Advances in analytics and AI-supported testing can evaluate larger populations of and activities than traditional sampling approaches allow. The firm is careful about limits, though. These capabilities do not eliminate the need for human oversight, so programs must still maintain appropriate governance and review processes. Technology serves as an enabler that lets human attention focus on higher-risk areas. A side effect worth noting for legal-ops planners: when compliance activities become more automated, engineering and operational staff spend less time responding to evidence requests and more time on platform improvement and innovation.

Step four: keep evolving

The final step is a change of phase, not a change of task. The first years of DSA compliance focused on implementation. The next phase, in Grant Thornton's words, is about optimization. To control compliance costs, complexity and operational burden, organizations need to embed compliance into current business operations and plan to keep evolving their programs. That is the substance of treating DSA as an ongoing and evolving business capability rather than a standalone initiative.

What this means in practice

For compliance and legal-ops teams, the four-step model translates into a few operational consequences, bounded by the sourced :

  1. Schedule a control rationalization review against the five criteria above, accepting that the count of controls may stay flat even as their operability improves.
  2. Audit where evidence is created today; if controls sit on top of workflows rather than inside them, engineering, safety, legal and operations are absorbing avoidable work.
  3. Price the internal cost of manual evidence collection before comparing it to technology spend — Grant Thornton's point is that the internal burden can exceed external assurance costs.
  4. Plan governance and human review into any automation, since the firm states explicitly that technology does not remove the oversight requirement.

The wider lesson for practitioners is that DSA compliance has entered its maintenance era. The regulation has not changed in this account; the organizations subject to it have. Teams that built fast under uncertainty now have the operating history to build lean, and the four steps describe how. For related coverage of how examiners treat evidence and automated decisioning, see the site's Digital section and its reporting on GDPR Article 22 and fraud models. Readers following the broader rulebook can also browse the Regulation desk. Readers following this should also see GDPR Article 22 and Fraud Models: When Automated Decisions Need Human Review in the EU.

Sources

  1. Four steps to upgrade Digital Services Act compliance - Grant Thornton — Grant Thornton

More from our brands

Part of the VUGA Network