#1
proctoring tool for ease of use

Resource Center

Research, guides, and real-world insights on online proctoring; helping your program deliver results that are fair, trustworthy, and defensible.

10M+

Assessments secured

Zero

Data breaches in 12+ years

98%

Client retention rate

120+

Resources published

All resources

Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.
Tag value
Man taking an online exam at his desktop computer while being recorded, illustrating hybrid AI and human proctoring.
Blogs & articles
All Industries

AI-Only, Live, or Hybrid: Which Proctoring Model Is Right for Your Program?

April 7, 2026

|

5 min read

Before you compare proctoring features or pricing, the model underneath matters most. This post breaks down AI-only, live, and hybrid proctoring, where each fits, and why not all hybrid models are actually hybrid.

Not all proctoring tools work the same way. Before you compare features, pricing, or integrations, the most important decision is the model underneath the platform. If you get that wrong, everything else falls apart.

There are three approaches to online proctoring. Each has a legitimate use case. Each has a real trade-off. And one of them is consistently misunderstood as the safe middle ground when, in practice, not all hybrid models are equal.

25%+
Projected annual growth rate for the global online proctoring market through 2035 — the tools are scaling fast, but not all of them in the right direction.
Source: Business Research Insights, 2026

As the market scales, programs are under more pressure than ever to choose the right model. Here is what each one actually means and what it means for your program.

The Three Proctoring Models

1. AI-Only Proctoring

AI-only platforms monitor sessions using algorithms. They track eye movement, audio patterns, browser behavior, and screen activity. When the system detects something outside expected parameters, it flags it. The report goes to your institution. Your team decides what to do with it.

The appeal is real. These tools are low cost, highly scalable, and require minimal vendor involvement. For programs running thousands of low-stakes assessments, that efficiency matters.

49% of students globally participated in online learning by March 2025 — driving demand for proctoring that scales without sacrificing accuracy. Source: Business Research Insights, 2026

The risk is also real. AI-only platforms typically flag 15 to 20 percent of all sessions. Many of those flags are not genuine integrity violations. Without a human reviewing the flag before it reaches your inbox, your team is doing that work. The savings on the tool often do not account for the time your staff spends sorting through incidents.

"When a result is challenged, the answer 'the algorithm flagged it' is not a defensible audit trail."

For programs where outcomes carry weight, that gap is a liability.
AI-only works when stakes are low, volume is high, and your institution has capacity to review flags internally.

2. Live Human Proctoring

Live proctoring puts a trained human proctor in the session in real time. The proctor monitors the exam as it happens, can communicate with the test taker, and can intervene if something goes wrong.

The accuracy is high. The human judgment is present. The audit trail is strong. For high-stakes licensing exams, certification bodies with regulatory requirements, and professional credentials where disputes are foreseeable, live proctoring has historically been the answer.

The trade-offs are scheduling and cost. Test takers need to book a time slot. Proctors need to be available. Per-session pricing adds up quickly at scale. For programs delivering hundreds or thousands of exams across flexible windows, the logistics become unworkable.

48% Of students expressed discomfort with webcam-based monitoring during exams — a signal that the model you choose directly affects learner trust in your program. Source: Business Research Insights survey, 2023


Live proctoring is also more intrusive for the learner. Being watched in real time creates anxiety that can affect performance. For programs that care about the experience of their test takers, that friction is worth accounting for.
Live proctoring works when stakes are high, volume is manageable, scheduling is structured, and real-time intervention is a non-negotiable requirement.

3. Hybrid Proctoring: The Model That Varies Most

Hybrid proctoring combines AI monitoring with human review. In principle, it offers the best of both approaches. In practice, it depends entirely on one question: when does the human review happen, and is it mandatory?

Many platforms that describe themselves as hybrid use AI for detection and offer human review as an optional tier or a paid escalation. That is not a genuine hybrid. It is AI-only with an appeal process.


Integrity Advocate is built on this model. Human review is not an upgrade.

A genuine hybrid model means a trained reviewer looks at every flag before it becomes an outcome. AI identifies. Humans verify.


Hybrid proctoring with mandatory human review delivers scale without shifting the review burden to your institution.

AI-Only Live Proctoring Hybrid Best
Human review None Live only Every flag
Scales at volume Yes Limited Yes
Defensible results Algorithm only Yes Yes
False positive risk High Low Filtered by humans
Learner experience Neutral High anxiety Fair, low friction
Cost efficiency Low per exam High per session Scalable
Audit trail AI flag only Session record Human review on file
AI-Only
Human review
None
Scales at volume
Yes
Defensible results
Algorithm only
False positives
High
Learner experience
Neutral
Cost efficiency
Low per exam
Audit trail
AI flag only
Live Proctoring
Human review
Live only
Scales at volume
Limited
Defensible results
Yes
False positives
Low
Learner experience
High anxiety
Cost efficiency
High per session
Audit trail
Session record
Hybrid Best
Human review
Every flag
Scales at volume
Yes
Defensible results
Yes
False positives
Filtered by humans
Learner experience
Fair, low friction
Cost efficiency
Scalable
Audit trail
Human review on file

Not all hybrid models are equal. The difference is whether human review is mandatory on every flag — or only available as a paid upgrade. That question determines what your results are actually worth.

The Question to Ask Every Vendor

When a flag is raised, who reviews it, and when?

If the answer is your team reviews it, or a human reviews it if you escalate, you are looking at AI-only with extra steps. If the answer is our reviewers examine every flag before it becomes an outcome, you are looking at a genuine hybrid. That question takes 30 seconds and tells you more than a 90-minute demo will.

{{post-cta}}

Human Review
Online Proctoring
Proctoring Comparison
No items found.
Close-up of hands typing an AI prompt on a laptop, representing how AI tools are changing academic cheating and exam integrity.
Blogs & articles
All Industries

What Defensible Assessment Looks Like in 2026

April 7, 2026

|

5 min read

AI tools have changed what cheating looks like, and most proctoring systems were built for a different problem. This post covers why an automated flag alone can't defend an outcome, and what a defensible assessment record requires in 2026.

We talk to a lot of programs right now that are dealing with the same thing. AI tools have changed what cheating looks like, and most proctoring systems were built for a problem that’s no longer the only one on the table. The gap is showing up in appeals, in complaints, and in outcomes that are getting harder and harder to defend.

What’s actually happening out there

The classic image of cheating a second phone, a friend on the other side of the room, notes taped to a monitor is still real. But it’s not the conversation we’re having with most programs anymore. The harder stuff is subtler.

AI writing tools can produce a natural, well-reasoned answer in seconds. Paraphrasing tools can disguise lifted content well enough to pass similarity checks. And the behavioral signals that used to flag something suspicious eye movements, typing pace, browser switching don’t tell you much when the assistance is happening invisibly, in another tab or on another device entirely.

The problem isn’t that AI cheating is impossible to catch. It’s that catching it requires a level of context and judgment that an algorithm alone doesn’t have.

An algorithm can tell you something looked unusual. It can’t tell you what actually happened or whether it matters. That part still requires a person.

Why a flag without a human isn't enough anymore

Automated proctoring was designed to catch visible, definable behaviors tab switching, phone use, an unauthorized person on screen. For those cases, it works. But AI-assisted cheating often leaves no visible trace at all.

So when an automated system flags something in this environment, what it's actually telling you is: something here didn't fit the expected pattern. That's a starting point, not a conclusion. The problem is when programs treat it like one.

A wrongful finding based on an automated flag isn't just uncomfortable it can seriously damage a student's record or a professional's career. And when that decision gets challenged, "the system flagged it" isn't a defensible answer. You need a record of what actually happened and a human judgment behind the decision.

{{post-stat-highlight}}

What it actually takes to be defensible

Defensibility isn't really about technology. It's about being able to look anyone in the eye a student, a candidate, a regulator, a board member and explain clearly why a decision was made and what it was based on.

In this environment, that takes three things:

  • Human review on every flag, before any decision goes out. Not as an appeal process. Before the outcome is issued.
  • Reviewers who are looking at AI-use patterns specifically, not just traditional integrity signals, and who understand the difference between something suspicious and something definitively wrong.
  • A complete session record identity verification, monitoring log, what was flagged, what the reviewer saw, what was decided ready to export the moment someone asks.

What actually changes with human review

Automated-Only Outcome Human-Reviewed Outcome
Flag is issued, decision follows automatically. No context evaluated. Flag is issued, a real person looks at what happened before any decision is made.
False positive rate is high, especially for anything AI-adjacent. Context filters the noise. Genuine violations are confirmed. Ambiguous situations stay ambiguous until they're not.
When challenged, you can produce a log. You can't produce a judgment. When challenged, you have a complete record including a human assessment. The outcome holds up.
A wrongly flagged candidate has grounds for complaint that are hard to counter. A candidate who appeals gets a real process. You have the documentation to back your position.

One question to sit with

If an outcome from one of your proctored exams was challenged today by a student, a candidate, an employer, an accreditor what could you actually put in front of them? An automated flag, or a complete human-reviewed record of what happened and why?

For programs where the result genuinely matters, that's not a rhetorical question. It's the one worth answering before you need to.

We built Integrity Advocate around exactly this human review on every flagged session, a complete audit trail for every outcome, and the kind of defensibility that holds up when someone actually pushes back.

{{post-cta}}

Online Proctoring
AI Cheating
No items found.
Woman smiling while typing on a laptop in an office, with a "Guest Blog: uxpertise" banner.
Blogs & articles
All Industries

What It Takes to Successfully Roll Out Online Proctoring Inside an LMS

April 15, 2026

|

5 min read

Rolling out online proctoring inside an LMS doesn't have to be disruptive. This guest post from uxpertise shares six practical steps for a smooth launch, plus how CMRAO cut support requests by 80% after switching to Integrity Advocate.

Guest blog by uxpertise

Rolling out online proctoring inside a Learning Management System (LMS) can feel daunting—for administrators and learners alike. Concerns around usability, learner stress, and an increase in customer support requests often slow adoption.

The reality is that when online proctoring is implemented thoughtfully, it can be seamless, learner-friendly, and highly effective—while actually reducing operational complexity.

Based on uxpertise’s experience supporting regulators and credentialing bodies, here’s what it truly takes to successfully roll out online proctoring inside an LMS, while ensuring reliable results and a positive learner experience.

{{download-resource-cta}}

1. Choose an LMS With Proctoring Already Integrated

One of the most important decisions happens before rollout even begins.

Whenever possible, organizations should choose an LMS with online proctoring already integrated, rather than relying on disconnected third-party tools. An integrated approach:

  • Simplifies onboarding for administrators and learners
  • Enables faster deployment of proctored exams
  • Reduces technical friction and user confusion
  • Minimizes IT and support dependencies

When proctoring is built directly into the LMS, learners stay in a single, familiar environment—no juggling platforms, no unnecessary steps.

2. Pilot Before Scaling

Before launching to your full learner population, run a pilot test with internal staff or a small group of learners.

A pilot helps you:

  • Validate exam workflows end-to-end
  • Identify usability or communication gaps
  • Confirm rules and technical requirements
  • Gather real user feedback

This step alone can prevent a large volume of avoidable support requests and ensures a smoother full-scale rollout.

3. Prepare Learners With Clear, Simple Resources

Learner preparation is one of the biggest drivers of success.

We recommend creating:

  • A short video tutorial explaining the proctoring experience
  • A simple written guide outlining key steps
  • A practice proctored exam so learners can test the process in advance

Practice exams are especially effective. They reduce anxiety, build confidence, and ensure learners know exactly what to expect—long before exam day.

4. Clearly Communicate Exam Rules and Requirements

Transparency builds trust and compliance.

Make sure learners understand:

  • Identification requirements (for example, government-issued ID)
  • What is not permitted (phones, notes, additional devices)
  • The need for a quiet, private testing environment
  • Technical requirements such as camera, microphone, and internet connection

Clear expectations upfront significantly reduce issues during the exam and lower post-exam support inquiries.

5. Let Learners Know What Happens After the Exam

Many learners are uncertain about what happens once an exam is submitted.

Communicate clearly:

  • How exams are reviewed
  • When results will be available
  • Whether any additional verification may occur
  • How to get help if they have questions

This clarity reinforces confidence in the integrity of the process and reduces unnecessary follow-up requests.

6. Prioritize User Friendliness and Reliable Results

Successful online proctoring should support learners—not intimidate them.

A well-integrated solution:

  • Is intuitive and easy to use
  • Requires minimal technical knowledge
  • Produces reliable, defensible outcomes
  • Strengthens trust in assessment integrity

When learners feel supported, adoption increases and confidence in the system grows.

{{post-stat-highlight}}

Case Study: CMRAO’s 80% Reduction in Support Requests After Switching Proctoring Technology

CMRAO, a uxpertise client, had been delivering online exams using a different proctoring solution within the uxpertise LMS. While functional, the experience created friction for learners and resulted in a high volume of customer support requests.

When uxpertise made the decision to switch technology providers and integrate Integrity Advocate directly into the LMS, the impact was immediate.

After the transition, CMRAO experienced:

  • An 80% reduction in customer support requests
  • A noticeably easier experience for learners
  • No required software downloads
  • A more intuitive, user-friendly interface
  • A truly seamless, all-in-one assessment environment

By combining an integrated proctoring solution with clear learner preparation and guidance, CMRAO significantly improved both learner experience and operational efficiency.

A Successful Rollout Is About Preparation, Not Complexity

Rolling out online proctoring inside an LMS doesn’t need to be complex or disruptive.

By choosing an integrated solution, piloting before launch, preparing learners proactively, and focusing on usability, organizations can:

  • Reduce support requests
  • Improve learner confidence
  • Maintain high standards of integrity
  • Scale assessments with confidence

At uxpertise, we believe the most effective proctoring solutions are the ones learners trust—because everything simply works.

Access our webinar on-demand

Ahead of the Curve: Building Trustworthy Licensing Programs in a Changing Assessment Security Landscape
Why modern regulators and credentialing bodies need integrated systems, not disconnected tools, to stay credible, compliant, and confident.

On-demand webinar

Protecting your licensing program
in the age of AI.

Watch our joint session with uxpertise and CMRAO to see how leading credentialing bodies are securing exam integrity without sacrificing the candidate experience.

Human review on every flag No install required 98% client retention Zero breaches in 12 years
Recognized on G2 G2 Spring 2026 Leader G2 Spring 2026 Easiest To Use G2 Spring 2026 Best Usability
Watch On Demand Free to watch. No registration required.
Ready when you are.
LMS Integration
Ease of Use
No items found.
Man holding up an ID card to a laptop camera for identity verification at home.
Blogs & articles
All Industries

Why Automated Identity Verification Isn’t Enough for High-Stakes Exams

May 18, 2026

|

5 min read

All proctoring vendors say they verify identity, but they don't all mean the same thing. Explore where automated-only ID checks fall short and what to ask when evaluating a platform.

There’s a difference between an algorithm saying “these two images match” and a trained person saying “I reviewed this ID and confirmed it.” One is a data point. The other is evidence. When a result gets challenged, you need evidence. Here’s something worth knowing about online proctoring vendors: they all say they verify identity. What they don’t all mean is the same thing. And that gap, between capturing an image and actually confirming who someone is, is where a lot of programs are quietly sitting on risk they haven’t fully thought through. If you’re currently evaluating proctoring platforms, or you’re starting to wonder what your current vendor actually does when a test taker shows up to an exam, this is for you. We’re going to cover what identity verification in online assessment actually looks like, where automated-only systems run into trouble, and what it takes to produce a result that holds up when it counts. What identity verification actually means in an online exam context


The basics are simple. Identity verification confirms that the person taking your assessment is the person who enrolled for it. Most platforms handle this by asking test takers to hold a government-issued ID up to their camera, capturing a live photo, and comparing the two. What varies, a lot, is what happens after those images are captured. In a fully automated system, an algorithm makes the comparison and moves on. In Integrity Advocate’s human-reviewed system, a trained reviewer examines the ID and live photo after the session is completed, verifying both that the ID is a genuine match and that the same person was there for the entire assessment. That’s a meaningfully different thing.

The key distinction

Automated identity verification produces a result. Human-reviewed identity verification produces a record. One is a data point. The other is evidence. When outcomes get challenged, you need evidence.

That might sound like a subtle difference right now. It won’t feel subtle when you’re sitting across from an accreditor, or responding to a candidate appeal, or explaining your identity controls to a regulatory body. “Our algorithm flagged it” and “a trained reviewer verified the ID match and confirmed the same person was present for the entire session” don’t carry the same weight in that room.

The actual threats identity verification is meant to stop

Before you evaluate any solution, it’s worth being clear about what you’re actually protecting against. Identity verification in online assessment is mainly a defence against three things.

Candidate impersonation

Someone other than the enrolled candidate sits the exam. Could be a friend, a sibling, or a professional impersonator hired through a contract cheating service. In high-stakes contexts, professional certification, regulatory licensing, safety-critical credentials, the consequences go well beyond academic dishonesty. They touch public trust in the credential itself. That’s a different kind of problem.

Proxy testing and contract cheating services

Proxy testing is impersonation at scale, and it’s growing. The same infrastructure that made remote work possible made organized contract cheating more accessible too. Professional exam-sitters exist. They’ve been around for years and they’ve gotten more sophisticated as online testing has expanded.

What makes proxy testing particularly hard to catch with automation is that the person attempting the ID check is often well-prepared. They may have a convincing fake or borrowed ID. They may have done this before, for other clients, on other platforms. An algorithm looking for obvious facial mismatches isn’t going to catch someone who’s specifically prepared to pass that check.

{{post-stat-highlight}}

Manipulated or non-standard identity documents

Automated systems compare images. They measure how closely two images match. They’re not built to assess whether a document looks legitimate, whether something about it seems off, or whether the context around the ID presentation is consistent with someone who is genuinely who they say they are.

If you need a recent illustration of just how thin that defense is: a UK nonprofit surveyed around 1,300 children aged 9 to 16 and found that about half believe online age verification checks are easy to bypass. One documented method was drawing a fake mustache on their face with a makeup pencil. A 12-year-old was verified as 15. It worked. Other workarounds included pointing webcams at video game characters and making unusual facial expressions until the software stopped trying. TechCrunch covered it in May 2026.

These are AI systems built specifically for facial verification. A makeup pencil broke them. In an exam context, where a candidate may have a professional credential, a licence, or a career on the line, the motivation to try something is considerably higher; and the workarounds available are more sophisticated than drawn-on facial hair. Automated ID checks in high-stakes assessments face the same fundamental vulnerability, with significantly higher consequences when something slips through.

Beyond outright manipulation, non-standard ID documents from other countries are a real operational headache for automated systems. A document that an algorithm can’t parse correctly – because it looks different from its training data, often gets flagged for the wrong reasons. Not because anything is wrong. Just because it looks unfamiliar. That’s a fairness problem as much as it is a fraud one.

Where automated identity verification falls short

Speed and scale, those are the real advantages of fully automated ID verification. They’re genuine. The problem is that optimising for speed and scale means accepting trade-offs that start to matter the moment your results have any real consequence attached to them.

It produces a log, not a defensible record

When a fully automated system approves an identity check, what it creates is a timestamp and a confidence score. That score tells you how closely two images matched according to the model. It doesn’t tell you that a human looked at the documents and made a judgment call.

The moment an outcome is challenged, that distinction is everything. There’s a big difference between “our algorithm scored the match at 94.3%” and “a trained reviewer examined the ID and the live photo and confirmed the identity match.” One is data. The other is documentation. If you’ve ever had to respond to an accreditor asking about your identity controls, you know which one you want to be holding.

Edge cases aren’t actually that rare

Facial recognition systems are trained on datasets. Those datasets have gaps, and those gaps don’t affect all test takers equally. People with darker skin tones, older candidates, people with facial differences or disabilities, and test takers presenting documents from underrepresented countries, these populations consistently get worse outcomes from automated systems.

In a program serving thousands of test takers across many countries, these aren’t rare edge cases. They’re a predictable share of your assessment cycle. A system that handles them badly is a system that consistently disadvantages specific groups of people. That’s both a fairness problem and a real compliance exposure under frameworks like WCAG and AODA.

Accommodations are invisible to algorithms

A lot of programs serve test takers with documented accommodations. Some of those accommodations affect how a test taker looks at the identity check stage. A test taker with a visual impairment may present their ID differently. Someone with a facial difference may not match their ID photo the way an algorithm expects.

An automated system has no way to know an accommodation exists. A human reviewer can, because that information can be passed to them before the check happens. They apply the context, the check goes smoothly, and the test taker isn’t penalized for something their program already knew about and approved.

What human-reviewed identity verification actually adds

Human review at Integrity Advocate isn’t a fallback for when automation fails. It’s the standard for every single check. That changes what the whole process produces, and what you can do with the results.

Judgment, not just pattern matching

A trained reviewer looking at an ID document and a live photo is doing something different from what a facial recognition model does. They’re not just asking “do these two images match?” They’re assessing whether the identity claim is plausible, taking in the quality of the document, the context of the photo, whether something feels off. That’s judgment. It’s not something you can fully replicate with a model.

It also means programs can explain what happened. Not just cite a score. “A trained reviewer examined the ID and the live photo and confirmed the match” is a sentence a human can understand, investigate, and stand behind.

A record that travels with the session

At Integrity Advocate, every identity check creates a time-stamped record permanently attached to the session. What was verified, when, and by whom. If an outcome from that session ever gets challenged, the identity verification record is already part of the documentation, not sitting in a separate system you have to dig through.

Appeals rarely come with advance warning. Programs that have a complete, human-confirmed record don’t have to reconstruct anything after the fact. The evidence was created at the moment of verification. It hasn’t changed.

Deterrence, not just detection

Here’s something that doesn’t get talked about enough: people behave differently when they know a human is watching. A test taker who knows their government-issued ID will be examined by a trained reviewer before the exam starts isn’t approaching that check the same way as someone who knows it’s algorithmic.

Programs that shift from automated-only to human-reviewed verification consistently see a change in the behaviour of the small slice of candidates who were willing to try something. The check itself becomes a deterrent. You catch less because less gets attempted.

What to look for when you’re evaluating

If you’re shopping around, or starting to question what your current vendor actually does, here are the questions that cut through the noise.

Is a human involved in every check, or just the flagged ones?

A lot of platforms say “human review.” What they mean is that a human reviews AI-flagged sessions only, and only when the algorithm decides something is worth escalating. At Integrity Advocate, a trained reviewer looks at every session after it’s completed, verifying the ID match and confirming the same person was present throughout. That’s the question to ask: is every session reviewed, or only the ones the algorithm flags?

What does the record actually contain?

Ask to see a sample identity verification record. If the answer is a confidence score and a timestamp, that’s an automated log. A defensible record includes the ID image, the live photo, the match determination, who made it, and when. If you can’t show an accreditor a complete documentation trail, the check isn’t giving you what you actually need.

How does it handle non-standard IDs and accommodations?

Ask specifically what happens when a test taker shows up with an ID from a country with an unfamiliar format, or when an accommodation affects how they look at the check stage. If the answer is vague or relies heavily on “the algorithm handles it,” that tells you something important about how these scenarios were thought about when the product was designed.

Where does the privacy risk sit?

Identity verification collects sensitive data. Ask specifically what’s collected, how long it’s retained, and whether it’s used for anything beyond the identity check. If you have GDPR, FERPA, or PIPEDA obligations, and most programs doing anything at scale do, you need clear answers here before you commit.

Automated vs human-reviewed: a direct comparison

Here's how automated-only identity verification, Integrity Advocate's human-reviewed approach, and in-person proctoring stack up against each other.

What programs need AI-only IA Human-reviewed In-person
Human judgment on every check✗ Algorithm only✓ Every session reviewed✓ Proctor present
Defensible audit record✗ Confidence score only✓ Full human-confirmed record~ Paper-based
Handles non-standard IDs✗ Fails on unfamiliar formats✓ Any government ID accepted✓ Proctor applies judgment
Accommodation-aware✗ No accommodation context✓ Reviewer applies context✓ Proctor applies context
Works on any device, no install~ Varies✓ Browser-based, zero install✗ Physical presence required
Proxy testing deterrence~ Algorithmic only✓ Human raises barrier significantly✓ Physical presence
Privacy-compliant~ Varies by vendor✓ GDPR, FERPA, PIPEDA~ Depends on policy
Scales without overhead✓ Scales automatically✓ Scales, IA manages review✗ Requires staffing

✓ Fully supported  ·  ~ Partial support  ·  ✗ Not supported

The bottom line

Automated identity verification is better than nothing. That’s true. But if your program issues results that actually mean something, credentials that affect career progression, licences that protect public safety, certifications that carry professional weight, “better than nothing” isn’t where you want to land.

What you need is a check that creates a record you can stand behind. Something that answers not just “did the algorithm approve this?” but “can we show that a qualified person verified this person’s identity before the exam began?” Those are different questions, and they get different responses from the people who ask them.

Identity fraud isn't a maybe. It's a risk. A login won't stop impersonation. Human-reviewed ID verification will.

Integrity Advocate

The cost of getting identity verification wrong doesn’t show up at the time of the exam. It shows up later, when results are challenged, when accreditors start asking questions, when credential fraud surfaces somewhere down the line. By then, piecing together what happened is hard. Having a complete record from the moment of verification isn’t.

{{post-cta}}

Identity Verification
Online Proctoring
No items found.
Woman with glasses smiling while working on a laptop in a modern office setting.
Blogs & articles
Regulated industries
Corporations
Credentialing

Payroll Certification Programs Are No Longer Just Delivering Exams. They’re Delivering Trust.

May 10, 2026

|

5 min read

Legacy testing infrastructure puts credential trust at risk. See why payroll certification programs are modernizing, what a "trust engine" looks like, and the real-world results from the National Payroll Institute, including a 57% drop in integrity incidents.

For decades, payroll certification programs operated within a relatively stable testing model. Candidates tested in controlled environments. Exams were delivered in classrooms or testing centers. Proctors supervised sessions physically. And the credibility of the designation was largely tied to the rigor of the exam itself.

That environment no longer exists. Today’s payroll associations and certification bodies are serving remote, digitally connected professionals who expect flexible testing experiences that work on any device, from anywhere, without technical friction or invasive surveillance.

At the same time, employers, regulators, and stakeholders are demanding stronger assurance that certifications remain credible, defensible, and independently verifiable.

This shift fundamentally changes the role of certification organizations.

As the new Payroll Influences eBook, Enabling a Trust Engine: A Modern Blueprint for Scalable Payroll Certification Testing, explains:

{{post-stat-highlight}}

And that distinction matters more than ever.

{{download-resource-cta}}

The Credential Is Only as Trusted as the Process Behind It

In a digital-first testing environment, the exam itself is no longer the only thing being evaluated, candidates evaluate the experience, employers evaluate the credibility of the designation, program administrators evaluate operational risk, and stakeholders increasingly evaluate whether the certification process can withstand scrutiny, disputes, appeals, and governance requirements.

That means credential trust is now directly connected to:

  • Identity verification
  • Evidence-backed integrity decisions
  • Candidate experience
  • Accessibility
  • Privacy practices
  • Operational consistency
  • Defensible audit trails

Programs that fail to modernize these areas risk something much larger than isolated technical issues. They risk erosion of designation value itself. The report refers to this growing challenge as the certification “Testing Risk Stack.”

The Hidden Costs of Legacy Testing Infrastructure

Many certification programs still rely on testing models designed for another era. The assumptions behind traditional proctoring systems; controlled rooms, supervised desktops, mandatory downloads, rigid browser restrictions, increasingly clash with modern candidate expectations and operational realities.

The Certification “Testing Risk Stack”

Risk Area Business Impact
Brand Impact Employer confidence and credential differentiation decline
Defensibility Gaps Appeals become difficult to resolve consistently
Participation Leakage Friction reduces enrollment and completion
Operational Drag Support burdens and false flags consume staff resources
Privacy Exposure Over-collection of data increases governance and reputational risk

This is one of the most important shifts happening in assessment security right now: The biggest risk is no longer simply cheating, the biggest risk is loss of trust in the credential itself.

AI Has Changed the Integrity Conversation, But Not in the Way Most Programs Think

AI-driven integrity threats are accelerating across education, certification, and workforce training environments. But many organizations have responded by increasing automation and surveillance instead of improving verification quality. That approach often creates new problems:

  • Higher false positive rates
  • More candidate distrust
  • Increased appeals
  • Poorer learner experiences
  • Greater operational burden

The report makes a critical distinction: “AI alone creates false flags. Surveillance erodes trust. Mandatory installs block access.”

This is where many legacy proctoring models break down. Detection alone is not defensibility. Programs still need context, evidence, and human review to produce fair and trustworthy outcomes. This aligns closely with Integrity Advocate’s broader approach to Security-Based Proctoring; a framework focused on verified outcomes, evidence-backed review, and proportional response instead of surveillance-heavy automation.

Related reading:

What Modern Certification Testing Actually Looks Like

The report outlines a more sustainable model for modern certification programs, one built around what it calls a “Trust Layer.” Rather than relying on fragmented tools, modern programs are increasingly connecting:

  • LMS or testing platforms
  • Human-reviewed online proctoring
  • Digital credentialing systems

Together, these systems create what the report describes as “An end-to-end chain of evidence from session to credential.”

The Modern Certification Workflow

Phase Purpose
Detect Automation identifies potential integrity signals
Verify Human reviewers provide context and reduce false accusations
Decide Administrators receive validated incidents with clear evidence
Defend Audit-ready reporting supports fairness and appeals

This is a major evolution from “flag generation” toward defensible outcome validation.

Real-World Results: National Payroll Institute

One of the strongest sections of the report highlights how the National Payroll Institute modernized its certification testing infrastructure with Integrity Advocate. NPI faced challenges familiar to many certification organizations:

  • Technical failures
  • Limited accessibility support
  • Operational strain
  • Candidate frustration
  • Scalability concerns

After implementing Integrity Advocate’s browser-native, low-friction, human-reviewed proctoring model, the organization reported:

Modernization Outcomes

Outcome Result
Reduction in integrity incidents 57% decrease
Technical escalation rate Less than 0.1%
Incident resolution time Reduced from weeks to 48 hours
Exam scalability 30,000+ exam instances annually
Deployment timeline Pilot to full deployment in 3 months

Equally important, the organization improved both operational efficiency and candidate experience without introducing heavier surveillance or technical barriers. That balance is becoming a defining competitive advantage for certification programs.

What Payroll Associations Should Prioritize in a Testing Partner

The report outlines several key capabilities modern certification organizations should prioritize when evaluating online proctoring and assessment security partners:

Low-Friction Participation

Candidates should be able to test without downloads, plugins, or complicated setup requirements.

Human Verification

Human-reviewed incidents reduce false positives and improve fairness and defensibility.

Privacy-First Infrastructure

Modern programs need strong data minimization and responsible retention practices.

Accessibility and Inclusion

Multilingual support, accommodation readiness, and flexible testing experiences improve participation and reduce barriers.

Defensible Evidence Trails

Programs need audit-ready evidence and reviewable integrity decisions that can withstand appeals and scrutiny.

These capabilities are no longer “nice-to-have” operational features, they are becoming core drivers of credential trust and market credibility.

The Future of Certification Is Defensible, Verifiable, and Low Friction

The organizations that will lead the next decade of credentialing are not simply the ones with the hardest exams, they are the ones capable of proving:

  • Who took the exam
  • How integrity decisions were made
  • Whether outcomes can withstand scrutiny
  • That the process was fair, accessible, and privacy-conscious

Trust is becoming infrastructure, and certification programs that proactively modernize now will be better positioned to:

  • Protect designation value
  • Increase employer confidence
  • Improve learner participation
  • Reduce operational burden
  • Scale securely in an AI-driven environment

As the report concludes:

"The strongest partner doesn’t just proctor the exam; they connect verified outcomes to credential issuance.”

{{post-cta}}

Defensible Outcomes
Online Proctoring
No items found.
An over-the-shoulder view of a person using a laptop displaying a cybersecurity and login interface, sitting beside a coffee cup, illustrating a guest post on secure online assessments and data privacy.
Blogs & articles
Education

Balancing Assessment Security and Privacy Within Modern Online EdD Programs

May 22, 2026

|

5 min read

Online EdD programs face a growing tension: assessments must be secure, but doctoral learners expect their privacy to be respected. In this guest post, Research.com's Stephanie Dion explores how institutions can move beyond surveillance-heavy models toward verification-based systems, risk-based authentication, and faculty preparedness that protect both academic integrity and learner trust.

The rapid growth of doctoral-level education delivered through digital platforms has transformed how institutions design, deliver, and evaluate learning. While flexibility and accessibility have improved, new challenges have emerged around maintaining academic integrity without compromising learner privacy. Programs must now navigate a complex balance between safeguarding assessments and respecting personal data boundaries.

Modern online learning environments—especially within advanced doctoral pathways—require systems that are both secure and ethically designed. Achieving this balance is critical not only for institutional credibility but also for learner trust.

The Evolving Landscape of EdD Assessment Integrity

Doctoral programs have always emphasized rigorous evaluation standards. However, the shift to remote delivery has introduced new vulnerabilities, from identity fraud to unauthorized collaboration. Within an EdD context, where research-based outputs and professional practice are central, the stakes are even higher.

Institutions are increasingly turning to layered assessment strategies that combine human oversight with technological safeguards. Yet, implementing these systems without overstepping privacy expectations remains a nuanced challenge.

Key Risks in Modern Assessment Environments

  • Unverified identities can undermine the credibility of academic credentials, making it essential to confirm that enrolled learners are the ones completing assessments.
  • Over-surveillance can erode student trust and engagement, particularly when monitoring tools feel intrusive or disproportionate to the assessment type.
  • Data storage vulnerabilities increase institutional liability, especially when sensitive learner information is collected and retained unnecessarily.

Balancing these risks requires thoughtful system design and governance.

The Role of Digital Credential Verification Systems

One of the most effective approaches to maintaining integrity without excessive monitoring is the use of digital credential verification systems. These tools enable institutions to validate learner achievements and identities through secure, traceable methods.

Rather than relying solely on real-time surveillance, verification systems focus on verifying the authenticity of outcomes. This shift allows institutions to uphold standards while reducing reliance on invasive monitoring practices. Similar conversations around the importance of verified credentials and accountability are explored in Integrity Advocate’s article on the case for verified credentials in private security.

How Verification Systems Strengthen Trust

  • Blockchain-backed credentials create tamper-proof academic records, ensuring that qualifications remain verifiable over time without requiring constant oversight.
  • Decentralized identity frameworks give learners greater control over their data, allowing them to share only necessary information during verification processes.
  • Automated validation processes reduce administrative burden, enabling institutions to scale securely while maintaining accuracy.

To better understand broader approaches to protecting credentials in digital ecosystems, exploring resources on the future of assessment security and credential integrity can provide additional context.

Research Insight: Data, Trust, and Digital Education

Recent findings from the OECD highlight that trust in digital education systems is strongly correlated with transparency in data usage and governance. A 2023 report emphasizes that learners are more likely to engage fully when they understand how their data is collected, stored, and protected.

This insight reinforces the importance of designing systems that prioritize both security and transparency, particularly within online doctoral programs.

Designing Privacy-Conscious Assessment Frameworks

Creating secure yet respectful assessment environments requires a shift from surveillance-heavy models to privacy-conscious frameworks. Institutions must evaluate each tool and process through both a security and ethical lens, particularly when balancing the need for security with the responsibility of protecting learners and institutional reputation.

How to Build Balanced Assessment Systems

  • Adopt risk-based authentication methods that adjust security levels based on assessment type, ensuring that high-stakes exams receive stricter controls while lower-risk tasks remain less intrusive.
  • Limit data collection to essential information only to reduce exposure to privacy risks and align with global data protection regulations.
  • Provide clear communication about monitoring practices, helping learners understand what is being tracked and why.

Expert Tips for Implementation

  • Engage stakeholders, including students and faculty, in system design discussions, ensuring that solutions reflect real-world concerns and expectations.
  • Regularly audit assessment technologies for compliance and effectiveness, identifying opportunities to improve privacy without weakening security.
  • Integrate ethical guidelines into institutional policies to create a consistent framework for decision-making across departments.

Financial and Sociological Considerations

  • Over-investment in intrusive monitoring tools can lead to diminishing returns, as student resistance may reduce engagement and performance.
  • Transparent systems can improve retention rates, as learners feel more confident in the program’s fairness and integrity.
  • Efficient processes reduce administrative costs, allowing institutions to allocate resources toward teaching and research.

These considerations highlight the need for balanced, sustainable solutions.

Online Proctoring: Finding the Middle Ground

Remote assessment monitoring remains a critical component of many programs, but it must be implemented thoughtfully. Online proctoring technologies can provide valuable oversight when used appropriately, yet they often raise concerns about privacy and data usage.

Institutions are now exploring hybrid models that combine automated monitoring with human review, reducing reliance on invasive techniques. Recent findings discussed in AI and online exams: what the data reveals about assessment security further highlight how institutions are adopting smarter, risk-based approaches to digital assessment monitoring.

For a deeper look into how monitoring technologies are evolving, the discussion on online proctoring offers valuable industry insights.

Best Practices for Ethical Proctoring

  • Use AI-driven monitoring selectively to flag anomalies rather than continuously surveil learners, allowing human evaluators to make final decisions.
  • Offer alternative assessment formats where possible, such as open-book exams or project-based evaluations that reduce the need for strict monitoring.
  • Ensure compliance with regional data protection laws, protecting both institutions and learners from legal risks.

Why is faculty preparedness essential for secure online EdD assessments?

Technology alone cannot ensure assessment integrity within modern doctoral education. Faculty members and program administrators play a central role in creating ethical, secure, and privacy-conscious evaluation environments. Without proper training, even advanced assessment systems may be implemented inconsistently, increasing both security risks and learner concerns.

Online EdD programs often involve complex assignments such as research projects, reflective analysis, and applied leadership evaluations. These formats require instructors to understand not only digital assessment tools but also ethical data practices, accessibility considerations, and evolving academic integrity standards.

Institutions that invest in faculty preparedness can improve consistency across assessment processes while strengthening learner trust. Professional development initiatives frequently include training in secure assessment design, responsible use of proctoring technologies, and privacy-focused communication practices. As online doctoral education continues to expand, many academic leaders are also exploring accelerated pathways for advanced educational leadership training through resources such as the Research.com list of shortest online EdD programs, which highlights flexible options for professionals pursuing doctoral advancement.

Key benefits of faculty preparedness include:

  • More consistent implementation of assessment security policies
  • Improved communication regarding privacy and monitoring practices
  • Reduced misuse of intrusive technologies during evaluations
  • Stronger alignment between institutional ethics and assessment methods
  • Greater student confidence in the fairness of online learning environments

By prioritizing faculty readiness alongside technological safeguards, institutions can create more balanced online EdD programs that protect both academic integrity and learner privacy.

The Future of Digital Credential Verification Systems

As education continues to evolve, digital credential verification systems will play an increasingly central role in maintaining trust. These systems offer a scalable solution that aligns with both security requirements and privacy expectations.

Emerging technologies such as decentralized identity and zero-knowledge proofs are set to further enhance verification processes, allowing institutions to confirm authenticity without exposing sensitive data.

Forward-Looking Insights

Several emerging trends highlighted in what’s changing in assessment security in 2026 are already shaping how institutions approach assessment integrity and learner privacy.

  • Decentralized verification models will reduce reliance on centralized databases, minimizing the risk of large-scale data breaches.
  • Integration with global credential networks will improve portability, enabling learners to share verified achievements across institutions and employers.
  • Advanced encryption techniques will strengthen data protection, ensuring long-term security for academic records.

These developments signal a shift toward more ethical and efficient systems.

Key Insights

  • Balancing security and privacy requires a shift from surveillance-heavy models to transparent, verification-based systems.
  • Thoughtful implementation of technology enhances both institutional credibility and learner trust.
  • Future-ready programs will integrate security seamlessly into design rather than treating it as an add-on.

{{post-cta}}

Assessment Security
Privacy & Data Protection
No items found.
Integrity Advocate ranked #1 in the G2 Summer 2026 Usability Index for Online Proctoring, its second consecutive season at the top.
Company updates
All Industries

Integrity Advocate Is Ranked #1 for Online Proctoring on G2. Here’s What That Means.

May 29, 2026

|

5 min read

Integrity Advocate ranked #1 in the G2 Summer 2026 Usability Index for Online Proctoring, its second consecutive season at the top. This post breaks down what the ranking measures, how IA scored against Honorlock, Proctorio, and Meazure Learning, and the design decisions behind the results: no-install access, human review on every flag, and privacy by design.

Integrity Advocate ranked #1 in the G2 Usability Index for Online Proctoring, for the second consecutive season. G2’s rankings are built entirely on verified reviews from real users: the administrators, directors, and instructors who actually run exams on these platforms every day. They rated us best, and that matters.

Here’s a look at what the ranking measures, what the data shows, and why it reflects something real about how IA is built.

What Is the G2 Usability Index?

G2 is the largest peer-to-peer software review platform in the world. Their Usability Index ranks products within a category based on three user-rated dimensions:

  • Ease of Use — how intuitive the platform is for test takers and administrators
  • Ease of Administration — how much overhead it takes to set up and manage
  • Meets Requirements — whether the platform actually does what programs need it to do

Every score comes from authenticated, verified reviews. Companies cannot pay to improve their position. There is no sponsorship or placement influencing the results. The index score reflects what users say nothing more.

The Summer 2026 Rankings

Here is how the full category stacked up in the G2 Summer 2026 Usability Index:

# Product Usability Score G2 Index Score
1
Integrity Advocate
85% usability
8.45 #1
2
Honorlock
81% usability
8.07
3
Proctorio
79% usability
7.94
4
Quilgo
78% usability
7.81
5
Talview
78% usability
7.78
6
Meazure Learning
72% usability
7.24

Source: G2 Usability Index for Online Proctoring | Summer 2026 (Draft). Products ordered by index score.

Source: G2 Usability Index for Online Proctoring, Summer 2026. Products ordered by index score.

Integrity Advocate holds a 0.38-point lead over the second-ranked platform and a 1.21-point lead over the lowest-ranked platform in the category. In an index where scores cluster tightly, that gap is significant.

Above Category Average Across Every Dimension

G2 scores IA above the category average on every metric the Usability Index measures:

Overall Usability Score
85%
IA
85%
Avg
79%
G2 Index Score
8.45
Summer 2026 · #1 Ranked

No other platform in the category leads the field on all three dimensions simultaneously.

What the Data Looks Like Head to Head

Numbers tell the story more clearly than positioning claims. Here’s how IA compares to the platforms most programs evaluate side by side:

Integrity Advocate vs. Honorlock

  • Ease of Use: 94% vs. 90%
  • Ease of Admin: 92% vs. 93%
  • User Adoption: 76% vs. 50% (+26 points)
  • G2 Index Score: 8.45 vs. 8.07

The user adoption gap is the one worth paying attention to. A 26-point difference in adoption rates suggests that one platform is meaningfully easier for test takers to actually use — not just to set up.

Integrity Advocate vs. Proctorio

  • Ease of Use: 94% vs. 89% (+5 points)
  • Ease of Admin: 92% vs. 87% (+5 points)
  • Meets Requirements: 91% vs. 89% (+2 points)
  • G2 Index Score: 8.45 vs. 7.94

Integrity Advocate vs. Meazure Learning

  • Ease of Use: 94% vs. 75% (+19 points)
  • Meets Requirements: 91% vs. 77% (+14 points)
  • Ease of Admin: 92% vs. 83% (+9 points)
  • G2 Index Score: 8.45 vs. 7.24

Why IA Scores Where It Does

Rankings don’t come from nowhere. The G2 scores reflect specific, deliberate decisions we made about how to build this platform.

No install. Any device. Any browser. Test takers don’t download anything. There’s no browser extension, no IT ticket, no pre-exam anxiety about whether the software will work. They log in and start. Administrators don’t field support calls about setup. That’s a direct driver of a 94% Ease of Use rating — 6 points above average.

Human review on every flag. At every pricing tier. Most platforms treat human review as a premium feature. At IA, a trained reviewer assesses every flag before any outcome is issued — regardless of which plan a program is on. That’s not an add-on. It’s the standard. When a result gets challenged by a student, an employer, or an accreditor, there’s a reasoned judgment behind it, not just an automated flag.

Privacy first, by design. We collect only what is necessary. The platform is FERPA, GDPR, and PIPEDA compliant. Zero data breaches across more than a decade of operation. Programs that have faced scrutiny for invasive proctoring practices know what’s at stake. IA is built to keep programs defensible on that front.

Results that hold up. From identity verification before the exam to reviewed outcomes after it, every stage connects into one documented record. When something is challenged, administrators have what they need to respond. That completeness shows up in the “Meets Requirements” score.

What Users Are Actually Saying

These reviews are authenticated and verified by G2.

{{post-block-quote}}

The Numbers Behind the Platform

The G2 ranking reflects a platform that has been in continuous operation for over a decade:

  • 98% client retention — programs that stay because the platform keeps working, year after year
  • Zero data breaches — across more than 12 years of operation
  • 10M+ proctored sessions — at scale, across credentialing bodies, institutions, and training providers
  • 4.5 stars on G2 — based on 23 verified reviews

See the Full G2 Report

The G2 Summer 2026 Usability Index for Online Proctoring is available in full. If you’re evaluating platforms, it’s worth reading the methodology alongside the scores.

IA G2 Report CTA Section
G2 SUMMER 2026 #1 USABILITY INDEX

See the Full G2 Report

The G2 Summer 2026 Usability Index for Online Proctoring is available in full. If you're evaluating platforms, it's worth reading the methodology alongside the scores.

8.45
G2 Index Score
94%
Ease of Use
4.5
G2 Star Rating
#1
Out of 6 Platforms

Access the G2 Report | Request a Demo

Integrity Advocate is a browser-based online proctoring platform built for credentialing organizations, education institutions, and training providers. Human review is included in every session, at every pricing tier, by default.

Online Proctoring
Ease of Use
Featured
A professional points to a training compliance document at a desk, representing the legal and regulatory standards organizations must meet for internal workforce training.
Blogs & articles
No items found.

Why Online Training Records Are Not Proof of Training

December 16, 2022

|

5 min read

A training completion record proves that a course was accessed. It does not prove who accessed it or whether they engaged with it. The PricewaterhouseCoopers case, in which fines of over one million Canadian dollars were assessed after staff shared answers to internal training courses, demonstrates what happens when organizations cannot verify who actually completed their training. This post examines the regulatory standard, the insurance gap, and how Integrity Advocate helps organizations build training records that hold up to scrutiny.

Corporate training serves many purposes. Meeting regulatory requirements. Building workforce capabilities. Demonstrating due diligence. But across all of these purposes, the same assumption is made: that a training completion record is proof that training happened.

It is not.

A completion record is proof that training was accessed. It is not proof of who accessed it, whether they engaged with it, or whether the person on record is the person who actually completed it. In a regulatory investigation or legal proceeding, that distinction matters enormously.

The PricewaterhouseCoopers Case

PricewaterhouseCoopers is one of the Big Four accounting firms and the second-largest professional services network in the world. In a published regulatory investigation conducted by the Canadian Public Accountability Board, fines of over one million Canadian dollars were assessed after it was found that junior staff, managers, directors, and partners of PwC shared answers to internal training courses on auditing, accounting, and professional independence.

The regulator found that PwC had failed to establish policies and procedures to provide the firm with reasonable assurance that its workforce was completing required training as intended.

This was not a small organization with limited resources. This was one of the most sophisticated professional services firms in the world, with dedicated compliance infrastructure. And still, the internal training program failed to verify that the right people were completing the right training.

If it can happen at PwC, it can happen anywhere.

What Regulators Actually Require

Conversations with private company leaders reveal a consistent gap in understanding. Regulators generally do not stipulate specific oversight requirements for how training must be delivered or verified. They specify the outcome: that the workforce is trained.

The assumption that providing access to online training satisfies that outcome is where organizations get into trouble. Online training records are proof of training accessed, not training completed, and not by whom. Company leadership often has no evidence of individual workers' participation, and no process in place to obtain it.

When a regulatory investigation or legal action follows a workplace incident, that gap becomes the story.

Why Insurance Does Not Solve This Problem

When facing regulatory or legal action, many organizations turn to insurance protection as a backstop. It is worth understanding what insurance does and does not cover.

Insurance policies do not cover bad faith or gross negligence. The argument that company leaders have demonstrated gross negligence rests on the definition established in Hart v. Kline (1941): gross negligence as an indifference to a legal duty of care. An organization that provided training access without any mechanism to verify who completed it, or whether they engaged with it, may find that argument difficult to counter.

A completion record that cannot confirm identity or participation is not a defense. It is evidence of the gap.

What Verified Internal Training Looks Like

Integrity Advocate works with organizations to close that gap by verifying the identity and confirmed participation of internal personnel in every training session. The result is a record that demonstrates not just that training was accessed, but that the right person completed it and was present throughout.

This eliminates the exposure that comes from unverifiable training records in regulatory investigations, legal proceedings, and insurance disputes.

As one client senior leader put it: "How we deliver information to our personnel is indicative of the importance of that information to them."

The way an organization approaches training verification sends a signal about how seriously it takes what it is training people to do. For compliance training, safety training, and any instruction with regulatory or legal weight, that signal matters.

{{post-cta}}

Online Proctoring
Defensible Outcomes
No items found.
A digital interface displaying personal data fields and identity information, representing the data stockpiling practices that put student privacy at risk in online proctoring.
Blogs & articles
Education
Corporations
Credentialing
Government
Regulated industries

How to Stop Personal Information from Being Stockpiled, Sold, and Hacked

October 18, 2021

|

5 min read

Most proctoring platforms accumulate years of student identity data, session recordings, and behavioral information, and their privacy policies explicitly allow that data to be transferred in a business sale. This post examines the risk of data stockpiling, the 400,000-student breach that demonstrated what happens when that data is targeted, and how Integrity Advocate's data minimization approach eliminates the risk by not holding data that does not need to exist.

At the heart of genuine privacy protection is a concept that sounds straightforward: data minimization. If personal data is never collected in the first place, it cannot be leaked, hacked, or sold. It cannot be transferred to a buyer in an acquisition. It cannot appear on the dark web.

The problem is that data minimization runs directly against the financial incentives of most technology companies. User data increases company valuation. The more a platform collects and retains, the more it is worth to investors, acquirers, and advertisers. For proctoring companies specifically, years of student behavioral data, identity images, and session recordings represent a significant asset on the balance sheet.

That asset belongs to your learners. And most of them have no idea it is being accumulated.

What Proctoring Privacy Policies Actually Say

A review of privacy policies from proctoring companies around the world reveals language like this:

"In the event we sell some or all of our assets, it is possible your personal data could be one of the assets transferred to the purchaser."

"We may disclose your personal information to third parties if we are involved in a merger, acquisition, or sale of any or all of our business and/or our assets to a third party."

These are not edge cases buried in fine print. They are standard provisions in proctoring company privacy policies. They mean that the identity images, session recordings, and behavioral data your learners submitted for the purpose of completing an assessment can be transferred to an entirely different organization without their knowledge or consent.

Why Stockpiled Data Is a Security Risk

The volume of data retained and the length of time it is kept directly increases the likelihood that it will be used, intentionally or unintentionally, in ways that harm the individuals it belongs to.

Encryption certificates and security procedures are frequently cited as assurances. They are not guarantees. A well-known proctoring service was breached despite these assurances, resulting in years of data involving over 400,000 students being obtained illegally and shared on the dark web.

The lesson is not that security measures are useless. It is that the most effective security measure is not having the data to begin with. Why would anyone hack a system that holds nothing of value?

What Data Minimization Looks Like in Practice

Data minimization is not a policy position. It is an architectural decision. It means building a platform that:

  • Collects only what is required for the specific purpose of the session
  • Does not retain data beyond that purpose
  • Does not share identity credentials or session recordings unnecessarily
  • Deletes recordings automatically when the session is complete and no violations are found
  • Does not treat personal data as a transferable asset in any circumstance

Integrity Advocate deletes session recordings and identity images within 24 hours of completion for sessions with no violations. Personal data is not included as a transferable asset in any business transaction. As a Canadian company operating outside US jurisdiction, the data available on the vast majority of users in the unlikely event of a compelled disclosure would be limited to a name and a facial image represented as a string of code.

What to Look for When Choosing a Proctoring Vendor

Before selecting a proctoring provider, organizations should be able to answer these questions from the vendor's privacy policy and data processing documentation:

  • Does the privacy policy include personal data as a transferable asset in a sale or acquisition?
  • How long is session data retained and what triggers deletion?
  • Are identity credentials and session recordings shared with the client organization by default, or only when a specific violation requires it?
  • Does the vendor's business model depend on accumulated user data, or is data minimization built into how the platform works?

If the answers are not clearly documented, that is itself an answer.

{{post-cta}}

Privacy & Data Protection
Online Proctoring
No items found.
Smiling woman in gray polo shirt using a tablet with an ID badge clipped to her shirt.
To get support, please visit support center