
Resource Center
Research, guides, and real-world insights on online proctoring; helping your program deliver results that are fair, trustworthy, and defensible.
10M+
Assessments secured
Zero
Data breaches in 12+ years
98%
Client retention rate
120+
Resources published
Featured article

Trust by Evidence: A New Framework for Defensible AI Decisions
Integrity Advocate has released a new whitepaper, Trust by Evidence, introducing a framework that connects AI due process, learner rights, and credential security into one model for defensible AI-assisted assessment. This post walks through what the framework covers, why AI adoption alone no longer settles the integrity question, and links to the full whitepaper download.
Assessment integrity used to mean one thing: was the exam monitored? That question is no longer enough. AI now plays a role in identity verification, proctoring flags, authorship review, scoring, and credential validation, and each of those touchpoints can be challenged.
Confidence in an outcome isn't just about whether AI was accurate. It's about whether the decision it contributed to can be explained, reviewed, appealed, and verified after the fact.
As AI becomes embedded deeper into assessment, institutions are being asked a more pointed question: Can you defend the decision AI helped you make?
That question requires more than accurate technology. It requires a system.
In our latest whitepaper, Trust by Evidence, CEO Brandon A. Smith introduces a framework that connects AI due process, learner rights, and credential security into one model for defensible outcomes.
{{download-resource-cta}}
The Shift From AI Adoption to Defensible Outcomes
For the past several years, the conversation in education and credentialing has centered on adoption: which AI tools to use, how to deploy them, how accurate they are. That conversation is largely settled. Most programs already use AI somewhere in the assessment lifecycle.
What hasn't been settled is defensibility. When an AI-influenced decision is challenged, whether by a learner, an employer, or a regulator, an institution needs to answer a specific set of questions: was there notice, meaningful human review, supporting evidence, and a path to appeal? If any of those answers are unclear, the decision isn't defensible, and the institution is exposed right along with the learner.
The next major challenge in education isn't AI adoption. It's building outcomes that hold up under scrutiny.
Why Treating AI as a Single Safeguard Creates Risk
Many programs rely on AI to do one job: flag anomalies. That model treats a flag as a finding rather than a signal, and it breaks down under three conditions:
- No documented process exists for what happens after a flag is raised.
- Human review means approving the AI's output rather than independently evaluating it.
- There's no clear path for the learner to respond, and no record for the institution to point to later.
Any one of those gaps makes an outcome difficult to defend. Together, they create real exposure, not just to individual learners, but to the institution's accreditation standing, employer trust, and legal risk.
The Trust by Evidence Framework
The whitepaper introduces Trust by Evidence, a framework that connects three ideas typically treated in isolation:
AI Due Process: A fair, documented process for any consequential decision AI contributes to, so a flagged learner has an actual process to walk through rather than a black box to accept.
The Learner Rights Layer: Seven specific rights, to know, to meaningful human review, to explanation, to evidence, to appeal, to proportionality, and to verification, that turn "the system flagged it" into a decision an institution can explain and stand behind.
The Credential Security Trifecta: A secure chain of trust connecting learning, assessment, and credentialing, where a weakness in any one layer undermines the others.
Individually, each idea is familiar. Together, they hold up under scrutiny from everyone with a stake in the outcome: the learner, the institution, employers, regulators, and the public.
What a Defensible AI-Assisted Decision Looks Like
A defensible process doesn't rely on confidence in the algorithm. It provides an actual record. It lets an institution answer, with certainty:
- Was the individual notified that AI was involved?
- Did a qualified reviewer examine the evidence, not just the score?
- Could the individual respond before a consequence was applied?
- Is there a documented, time-bound appeal path?
- Can the outcome be explained to someone outside the institution?
These are governance questions as much as technical ones. Answering them well protects accreditation standing, employer trust, and learner confidence all at once.
What You'll Learn in the Whitepaper
The full whitepaper expands on:
- Why algorithmic due process, procedural justice, and automation bias research all point toward the same conclusion for education
- The Defensible Outcomes Responsibility Matrix, a governance tool for assigning clear ownership across vendors, institutions, and credential issuers
- The five-stage AI Appeals Framework, walked through with a real worked example of a contested proctoring flag
- Sector-specific guidance for K-12, higher education, workforce certification, and employers
- A candid discussion of the framework's limitations, including cost, scale, and surveillance risk
It's written for compliance leads, credentialing bodies, assessment teams, and program leaders responsible for the outcomes their institution has to stand behind.
{{post-cta}}
All resources

When Is "Online Training" Not Training in the Eyes of Regulators and Judges?
March 18, 2021
|
5 min read
Online training completion records are not the same as verified training, and courts are making that distinction with real consequences for employers. This post examines the R. v. Rose's Well Services case, the legal standard for due diligence in workforce training, and what organizations in high-risk industries need to do to ensure their online training holds up when it matters most.
Your organization spent money on an online safety training program. Employees completed it. You have completion records. You feel confident that if something goes wrong, you can demonstrate due diligence.
You may be wrong.
Courts and regulators are increasingly drawing a distinction between online training that can be verified and online training that cannot. If your platform cannot confirm who completed the training and whether they actually participated, that training may not count when it matters most.
The Standard Has Changed
Workforce training moved from the classroom to the screen gradually, then all at once. The cost savings are real, the scheduling flexibility is genuine, and for many organizations online training is now the only practical option for reaching a distributed workforce.
But the shift to online created a problem that classroom training never had: how do you prove that the right person completed the training, and that they actually engaged with it rather than clicking play and walking away?
In a physical classroom, an instructor can confirm attendance and participation. Online, without the right technology, you cannot. And in high-risk industries, that gap has real legal consequences.
What the Courts Have Said
The landmark case of R. v. Rose's Well Services Ltd. made this problem impossible to ignore. During the investigation, an employee admitted to completing online training on behalf of other employees. The employer had training records. The employer had completion data. None of it mattered, because the records could not demonstrate that the right people had actually done the training.
Courts determining fault in workplace incidents use due diligence as a central test. Did the employer take all reasonably practical steps to prevent the incident? Providing online training that cannot be verified does not satisfy that test.
The legal counsel of a multinational energy company put it plainly:
"Making our safety orientation and training available on the web and requesting that personnel take the training without the ability to provide documented evidence that personnel had actually completed the required safety orientation and training would, in my opinion, not be reviewed positively in an analysis of whether a company had satisfied its due diligence requirements in the event of an incident. Due diligence is a company's only defense against a strict liability offense."
That is not a hypothetical risk. It is a legal opinion from inside a major organization that had already thought carefully about what their online training program would look like in front of a judge.
The Three Risks Unverified Online Training Creates
Someone else completes the training
Without identity verification, there is no way to confirm that the person who registered for the training is the person who completed it. The Rose's Well Services case is not an isolated incident. Proxy completion is a known problem in workplace training, particularly for mandatory compliance courses that employees view as a checkbox rather than a learning opportunity.
The learner clicks through without engaging
Completion records show that a course was finished. They do not show that anyone watched it, read it, or absorbed any of it. A learner who clicks play, leaves the room, and returns to click through the assessment has a completion record identical to one who engaged with every module. In a regulatory investigation, that distinction matters.
The record cannot be defended
Even if training was completed legitimately, an employer who cannot provide documented evidence of who completed it and how they participated is in a weak position. Regulators and courts do not give credit for training that cannot be verified.
What Some Organizations Have Done in Response
Some organizations, including Spectra Energy, have responded to this problem by removing online training from high-risk content categories entirely, citing security concerns around confirming student attendance. That is a significant operational step backward.
The Chartered Professionals in Human Resources of Alberta has taken a different position, advising that technology exists that mitigates the issues facing compromised training by verifying both the identity and participation of trainees.
That technology exists. The question is whether your organization is using it.
What Verifiable Online Training Looks Like
Verified online training confirms three things that unverified training cannot:
- Identity — the person who registered is the person completing the training
- Participation — the learner was present and engaged throughout the session, not just logged in
- Documentation — a record exists that can be produced in a regulatory investigation or legal proceeding and withstand scrutiny
Integrity Advocate has worked with organizations across construction, mining, oil and gas, and other high-risk industries to help hundreds of thousands of personnel complete training online in a way that meets regulatory standards and holds up as evidence of due diligence.
The difference between online training that counts and online training that does not is not the content of the course. It is whether you can prove who did it and that they were there for it.
The Choice Every Employer Needs to Make
Organizations running online workforce training face a straightforward decision. Implement training without identity verification and participation monitoring, and accept the legal and regulatory exposure that comes with it. Or implement training with the technology to verify both, and be able to demonstrate due diligence if it ever matters in court.
With Integrity Advocate, that second option does not require rebuilding your training program. It works with your existing LMS and course content, adding the verification layer that transforms a completion record into a defensible document.
{{post-cta}}

The Hidden Liability in Every Online Safety Training Program
June 10, 2026
|
5 min read
Online safety training scaled compliance but it also created an accountability gap that most programs haven't closed. When an incident happens, a timestamp isn't enough; what protects your organization is a verified record proving the right person completed the training, with real engagement, that holds up under scrutiny.
Key Takeaways
- June is National Safety Month, emphasizing the urgency for effective workplace safety training verification due to ongoing workplace injuries.
- In 2024, there were 4,337 worker fatalities from preventable causes, highlighting the need for genuine training engagement.
- Online safety training lacks accountability, often reducing training completion to merely clicking through modules without true understanding.
- Verified training completion can significantly lower workplace injuries, with organizations reporting up to a 50% reduction when using structured programs.
- Integrity Advocate’s platform addresses the accountability gap by ensuring verified completion of safety training through human-reviewed proctoring.
June is National Safety Month. At Integrity Advocate, we work with organizations in regulated industries every day, the people responsible for making sure workers know what to do, and can prove it. This month always sharpens that focus.
The National Safety Council puts real numbers behind why this matters. According to NSC data, 4,337 workers died from preventable causes on the job in 2024. That is a 5% decrease from 2023. Progress is happening. But preventable means exactly that; those deaths did not have to happen.
The Bureau of Labor Statistics adds more weight to the picture. Employers reported 2.5 million nonfatal workplace injuries and illnesses in 2024, down 3.1% from the year prior. The top three causes resulting in days away from work were contact incidents, overexertion, and slips, trips, and falls.
Source: Avetta Insights and Impact Report, 2025
The Problem Most Safety Programs Do Not Talk About
Most organizations operating in regulated industries have mandatory safety training programs in place. Certifications, compliance courses, onboarding modules. The infrastructure exists. What is harder to answer is whether that training actually reaches the people it is meant to protect.
There is a meaningful difference between a worker who was assigned a course and a worker who completed it, genuinely engaged with it, and can be held accountable for what they learned. That difference tends to surface at the worst possible moment.
We know from learning research that retention drops sharply when people can move through content without real engagement. Clicking through slides, finishing an assessment with a second browser tab open, or having a coworker complete a course on someone else’s behalf are not fringe scenarios. They happen. And in environments where a certification is supposed to reflect real knowledge, that creates a serious liability.
When Training Records Fail, This Is What Follows
When an incident occurs and an organization cannot demonstrate that its workers received and understood the required training, the consequences go well beyond the immediate human cost:
- Injury
- OSHA citations
- Legal exposure
- Workers’ compensation claims
- Audit failures
The data on what verified, consistent compliance produces is not ambiguous. OSHA’s own research shows that organizations with structured safety and health programs consistently outperform their peers on injury rates, workers’ compensation costs, and audit outcomes. The gap between organizations that treat compliance as a system and those that treat it as a checkbox shows up in the numbers every time.
The question every safety and compliance leader should be asking is not just whether training was provided. It is whether they can prove it was completed by the right person, with genuine engagement, in a way that will hold up to scrutiny.
Which Industries Face the Highest Risk
The industries with the highest rates of workplace injury are also the ones most likely to have mandatory certification and compliance training requirements. That overlap is not a coincidence. It is the reason training accountability matters so much in these sectors.
In none of these industries is training optional or aspirational, it is a legal requirement, a liability protection, and in many cases the most direct line between a worker going home at the end of a shift and not.
The Accountability Gap That Online Training Created
As organizations moved safety training online, the efficiency gains were real. Training became more scalable, more cost-effective, and more accessible for distributed workforces. Those benefits are not going away. Online delivery is now the standard in most regulated industries.
But it introduced a problem that does not get discussed enough. In a classroom or on a job site, there is inherent accountability: someone is present, someone is watching. When training moves to a screen, that oversight disappears unless you deliberately build it back in. And most organizations have not.
The result is that completion becomes the goal rather than competency. Workers click through slides. Assessments get finished with a browser tab open on the side. In some cases, a coworker completes a course on behalf of someone else. These are not edge cases, they are compliance failures waiting to be discovered.
Attorneys handling workplace injury claims put it plainly: employees are often described as “experienced” or “shown once,” which in practice becomes a substitute for structured, verified training. In a legal context, when something goes wrong, the question is not whether someone had been around the job long enough. It is whether they were properly equipped to do it safely and consistently under pressure. That distinction is what gets tested in litigation.
What protects organizations from that exposure is verified completion. Not just a timestamp that says someone clicked through a module, but a confirmed record showing the right person completed the training, engaged with the material throughout, and did not have assistance. That level of documentation is what separates a defensible compliance program from one that looks fine on paper until it is tested.
At Integrity Advocate, this is the problem we built our platform to solve. Our proctoring is browser-based with no software installation required, which matters because safety training does not happen in controlled computer labs. It happens on job sites, in field offices, on shared devices, by workers who are not at corporate desks. Every AI flag in our system is reviewed by a human before any decision is made. No completion is rubber-stamped. Every record is built to withstand scrutiny.
For safety and compliance leaders, that is not a nice-to-have. It is the difference between a training program that protects your organization and one that only appears to.
What Defensible Safety Training Records Actually Look Like
Organizations with mature safety training programs share a few consistent characteristics that separate verified compliance from paper compliance.
Closing the Loop on Workplace Safety
The NSC’s theme for National Safety Month this year is Moving Safety Forward. Moving forward requires more than updated content libraries and awareness campaigns, it requires closing the loop between training delivery and training verification.
The research is clear on this. Organizations that sustain long-term compliance programs do not just check a box year over year. They build systems where training is taken seriously, completion is verified, and records can withstand scrutiny. The 45% lower fatality rate among organizations with more than a decade of consistent compliance engagement is not a coincidence. It is the compounding effect of accountability done right, over time.
The organizations that will see meaningful, sustained reductions in preventable injuries over the next decade are the ones treating training accountability as a safety mechanism and not just an administrative requirement.
We are proud to work alongside the safety professionals, compliance officers, and learning leaders doing that work every day. If your organization delivers safety-critical training online and you are not confident you can answer who completed it, when, and under what conditions, that is a gap worth taking seriously.
{{post-cta}}

AI-Only Proctoring Has a False Positive Problem. Here’s What That Costs Your Program.
June 24, 2026
|
5 min read
AI-only proctoring flags behavior. It doesn't evaluate it. When automated systems skip human review, wrongful invalidations follow, and programs are left with outcomes they can't defend.
A student finishes a high-stakes licensing exam. They followed every rule. The automated proctoring system flagged them anyway, unusual eye movement, a glance off-screen, a pause the algorithm found suspicious. This is a common example of AI proctoring false positives. The result gets invalidated.
No human ever looked at the session. No one evaluated whether any of it actually constituted cheating. The outcome went out the door based entirely on pattern-matching software making a call it was never designed to make.
That’s the AI proctoring false positive problem. And it isn’t a software glitch or an edge case. It’s what happens when automated flags are treated as decisions.
What Is a False Positive in Online Proctoring?
A false positive is when a proctoring system flags a test taker for suspected misconduct, and the flagged behavior wasn’t actually a violation.
This happens more than people expect. The behaviors that trigger automated flags are often completely ordinary:
- Looking away from the screen to think through a question
- Moving their lips while reading
- A family member walking past in the background
- Connectivity drops in low-bandwidth environments
- Disability-related behaviors covered under accommodations
A human reviewer with a few seconds of context can usually tell the difference. An algorithm can’t. It sees patterns. It doesn’t see people.
Why AI-Only Proctoring Keeps Generating False Positives
Automated proctoring systems do one thing well: they detect anomalies at scale. They’re fast, consistent, and cheap to run. What they can’t do is evaluate whether an anomaly matters.
Flagging is not deciding. Someone still has to look at what was flagged and make a judgment call about whether it rises to the level of misconduct. When AI-only platforms skip that step, when a flag becomes an outcome without any human ever weighing in, you get false positives baked into your process.
That’s the design flaw. The technology does what it was built to do. The problem is treating its output as something it was never meant to be.
An algorithm identifies anomalies. It doesn’t evaluate them.
The flag is not the decision. That part still requires a person.
What False Positives Actually Cost a Program
The downstream effects of a wrongful flag aren’t abstract. They show up in real ways.
Results that can’t be defended: When an outcome is invalidated based on an automated flag alone, you have no documented judgment to point to, just an algorithm’s output. If that result is challenged in an appeal, a grievance, or a legal proceeding, “the system flagged it” isn’t a sufficient answer.
Liability exposure: Organizations issuing regulated credentials in healthcare, food safety, financial services, and similar fields face real consequences when they can’t substantiate an outcome. One indefensible invalidation can undo years of program credibility.
Trust that erodes quietly: Candidates who feel unfairly flagged, or watch a peer get penalized without explanation, lose confidence in the program. Stanford research published in Cell Press found that over half of writing samples from non-native English speakers were misclassified as AI-generated by automated detectors, while native samples were identified accurately. The same bias risk exists in proctoring systems that act on flags without human review.
Compliance exposure: Privacy regulations in Canada, the EU, and the US restrict what behavioral and biometric data can be collected and how it can be used. Automated systems that collect broadly and act without human review create audit risk, especially where proportionality is a legal requirement.
The AI Cheating Problem Makes This Harder, Not Easier
If false positives were already a challenge with conventional exam conditions, add AI-assisted cheating to the picture and automated proctoring’s limitations get worse.
AI cheating tools, such as answer generators, paraphrasing engines, and real-time lookup, leave no behavioral fingerprint. There’s no eye movement pattern to detect, no device anomaly, no audio signal. A candidate using an AI tool looks identical to one who simply knows the material.
Automated systems have no way to distinguish between the two. Some platforms compensate by flagging more aggressively — which only increases false positive rates. JISC’s 2025 guidance on AI detection found that even a 1% false positive rate across a large institution could generate thousands of wrongful accusations annually, without catching a single genuine case of AI-assisted cheating.
The only layer that can evaluate what an algorithm can’t is a person reviewing the session with context. That’s not a workaround. That’s the whole point.
Which Proctoring Providers Combine AI Monitoring with Human Review?
This has become one of the most common questions from programs evaluating proctoring platforms, and the answer depends heavily on how you ask it.
Many platforms offer human review. Some make it an optional add-on. Some include it at higher tiers. A few build it in by default. The gap between those options is significant: if human review is optional, the vast majority of flagged sessions will never receive it. Flags become outcomes. The problem persists.
The question worth asking isn’t “does this platform offer human review?” It’s: “Does every flagged session get reviewed by a person before any outcome is issued, at every price point, without paying extra?”
How Integrity Advocate Handles This
The platform is built on one principle that addresses the AI proctoring false positive problem directly: a flag is not a decision.
Every session that gets flagged is reviewed by a trained human reviewer before any outcome goes out. Not as a premium feature. Not as an upgrade. As the default, at every price point, for every client.
That review produces something an automated system never can: a documented judgment. A record of what was observed, what was evaluated, and what conclusion was reached. When a result gets challenged, and sometimes they do, that record is what the program defends with.
A few other things worth knowing:
- No download or extension required: candidates start on any device or browser, which eliminates a whole category of friction-related anomalies that trigger false flags
- Privacy-first data collection: only what’s necessary for the stakes involved, GDPR and PIPEDA compliant, with sensitive data deleted within 24 hours
- Full lifecycle coverage: identity verification before the exam, monitoring during, validated results after
- Fewer than 1% of test takers ever need support: a reasonable proxy for how well the experience actually works
{{post-cta}}

Is Your Online Proctoring Platform FERPA Compliant? What US Educational Institutions Need to Know
February 10, 2021
|
5 min read
FERPA governs how US educational institutions and their vendors handle student education records, and online proctoring data tied to specific students falls squarely within its scope. This guide explains how FERPA applies to proctoring vendors, what institutions must look for to maintain compliance, and how Integrity Advocate's data minimization, human review, and 24-hour deletion practices support your FERPA obligations.
The Family Educational Rights and Privacy Act has governed student education records in the United States since 1974. For most of its history, compliance meant controlling access to paper files and transcripts. Today, it means carefully evaluating every technology platform that touches student data, including online proctoring.
If your institution is subject to FERPA and you use online proctoring, the data your proctoring vendor collects may constitute part of a student's education record. That makes vendor selection a FERPA decision, not just a technology decision.
This guide explains what FERPA requires, how it applies to online proctoring, and how Integrity Advocate is built to support your institution's compliance obligations.
What Is FERPA and Who Does It Apply To?
The Family Educational Rights and Privacy Act is a United States federal law that protects the privacy of personally identifiable information in students' education records. It applies to any educational institution that receives funding from the US Department of Education, which includes virtually all public schools, colleges, and universities.
FERPA gives students two primary rights. First, the right to access their own education records. Second, the right to control the disclosure of those records to third parties. Institutions that violate FERPA risk losing federal funding.
Under FERPA, an education record includes any record directly related to a student that is maintained by an institution or a party acting on its behalf. When a proctoring platform collects session data, identity images, and behavioral flags tied to a specific student, that data can fall within the definition of an education record.
How FERPA Applies to Online Proctoring
FERPA addresses proctoring vendors through the concept of a school official with legitimate educational interest. Institutions can share student education records with third-party vendors without explicit student consent if the vendor meets specific criteria:
- The vendor performs a service or function that the institution would otherwise perform itself
- The vendor is under the direct control of the institution with respect to the use and maintenance of education records
- The vendor uses the data only for the purposes for which the disclosure was made
- The vendor does not re-disclose the data without authorization
This means your proctoring vendor must operate as a legitimate school official under your institution's direction, not as an independent party free to use student data for its own purposes.
Proctoring vendors that use student session data for product development, algorithmic training, secondary research, or any purpose beyond delivering the proctoring service are operating outside what FERPA permits.
What FERPA Requires of Proctoring Vendors
For a proctoring vendor to support rather than undermine your FERPA compliance, they must be able to demonstrate the following:
Data Use Limitation
Student data collected during proctoring sessions must be used only for the purpose of delivering the proctoring service. It cannot be sold, transferred, or used for any secondary purpose without explicit institutional authorization.
Integrity Advocate uses session data exclusively for assessment integrity purposes. Student data is not sold, leased, repurposed for research, or used to train algorithms beyond the scope of the specific session it was collected for.
No Unauthorized Re-disclosure
FERPA prohibits vendors from re-disclosing student education records to third parties without authorization from the institution.
Integrity Advocate does not disclose session data to any third party beyond the institution that deployed the assessment. When a session is flagged, only the minimum information required to document the specific concern is shared. Data from sessions with no violations is not shared at all.
Collection Limitation
While FERPA does not specify collection limits as precisely as some privacy laws, the requirement that vendors act under institutional direction and use data only for authorized purposes creates an implicit obligation to collect only what is necessary.
Integrity Advocate collects only the data required to verify a student's identity and monitor their session. Browser history, desktop file contents, and program inventories are not collected. If a student is not permitted to access other tabs during their exam, Integrity Advocate monitors that and nothing more.
Data Security
Institutions are responsible for ensuring that the vendors they work with protect student data with appropriate security measures.
Integrity Advocate uses 256-bit encryption in transit and at rest, stores data on AWS infrastructure in Montreal by default, and has maintained zero data breaches across 12 or more years of operation. The platform holds SOC 2 certification, providing independent verification of security controls. Student identity images and session recordings are deleted within 24 hours of session completion for sessions with no violations.
Student Notification
FERPA gives students the right to know what information is maintained about them. Integrity Advocate proactively addresses this by sending every student an email after their completed and reviewed session, detailing what data was retained and what conclusions were drawn.
FERPA and the Annual Notification Requirement
FERPA requires institutions to notify students annually of their rights under the Act. If your institution uses online proctoring, that notification should include information about how proctoring session data is handled, how long it is retained, and what rights students have to access it.
Working with a proctoring vendor that provides clear, documented data practices makes this notification straightforward. Working with a vendor whose data practices are opaque or poorly documented creates a disclosure problem your institution has to solve on its own.
FERPA in the Context of AI-Based Proctoring
One area where FERPA compliance is increasingly relevant is the use of automated AI systems to make decisions about students based on session data. When an algorithm flags a student for suspected misconduct and that flag becomes part of the student's record, the accuracy of that flag matters under FERPA.
Integrity Advocate's human review process directly addresses this concern. Every automated finding is reviewed by a trained person before any conclusion is recorded. Students are not penalized based on an algorithm alone, and the information that enters any record reflects a reviewed, documented judgment rather than an automated output.
FERPA Is a Floor, Not a Ceiling
FERPA sets minimum standards for the protection of student education records. Institutions in states with stronger privacy laws, or those serving students subject to GDPR, PIPEDA, or other frameworks, need to meet the higher standard where applicable.
Integrity Advocate is built to support compliance across multiple frameworks simultaneously. The same Privacy by Design architecture that meets FERPA's requirements also supports PIPEDA, FIPPA, PIPA, POPIA, and GDPR, making it a consistent choice for institutions with a geographically diverse student population.
{{post-cta}}

Is Your Online Proctoring Platform POPIA Compliant? What South African Organizations Need to Know
February 9, 2021
|
5 min read
POPIA has been fully enforceable in South Africa since July 2021, and online proctoring platforms that collect identity and biometric data from South African test takers must meet its eight conditions for lawful processing. This guide walks through each condition and explains how Integrity Advocate is built to meet them, from collection limitation and informed consent to 24-hour biometric deletion, human review, and proactive learner transparency.
If your organization operates in South Africa or processes the personal information of South African data subjects, the Protection of Personal Information Act applies to you. POPIA is South Africa's comprehensive data privacy law, and since the Information Regulator began enforcement on July 1, 2021, non-compliance carries real consequences including fines of up to R10 million and potential criminal liability.
For organizations using online proctoring, POPIA is directly relevant. Proctoring platforms collect identity information, facial images, session recordings, and behavioral data from every test taker. That is personal information under POPIA's definition, and how it is collected, used, stored, and deleted must meet the Act's requirements.
This guide explains what POPIA requires, how it applies to online proctoring, and how Integrity Advocate is built to support your compliance obligations.
What Is POPIA and Who Does It Apply To?
The Protection of Personal Information Act was signed into law in 2013 and came into full effect on July 1, 2021. It governs how both public and private bodies process personal information in the course of their activities. POPIA applies to any organization that processes personal information of South African data subjects, regardless of whether the organization is based in South Africa.
For online proctoring specifically, POPIA applies to any personal information collected from South African test takers, including:
- Names and identity verification data
- Facial images and biometric confirmation
- Session recordings and behavioral monitoring data
- Device and browser activity during an assessment
The Act places accountability on both the organization deploying the proctoring platform and the platform itself. If your vendor does not meet POPIA standards, your organization shares the compliance exposure.
POPIA's Eight Conditions for Lawful Processing and How Integrity Advocate Meets Each One
POPIA organizes its requirements around eight conditions for lawful processing of personal information.
1. Accountability
The responsible party must ensure that the conditions for lawful processing are met at all times.
Integrity Advocate's platform is built around a documented privacy management framework. Data governance responsibilities are clearly defined, and clients receive the documentation they need to demonstrate that their proctoring vendor meets POPIA's accountability requirements.
2. Processing Limitation
Personal information may only be processed in a lawful manner and in a way that does not infringe on the privacy of the data subject. Collection must be adequate, relevant, and not excessive.
Integrity Advocate collects only what is required to verify a learner's identity and monitor their assessment session. If a learner is not permitted to access other browser tabs during their session, Integrity Advocate monitors exactly that and nothing more. Browsing history, desktop file contents, and program lists are not collected.
3. Purpose Specification
Personal information must be collected for a specific, explicitly defined, and lawful purpose, and data subjects must be made aware of that purpose before collection.
Integrity Advocate requires every test taker to review and actively accept a privacy policy before any personal information is collected. The policy explains what data is collected, why it is collected, and how it will be used and deleted. It is available in over 70 languages to ensure genuine informed consent across South Africa's multilingual population.
4. Further Processing Limitation
Personal information may not be processed for a purpose that is incompatible with the purpose for which it was originally collected.
Integrity Advocate uses session data exclusively for the purpose of assessment integrity. Data is never repurposed for advertising, research, or any secondary commercial use. It is not sold, leased, or transferred to any third party for purposes beyond what the assessment requires.
5. Information Quality
The responsible party must take reasonably practicable steps to ensure that personal information is complete, accurate, and not misleading.
Integrity Advocate addresses this through human review. Every flagged session is assessed by a trained reviewer before any finding is recorded. This ensures that the information your organization acts on reflects an accurate, contextually reviewed judgment rather than an automated algorithmic flag that may be incorrect.
6. Openness
Data subjects must be notified of the collection of their personal information, and the responsible party must maintain documentation of all processing activities.
Integrity Advocate notifies every test taker of data collection before their session begins through the mandatory privacy policy acceptance step. After each completed and reviewed session, Integrity Advocate sends every test taker an email detailing what information was retained and what conclusions were drawn. This proactive transparency eliminates the need for formal access requests and supports the responsible party's documentation obligations.
7. Security Safeguards
The responsible party must secure the integrity and confidentiality of personal information through appropriate technical and organizational measures.
Integrity Advocate uses 256-bit encryption for all data in transit and at rest, stores data on AWS infrastructure in Montreal by default, and has maintained zero data breaches across 12 or more years of operation. The platform holds SOC 2 certification, providing independent third-party verification of security controls. Session recordings and identity images of compliant users are deleted within 24 hours of session completion. Personal data that does not exist cannot be compromised.
8. Data Subject Participation
Data subjects have the right to request access to their personal information, to request corrections, and to object to the processing of their information.
Integrity Advocate proactively eliminates the need for formal access requests by notifying every test taker by email after their session is reviewed. The notification details what was retained and what was found. Where a test taker believes information is inaccurate, the human review process and documented session record provide the basis for a meaningful correction process.
Special Personal Information and Online Proctoring
POPIA places additional restrictions on the processing of special personal information, which includes biometric data, health information, and information about children. Online proctoring platforms that use facial recognition or biometric verification to confirm identity are processing special personal information under POPIA's definition.
Integrity Advocate's approach to biometric data is proportionate and limited. Facial images used for identity verification are deleted within 24 hours of session completion for compliant users. Biometric data is not retained beyond its immediate purpose, is not shared with third parties, and is not used for any purpose other than confirming the identity of the person completing the assessment.
The Information Regulator and Enforcement
South Africa's Information Regulator has the authority to investigate complaints, conduct audits, issue compliance notices, and impose penalties. Administrative fines under POPIA can reach R10 million, and certain offences carry criminal liability including imprisonment.
Organizations that use proctoring platforms not built to meet POPIA's requirements are exposed. The accountability obligation rests with the responsible party, meaning your organization, not just your vendor.
Built for Global Privacy Compliance
Integrity Advocate is designed to support compliance across multiple privacy frameworks simultaneously. Whether your organization operates under POPIA in South Africa, GDPR in Europe, PIPEDA in Canada, or FIPPA in Ontario, the same foundational Privacy by Design architecture applies: collect only what is necessary, use it only for its stated purpose, protect it to the highest standard, and delete it when it is no longer needed.
{{post-cta}}

Is Your Ontario Institution FIPPA Compliant? What Online Proctoring Providers Need to Know
February 9, 2021
|
5 min read
Ontario universities, colleges, hospitals, and designated agencies are subject to FIPPA, and every vendor handling learner personal information must meet its standards. This guide walks through FIPPA's seven key principles and explains how Integrity Advocate meets each one, from limiting collection to automated data deletion, proactive learner notification, and human review that limits what gets shared with institutions.
If your organization is a university, college, hospital, or designated agency in Ontario, the Freedom of Information and Protection of Privacy Act applies to every vendor you work with that handles personal information, including your online proctoring platform.
FIPPA has governed Ontario institutions since June 10, 2006. It establishes a uniform regulatory framework for how personal information is collected, used, disclosed, retained, and destroyed. For online proctoring, which collects identity data, session recordings, and behavioral information from learners, FIPPA compliance is not optional. It is a condition of operating within Ontario's public sector ecosystem.
This guide walks through FIPPA's seven key principles and explains exactly how Integrity Advocate meets each one.
What Is FIPPA and Who Does It Apply To?
The Freedom of Information and Protection of Privacy Act serves two purposes. First, it gives individuals the right to access information held by Ontario government institutions. Second, and more relevant to online proctoring, it protects the privacy of individuals by limiting how institutions and their service providers collect, use, and disclose personal information.
FIPPA applies to all Ontario government ministries and any agency, board, commission, corporation, or other body designated as an institution under the regulations. In practice, this includes Ontario universities, colleges, hospitals, and a broad range of publicly designated organizations.
When an Ontario institution uses an online proctoring platform, the vendor handling learner data becomes accountable to FIPPA standards. Choosing a vendor that does not meet those standards creates compliance risk for your institution.
Why FIPPA Compliance Matters for Online Proctoring
FIPPA places emphasis on Privacy by Design, meaning privacy protections must be built into information systems from the ground up, not layered on after the fact. For proctoring platforms, this means the architecture itself must reflect the principles of collection limitation, purpose restriction, and timely data destruction.
Organizations using proctoring vendors that collect more data than necessary, retain it longer than required, or share it without appropriate controls are exposed to FIPPA investigations, Information and Privacy Commissioner findings, and reputational risk with learners who have a right to know how their data is handled.
FIPPA's Seven Key Principles and How Integrity Advocate Meets Each One
1. Authority to Collect and Manner of Collection
FIPPA limits the collection of personal information to authorized activities and requires that collection come directly from the individual except in limited circumstances.
Integrity Advocate collects only what is required to verify a learner's identity and monitor their session. If a learner is not permitted to access other browser tabs during their assessment, Integrity Advocate monitors exactly that and nothing more. Other proctoring providers routinely collect browsing history, desktop file lists, and program inventories that go well beyond what any assessment requires.
The only data Integrity Advocate receives from sources other than the learner directly is the learner's first name, last name, and email address, which comes from the Learning Management System solely for the purposes of identity verification and session communication.
2. Notice Requirements
FIPPA requires that individuals be informed of the collection of their personal information before it occurs.
Integrity Advocate presents its privacy policy to every user at the start of every session. Users must actively accept the policy before any personal information is collected. The privacy policy and session instructions are available in dozens of languages to ensure that consent is genuinely informed, regardless of the learner's primary language.
3. Proper Use and Disclosure
FIPPA limits the use and controls the sharing of personal information to authorized activities only.
Integrity Advocate provides a full human review service specifically designed to limit what gets shared with client organizations. When a session produces no violations, no session media is shared. When a session is flagged, only the minimum information required to document the specific concern is shared, with unrelated personal information redacted. This is the opposite of how most proctoring platforms operate, where full session recordings are routinely handed over to institutions regardless of whether a violation occurred.
4. Accuracy
FIPPA requires that processes be in place to keep personal information accurate.
Integrity Advocate session findings represent a documented snapshot of what occurred during a specific assessment. Because findings are based on human review rather than automated algorithmic flags, the information recorded is assessed for accuracy before it becomes part of any record. Session data does not change over time, which eliminates the risk of drift or corruption that can affect systems relying on ongoing data updates.
5. Retention
FIPPA requires that individuals be able to obtain access to their own personal information for a defined period.
Integrity Advocate eliminates the need for learners to submit formal access requests by proactively notifying every user by email after their session is completed and reviewed. The notification details what information was retained beyond the session and what conclusions were drawn. Learners know exactly what is on file about them without having to ask.
6. Security
FIPPA requires that personal information be kept secure and confidential.
Integrity Advocate uses 256-bit encryption for all data in transit and at rest, stores data on AWS infrastructure in Montreal by default, and has maintained zero data breaches across 12 or more years of operation. The platform holds SOC 2 certification, providing independent third-party verification of security controls. Compliant user identification images and session media are deleted within 24 hours of session completion. Personal data that does not exist cannot be breached.
7. Disposal and Destruction
FIPPA requires that the disposal and destruction of personal information be authorized and secure.
Every piece of personal data collected by Integrity Advocate carries a programmatically applied time-to-live setting. When a session is complete, deletion occurs automatically and exactly as communicated to the learner. There is no manual process, no exception handling, and no risk of data persisting beyond its intended retention period.
Built for Ontario Institutions
FIPPA is one of several privacy frameworks that Ontario institutions need to navigate. Depending on the nature of your program and the location of your learners, PIPEDA, PIPA, GDPR, and FERPA may also apply. Integrity Advocate is built to support compliance across multiple frameworks simultaneously, with the same foundational Privacy by Design architecture underlying each.
For Ontario institutions specifically, Integrity Advocate provides the documentation, audit trail, and data handling practices your compliance and legal teams need to demonstrate that your proctoring vendor meets FIPPA's standards.
{{post-cta}}

Why Most Remote Proctoring Companies Don't Want You to Read Their Privacy Policy
September 15, 2020
|
5 min read
Most proctoring companies collect far more personal data than test takers realize, and their privacy policies say so explicitly. This post breaks down what proctoring providers are actually collecting, shares four real privacy policy excerpts that should concern any organization, and explains how Integrity Advocate's Privacy by Design approach limits collection, mandates deletion, and keeps learner data out of the hands of third parties.
Consider two scenarios.
In the first, security cameras in a school record a student walking through the hallways and interacting with friends. The school stores the recording indefinitely as part of the student record and shares it with other organizations.
That feels wrong.
In the second scenario, cameras capture the same student bullying a younger student. Only the portion of the recording showing the behavior is retained, and it is shared with the organizations responsible for taking appropriate action.
That feels reasonable. There is a legitimate purpose, a proportionate response, and a clear limit on what gets shared and why.
Remote proctoring technology is an extension of the same principle. The question is whether the companies providing it are applying that principle, or ignoring it entirely.
What Proctoring Companies Are Actually Collecting
Most people assume online proctoring captures what it needs to verify identity and monitor an assessment session. The reality, based on the privacy policies of many proctoring providers, is considerably broader.
Many proctoring services collect, intentionally and unintentionally, personal information that includes:
- Social security numbers, driver's license numbers, and passport numbers
- Biometric information including facial geometry, physiological and behavioral characteristics, and genetic data
- IP addresses and device identifiers
- Full browsing history, search history, and records of interactions with websites and applications
- Medical information including physical and mental health conditions
- Drug use history and political affiliations
- Footage of children, spouses, and other individuals who happen to be in the same space as the person being proctored
This is not a hypothetical. This is what the privacy policies say.
Four Things You Will Find in Proctoring Privacy Policies
The following are real excerpts from proctoring company privacy policies currently in use. Read them carefully.
1. "By accessing and using our Services, you consent to allow free exchange of proctoring information between [Proctoring Service Company] and your educational institution. We, or vendors on our behalf, may track the websites you visited before and after our websites as part of the traffic data described above for our internal business purposes."
2. "If your institution has consented, we may also use third-party solutions to process selected data."
3. "We may disclose information, including video and audio recording of your exam session, to your educational institution/certifying entity upon request. Your information may be sold or transferred as part of that transaction."
4. "We cannot ensure or warrant the security of any information you transmit to us or store on the Services, and you do so at your own risk."
Students and workers taking online assessments are required to submit to proctoring. They do not have the option to choose a different provider or opt out. That disparity in power makes these policies more than a legal formality. It makes them an ethical issue.
Why Privacy by Design Is the Only Acceptable Standard
The school camera analogy holds here too. We expect schools to share footage of students only when there is a legitimate reason and only to the extent necessary. We should expect the same from proctoring technology.
Privacy by Design is not a compliance label. It is an architectural commitment — the decision to build data minimization, purpose limitation, and deletion into the product from the start, rather than adding privacy language to a policy document after the fact.
That is how Integrity Advocate is built.
What Integrity Advocate Collects and What It Deletes
Integrity Advocate collects only what is necessary to verify a learner's identity and confirm whether they followed the rules set by the organization running the assessment. Nothing more.
The approach is similar to how PayPal operates as an intermediary in a financial transaction, protecting both parties without either side needing to expose more than is required. Integrity Advocate sits between the organization and the test taker's personal data, sharing only what is needed and only when there is a documented reason.
In practice, that means:
- With the exception of a single identity photo, all recordings of the user and their desktop are deleted within 24 hours if no rule violations are found
- When a session is flagged, only the minimum information required to document the concern is shared with the organization
- As a Canadian company, Integrity Advocate operates outside US government jurisdiction. In the unlikely event of a compelled disclosure, the data available on the vast majority of users would be limited to a first and last name and a facial image represented as a string of code
Read the privacy policies of other proctoring providers and ask how many of them can say the same.
What to Look for Before Choosing a Proctoring Provider
Before signing a contract with any proctoring platform, your organization should be able to answer the following questions from their privacy policy and data processing documentation:
- What personal information is collected, and is collection limited to what is necessary?
- Is data sold, transferred, or shared with third parties beyond the assessment organization?
- How long is data retained, and what triggers deletion?
- Is the vendor subject to US government data requests, and what would they be required to disclose?
- Is there a human review process, or are automated findings shared directly with the institution?
If the answers are not clearly documented, that is an answer in itself.
{{post-cta}}

Is Your Online Proctoring Platform PIPA Compliant? What BC Organizations Need to Know
August 25, 2020
|
5 min read
BC's Personal Information Protection Act places specific obligations on organizations that collect personal information from test takers, and online proctoring platforms fall squarely within its scope. This guide walks through what PIPA requires across collection, use, disclosure, and retention, and explains how Integrity Advocate is built to meet each obligation, from data minimization and meaningful consent to human review and proactive transparency with test takers.
If your organization operates in British Columbia and uses online proctoring, the Personal Information Protection Act applies to you. PIPA is BC's provincial private-sector privacy law, and it governs how organizations collect, use, disclose, and retain personal information, including the identity and behavioral data that proctoring platforms collect from every test taker.
Unlike federal PIPEDA, which applies across most of Canada, PIPA is BC-specific legislation with its own requirements and its own Office of the Information and Privacy Commissioner (OIPC) for enforcement. Organizations operating in BC cannot assume PIPEDA compliance covers their PIPA obligations. The two frameworks are substantially similar but not identical.
This guide explains what PIPA requires, how it applies to online proctoring, and how Integrity Advocate is built to support your compliance obligations.
What Is PIPA and Who Does It Apply To?
The Personal Information Protection Act came into force in British Columbia on January 1, 2004. It applies to private-sector organizations operating in BC that collect, use, or disclose personal information in the course of their activities.
For organizations using online proctoring, PIPA applies to any personal information collected from BC-based test takers, including:
- Name and identity verification data
- Facial images and biometric confirmation
- Session recordings and behavioral monitoring data
- Device and browser activity during an assessment
The law places clear obligations on both the organization deploying the proctoring platform and the platform itself. Choosing a vendor that is not built with PIPA in mind creates compliance exposure for your organization.
What PIPA Requires
PIPA is organized around four core obligations that mirror the intent of federal privacy law while establishing BC-specific standards.
1. Collection of Personal Information
Organizations may only collect personal information that a reasonable person would consider appropriate in the circumstances. Collection must be limited to what is necessary for the identified purpose, and individuals must be notified of what is being collected and why before collection begins.
Integrity Advocate collects only the data required to verify identity and monitor assessment sessions. Test takers are informed of what data is being collected and for what purpose before their session begins, and consent is obtained as a documented step in the onboarding process.
2. Use of Personal Information
Personal information may only be used for the purpose for which it was collected, or for a directly related purpose the individual would reasonably expect.
Integrity Advocate uses session data exclusively for the purpose of assessment integrity. Data is not repurposed, analyzed for secondary uses, or shared beyond what is required to substantiate a specific finding. When a session is flagged, only the minimum information required to document the concern is shared with the organization.
3. Disclosure of Personal Information
Organizations may only disclose personal information with the consent of the individual or in specific circumstances defined by PIPA. Disclosure to third parties requires the same standard of care as the original collection.
Integrity Advocate does not sell, lease, or transfer personal data to any third party for commercial purposes. Session data is shared only with the organization that deployed the assessment, and only to the extent required for the review of flagged sessions.
4. Retention and Disposal of Personal Information
Personal information must not be retained longer than necessary to fulfill the purpose for which it was collected. Organizations must have a defined retention schedule and dispose of personal information securely.
Integrity Advocate deletes sensitive identity data, including facial images and government-issued ID, within 24 hours of session completion unless retention is required for an active dispute. Retention schedules are defined and documented, and disposal is handled securely.
Accuracy and the Case for Human Review
PIPA requires that personal information used to make decisions about individuals be as accurate and complete as possible. For online proctoring, this principle has direct implications for how session flags are handled.
Fully automated proctoring systems generate flags based on algorithmic pattern detection. If that flag is inaccurate, the decision made on the basis of it is inaccurate, and the organization is exposed both to a PIPA accuracy challenge and to a fairness complaint from the test taker.
Integrity Advocate addresses this through human review. Every flagged session is assessed by a trained reviewer before any outcome is recorded. That means the information your organization acts on reflects a reasoned judgment, not an automated signal, and is far more likely to meet PIPA's accuracy standard in the event of a challenge.
Security Safeguards
PIPA requires organizations to protect personal information using security measures appropriate to the sensitivity of the data. For biometric and identity data, that threshold is high.
Integrity Advocate uses 256-bit encryption in transit and at rest, stores data on AWS infrastructure in Montreal by default, and has maintained zero data breaches across 12 or more years of operation. The platform holds SOC 2 certification, providing independent verification of security controls.
Individual Rights Under PIPA
PIPA gives BC residents the right to access their personal information and to request corrections where information is inaccurate or incomplete. Organizations must respond to access requests within 30 business days.
Integrity Advocate proactively addresses this by notifying test takers by email after each completed and reviewed session. The notification details what information was retained and what conclusions were drawn, reducing the likelihood of formal access requests and creating a transparent record that supports both individual rights and organizational accountability.
The OIPC and Enforcement
The Office of the Information and Privacy Commissioner for British Columbia oversees PIPA compliance and has the authority to investigate complaints, conduct audits, and order organizations to take corrective action. The OIPC has been active in the technology and education sectors and has issued findings against organizations that failed to meet PIPA's standards for consent, collection limitation, and data security.
Organizations using non-compliant proctoring platforms carry real exposure. The liability does not rest solely with the vendor. If your platform collects more data than is necessary, fails to obtain meaningful consent, or retains data beyond its purpose, your organization is accountable.
Built for Privacy Across Jurisdictions
Integrity Advocate is designed to support compliance across multiple privacy frameworks simultaneously. Whether your organization operates under PIPA in BC, PIPEDA federally, GDPR for international learners, or FERPA for US-based education, the same foundational principles apply: collect only what is necessary, use it only for its stated purpose, protect it properly, and delete it when it is no longer needed.
That is not a compliance checklist. It is how the platform is built.
Want to see how Integrity Advocate supports your PIPA obligations in practice?
Book a Demo
{{post-cta}}

How the University College Dublin Achieved a Triple Win with Online Proctoring
August 19, 2020
|
5 min read
When the University College Dublin moved examinations online during the pandemic, they chose to look at the entire assessment process rather than simply adding monitoring to an existing exam format. Working with Integrity Advocate, UCD achieved a triple win: maintained academic integrity, a low-friction student experience, and a manageable implementation for faculty and administration. Fewer than 2% of students required support and there was not a single complaint.
When the COVID-19 pandemic forced higher education institutions to move assessments online almost overnight, most focused on one question: how do we stop cheating? The University College Dublin asked a better one: how do we make this work well for everyone?
The answer produced what UCD called a triple win: a proctoring outcome that served the institution, the students, and the faculty simultaneously. Here is how they got there.
The Challenge
UCD is Ireland's largest university, with over 33,000 students and a long-standing reputation for academic excellence. Maintaining that reputation meant that moving examinations online could not come at the cost of assessment integrity. But UCD also understood that how they proctored those exams would reflect directly on the student experience they were known for.
In-person examinations had always relied on physical controls: exam centers, invigilators, student ID checks at the door, and a clear prohibition on unauthorized materials or devices. Replicating that environment online without creating friction, privacy concerns, or an invasive experience for students was the core challenge.
UCD had additional considerations that many institutions overlook. They were unwilling to require students to install monitoring software on personal devices. They were concerned about the stress that aggressive proctoring creates. And they wanted a solution that would hold up to scrutiny on accessibility and privacy grounds.
The Approach: Looking at the Whole Assessment, Not Just the Monitoring
Rather than simply dropping a proctoring tool on top of their existing exam process, UCD worked with Integrity Advocate to look at the entire assessment lifecycle.
That meant evaluating the manner of assessment itself, not just the monitoring layer. It meant considering how questions were structured for a remote environment. It meant thinking carefully about student communication before, during, and after the exam. And it meant choosing a proctoring approach built on reasonable discretion rather than rigid algorithmic enforcement.
UCD also prioritized identity authentication from the start, replicating the student ID check that had always been part of in-person examination, but in a way that was proportionate and privacy-respecting for a home environment.
"Every flagged session at Integrity Advocate is reviewed by a trained human before any determination is made. The algorithm identifies. The reviewer decides. That's not a nice-to-have — it's the only way to produce outcomes programs can stand behind."
Chris Viso
Founder - My Food Service License
The Outcome: Less Than 2% Support Rate, Zero Complaints
The results were measurable and clear.
After completing online proctored assessments, Integrity Advocate gathered feedback from both students and faculty. The student-facing communication, combined with the use of reasonable discretion rather than automated algorithmic flags, produced an assessment experience where fewer than 2% of students reached out for support. There was not a single complaint received.
For a rollout of this scale, at one of Europe's largest universities, that is a remarkable outcome. It reflects what happens when the assessment experience is designed with the student in mind from the start, rather than treated as a control problem to be solved after the fact.
The Triple Win
The UCD implementation demonstrated that online proctoring done well does not require tradeoffs. It can deliver across all three dimensions simultaneously.
For the institution: Assessment integrity was maintained at the standard UCD's reputation demands. Results are documented, human-reviewed, and defensible.
For students: The experience was low-friction, privacy-respecting, and did not require installing software on personal devices. Students completed exams in a comfortable environment without unnecessary stress or invasive monitoring.
For faculty and administration: The process was manageable, support demand was minimal, and the transition did not create the operational burden that many institutions feared.
What UCD's Experience Means for Other Institutions
Since the shift to remote assessment during the pandemic, many higher education institutions have made online proctoring a permanent part of their strategy. The reasons are practical: reduced facility costs, greater scheduling flexibility, the ability to reach international students without travel constraints, and a more accessible experience for students who face barriers to in-person examination.
But the UCD experience points to something more important than logistics. The difference between a proctoring implementation that works and one that generates complaints, disputes, and staff burden comes down to approach.
Implementing online proctoring is not a simple process swap. It requires thinking about the impact on students, faculty, and administration from the start. It requires a partner willing to work through that process collaboratively, not just hand over a platform and step back.
That partnership is what UCD found with Integrity Advocate, and it is what made the difference.
{{post-cta}}


