
Resource Center
Research, guides, and real-world insights on online proctoring; helping your program deliver results that are fair, trustworthy, and defensible.
10M+
Assessments secured
Zero
Data breaches in 12+ years
98%
Client retention rate
120+
Resources published
Featured article

Trust by Evidence: A New Framework for Defensible AI Decisions
Integrity Advocate has released a new whitepaper, Trust by Evidence, introducing a framework that connects AI due process, learner rights, and credential security into one model for defensible AI-assisted assessment. This post walks through what the framework covers, why AI adoption alone no longer settles the integrity question, and links to the full whitepaper download.
Assessment integrity used to mean one thing: was the exam monitored? That question is no longer enough. AI now plays a role in identity verification, proctoring flags, authorship review, scoring, and credential validation, and each of those touchpoints can be challenged.
Confidence in an outcome isn't just about whether AI was accurate. It's about whether the decision it contributed to can be explained, reviewed, appealed, and verified after the fact.
As AI becomes embedded deeper into assessment, institutions are being asked a more pointed question: Can you defend the decision AI helped you make?
That question requires more than accurate technology. It requires a system.
In our latest whitepaper, Trust by Evidence, CEO Brandon A. Smith introduces a framework that connects AI due process, learner rights, and credential security into one model for defensible outcomes.
{{download-resource-cta}}
The Shift From AI Adoption to Defensible Outcomes
For the past several years, the conversation in education and credentialing has centered on adoption: which AI tools to use, how to deploy them, how accurate they are. That conversation is largely settled. Most programs already use AI somewhere in the assessment lifecycle.
What hasn't been settled is defensibility. When an AI-influenced decision is challenged, whether by a learner, an employer, or a regulator, an institution needs to answer a specific set of questions: was there notice, meaningful human review, supporting evidence, and a path to appeal? If any of those answers are unclear, the decision isn't defensible, and the institution is exposed right along with the learner.
The next major challenge in education isn't AI adoption. It's building outcomes that hold up under scrutiny.
Why Treating AI as a Single Safeguard Creates Risk
Many programs rely on AI to do one job: flag anomalies. That model treats a flag as a finding rather than a signal, and it breaks down under three conditions:
- No documented process exists for what happens after a flag is raised.
- Human review means approving the AI's output rather than independently evaluating it.
- There's no clear path for the learner to respond, and no record for the institution to point to later.
Any one of those gaps makes an outcome difficult to defend. Together, they create real exposure, not just to individual learners, but to the institution's accreditation standing, employer trust, and legal risk.
The Trust by Evidence Framework
The whitepaper introduces Trust by Evidence, a framework that connects three ideas typically treated in isolation:
AI Due Process: A fair, documented process for any consequential decision AI contributes to, so a flagged learner has an actual process to walk through rather than a black box to accept.
The Learner Rights Layer: Seven specific rights, to know, to meaningful human review, to explanation, to evidence, to appeal, to proportionality, and to verification, that turn "the system flagged it" into a decision an institution can explain and stand behind.
The Credential Security Trifecta: A secure chain of trust connecting learning, assessment, and credentialing, where a weakness in any one layer undermines the others.
Individually, each idea is familiar. Together, they hold up under scrutiny from everyone with a stake in the outcome: the learner, the institution, employers, regulators, and the public.
What a Defensible AI-Assisted Decision Looks Like
A defensible process doesn't rely on confidence in the algorithm. It provides an actual record. It lets an institution answer, with certainty:
- Was the individual notified that AI was involved?
- Did a qualified reviewer examine the evidence, not just the score?
- Could the individual respond before a consequence was applied?
- Is there a documented, time-bound appeal path?
- Can the outcome be explained to someone outside the institution?
These are governance questions as much as technical ones. Answering them well protects accreditation standing, employer trust, and learner confidence all at once.
What You'll Learn in the Whitepaper
The full whitepaper expands on:
- Why algorithmic due process, procedural justice, and automation bias research all point toward the same conclusion for education
- The Defensible Outcomes Responsibility Matrix, a governance tool for assigning clear ownership across vendors, institutions, and credential issuers
- The five-stage AI Appeals Framework, walked through with a real worked example of a contested proctoring flag
- Sector-specific guidance for K-12, higher education, workforce certification, and employers
- A candid discussion of the framework's limitations, including cost, scale, and surveillance risk
It's written for compliance leads, credentialing bodies, assessment teams, and program leaders responsible for the outcomes their institution has to stand behind.
{{post-cta}}
All resources

Online Safety Training Must Be Proctored. Industry Has Said So
August 1, 2020
|
5 min read
Industry regulators and standards bodies across HR, health and safety, petroleum, professional accreditation, and standards-setting are aligned: online training must include identity verification and active proctoring to be considered legally defensible. This post examines what five major industry bodies require, where legislation has made proctoring mandatory, and what it means for organizations running online safety training today.
When an organization faces legal scrutiny over a workplace incident, one of the first questions asked is whether employees received proper training. The second question is whether that training can be verified.
Industry regulators and standards bodies set the benchmarks courts use to determine due diligence. If your organization's training practices fall short of what industry associations define as reasonable, that gap becomes a liability. And across multiple industries, those associations are now saying the same thing: online training must include identity verification and proctoring to count.
Here is what five major industry bodies have said, and what it means for your organization.
Why Industry Standards Shape Legal Outcomes
Courts do not invent the definition of "reasonable" from scratch. They look to the standards published by recognized industry organizations to determine whether an employer took all practically reasonable steps to prevent harm.
That means the training practices your industry association recommends are not just best practices. In the event of an incident, they become the benchmark against which your organization is measured.
As more training moves online, those standards increasingly address a specific question: how do you know the right person completed the training, and that they actually participated?
What Five Industry Bodies Require
Human Resources Professionals
HR professionals use online training to address ethics, harassment, violence prevention, and job-specific compliance. In 2017, the Chartered Professionals in Human Resources (CPHR) issued an alert to members conducting online training of regulatory, due diligence, or operational significance:
"Some organizations have already responded by not accepting online training for high-risk activities, while others have mandated the utilization of technology that verifies both the identity and the participation of personnel completing online training that is legally and/or operationally critical. Technology exists that mitigates the issues facing compromised training by verifying both the identity and participation of trainees."
Industry Associations
Organizations in high-risk operational sectors use online training to manage safety and emergency preparedness. The Canadian Association of Petroleum Producers (CAPP) has stated directly that it is vital that employers can verify that the intended personnel received the online training and that they participated in it as intended.
Health and Safety Associations
Health and safety bodies are responsible for defining what counts as reasonable risk control for their sectors. In the IOSH Alberta Industry best practice guidelines, they state that identity verification and proctoring technology is particularly critical when organizations use web-enabled educational materials as part of risk control strategies.
Professional Accreditation Entities
Organizations that issue Continuing Education Units (CEUs) have a direct stake in confirming that the person who registered for training is the person who completed it. The IACET Standard for Continuing Education and Training, category 8.1, states that the provider shall have a process verifying that the learner who registers and participates in the learning event is the same learner who receives IACET CEU.
Standards-Setting Bodies
Standards bodies provide the technical requirements that regulators and industry groups reference. The ANSI/ASSE Z490 standard specifies that each trainee being evaluated shall be properly identified, and that delivery records for each training event shall identify the trainee's participation in the training.
When Regulators Make It Law
Industry standards inform expectations. But in some jurisdictions, those expectations have become legal requirements.
For OSHA training in New York City, only in-person training and actively proctored online training will be accepted. The standard is explicit: unproctored online training does not meet the requirement.
In November 2020, Transport Canada added requirements for online Dangerous Goods training stating that the person's identity has been confirmed prior to or at the time of the training, and that training is completed by the person whose identity has been confirmed prior to or at the time of the assessment.
These are not suggestions. They are compliance thresholds. Organizations that cannot demonstrate identity verification and active participation monitoring for regulated training are exposed.
What This Means for Your Organization
The direction is clear across every sector examined here. Online training without identity verification and participation monitoring is increasingly unacceptable, both to industry bodies and to regulators. The organizations that recognize this now are the ones that will be able to demonstrate due diligence if it ever matters in court.
Integrity Advocate works with organizations across training, certification, and compliance sectors to verify learner identity and confirm participation in online safety training, so the record your organization holds is one you can stand behind.
{{post-cta}}

How Integrity Advocate Meets PIPEDA: A Practical Compliance Guide for Online Proctoring
June 25, 2020
|
5 min read
PIPEDA sets 10 fair information principles that apply directly to online proctoring, and most platforms were not built with them in mind. This guide walks through each principle and explains exactly how Integrity Advocate meets it, from limiting data collection and requiring meaningful consent to human review on every flagged session and proactive transparency with test takers.
If your organization delivers online proctoring or participation monitoring in Canada, PIPEDA applies to you. The Personal Information Protection and Electronic Documents Act governs how the private sector collects, uses, and discloses personal information, and online proctoring sits squarely within its scope.
This guide draws from Integrity Advocate's PIPEDA compliance brief to explain exactly how IA's platform meets each of the 10 fair information principles, so your organization can deploy online proctoring with confidence that your privacy obligations are covered.
What PIPEDA Covers and Who It Applies To
PIPEDA became law on April 13, 2000, and applies to organizations' commercial activities across most of Canada. Alberta, British Columbia, and Quebec have substantially similar provincial privacy laws that apply instead, though PIPEDA continues to govern interprovincial and international transfers of personal information. For healthcare information, Ontario, New Brunswick, Newfoundland, and Labrador are also subject to similar provincial legislation.
For online proctoring specifically, PIPEDA applies to any personal information collected from test takers during identity verification or session monitoring, including images, behavioral data, and session recordings.
Why PIPEDA Compliance Matters for Online Proctoring
The impact of PIPEDA on online education services is direct. Organizations are accountable for the personal data they hold, including documentation of what data exists, why it is retained, who has access to it, and how it is protected.
PIPEDA also places emphasis on Privacy by Design, meaning privacy protections must be built into information systems from the start, not added as an afterthought. For proctoring platforms, this means the way data is collected, processed, and deleted needs to be addressed at the architecture level, not the policy level alone.
The 10 PIPEDA Principles and How Integrity Advocate Meets Each One
1. Accountability
PIPEDA requires organizations to establish a privacy management program and designate a person responsible for compliance.
Integrity Advocate's entire platform is built around protecting individual privacy while maintaining assessment integrity. This includes recognizing what constitutes personal information, minimizing collection, limiting use, deleting data as soon as it is no longer required, restricting access, and ensuring full transparency with test takers.
2. Identifying Purposes
Organizations must identify and document why personal information is being collected before or at the time of collection.
Integrity Advocate requires informed consent from each test taker through a privacy policy that explains specifically why their information is being requested and how it will be used and deleted.
3. Consent
Consent under PIPEDA must be meaningful. People must understand what they are agreeing to.
Integrity Advocate provides privacy statements and policies in plain language and in over 70 languages, so every test taker can give genuine informed consent before their session begins, regardless of their primary language.
4. Limiting Collection
Only the personal information required to fulfill a legitimate identified purpose should be collected.
Integrity Advocate is designed to minimize what it collects. For example, the platform monitors whether a user accesses other browser tabs without recording which tabs or pages were visited. On return visits, users can be verified biometrically against a prior confirmed image, eliminating the need to present government-issued ID again.
5. Limiting Use, Disclosure, and Retention
Personal information must only be used for the purpose for which it was collected, retained only as long as necessary, and not disclosed unnecessarily.
Integrity Advocate operates as an intermediary between the organization and the test taker's personal data, similar to how a payment processor protects both parties in a transaction. When a session is flagged, only the test taker's image and the minimum number of images required to substantiate a rule violation are shared with the organization. Data from fully compliant sessions is not disclosed. Integrity Advocate does not transfer or provide access to all personal information collected during a session.
6. Accuracy
Organizations must minimize the possibility of using incorrect information when making decisions about individuals.
Integrity Advocate uses AI in the review of sessions, but every automated finding requires human review and verification before any conclusion is recorded. This ensures that decisions about test takers are based on accurate, contextually reviewed information rather than algorithmic flags alone.
7. Safeguards
Personal information must be protected with security appropriate to its sensitivity.
Integrity Advocate uses 256-bit encryption in transit and at rest, stores data on AWS infrastructure in Montreal by default, and holds SOC 2 certification. The platform has maintained zero data breaches across 12 or more years of operation.
8. Openness
Organizations must make their privacy policies and practices readily available.
Integrity Advocate's privacy practices are documented and accessible to both client organizations and test takers. Organizations deploying Integrity Advocate can direct test takers to clear privacy information before any session begins.
9. Individual Access
Individuals have the right to know what personal information an organization holds about them and to have inaccurate information corrected.
Integrity Advocate proactively addresses this by sending each test taker an email after their session is completed and reviewed. The email details what information was retained and what conclusions were drawn, eliminating the need for test takers to make a formal request.
10. Challenging Compliance
Organizations must have a straightforward complaint handling and investigation process.
The post-session email creates a direct and transparent channel for test takers to raise concerns and have records corrected where required. This approach supports both the spirit and the letter of PIPEDA's challenge principle.
Privacy by Design in Practice
What separates Integrity Advocate from most proctoring platforms is that privacy is not a compliance layer added on top of the product. It is built into the architecture. Data minimization, deletion timelines, restricted disclosure, and human review in place of purely automated decisions are not policies written after the fact. They are product decisions made from the start.
That is what PIPEDA's Privacy by Design principle requires. And it is what your organization needs from a proctoring partner when your learners' data is on the line.
Download the Full PIPEDA Compliance Brief
For a complete breakdown of how Integrity Advocate meets each PIPEDA principle, including the full compliance table, download the official compliance brief.
Download the PIPEDA Compliance Brief →
Ready to see how it works in practice?
Book a Demo →
{{post-cta}}

Top No-Download, Browser-Based Proctoring Tools
June 16, 2026
|
5 min read
This blog post compares the leading no-download, browser-based proctoring platforms across key criteria - device compatibility, AI cheating detection, privacy design, and implementation friction - making the case that Integrity Advocate stands apart by including human review at every pricing tier as a standard feature, not an add-on.
Before a single question is answered, your proctoring platform has already made an impression.
Some no-download proctoring tools get out of the way entirely. Open a browser, click a link, begin. Others require a software download, a browser extension, or a system-level install before an exam can begin.
That distinction matters more than most buyers realize. The install prompt is not a minor inconvenience. It is a compatibility risk, a support burden, a privacy exposure, and the first signal your learners receive about what this experience is going to feel like. We have seen programs lose candidates before the exam starts simply because an install failed on a managed device, a browser was unsupported, or a permission prompt could not be resolved in time.
For programs where results carry real consequences, the no-download question also raises a harder one: if getting into the exam is this complicated, how confident are you in what the platform is doing once they are inside?
This guide covers what no-download, browser-based proctoring actually means, where the leading platforms differ on the criteria that determine whether outcomes hold up, and how to find the right fit for your program, whether you run a university course, a professional certification, a workforce training program, or a compliance assessment.
What browser-based actually means, and what it does not
A genuinely no-download platform runs entirely within a standard browser session. No extension to install before the exam. No lockdown browser to download. No system-level permissions that extend beyond what proctoring actually requires. A learner opens a link and begins, on any device, any browser, anywhere.
Several platforms in this comparison approach the no-download question differently. Some require a Chrome extension added before the exam, which means the platform runs within Chrome specifically. Others use a dedicated secure browser that candidates download and install. Understanding which category a platform falls into matters for programs with diverse device environments, distributed learner populations, or managed corporate devices where installs require IT authorization.
The no-download question is not about convenience. It is about whether your platform works for the full range of people who need to take your assessments, including field workers on tablets, employees on managed corporate laptops, and learners who are not sitting at a desktop in a controlled environment.
The four criteria that matter
Getting learners into the exam without friction is necessary. It is not sufficient. The platforms in this comparison were evaluated across four dimensions that determine whether results are worth standing behind:
How the leading platforms compare
Not every platform marketed as browser-based delivers the same experience, or the same level of confidence in outcomes. Here is how the leading tools compare across the criteria that determine whether results are fair, trustworthy, and defensible.
1. Integrity Advocate
Integrity Advocate is a fully browser-based proctoring platform with no download, no extension, and no install required. It runs on any device and browser, integrates with any LMS, and is built around a privacy-first architecture that collects only what is necessary to protect assessment integrity. Zero data breaches in over 12 years of operation.
What sets Integrity Advocate apart from every other platform in this space: human review is included at every pricing tier by default. Every flagged session is reviewed by a trained person before any decision is made. That is not a premium add-on. It is the standard. The result is outcomes that are not just automated flags – they are documented, reasoned judgments that hold up to scrutiny and in audits.
G2 #1 Ease of Use. 98% client retention. Fair, trustworthy, and defensible by design.
Side-by-side comparison
Based on publicly available documentation, G2 reviews, and vendor-published feature listings. Features subject to change.
The bottom line
No-download access gets learners in. What happens once the exam is underway is what determines whether results can be trusted.
Most platforms rely on AI-based flagging, algorithms that surface alerts without human judgment applied to them. A flag is not a decision. When a result gets questioned, you need something more than an algorithm to back it up.
Integrity Advocate puts a trained reviewer behind every flagged session before any outcome is issued. That human review layer is not a premium tier, it is built into every plan, for every program. The result is not just a monitored exam. It is a documented, reasoned judgment that holds up in audits and under appeal.
That is why 98% of Integrity Advocate clients stay. Not because switching is hard. Because the outcomes are worth keeping.
{{post-cta}}

Key Takeaways from eAA | What “The Trust Imperative” Actually Means for Assessment Right Now
June 19, 2026
|
5 min read
At the 2026 e-Assessment Association International Conference in London, the central theme was trust - specifically, how assessment programs can stay ahead of rapidly evolving AI-enabled cheating while preserving human oversight, candidate experience, and the credibility of every credential they issue.
Last week I was in London for the e-Assessment Association’s 2026 International Conference, and if I had to distill three days of conversations, keynotes, and hallway debates into a single word, it would be this: trust.
Not trust as a buzzword. Trust as a genuine crisis question. As AI capabilities accelerate and new tools emerge faster than most teams can keep up with, the field is being forced to reckon with something foundational: do assessment results still mean what we say they mean?
That tension ran through nearly every session I attended, and it’s one our industry can’t afford to get wrong.

The Threat Landscape Is Moving Fast
One of the clearest messages from the conference was that assessment security is no longer a static problem. Cheating technologies are growing more sophisticated by the month. What worked two years ago may not be sufficient today, and relying on yesterday’s approach while hoping for the best is not a strategy.
At the same time, there’s a real risk of overcorrecting. Security measures that create friction, penalize legitimate candidates, or feel invasive erode trust from a different direction. The most mature programs in the room were the ones thinking about security, accessibility, and candidate experience as a unified design challenge rather than competing priorities.

Human Oversight Is Not Negotiable
One point emerged from this conference without serious debate: keeping a human in the loop is not optional. Multiple sessions, including remarks from several CEOs, affirmed that governance, transparency, and meaningful human involvement are essential to maintaining confidence in assessment outcomes.
This is not a novel position for us at Integrity Advocate. It is the architecture we have built around since day one. But it was validating to hear it stated so clearly and so universally, particularly at a moment when the industry is under pressure to automate everything in the name of efficiency.
When an assessment result affects someone’s career, their credential, their livelihood, cutting corners on human review is not a cost savings. It is a liability.
Candidate Experience Is Now a Trust Variable
Something I found particularly valuable in this year’s programming was the explicit connection being drawn between candidate experience and assessment integrity. Fairness used to be discussed almost exclusively through the lens of psychometrics and policy. That framing is expanding.
How candidates are treated during an assessment, whether the process feels transparent, whether accommodations are genuinely accessible, whether the communication is clear, these factors now register as trust signals for institutions, employers, and regulators alike. A technically sound exam delivered badly is still a trust problem.

The Takeaway I’m Bringing Home
The strongest assessment programs are designing trust in from the beginning, not retrofitting it as a compliance requirement after the fact. That principle is easy to say and genuinely hard to operationalize, especially when the tooling, the regulations, and the threat environment are all shifting simultaneously.
What gives me optimism is that the people in that room in London were asking the right questions. The eAA has always been a community that takes this work seriously, and this year’s conference reflected that.
AI is not going away. The integrity gap will not close on its own. But with the right governance structures, the right human oversight, and a genuine commitment to candidate experience, it is a solvable problem.
I’m leaving with new ideas, new connections, and renewed conviction that this is exactly the work worth doing.
{{post-cta}}

Accredible and Integrity Advocate Partner to Deliver Proctoring and Digital Credentialing
February 25, 2026
|
5 min read
Accredible and Integrity Advocate have announced a strategic partnership that connects verified online proctoring directly to secure digital credential issuance. The integration ensures credentials are automatically issued only to verified test takers who complete assessments without misconduct, closing the critical gap that exists when proctoring and credentialing systems operate independently. Initial support is available for D2L Brightspace environments, with a unified offering for new customers launching in Spring 2026.
Press Release
FOR IMMEDIATE RELEASE | Mountain View, Calif. & Calgary, AB, Canada (March 2026)
New integration connects verified online proctored exams with digital credential issuance, protecting trust from test to certification
Accredible, the world’s leading digital badging platform, and Integrity Advocate, the most trusted online proctoring solution, today announced a strategic partnership to connect verified proctoring with secure digital credential issuance. The integration ensures credentials are automatically issued only to verified test takers who complete assessments without misconduct, helping programs preserve trust, defensibility, and brand integrity at scale.
As remote and online assessment continues to scale, credential fraud and assessment misconduct pose significant risks to program integrity and organizational reputation. While many testing and certification programs rely on proctoring or digital credentialing solutions independently, these systems are often deployed in isolation. The result is a critical gap: exams may be monitored and verified, but credentials are issued separately without a defensible, auditable link back to verified assessment participation.
The Accredible and Integrity Advocate partnership closes that gap by connecting assessment integrity directly to credential issuance. Integrity Advocate handles identity verification and ensures no exam misconduct. When a test taker passes an exam with verified human results, Accredible automatically issues secure, tamper-proof digital credentials within the program’s existing Learning Management System (LMS). Test administrators configure credentialing and proctoring rules within the LMS, and the system enforces them consistently at any scale.
{{post-block-quote}}
For testing and certification teams, the integration reduces manual reconciliation, simplifies exception handling, and strengthens defensibility across audits, appeals, and accreditation reviews. Programs can scale with confidence, knowing credentials are awarded consistently and backed by verified assessment evidence. Test takers experience fair, secure assessments and timely delivery of verifiable credentials, while employers and regulators gain a reliable way to verify authenticity long after the exam — protecting the value of the credential and every legitimate credential holder.
“A credential is only as trustworthy as the process that created it,” said Danny King, CEO and co-founder of Accredible. “This partnership gives programs a defensible way to protect their brand and stand behind every credential they award at scale.”
The Accredible and Integrity Advocate integration is available now, with initial support for D2L Brightspace environments. In Spring 2026, the companies will launch a unified offering that enables new customers to purchase both proctoring and credentialing services together. Existing customers can add credentialing or proctoring capabilities through their current provider relationship.
Accredible and Integrity Advocate will be showcasing the integration at the ATP Innovations in Testing Conference, March 1-4, 2026. To learn more about the integration, visit integrityadvocate.com/integrations/accredible.
About Integrity Advocate
Integrity Advocate delivers modern online proctoring that protects assessment integrity through identity verification and intelligent exam monitoring. Trusted by certification bodies, training organizations, and educational institutions, Integrity Advocate supports compliance and accreditation with clear, audit-ready records, without compromising privacy or accessibility. Learn more at integrityadvocate.com.
About Accredible
Accredible is the world’s leading digital badging platform, enabling education and training leaders to increase learner engagement and drive program growth. Over 2,300 organizations, including Google, IAPP, McGraw Hill, Rutgers, Skillsoft, and the University of Cambridge, rely on Accredible to manage and measure everything from issuing digital certificates and badges to visualizing learning pathways to spotlighting certified learners. Founded in 2013, Accredible has helped issue and verify over 170 million career-advancing credentials. To learn more, visit accredible.com.
{{post-cta}}

The Student Who Implanted a Bluetooth Device to Cheat. And What It Actually Tells Us
May 25, 2020
|
5 min read
The student who surgically implanted a Bluetooth device to cheat in an exam made headlines. But the more important question is why the exam was so easy to cheat on. This post explores how Bloom's Taxonomy and higher-order assessment design reduce academic integrity risks at the source, lowering the burden on proctoring technology and creating a fairer experience for every test taker.
A student surgically implanted a Bluetooth device into their own ear to receive answers during a final exam. It made headlines. It was extreme, it was alarming, and it completely missed the more important question.
Why was the exam so easy to cheat on in the first place?
The conversation around academic integrity almost always focuses on the student: what they did, how they did it, and how to stop them next time. The assessment itself rarely comes under the same scrutiny. That's a problem. Because in many cases, the design of the exam is the vulnerability, and fixing it does more for integrity than any monitoring technology can.
The Variable Most Organizations Overlook
When an organization moves assessment online, two things typically happen. First, they worry about cheating. Second, they look for proctoring technology to solve it. What often gets skipped is the question that should come first: is this assessment actually designed for an online environment?
The method of assessment is a variable entirely within the organization's control. When that variable is addressed, the result is better academic integrity, a less stressful experience for test takers, and lower proctoring costs. All three, at once.
How Bloom's Taxonomy Changes the Integrity Equation
Bloom's Taxonomy is a framework for categorizing educational objectives by cognitive complexity. Developed by Benjamin Bloom in collaboration with other education experts and published in 1956, it has been refined over decades into six levels of learning:
- Remember - recall of facts and basic concepts
- Understand - explanation of ideas or concepts
- Apply - use of information in new situations
- Analyze - drawing connections and comparisons
- Evaluate - justifying a decision or course of action
- Create- producing something new from learned knowledge
Each level requires a greater degree of cognitive processing than the one before it. And crucially, each level also changes how much a proctoring system needs to do.
Why Lower-Order Questions Create Higher-Stakes Monitoring Needs
Remember
A question like "define representative democracy" or "spell rutabaga" can be answered in seconds with a quick search, a phone, or a note. Monitoring this type of question requires tracking browser activity, device use, eye movement, and the presence of others in the room. The proctoring burden is high. The assessment value is low.
Understand
Questions at this level, such as "explain the role of citizens in a representative democracy," carry the same risks. The answer can be found, copied, and paraphrased quickly enough that standard monitoring is the only safeguard.
Apply
Here the dynamic starts to shift. Application questions require a test taker to work through a problem, not just retrieve an answer. When combined with time limits, large question banks, and randomized question and answer combinations, the advantage of external resources is significantly reduced. Proctoring at this level can focus on identity verification and confirming sole participation, which is lower cost and far less invasive.
Analyze, Evaluate, and Create
At these levels, the integrity risk drops substantially. A question like "compare and contrast the economic motivations of..." or "explain the effect of X on a country's economy" requires original reasoning that cannot be copied. No search result, no friend in an earpiece, and no surgically implanted Bluetooth device provides a meaningful advantage when the question demands genuine synthesis and judgment.
The Practical Implication
Higher-order assessments don't eliminate the need for proctoring. Identity still needs to be verified. Sole participation still matters. But they do change what proctoring needs to accomplish, and that changes what it costs and how intrusive it has to be.
For organizations running online assessments, this is worth reviewing before adding monitoring layers. If your questions can be answered by someone with a phone and thirty seconds, the proctoring challenge is structural, not technological.
A More Useful Question Than "How Do We Catch Cheaters?"
The default response to academic integrity concerns is tighter controls and more invasive monitoring. That response treats the symptom. Reviewing the assessment design treats the cause.
Integrity Advocate works with organizations to look at the full assessment process, not just the monitoring window. When the exam itself is designed to require genuine knowledge and reasoning, the monitoring becomes simpler, the experience becomes fairer, and the outcomes become more defensible.
That's a better result for everyone, including the test taker who never has to wonder if an algorithm flagged them unfairly.
{{post-cta}}

Your Online Proctoring Platform PIPEDA Compliant? Here's How to Tell
May 25, 2022
|
5 min read
PIPEDA sets the standard for how personal information must be handled in Canada, and online proctoring platforms are not exempt. This guide breaks down all 10 PIPEDA principles and explains exactly how Integrity Advocate meets each one, from minimal data collection and 24-hour deletion of sensitive identity data to human review on every flagged session. If your organization uses online proctoring, here's what compliance actually looks like in practice.
Online proctoring collects sensitive personal information — names, government-issued ID, facial images, behavioral data. That means any organization using a proctoring platform in Canada isn't just making a technology decision. They're making a privacy decision. And under Canada's Personal Information Protection and Electronic Documents Act (PIPEDA), that decision carries real accountability.
This guide breaks down what PIPEDA requires, how it applies to online proctoring specifically, and how Integrity Advocate is built to meet every one of its 10 principles so your program can operate with confidence.
What Is PIPEDA and Who Does It Apply To?
PIPEDA is Canada's federal private-sector privacy law. It governs how organizations collect, use, and disclose personal information in the course of commercial activity. For educational institutions, certifying bodies, and training providers using online proctoring, PIPEDA applies to any personal data collected from test takers, including biometric data, session recordings, and identity verification images.
Non-compliance isn't just a legal risk. It's a trust risk. When test takers don't trust how their data is handled, confidence in your program erodes, and that's a problem no assessment result can fix.
The 10 PIPEDA Principles and How Integrity Advocate Meets Each One
PIPEDA is organized around 10 fair information principles. Here's how Integrity Advocate addresses each:
1. Accountability
An organization is responsible for the personal information under its control. Integrity Advocate maintains a clearly defined data governance structure and designates responsibility for PIPEDA compliance internally. Clients receive documentation to support their own accountability obligations.
2. Identifying Purposes
The purposes for collecting personal information must be identified before or at the time of collection. Integrity Advocate collects only the data required to verify identity and monitor assessment sessions, nothing more. Collection purposes are communicated clearly to test takers before any session begins.
3. Consent
Individuals must give meaningful consent for the collection, use, or disclosure of their personal information. Test takers are informed of what data is collected and why before they begin, and consent is obtained as part of the session onboarding process.
4. Limiting Collection
Personal information collected must be limited to what is necessary. Integrity Advocate follows a minimal data collection model. Sensitive data, including facial images and government-issued ID, is deleted within 24 hours of session completion unless retention is required for dispute resolution.
5. Limiting Use, Disclosure, and Retention
Data must not be used or disclosed for purposes other than those for which it was collected, and must be retained only as long as necessary. Session data is used solely for the purposes of assessment integrity. Integrity Advocate does not sell, share, or repurpose personal data for any secondary use.
6. Accuracy
Personal information must be as accurate, complete, and up-to-date as necessary. Integrity Advocate's human review process ensures that session flags are assessed by a trained reviewer, not an algorithm alone, before any outcome is recorded. This reduces the risk of inaccurate findings based on automated misclassification.
7. Safeguards
Personal information must be protected by appropriate security safeguards. Integrity Advocate uses 256-bit encryption in transit and at rest, stores data on AWS infrastructure in Montreal by default, and has maintained zero data breaches across 12+ years of operation.
8. Openness
Organizations must make their privacy policies and practices readily available. Integrity Advocate's privacy practices are documented and available to clients and test takers. Organizations deploying Integrity Advocate can point test takers to clear, accessible privacy information before their session begins.
9. Individual Access
Individuals have the right to access their personal information held by an organization. Integrity Advocate supports client organizations in responding to data access requests in accordance with PIPEDA requirements.
10. Challenging Compliance
Individuals must be able to challenge an organization's compliance with these principles. Integrity Advocate provides the documentation and audit trail that organizations need to respond to any compliance challenge, including detailed session records and human reviewer notes, not just automated flags.
Why Human Review Matters for PIPEDA Compliance
One PIPEDA principle that automated proctoring platforms often struggle with is accuracy. Fully automated systems issue flags based on algorithmic pattern detection. If that flag is wrong, and automated systems do produce false positives, the data on record is inaccurate, the outcome may be unfair, and the organization is exposed.
Integrity Advocate's human review model addresses this directly. Every flagged session is reviewed by a trained person before any decision is recorded. That means the information your organization acts on is accurate, defensible, and consistent with what PIPEDA requires.
Built for Privacy From the Ground Up
PIPEDA compliance isn't a feature Integrity Advocate added. It's reflected in foundational design decisions:
- Minimal data collection, only what's required for the session
- 24-hour deletion of sensitive identity data post-session
- No secondary use of personal data for advertising, research, or resale
- Data stored in Canada, AWS Montreal by default
- SOC 2 certified for four consecutive years
- GDPR and PIPEDA compliant, designed for organizations operating across jurisdiction
Your Program Deserves a Proctoring Partner You Can Stand Behind
Choosing a proctoring platform means trusting a vendor with your learners' most sensitive personal information. That trust needs to be backed by more than a checkbox. It needs to be backed by architecture, policy, and a track record.
Integrity Advocate has operated for 12+ years with zero data breaches and 98% client retention. We're built to be the partner your compliance team can point to with confidence.
{{post-cta}}

Online Proctoring and Accessibility: How the Industry Is Failing People with Disabilities
April 14, 2022
|
5 min read
Online proctoring platforms routinely fail test takers with disabilities through room scan requirements, biometric systems that flag facial differences, and eye tracking that penalizes neurological variation. This post examines where the industry gets it wrong, what accessibility legislation now requires, and how Integrity Advocate is built to assess every test taker fairly, with WCAG 2.1 AA compliance and human review on every flagged session.
Most online proctoring platforms were not designed with disabled test takers in mind. That's not an assumption, it shows up in the product.
Some platforms require test takers to physically lift their monitor and scan the room. Others use AI-based facial monitoring that flags people with facial deformities as suspicious. Eye-tracking systems penalize unconventional eye movements — the kind that are entirely normal for people with certain neurological or visual conditions. These aren't edge cases. They're design failures that exclude a significant portion of the population from participating in online assessment at all.
As accessibility legislation tightens globally and courts begin issuing financial penalties, proctoring providers can no longer treat accessibility as optional. This post looks at what's at stake, where the industry is falling short, and what responsible design actually looks like.
Why Accessibility in Online Proctoring Matters
A disability is broadly defined as a physical or mental impairment that substantially limits one or more major life activities. The scale of the population affected is significant:
- The World Health Organization estimates that over 1 billion people globally live with some form of disability
- An estimated 285 million people worldwide experience visual impairment
- Nearly 2.5 billion people are projected to have some degree of hearing loss by 2050
- Between 250,000 and 500,000 people suffer a spinal cord injury every year
These individuals are active participants in education, professional development, and certification. They sit exams. They complete workplace training. They pursue credentials. And when a proctoring platform isn't designed to accommodate them, they are effectively locked out of those opportunities.
Where Proctoring Platforms Get It Wrong
The accessibility failures in online proctoring tend to fall into three categories:
Physical requirements that exclude
Asking a test taker to lift and rotate their monitor to scan their environment assumes a level of physical ability that many people don't have. For someone with a spinal cord injury, limited upper body mobility, or a motor impairment, this requirement isn't just inconvenient. It makes the exam inaccessible.
Biometric systems that discriminate
AI-based facial recognition and monitoring tools are trained on datasets that often underrepresent people with facial differences, asymmetrical features, or conditions that affect facial muscle movement. When these systems flag a test taker as suspicious based on appearance rather than behavior, the result is discriminatory, and the test taker has no recourse against an algorithm.
Eye tracking that penalizes neurological difference
Eye tracking is used by some platforms to detect when a candidate looks away from the screen, interpreting it as potential cheating. For test takers with nystagmus, ADHD, autism, or certain visual processing conditions, atypical eye movement is normal. Penalizing it is both inaccurate and unfair.
What the Regulatory Environment Looks Like Now
Numerous countries have begun actively enforcing digital accessibility rights, including equivalent access to electronic and information technology. In Canada, the Accessible Canada Act sets federal obligations. In the United States, Section 508 and the ADA apply to digital services. In the UK and EU, accessibility standards are increasingly enforceable with real financial consequences.
Organizations that use non-compliant proctoring platforms carry risk. When a test taker with a disability is excluded or penalized by your proctoring tool, the liability doesn't rest only with the vendor. It rests with your program too.
What Responsible Accessibility Design Looks Like
The solution isn't accommodation after the fact. It's accessibility built into the design from the start. That means:
- Involving people with disabilities in the development and testing phases
- Testing the end-user experience using assistive technologies such as JAWS, NVDA, ZoomText, Dragon NaturallySpeaking, and keyboard-only navigation
- Evaluating the product against established accessibility standards before launch
- Engaging third-party auditors to assess compliance independently
The current benchmark is WCAG 2.1 AA — the Web Content Accessibility Guidelines that set the international standard for digital accessibility. Any proctoring platform that cannot demonstrate WCAG 2.1 AA compliance should not be considered a complete solution.
How Integrity Advocate Approaches Accessibility
Integrity Advocate is built on a straightforward principle: assessment integrity should never come at the cost of a test taker's rights.
That means no room scans requiring physical ability beyond what the assessment demands. It means human review on every flagged session, so that an unusual eye movement or facial difference is assessed by a trained person with context — not an algorithm making an automated call. It means a no-download, browser-based platform that works with assistive technologies without friction.
Integrity Advocate is WCAG 2.1 AA compliant and designed to work for the full range of people who take exams, not just those who fit a narrow definition of typical.
Privacy and accessibility are not constraints on assessment integrity. They are part of what makes an outcome trustworthy.
The Bottom Line
Online proctoring platforms that haven't prioritized accessibility aren't just falling behind on compliance. They're actively excluding people with disabilities from the credentials and opportunities those assessments unlock.
Your program deserves a proctoring partner that takes this seriously, one where every test taker, regardless of ability, can be assessed fairly.
{{post-cta}}

Is Your Online Proctoring Platform BIPA Compliant? What Illinois Organizations Need to Know
January 1, 2020
|
5 min read
BIPA sets strict standards for how organizations must collect, store, and use biometric data in Illinois, and online proctoring platforms fall squarely within its scope. This guide breaks down what BIPA requires, where proctoring platforms create compliance risk, and how Integrity Advocate is designed to support your obligations, from informed consent and data deletion to zero commercial use of biometric data.
If your organization uses online proctoring and operates in Illinois, or serves Illinois residents, the Biometric Information Privacy Act applies to you. And unlike most privacy legislation, BIPA has teeth. Private individuals can sue directly, without needing to prove actual harm, and statutory damages start at $1,000 per negligent violation and $5,000 per intentional one.
This is not a checkbox compliance exercise. It is a legal and reputational risk that organizations need to address before they deploy any technology that touches biometric data.
This guide explains what BIPA requires, how it applies to online proctoring specifically, and how Integrity Advocate is built to support your organization's compliance obligations.
What Is BIPA?
The Biometric Information Privacy Act is an Illinois state law that establishes standards for how companies must collect, store, use, and disclose biometric information. It was enacted in 2008 and remains one of the strictest biometric privacy laws in the United States.
BIPA covers any information based on an individual's biometric identifiers, including:
- Retina and iris scans
- Fingerprints
- Voiceprints
- Face geometry and facial recognition data
- Hand geometry
For online proctoring, the most relevant category is facial geometry. Any platform that uses facial recognition or AI-based facial monitoring to verify identity or flag behavior is collecting biometric data under BIPA's definition.
What BIPA Requires
BIPA places four core obligations on organizations that collect biometric data:
1. Written Policy and Retention Schedule
Organizations must have a publicly available written policy establishing a retention schedule and guidelines for permanently destroying biometric data. Data must not be retained beyond the purpose for which it was collected, or beyond three years, whichever comes first.
2. Informed Written Consent
Before collecting biometric data, organizations must inform individuals in writing that biometric data is being collected, state the specific purpose and length of time for which it will be used, and obtain a written release. Consent cannot be buried in general terms and conditions.
3. No Commercial Benefit from Biometric Data
Organizations are prohibited from selling, leasing, trading, or otherwise profiting from an individual's biometric data. This applies to vendors and service providers as well.
4. Data Security Standards
Biometric data must be stored, transmitted, and protected using the same standard of care as other sensitive and confidential information, and in a manner consistent with the reasonable standard of care within the organization's industry.
Why Online Proctoring Is a BIPA Risk Area
Most online proctoring platforms collect biometric data as a core function. Facial recognition for identity verification, AI monitoring of facial expressions and eye movement, and behavioral biometric analysis all fall within BIPA's scope when delivered to Illinois residents.
The risk isn't hypothetical. Courts have consistently ruled that BIPA applies broadly, and class action litigation against organizations using biometric technology without proper consent frameworks has resulted in significant settlements.
The question isn't whether your proctoring platform uses biometric data. It almost certainly does. The question is whether it handles that data in a way that protects your organization.
How Integrity Advocate Supports BIPA Compliance
Integrity Advocate's identity verification and proctoring services are designed with biometric privacy obligations in mind.
Informed consent is built into the process. Test takers are informed of what data is collected, why it is collected, and how it will be used before any session begins. Consent is obtained as a documented step in the onboarding process, not assumed through general terms.
Data is not sold or used for commercial benefit. Integrity Advocate does not sell, lease, or repurpose biometric or session data for any secondary use. Data collected during a proctoring session is used solely for the purpose of that assessment.
Sensitive data is deleted promptly. Facial images and identity verification data are deleted within 24 hours of session completion, unless retention is required for a specific dispute resolution purpose. This supports compliance with BIPA's retention requirements.
Security standards are robust. Integrity Advocate uses 256-bit encryption in transit and at rest, stores data on AWS infrastructure in Montreal by default, and has maintained zero data breaches across 12+ years of operation.
Human review replaces over-reliance on facial AI. Rather than making automated decisions based on facial monitoring alone, every flagged session is reviewed by a trained person before any outcome is recorded. This reduces the risk of inaccurate findings and limits the extent to which facial geometry data drives decisions.
BIPA Is Part of a Broader Privacy Picture
BIPA is one of several privacy frameworks that organizations using online proctoring need to consider. Depending on where your test takers are located, GDPR, PIPEDA, FERPA, and other state-level legislation may also apply. Integrity Advocate is built to operate across jurisdictions, with privacy-first architecture that supports compliance across multiple frameworks simultaneously.
The Risk of Getting This Wrong
BIPA litigation is active and growing. Organizations that collect biometric data without proper consent frameworks, retain it beyond its purpose, or work with vendors who repurpose it commercially are exposed. Statutory damages per violation, multiplied across a class of test takers, add up quickly.
Choosing a proctoring partner that takes biometric privacy seriously is not just a compliance decision. It is a risk management decision.
{{post-cta}}


