#1
proctoring tool for ease of use

Resource Center

Research, guides, and real-world insights on online proctoring; helping your program deliver results that are fair, trustworthy, and defensible.

10M+

Assessments secured

Zero

Data breaches in 12+ years

98%

Client retention rate

120+

Resources published

All resources

Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.
Tag value
A professional uses a calculator beside a laptop and financial documents, representing the hidden costs organizations must account for when evaluating online proctoring solutions.
Blogs & articles
All Industries

The Hidden Cost of Remote Proctoring

May 8, 2024

|

5 min read

The listed price of an online proctoring tool is rarely the full cost. This post breaks down four hidden expenses that organizations often overlook: the support burden created by installation-based tools, the admin time required to investigate false positive flags from AI-only systems, the customization cost of adapting higher-ed-built tools for non-academic audiences, and the potential legal and regulatory liability when a proctoring system cannot produce defensible records.

Previously on the blog, we’ve made the case for treating online proctoring as an investment — in the safety of your learners, and the integrity of your testing. We’ve detailed some of the emerging threats against fair, secure online assessments, and we’ve shown what can happen when these threats aren’t taken seriously. 

But we haven’t done a deep dive into the actual cost of online proctoring. Different providers have different billing models; the specific features you need — ID verification, participation monitoring, recorded vs. live proctoring, etc. — as well as the anticipated volume of exams, will all determine your top-line numbers. And while those numbers are important, they don’t tell the whole story. To really understand the potential cost of remote proctoring, you need to understand the ‘shadow costs’ — hidden expenses that can crop up if you focus exclusively on pricing when making your decision. 

(ps. If you're looking for Integrity Advocate's pricing, we recommend contacting our sales team, as our services are generally customizable based on your needs.)

Hidden Cost #1: Support 

The number one complaint we hear from prospective customers coming to Integrity Advocate from a competitor is the high cost of support required to get learners set up and running with other solutions. When an online proctoring tool requires learners to install an application or browser plug-in, or make changes to system settings, support rates may be between 30-40%.

Let’s break that down and look at the numbers. If you run 1000 proctored exams a session, and approximately 30% of those require a support call, that’s 300 support calls/session. If each support call takes 10 minutes to resolve, that’s 3000 minutes, or 50 hours, of tech support required on top of the cost of your proctoring service.

Hidden Cost #2: Reviewing (and Re-reviewing)

Another hidden cost of online proctoring involves resolving disputes and correcting ‘false positive’ violation flags. Many of the cheapest online proctoring tools rely heavily on AI to identify rules violations. If these aren’t followed up with a human review, innocent test-takers can easily be penalized. Even putting aside the more insidious biases of AI facial recognition, the technology is still too unreliable to be the final arbiter of ethical behavior in an online exam. AI proctoring systems can — and have — mistakenly identified facial patterns in things like wallpaper and houseplants, leading to false positive rules violations. 

And what’s the cost of this? Some proctoring services charge for exam retakes, others don’t. Even if there is no additional fee involved, consider the admin time required to investigate learner complaints and clear violations that have been falsely flagged by low-cost, automated online proctoring tools. 

Hidden Cost #3: Accessibility

One underrated question worth asking when considering an online proctoring system is: ‘how easy is it to accommodate my learners’? Especially when running online testing, accommodation is about more than extra time or support: it’s about adapting a system — generally one built with one very specific user/use case in mind — to meet the unique needs of your program. 

Most online proctoring tools are built for a higher ed audience. But we’re seeing more and more clients come from food and alcohol server certification, skills trades/health and safety training, and professional certification. On everything from LMS integration, to rule sets, to participation monitoring, these systems may require extensive customization — and additional time and money — to accommodate the unique user base, environmental and technical requirements of a non-higher ed audience. 

Hidden Cost #4: Liability

All of the hidden costs we’ve spotlighted before involve, in one way or another, the effort required to get a remote proctoring system working perfectly.  But what about when things go wrong? Ultimately, the design and implementation of a proctoring system must take into consideration the worst case scenario. 

By this we mean, consider the potential cost of a nightmare scenario — say, for example, an employee on a construction site, who has received health and safety certification from your organization, causes an accident on the job. What are the legal, regulatory or reputation implications if you are unable to prove they participated in the training and completed the requirements fully? 

The bottom line is that, ultimately, online proctoring systems aren’t something to cheap out on. This doesn’t mean buying the most expensive option on the market, of course — it means doing your research, and considering the full costs and potential implications of your choice.

{{post-cta}}

Online Proctoring
Defensible Outcomes
No items found.
A judge's gavel rests on a legal desk with law books in the background, representing the court cases and regulatory decisions that have established organizational liability in online proctoring.
Blogs & articles
All Industries

Who Is Liable When Proctoring Goes Wrong? Lessons From Global Legislation and Cases

May 2, 2024

|

5 min read

Courts and regulators across Canada, the EU, and the United States have consistently found that organizations deploying proctoring tools bear liability for how participant data is handled, not the software vendors they use. CASL, GDPR, BIPA, and the Cleveland State Fourth Amendment case all point to the same conclusion: the organization collecting data is the accountable party. This post examines each case and framework and explains what organizations need to do to reduce their exposure.

When a proctoring tool violates a participant's privacy, who is responsible? The software vendor? The organization that deployed it? Both?

Recent legislation and court decisions from Canada, the UK, and the United States have answered this question with increasing clarity: the liability rests with the organization running the testing, not the software provider. For anyone deploying online proctoring, this is not an abstract legal point. It is a direct operational risk.

The Core Issue

Organizations that deliver online training and testing have a legitimate need to confirm who is taking their assessments and that participants are engaging in good faith. Meeting that need often requires collecting sensitive personal data: ID images, biometric verification, session recordings, and audio. The question of who bears legal responsibility for how that data is handled has been answered by courts and regulators in ways that most organizations have not fully reckoned with.

The consistent finding across multiple jurisdictions is that the data-collecting organization, not the software vendor, is the accountable party.

CASL: The Canadian Perspective

Canada's Anti-Spam Legislation was created in 2014 to reinforce best practices in electronic communications and combat spam and related cyber threats. Among its provisions, CASL requires organizations to obtain consent and written acknowledgement before using invasive computer programs, and to provide users with assistance in removing such programs afterwards.

Under CASL, software is considered invasive if it interferes with the user's control of their computer system by opening programs, printing, or accessing files without their knowledge, or if it changes system settings, preferences, or commands without their knowledge.

Online proctoring tools that block restricted sites, monitor web use, require camera access, or install browser extensions clearly fall within this definition. And most proctoring plugins do not provide uninstall assistance, remaining active by design after the session ends to reduce support overhead for the vendor.

The risk for organizations: CASL violations carry regulatory penalties of up to $10 million per violation. If your proctoring system leaves you liable to CASL noncompliance, that exposure belongs to you, not your vendor.

GDPR: The Global Standard That Places Liability on the Data Owner

The EU's General Data Protection Regulation has established a universal standard for data privacy that reaches any organization handling the personal data of EU residents, regardless of where that organization is based.

Under GDPR, the organization running the testing is the data controller, while the proctoring tool is the data processor. Fines for inappropriate collection, storage, transfer, or deletion of personal data fall on the data controller, not the data processor.

Ireland's Data Protection Commission made this distinction explicit in a judgment against Slane Credit Union Limited, stating that processors cannot be used by controllers as a legislative safety net, and that it is essential that due diligence is carried out to ensure the protection of personal data.

GDPR fines can reach 20 million euros or 4% of a company's total worldwide annual revenue, whichever is higher. The liability for how a proctoring vendor handles learner data belongs to the organization that chose to deploy it.

BIPA: The Illinois Warning

American organizations are increasingly coming under regulatory scrutiny for proctoring practices. Illinois' Biometric Information Privacy Act is one of the most consequential examples.

BIPA places liability on organizations when biometric data is collected or used in a way that violates participant privacy, including failing to secure written consent and failing to publish a retention schedule outlining when data will be permanently destroyed.

Two landmark cases illustrate how serious this exposure can be.

BNSF Railway Co. was subject to a $228 million jury verdict for scanning the fingerprints of truck drivers without consent. The case was eventually settled for $75 million. The third-party vendor that provided the scanning technology was not implicated in the charges.

White Castle System Inc. faced a separate BIPA lawsuit in which the Illinois Supreme Court ruled that claims accrue with each individual finger scan, exposing the restaurant chain to a potential liability in the billions of dollars. White Castle ultimately settled for approximately $10 million. Again, the vendor supplying the technology was not the party held accountable.

The pattern across both cases is consistent: the organization that deployed the biometric technology bore the liability. The software vendor did not.

Cleveland State: A Fourth Amendment Violation

In 2022, a federal court found that Cleveland State University's remote testing requirement of a room scan constituted unreasonable search and seizure in violation of students' Fourth Amendment rights.

Cleveland State used two separate proctoring providers to facilitate these scans. Both were named in the decision. Neither was fined. The university bore the consequences.

This case illustrates two important points. First, the room scan requirement itself was the violation, regardless of which vendor implemented it. Second, choosing a proctoring tool that conducts room scans does not transfer the legal risk to the vendor. The organization that required the scan is the one that faces the consequences when that requirement is found to violate participant rights.

What This Means for Online Training and Testing Providers

These cases are not outliers. They reflect a consistent and accelerating trend in privacy legislation globally: organizations are responsible for the actions of any third-party software, plugins, or services they deploy. Vendor liability does not substitute for organizational accountability.

For organizations delivering online training and testing, this has direct implications for vendor selection. The question is not just whether a proctoring tool works. The question is whether deploying it creates liability for your organization under CASL, GDPR, BIPA, or other applicable legislation.

The steps that reduce that liability are straightforward: choose a vendor with documented privacy practices, confirm that data handling complies with the legislation applicable to your jurisdiction and your learners' jurisdictions, require clear data deletion timelines, and ensure that any software deployed on learner devices complies with consent and removal requirements.

How Integrity Advocate Approaches This

Integrity Advocate is designed to reduce the compliance exposure that comes with deploying a proctoring tool, not to add to it.

No installation is required in most cases, which eliminates CASL's invasive software provisions entirely for the majority of deployments. Data is collected only for its stated purpose and deleted by default within 24 hours of session completion. Consent is obtained before any data collection begins. Data is stored in GDPR-designated jurisdictions. Room scans are optional rather than mandatory, and can be enabled or disabled based on the organization's assessment of their necessity and proportionality.

These are not policy commitments. They are architectural decisions built into how the platform works.

{{post-cta}}

Defensible Outcomes
Compliance
Privacy & Data Protection
No items found.
A professional works on a laptop with digital compliance and security icons overlaid, representing Integrity Advocate's SOC 2 Type II certification and ongoing commitment to data security standards.
Blogs & articles
All Industries

Integrity Advocate Achieves SOC 2 Type II Certification for the Third Consecutive Year

February 26, 2024

|

5 min read

Integrity Advocate has achieved SOC 2 Type II certification for the third consecutive year, verified by auditors at the Johanson Group and supported by security partner Carbide. This post explains what SOC 2 Type II involves, why annual recertification matters more than a one-time audit, and what it means for organizations using Integrity Advocate to handle sensitive learner data.

Integrity Advocate has completed SOC 2 Type II certification for the third consecutive year, with support from auditors at the Johanson Group and security partner Carbide.

SOC 2 Type II compliance represents an ongoing commitment to security, privacy, and the responsible handling of sensitive data. For partners, clients, and learners, it means the systems and processes protecting their information have been independently verified under real-world operating conditions, not just reviewed on paper.

What SOC 2 Type II Certification Involves

SOC 2 Type II is not a one-time audit. It is an extended review conducted over several months that evaluates how effectively an organization's security and privacy controls perform under actual operating conditions. The process includes defining security controls, implementing appropriate policies, conducting risk assessments, and continuously monitoring systems to ensure those controls hold up over time.

The Type II designation is significant. Where Type I confirms that controls exist at a point in time, Type II confirms that those controls operated effectively over an extended period. It is the higher standard, and the one that matters most to organizations evaluating a vendor's security posture.

Why Integrity Advocate Pursues SOC 2 Certification

SOC 2 Type II certification is commonly obtained by SaaS vendors to demonstrate effective security controls to enterprise clients and partners. At Integrity Advocate, the motivation goes further than that.

Data security is a responsibility, not a checkbox. Integrity Advocate handles sensitive data on behalf of clients every day, including government-issued ID images, biometric data, and session recordings. The people whose data this is should never have to wonder whether it is being handled securely. SOC 2 certification is one way of demonstrating that the answer is yes, backed by independent verification rather than self-assertion.

Trust is earned through consistent practice. SOC 2 Type II measures controls over time, not at a single moment. Achieving it three consecutive years reflects a sustained commitment to maintaining security standards as threats evolve, not a one-time effort to pass an audit.

Certification makes partnership easier. SOC 2 Type II is recognized across industries as a universal standard based on proven security practices. For organizations in higher education, professional certification, industrial training, and corporate learning evaluating a proctoring vendor, SOC 2 certification provides independent confirmation that Integrity Advocate's security controls meet the standard their own compliance teams require.

The Partners Behind the Process

Throughout the certification process, Integrity Advocate worked closely with auditors from the Johanson Group, whose expertise guided the audit with transparent communication and a shared commitment to rigorous standards. Integrity Advocate also leveraged Carbide as its security platform to support the process.

What This Means for Clients and Partners

For Integrity Advocate clients and partners, SOC 2 Type II certification is straightforward confirmation that the platform handling your learners' data meets independently verified security standards. It sits alongside Integrity Advocate's 12-plus years of operation with zero data breaches and 98% client retention as part of a consistent track record, not a single credential.

For more information about how Integrity Advocate handles data security and privacy, visit the Privacy page.

{{post-cta}}

Privacy & Data Protection
Assessment Security
Compliance
No items found.
A professional takes notes during a video call on a laptop, representing the remote invigilation and assessment delivery standards that Ofqual requires of Awarding Organisations in England.
Compliance briefs
All Industries

Is Your Online Proctoring Platform Ofqual Compliant? What Awarding Organisations in England Need to Know

April 24, 2024

|

5 min read

Ofqual's General Conditions of Recognition place specific requirements on Awarding Organisations using remote invigilation in England, covering learner identity verification, assessment confidentiality, reasonable adjustments, and assessment delivery standards. This guide walks through each relevant condition and explains how Integrity Advocate is configured to support Awarding Organisations in meeting Ofqual's expectations, from government-issued ID verification and GDPR-compliant session review to AI detection and support rates below 1%.

If your organisation issues regulated qualifications in England, the Office of Qualifications and Examinations Regulation governs how those qualifications are delivered and assessed. Ofqual does not prescribe exactly what compliance looks like. Instead, it sets conditions and principles that Awarding Organisations must understand and apply, balancing sometimes competing interests including academic integrity, accessibility, privacy, and learner experience.

For online proctoring and remote invigilation specifically, Ofqual's General Conditions of Recognition place clear expectations on how assessments must be delivered, how learner identity must be confirmed, and how the integrity of assessment materials must be maintained.

This guide walks through the key Ofqual conditions relevant to remote invigilation and explains how Integrity Advocate is built to support Awarding Organisations in meeting each one.

What Is Ofqual and Who Does It Apply To?

The Office of Qualifications and Examinations Regulation is a non-ministerial government department that regulates qualifications, exams, and tests in England. Established under the Apprenticeships, Skills, Children and Learning Act 2009 and also covered by the Education Act 2011, Ofqual sets rules for regulated qualifications including those related to education and vocational training.

Ofqual's stated priorities for 2022 to 2025 are quality and fairness for students and apprentices, clarity and effectiveness in the qualifications market, shaping the future of assessment and qualifications, and developing Ofqual as an effective and inclusive regulator.

For Awarding Organisations using remote invigilation to deliver assessments, Ofqual compliance requires addressing four key condition areas: confidentiality of assessment materials, registration and identity verification of learners, reasonable adjustments, and completion of the assessment under the required conditions.

The Key Ofqual Conditions for Remote Invigilation

Condition G4: Maintaining Confidentiality of Assessment Materials

Ofqual requires Awarding Organisations to take all reasonable steps to ensure that assessment materials remain confidential throughout the development and delivery process. For online assessments, this includes preventing participants from printing, copying, screenshotting, or otherwise distributing assessment content.

Integrity Advocate integrates directly with the assessment platform, allowing Awarding Organisations to restrict access to assessment materials. Where evidence must be collected for investigation or adjudication that could contain assessment materials, Awarding Organisations retain discretion over the extent and duration of access and storage. Integrity Advocate also provides the option to restrict and document printing, copy-pasting, and screenshotting of assessment materials during a session, reducing the risk of content becoming publicly accessible.

Condition G5: Registration of Learners

Ofqual requires that each learner taking a regulated qualification is registered in a way that permits clear and unique identification. All forms of high-stakes assessment require that the identity of the individual taking the assessment is verified. A candidate sitting an examination under another candidate's name constitutes malpractice or maladministration.

Integrity Advocate verifies learner identity at the point of registration using government-issued photo ID, confirming that the image on the ID matches the learner present and that the name on the ID matches the name provided at registration. Where a learner's identity has been previously confirmed, Integrity Advocate eliminates the need for repeat ID checks, streamlining the assessment process without compromising verification standards.

Condition G6: Arrangements for Reasonable Adjustments

Ofqual requires Awarding Organisations to have clear arrangements for making reasonable adjustments in relation to regulated qualifications, in accordance with Equalities Law.

Integrity Advocate's interface design accommodates dyslexia, visual impairment, and colour blindness. The user experience can be configured to accommodate physical disabilities and anxiety disorders. All integrations provide a secure opt-out capability for use in situations where accommodations make standard invigilation unnecessary, and invigilation findings can be overridden manually where reasonable accommodation factors were not accounted for.

Condition G8: Completion of the Assessment Under the Required Conditions

Ofqual requires Awarding Organisations to take all reasonable steps to ensure that evidence generated by a learner in an assessment is generated by that learner. Ofqual guidance notes that awarding organisations are likely to comply when they carry out regular checks that assessments are completed under the required conditions, including some unannounced checks.

Integrity Advocate addresses this through two options for reviewing assessment conditions:

Option 1: Flagged session review. Integrity Advocate's invigilators review sessions and flag those where potential rule violations occur. Flagged sessions can be overruled by the Awarding Organisation and do not include media unrelated to the suspected infraction. This is the preferred option where GDPR compliance is a necessary consideration.

Option 2: Full session review. Complete session recordings, including media not flagged by invigilators, can be reviewed where deemed necessary by the Awarding Organisation and supported by a privacy impact assessment.

Integrity Advocate also supports monthly reviews of cumulative data to ensure rules are being enforced and to monitor the frequency of noncompliance.

On learner privacy, Ofqual-referenced research found that around 40% of examinees experiencing remote invigilation reported a sense of intrusion to their privacy. Integrity Advocate addresses this directly: more invasive functions such as room scans are not mandatory and can be enabled or disabled based on the Awarding Organisation's assessment of their value and privacy impact. The system can also monitor for the difference between a learner talking to themselves and a conversation with others, without requiring audio recording of the session.

On AI-assisted cheating, Ofqual has noted that generative AI tools present challenges for remote invigilation that are becoming increasingly important as AI tools are more widely used in the education sector. Integrity Advocate monitors for and can restrict the use of AI-enabled browser plugins, cellular phones, and on-device communication tools. ExposeAI, Integrity Advocate's dedicated AI detection capability, uses a combination of technological and human review to identify AI-powered study aid tools that can automatically answer questions without learner input.

Condition G9: Delivering the Assessment Effectively and Efficiently

Ofqual guidance identifies negative indicators for compliance, including assessments that add unnecessary costs to learners by requiring specific equipment not reasonably obtainable. Research cited by Ofqual also notes that not all candidates are comfortable with technology, and this can affect their ability to sit assessments under remote invigilation.

Integrity Advocate works on all laptops, desktops, tablets, mobile devices, and Chromebooks without requiring installation, eliminating the likelihood that a learner will be disadvantaged by a requirement to access specific or costly devices.

Integrity Advocate's Integrity Lock feature restricts the use of multiple monitors and flags attempts to access other tabs or programs, without requiring installation. This reduces the stress and anxiety associated with technical setup requirements and creates a more even assessment experience across learner populations.

Integrity Advocate also provides a no-cost demo mode that learners can use to familiarise themselves with the technology before their assessment, alongside What to Expect pages with frequently asked questions. As a result, Awarding Organisations using Integrity Advocate typically see support requests from fewer than 1% of learners, compared to an industry standard of 25 to 40%.

Balancing Competing Interests Under Ofqual

Ofqual guidance recognises that Awarding Organisations have multiple and sometimes competing interests: academic integrity, accessibility, privacy under GDPR, security, human rights, and the technological constraints of their learner populations. Ofqual does not require organisations to maximise any one of these at the expense of others. It requires them to understand the principles and achieve a reasonable balance.

Integrity Advocate is designed to support that balance. Settings are configurable, not prescriptive. Invasive features are optional. Privacy protections are built in by default. And human review ensures that automated findings are assessed in context before any outcome is recorded.

{{post-cta}}

Compliance
Privacy & Data Protection
No items found.
A professional holds two puzzle pieces labeled Data and Protection, representing the security and privacy obligations organizations must meet when selecting an online proctoring solution.
Blogs & articles
All Industries

Is Your Proctoring Solution a Security and Privacy Threat?

August 27, 2023

|

5 min read

The US Department of Education's Privacy Technical Assistance Center has documented how data breaches and malware attacks have affected education systems across every sector. Most online proctoring services require browser extensions or plugins that create exactly the kind of installation-based malware vector that security researchers flag as high risk. This post examines the threat, what organizations should require from their proctoring vendors, and why a no-installation approach eliminates the risk at the source.

The US Department of Education's Privacy Technical Assistance Center published a presentation titled Security Threats: Education Systems in the Crosshairs, in which security advisor Mike Tassey documented how data breaches, hacks, and privacy incidents have affected organizations across virtually every sector, from NASA and Citigroup to local school systems.

The warning is directly relevant to any organization using online proctoring. The data that proctoring services collect, including names, government-issued ID, biometric images, and session recordings, is exactly the kind of information that makes education systems a target.

The Threat Landscape Has Changed

Cyber-theft has become fully commoditized. There is an active black market for personal data, and an underground economy where over two million pieces of malware are built and sold every year. This malware is designed to gather precisely the kind of information proctoring platforms collect: Social Security numbers, addresses, birth dates, and identity credentials.

Tassey specifically noted that children's identities are particularly valued by data thieves because they are, in his words, fresh. A child's identity may go undetected for years before the theft is discovered, making it a high-value target for long-term fraud.

The alarming part is how malware typically gets onto devices. It is not usually through pirated software or poor security settings. It enters through plugins and browser extensions that users install themselves, often for legitimate purposes. The installation is the vector.

Why Proctoring Plugins Create Specific Risk

Most online proctoring services require users to install browser extensions or plugins to enable monitoring. Each of these installations represents an opportunity for malware to enter the device, either during the initial installation or through a subsequent update, without the user's knowledge or permission.

Tassey's research notes that on average there are one to five bugs for every 1,000 lines of code. For organizations that have not completed independent code reviews of the proctoring software they deploy, those bugs represent an unexamined attack surface. Malware can be introduced into code updates without detection, meaning a plugin that was clean at installation may not remain so.

At minimum, organizations should be instructing learners to disable or uninstall proctoring plugins and extensions immediately after use. The risk does not end when the exam does.

What a Code Review Should Cover

Organizations that require learners to install proctoring software should conduct, or require their vendor to provide evidence of, a code review that addresses:

  • Potential malware embedded in the plugin or extension code
  • Errors or vulnerabilities that could be exploited by third parties
  • Whether the software receives automatic updates, and what review process governs those updates
  • What data the software transmits, to where, and under what conditions

If a vendor cannot provide clear answers to these questions, the software should not be deployed on learner devices.

The Case for No-Installation Proctoring

The most effective way to eliminate installation-based security risk is to remove the installation requirement entirely. Integrity Advocate's platform is browser-based and requires no plugin, extension, or application installation in most cases. There is nothing to install, nothing running in the background after the session ends, and no update mechanism that could introduce malware without the user's knowledge.

For use cases that do require a lockdown browser, Integrity Advocate's solution uses fully open source code, does not accept automatic updates after installation, and does not transmit data beyond what is required for the session. The code is publicly available for inspection.

The US Department of Education's guidance on protecting student privacy points to the same principle: the safest data handling approach minimizes what is collected, minimizes how long it is retained, and minimizes the software footprint on learner devices.

{{post-cta}}

Privacy & Data Protection
Assessment Security
No items found.
A professional interacts with a GDPR compliance interface, representing the data protection obligations online proctoring companies must meet when serving EU-based learners.
Blogs & articles
All Industries

Can Claims of GDPR Compliance by Proctoring Companies Be Trusted?

September 20, 2023

|

5 min read

Many proctoring companies claim GDPR compliance, but those claims are largely self-reported and rest on frameworks that have already been legally challenged. The EU-US Privacy Shield was invalidated in 2020, and its replacement relies on self-certification that does not resolve the underlying conflict between the US Patriot Act and GDPR's prohibition on non-consensual data disclosure. This post examines why US-based data storage creates a structural GDPR problem, what the DPF self-certification actually involves, and why Integrity Advocate's Canadian infrastructure and Privacy by Design architecture represent a substantively different approach.

Many online proctoring companies claim GDPR compliance. It is worth asking what that claim actually means, and whether it can be verified.

The short answer is that GDPR compliance claims are largely self-reported. There is no mandatory third-party verification process that a company must pass before making the claim. For organizations choosing a proctoring vendor on the basis of GDPR compliance, this creates a significant due diligence gap.

The US Patriot Act Problem

Many proctoring companies are registered in the United States or store data within US jurisdiction. This creates a direct conflict with GDPR that no privacy policy can resolve.

Data protection laws across the EU prohibit the disclosure of personal data without a data subject's consent or knowledge. The US Patriot Act gives the US government the ability to compel data disclosure from US-based companies or companies storing data on US infrastructure, without that consent and without notifying the individual.

A proctoring company that stores learner data on US servers and claims GDPR compliance is operating under two conflicting legal obligations. When those obligations conflict, US law governs US-based companies. The GDPR claim does not change that.

The Privacy Shield Failure

Many US-based organizations attempted to address this conflict by certifying under the EU-US Privacy Shield program, which was designed to provide a legal mechanism for transatlantic data transfers that satisfied GDPR requirements.

On July 16, 2020, Europe's top court invalidated the EU-US Privacy Shield, finding that the transfer mechanism did not ensure compliance with the level of protection required by EU law. The certification that many companies had pointed to as evidence of GDPR compliance was rendered invalid overnight.

The EU-US Data Privacy Framework: A Replacement With Familiar Weaknesses

Following the 2020 decision, negotiations between the EU and the US produced a new framework. On July 13, 2023, the US Department of Commerce launched the Data Privacy Framework program, intended to allow eligible US companies to self-certify their participation in the EU-US Data Privacy Framework.

The mechanism for self-certification is a short questionnaire and a fee to the US International Trade Administration, ranging from $375 to $4,875 USD depending on the company's revenue.

Critics have already noted that the new framework faces the same fundamental shortcomings as its Privacy Shield predecessor, including the unresolved tension between US surveillance law and EU privacy rights. Self-certification through a paid questionnaire does not resolve the underlying Patriot Act conflict.

What Meaningful GDPR Compliance Actually Requires

For a proctoring vendor's GDPR compliance claim to be substantive rather than self-reported, it needs to rest on something more than a certification program that can be obtained by filling out a form and paying a fee.

The most reliable indicator is where the data actually lives. If learner data is stored outside US jurisdiction, on infrastructure not subject to US government compelled disclosure, the conflict between the Patriot Act and GDPR does not arise.

Integrity Advocate's GDPR compliance is grounded in the same Privacy by Design architecture that underpins GDPR itself. All data is hosted in GDPR-designated jurisdictions, out of reach of governments with compelled data access authority. Integrity Advocate collects only what is necessary to confirm a learner's identity and compliance with exam rules, most of which is automatically deleted within 24 hours of session completion.

This is not a self-certification. It is an architectural position.

Questions to Ask Your Proctoring Vendor

Before accepting a GDPR compliance claim at face value, organizations should be able to answer the following:

  • Where is learner data physically stored, and in which legal jurisdiction?
  • Is the vendor registered in the United States or storing data on US infrastructure?
  • Is the GDPR compliance claim based on self-certification, third-party audit, or architectural design?
  • Has the vendor's compliance been reviewed independently, or is it self-reported?
  • What happens to learner data if the vendor receives a government data request?

If the answers are not clearly documented, the GDPR compliance claim deserves further scrutiny.

{{post-cta}}

Compliance
Privacy & Data Protection
No items found.
A hand points to an AI chip on a circuit board, representing the GPT-powered tools that are being used to compromise online assessment integrity.
Product releases
All Industries

AI Cheating Tools Are Outpacing LMS Defenses. Integrity Advocate Built a Solution

August 17, 2023

|

5 min read

GPT-powered browser plugins can now prefill answers to online exam questions the moment they appear, and LMS platforms have no effective countermeasures. Integrity Advocate's ExposeAI is a purpose-built detection capability that identifies AI-assisted cheating during assessment sessions, integrating directly into the existing monitoring suite without any client-side installation. This post explains how these tools work, why they matter for certified training programs, and how ExposeAI addresses the threat.

A few years ago, the concern about AI in online assessments was theoretical. Today it is not. GPT-powered browser plugins can prefill answers to multiple choice exam questions the moment they appear on screen, regardless of the topic or difficulty level. The learner does not need to read the question. They do not need to understand it. The answer is already there.

Integrity Advocate has been tracking this development closely. The response is ExposeAI, a new detection capability built directly into Integrity Advocate's monitoring suite.

How GPT-Powered LMS Plugins Work

Learning Management System plugins powered by generative AI have proliferated rapidly. Among the tools currently in use are Github Copilot, AnswersAI, ConchAI, Jasper, ChatSonic, Coursology, Hyperwrite, Quillbot, and Monica, among dozens of others that continue to emerge.

These tools share several characteristics that make them particularly difficult to address through standard LMS countermeasures:

  • They are inexpensive or free to obtain
  • They require no technical expertise to install or activate
  • Once installed, they operate automatically and continuously
  • They are designed to conceal their presence and adapt to detection attempts
  • New variants emerge faster than most platforms can respond

As a result, organizations relying on their LMS provider to develop effective countermeasures are unlikely to find one. LMS companies have no current solutions to this threat, and the nature of these plugins makes them unlikely to be eradicated through platform-level defenses alone.

The integrity of online assessments and certifications depends on a different approach.

Why This Matters for Assessment Integrity

The implications extend beyond academic dishonesty. For organizations issuing certifications that carry regulatory or legal weight, an assessment completed with AI assistance is not a valid measure of knowledge or competency. The certification it produces is as hollow as one issued without any training at all.

The same worker who received a fraudulent safety certification from a provider that did not deliver training could receive an equally fraudulent certification from an organization that delivered the training but could not prevent AI tools from completing the assessment on the learner's behalf. The outcome is the same: a credential that does not reflect what the person actually knows.

Introducing ExposeAI

ExposeAI is Integrity Advocate's purpose-built response to AI-assisted assessment fraud. It can be incorporated into Integrity Advocate's existing monitoring suite without any technical effort from clients, and works across the full range of devices and browsers that Integrity Advocate supports, from mobile to desktop.

ExposeAI is designed to detect the presence and use of GPT-powered plugins during an assessment session, giving organizations the visibility they need to maintain the integrity of their certification and training programs in an environment where AI tools are becoming standard equipment for learners looking to shortcut the process.

This is part of Integrity Advocate's broader commitment to staying ahead of the threats that matter most to the programs it serves. Human review remains at the core of every session. ExposeAI adds a layer of detection specifically designed for the AI-assisted cheating methods that automated systems alone cannot reliably identify.

The Broader Picture

AI cheating tools are not a passing trend. They are becoming cheaper, more capable, and more widely available. Organizations that do not have a response to this threat are issuing certifications they cannot stand behind.

Integrity Advocate's approach combines human review with purpose-built AI detection, so the results your program issues reflect what learners actually know, not what an algorithm answered for them.

{{post-cta}}

AI Cheating
LMS Integration
No items found.
Construction workers silhouetted against a sunset on scaffolding, representing the high-risk environments where verified safety training certification is a matter of life and safety.
News
Training providers
Associations and Awarding Bodies

Safety vs. Profit: What the Valor Indictment Says About Online Training

April 23, 2023

|

5 min read

The indictment of Valor Security and Investigations for issuing thousands of fraudulent safety certificates, connected to the death of construction worker Ivan Frias, illustrates what is at stake when safety training is treated as a commodity rather than a genuine investment in worker safety. This post examines the Valor case, the conditions that enabled it, and what verified identity and participation monitoring look like as the standard safety training must meet.

In February 2023, New York-based construction training provider Valor Security and Investigations, along with six of its executives, was indicted on charges that the company issued thousands of safety certificates without providing any training at all. The words belong to Manhattan District Attorney Alvin Bragg, who described it as thousands and thousands of safety certificates and cards issued without any training whatsoever.

The charges stem from a November 2022 incident in which construction worker Ivan Frias fell to his death from the 15th floor of a job site on West End Avenue. Frias was safety certified. He had, on paper, completed an eight-hour fall prevention course. He was one of more than 20,000 Valor-certified workers who allegedly received little or no actual safety training.

This is not an abstract compliance problem. A person died.

The System That Made This Possible

Valor's alleged fraud may be extreme, but the conditions that enabled it are not unusual. They reflect a broader pattern in how safety training is treated by some employers and some training providers.

For some employers, safety training is viewed as an expense to be minimized rather than an investment in the people doing the work. The demand for cheaper, faster, easier certification creates a market for providers willing to supply it. Valor appears to have been built to serve exactly that demand.

Training companies can be complicit in this. When the priority is volume and convenience rather than the integrity of the program, corners get cut. Verification gets skipped. Participation goes unconfirmed. A certificate gets issued that represents nothing.

That attitude then reaches the workers themselves. Disillusioned by a system that treats their safety as a formality, many disengage from training altogether. They navigate hazardous job sites without the knowledge they were supposed to have. The certificate says they are qualified. The training says otherwise.

What the Indictment Establishes

The Valor case is not just a criminal matter. It is a public statement about what verified training actually means, and what happens when it is absent.

Courts have consistently held that for safety training to carry legal and regulatory weight, it must involve confirmation of who completed it and whether they participated. The Valor indictment reinforces this standard at the criminal level. Issuing a certificate without delivering training is not just a compliance failure. It is fraud.

For employers, the implication is direct. A training record that cannot confirm identity or participation is not a defense in a regulatory investigation or a wrongful death proceeding. It is evidence of negligence.

What Meaningful Reform Looks Like

The Valor case makes clear that voluntary standards are not sufficient. Regulatory agencies need to strengthen oversight and codify what courts have already established: that valid safety training requires verified identity and confirmed participation.

Employers need to recognize that the cost of cutting corners is not abstract. It is measured in the lives of workers who trusted that their training prepared them for what they would face on the job.

And the industry needs to move past treating safety training as a checkbox. A certificate that was never earned is not protection. It is a liability, for the employer, for the certifying organization, and most importantly for the worker whose name is on it.

Every worker has the right to return home safely at the end of each day. Verified training is one of the most direct ways employers can uphold that right. Anything less is a failure of responsibility.

{{post-cta}}

Assessment Security
Identity Verification
Defensible Outcomes
No items found.
A food industry worker wearing gloves handles produce in a commercial setting, representing the food safety environments where verified manager certification is a regulatory requirement.
Blogs & articles
Corporations
Training providers
Credentialing

Four Ways to Improve Online Food Manager Certifications

April 17, 2023

|

5 min read

Food manager certification programs face four recurring challenges: inadequate identity verification, scheduling barriers, installation-based security risks, and equity issues created by AI-only proctoring. The Chipotle $25 million fine demonstrates what is at stake when food safety training compliance falls short. This post examines each challenge and explains how Integrity Advocate's installation-free, human-reviewed proctoring addresses all four.

Maintaining food safety across restaurants, processing plants, grocery stores, and other food handling environments is a complex, multi-layered challenge. Workers handle food directly. Managers set policies, define processes, and own the day-to-day culture of operations. Different roles require different training, and the stakes at the management level are particularly high.

When food manager certification programs fall short, the consequences are not abstract. In 2020, Chipotle incurred a $25 million fine because it failed to ensure that employees understood and complied with its food safety protocols. The fine followed a series of foodborne illness outbreaks between 2015 and 2018 that affected more than 1,100 people.

As Assistant Attorney General Jody Hunt stated at the time, the case highlights why it is important for restaurants and members of the food services industry to ensure that managers and employees consistently follow food safety policies.

Training is the first line of defense. And for online food manager certification specifically, there are four areas where most programs fall short.

Background: Food Handler vs. Food Manager Certification

In the US, state-level agencies determine training requirements for food handlers, generally following standards defined by the American National Accreditation Board's Conference for Food Protection Standards, which is based on American National Standards Institute guidelines.

Food safety manager certification applies to managers and team leads, the people responsible for those with food handler certification. It requires a deeper understanding of foodborne illness prevention, HACCP principles, sanitation practices, and regulatory requirements. ANAB/ANSI standards require that food manager certification exams are proctored and that test takers verify their identity before starting.

1. Verification and Proctoring

For certification to be meaningful, the person taking the exam must be who they say they are and must follow the rules throughout the session. ANAB/ANSI standards are explicit about this requirement.

The problem is that many proctoring services claim to check participant IDs without applying any meaningful standard of scrutiny. In many cases, a library card or gym card is accepted without question. When the identity check is that superficial, the system is open to abuse and the certification it produces is vulnerable to challenge.

Integrity Advocate's identity verification process confirms that the person completing the exam matches a government-issued photo ID, with human review of flagged sessions before any outcome is recorded. That is the standard that ANAB/ANSI compliance actually requires.

2. Scheduling

Food service workers often work long, unpredictable hours. Unless proctored certification exams are available on demand, finding time to complete them is genuinely difficult. When workers can find the time, some proctoring systems make them wait, with reported wait times of 45 minutes or longer before a session can begin.

On-demand proctoring that is available at any time, on any device, eliminates this barrier entirely. A food service manager working a split shift should be able to complete a proctored certification exam during their break, not schedule around a proctoring provider's availability.

3. Participant Security and Provider Liability

Most proctoring services require participants to install software, browser plugins, or extensions to enable remote monitoring. This can involve bypassing standard security restrictions, changing system settings, or disabling antivirus software. Participants typically receive no follow-up support, no instructions for re-enabling security features, and no help uninstalling the proctoring software after the exam.

For certifying organizations, this creates practical and legal exposure. Installation requirements increase participant support demands significantly and introduce security risks that the organization then shares responsibility for.

Integrity Advocate requires no installation. The platform is browser-based and works on any device without changing security settings, disabling protections, or leaving software behind after the session ends.

4. Equity

Online proctoring systems that require specific devices, operating systems, or browser configurations create disadvantages for participants who do not have access to the required setup. Food service and related industries are diverse workplaces. A certification system that privileges certain technological configurations over others introduces inequity into a process that is supposed to be objective.

AI-based proctoring compounds this problem. Systems that rely on automated behavioral monitoring without human oversight leave no room for context, nuance, or accommodation. A participant with a disability that affects eye movement could be flagged for a violation they did not commit, with no meaningful review process to catch the error.

Integrity Advocate's browser-based platform works on any device without configuration requirements, and every automated flag is reviewed by a trained person before any finding is recorded. That combination addresses both the access and the fairness dimension of equity in online certification.

Building a Food Manager Certification Program That Holds Up

Solving for these four challenges starts at the design and implementation stage. An online food manager certification program built on a foundation of proper identity verification, on-demand availability, no installation requirements, and human-reviewed proctoring produces certifications that mean what they are supposed to mean and hold up to regulatory scrutiny.

Integrity Advocate's identity verification and participation monitoring tools are built for assessments in high-stakes industries, with a seamless, installation-free experience that works for anyone, at any time, from any device.

For a real-world example of how this works in practice, read our case study with Smart Serve Ontario.

{{post-cta}}

Online Proctoring
Assessment Security
No items found.
Smiling woman in gray polo shirt using a tablet with an ID badge clipped to her shirt.
To get support, please visit support center