ExamsProctoringComputer-Based Testing
Exam security in practice: five layers that protect assessment integrity
A defensible exam needs more than a locked browser or webcam. Learn how assessment design, identity, session security, human oversight and privacy work together.
An exam result is a claim: this person completed this assessment, under the stated conditions, and the score is a trustworthy reflection of their work. Exam security exists to make that claim defensible.
That is broader than stopping someone from opening a second browser tab. A secure assessment must address impersonation, unauthorised access, content exposure, collusion, session takeover, technical disruption and the risk of treating an innocent irregularity as misconduct. It must also preserve accessibility and due process. A control that blocks legitimate candidates or produces conclusions nobody can review is not a complete security control.
The practical answer is a layered model. Each layer should answer a specific question, produce proportionate evidence and have a clear recovery path when something goes wrong.
Assessment security starts before anyone signs in
The strongest exam-security decision may happen while the assessment is being designed.
Begin by identifying what the exam is meant to measure and the consequence of a compromised result. A short formative quiz does not need the same controls as a professional certification or final examination. Higher-risk assessments justify stronger identity, session and oversight measures; lower-risk work may be better protected through thoughtful design and follow-up discussion.
The TEQSA assessment security guidance treats assessment design and operational security as connected. That is useful because monitoring cannot repair an assessment that rewards simple copying or relies on a small, repeatedly reused set of predictable questions.
Before adding surveillance, consider whether you can reduce avoidable opportunity through:
- questions that require application, comparison or explanation rather than transcription;
- an appropriate time window and duration;
- controlled access to the correct paper and candidate group;
- clear rules about permitted resources and collaboration;
- rehearsals that expose device, network and accessibility problems; and
- a documented response for disconnections, accommodations and suspected misconduct.
These choices do not remove the need for technical controls. They make those controls more targeted and easier to defend.
Identity and session controls answer different questions
Candidate identity and session security are often discussed as if they were one problem. They are not.
Identity verification asks whether the person beginning the assessment is the expected candidate. A login code alone may prove that someone has a credential, not that the expected person is using it. For higher-risk remote exams, a liveness check and comparison with an enrolled image can add evidence that a real, present person matches the institution's record.
This is also where restraint matters. NIST's current identity-proofing guidance describes presentation-attack detection, protected channels and defences against image or video injection as parts of a stronger remote identity process. NIST guidance is not an exam rulebook, but it provides a useful engineering principle: a face image by itself is not proof of live presence.
Session security asks what happens after admission. The application needs to keep the candidate bound to the correct exam and attempt, prevent casual reuse of an active session, enforce authorisation on every sensitive action, and close or expire access safely. The OWASP Session Management Cheat Sheet stresses that authentication, session state and access control must remain linked throughout the transaction. In an exam, that transaction lasts from sign-in to final submission.
A good workflow therefore treats identity approval as one event inside a protected attempt, not as a permanent pass that can be copied into another browser or reused for another exam.
Proctoring should produce evidence, not automatic certainty
Live proctoring can answer questions that identity verification cannot. An invigilator can confirm the candidate's environment, check that the intended screen is shared, communicate during a disruption and decide when the candidate may begin.
But a webcam view does not reveal intent, and a brief network interruption is not evidence of misconduct. Even a well-run session has blind spots outside the camera frame and events that require context. Proctoring is most useful when it creates a reviewable record for a trained person rather than a score that automatically labels behaviour.
An operational proctoring plan should say:
- who may observe a session and which candidates they may access;
- what the candidate must share before admission;
- what the invigilator checks before authorising the start;
- how messages and interventions should be used;
- how technical failure is distinguished from a conduct concern;
- what evidence is recorded, who can review it and for how long; and
- how a candidate can challenge an incorrect decision.
This protects both sides. Candidates know the conditions before the assessment, while institutions can show that decisions followed a consistent process.
Privacy and accessibility are part of exam security
Biometric and monitoring controls handle sensitive information. Their use should be necessary for the assessment risk, transparent to the candidate and limited to a stated purpose.
The NIST authentication guidance treats biometric data as sensitive personal information and calls for a non-biometric alternative. The UK's Information Commissioner's Office similarly emphasises necessity, proportionality and clear privacy information when organisations use facial recognition in education. The exact legal duties vary by jurisdiction, but the design lesson travels well.
Candidates should know what is collected, why it is needed, where it is processed, who can access the outcome and how long relevant records are retained. They also need a workable route when they cannot consent, cannot use a camera, experience a false non-match or require an accommodation.
That fallback is not a weakness. It prevents a technical control from becoming an unreviewable barrier to assessment. Security is stronger when exceptions are handled through an authorised, documented decision rather than an improvised workaround.
How examina.io supports layered exam security
examina.io brings these controls into one assessment workflow instead of leaving administrators to coordinate separate tools and disconnected evidence.
In Manager, authorised staff can map candidates to the intended exam and paper, configure timing and delivery conditions, and restrict administration through account roles and Circles. The candidate then enters a specific protected attempt rather than receiving general access to assessment content.
For assessments that require stronger identity evidence, eFaceID combines an enrolled candidate image with an express-consent flow, a live facial check and a comparison bound to the candidate, exam and attempt. The candidate sees processing and retention information before capture and can request a non-biometric review when consent, accessibility or technical circumstances require another route.
For assessments that need human oversight, Live Exam Proctoring lets an authorised invigilator request the candidate's webcam and shared-screen streams, verify the environment, communicate with the candidate and explicitly authorise the exam to begin. The invigilator can switch between the webcam, screen and session details while the candidate completes the assessment, then verify completion and results in Manager.

No single feature can prove academic integrity on its own. What examina.io provides is a connected set of controls and evidence: assessment configuration, candidate binding, identity verification where appropriate, protected attempt state, live human oversight and result review.
The next step for an institution is not to enable every control for every exam. Classify assessment risk, choose the smallest set of controls that addresses it, rehearse the full candidate and invigilator journey, publish the fallback process, and review what the evidence can actually support. That is how exam security becomes a repeatable practice rather than a collection of intimidating settings.