Education
Online exam integrity without surveillance
Most of the integrity of an online examination comes from how it is designed, not from watching candidates. This guide covers question banks, randomisation, timing, anomaly analysis and proportionate proctoring.
· 5 min read
When institutions move examinations online, the first instinct is often to replicate the invigilated hall with technology: webcams, screen recording, room scans and automated flags for suspicious behaviour. These tools have their place, but they are expensive, intrusive, unreliable on weak connections, and they shift attention away from the factors that matter most. An examination that is well designed is hard to cheat on even without a camera. One that is poorly designed is easy to cheat on even with one.
Design the question bank first
The foundation of integrity is a bank of questions large enough that no two candidates receive the same paper and no single leaked question changes an outcome. Build the bank around the learning outcomes of the course, tagging each item with the outcome it measures, its difficulty and its type. Favour questions that require application rather than recall: a short scenario to interpret, a calculation with candidate-specific values, or a judgement to justify. Recall questions can be answered by searching; application questions require understanding. Open-book formats deserve consideration too. If an examination assumes candidates will have their notes, the incentive to consult them secretly disappears, and the questions must instead test whether the candidate can use what they know. Designing for open-book conditions often produces better assessment as well as better integrity, because it rewards reasoning rather than memory. It does, however, take more time to write good items, so plan the work well before the examination period.
- Write several equivalent variants of each item, testing the same outcome at the same difficulty.
- Use parameterised questions where the numbers or names change for each candidate but the method does not.
- Retire items that have been exposed, and keep a record of when and where each item was used.
- Have a second academic review items for ambiguity, because ambiguous questions create disputes that look like misconduct.
Randomise from item pools
Rather than shuffling the order of a fixed paper, assemble each candidate’s paper by drawing one item from each pool, where a pool contains equivalent variants of the same question. This keeps papers comparable in coverage and difficulty while making answer-sharing between candidates far less useful. Shuffle answer options too, except where the order carries meaning, such as numeric ranges. Check the fairness of pools after each sitting: if one variant is consistently answered worse than its siblings, it is not equivalent and should be revised.
Use time, and plan for weak connections
A realistic time limit is one of the strongest and least intrusive controls available. Set it so that a prepared candidate can finish comfortably, but there is little spare time for consulting others. Combine it with forward-only delivery for sections where it is appropriate: once a candidate moves on, they cannot return, which limits the value of collecting answers mid-examination. Be careful with forward-only delivery on unreliable connections; the platform must save each answer as it is given and allow a candidate to resume after a dropped connection without losing work or time unfairly. Integrity measures that disadvantage candidates with poor connectivity, older devices or disabilities are not integrity measures; they are a different kind of unfairness. Test the examination on the cheapest device and slowest connection a candidate is likely to have. Publish a clear procedure for reporting technical failures during the sitting, and decide in advance how extra time, alternative formats and reasonable adjustments will be granted. The interface should meet WCAG 2.2 so that candidates using assistive technology are not penalised. Run a short technical rehearsal a week before the sitting so that problems with devices, browsers and connections surface while there is still time to fix them.
Analyse anomalies after the sitting
Misconduct often leaves traces in the data. The platform should record, for each candidate, when each answer was given and changed, the time spent per item, and connection events. Analysed after the sitting, these records can surface patterns worth investigating: Treat these as prompts for a conversation, never as verdicts. An anomaly is a reason to look more closely; the decision belongs to an academic process with the right to respond, not to an algorithm.
- Pairs or groups of candidates with unusually similar answer patterns, especially shared wrong answers.
- Correct answers to difficult items submitted in implausibly short times.
- Performance far out of line with the same candidate’s coursework or previous assessments.
- Clusters of connection drops immediately before difficult sections.
An examination that is well designed is hard to cheat on even without a camera.
Proctoring in proportion
Where the stakes justify it, for example professional licensing or final-year assessments, some proctoring may be reasonable. Choose the least intrusive form that addresses the specific risk. A live invigilator on a video call for a small group is often more proportionate than automated recording of every candidate. If recording is used, state the purpose, who will review it, how long it will be kept and when it will be deleted, and enforce those limits in the system rather than in a policy document alone. Avoid automated flags that act on facial analysis or room noise without human review, as they produce false accusations and fall hardest on candidates in shared or crowded homes. Finally, explain the arrangements to candidates before the examination, in writing and in plain language. Candidates who understand how papers are assembled, what is recorded, how anomalies are reviewed and how to appeal are less likely to attempt misconduct and more likely to accept the outcome. Publish a practice paper on the same platform so that the first time a candidate meets the interface is not under examination conditions. Transparency is itself an integrity control: it deters, it reduces disputes, and it signals that the institution is assessing learning rather than hunting for offenders. Where proctoring is not justified, say so, and rely on the design measures above.
A short checklist
- Questions mapped to learning outcomes, with variants in every pool.
- Randomised assembly, shuffled options and realistic time limits.
- Answers saved continuously, with fair resumption after disconnection.
- Accessibility and adjustments agreed before the sitting.
- Post-sitting anomaly review feeding a fair academic process.
- Proctoring, if any, justified by stakes and limited in retention and access.