Online proctoring can protect the value of a credential, but a badly chosen or badly configured setup creates false accusations, privacy exposure and accessibility complaints. This checklist is for edtech product owners, exam controllers and IT leads who are choosing a proctoring vendor or building proctoring into their own platform. Work through it before you go live with high-stakes exams.

Before you start: define the risk

  • [ ] List each assessment and rate its stakes (practice quiz, graded assignment, certification, admission or licensing exam).
  • [ ] Match the proctoring level to the stakes. Low-stakes quizzes rarely justify webcam and screen recording.
  • [ ] Write down the specific misconduct you are trying to prevent (impersonation, unauthorised help, content leakage, collusion).
  • [ ] Ask whether assessment design (open-book, randomised questions, viva follow-ups) could reduce the need for surveillance.
  • [ ] Name an accountable owner for integrity decisions, separate from the vendor.

Identity verification

  • [ ] Verify the candidate at login, and again at random points for long exams.
  • [ ] Decide which ID methods you accept, and provide a fallback for candidates without standard ID.
  • [ ] Confirm who reviews ID mismatches: automated match only, or a trained human.
  • [ ] Define what happens when verification fails (retry, manual check, reschedule), so candidates are not simply locked out.

Exam-session controls

ControlQuestion to askNotes
Browser lockdownDoes it work on the devices your candidates actually own?Test on low-end laptops and mobile if allowed
Webcam / audio monitoringIs it live, recorded, or both?Recording increases your data-protection duty
Screen recordingIs it necessary for this exam?Collect only what you can justify
Question randomisationAre pools and order randomised per candidate?Cheap and privacy-friendly
Time and attempt limitsAre they enforced server-side?Client-side limits are easy to bypass
  • [ ] Check behaviour when the network drops mid-exam: is progress saved and time fairly handled?
  • [ ] Confirm the system supports your exam formats (MCQ, coding, essays, oral).
  • [ ] Verify server-side logging of answers, timestamps and session events.

Flagging, review and appeals

  • [ ] Ask whether flags come from AI only, or whether a human reviews each flag in context before any outcome is issued.
  • [ ] Get documented false-positive handling: what triggers a flag, and how you can tune sensitivity.
  • [ ] Ensure a flag is evidence for review, never an automatic penalty.
  • [ ] Publish a written appeals process with a deadline and a named reviewer.
  • [ ] Keep an audit trail of every decision: who reviewed, what evidence, what outcome.

Privacy and data protection

  • [ ] Map every data type collected (video, audio, screen, ID images, keystrokes, device data, biometrics).
  • [ ] Remove any collection you cannot justify for the stated purpose (data minimisation).
  • [ ] Confirm encryption in transit and at rest, and who at the vendor can access recordings.
  • [ ] Set a retention period and confirm automatic deletion after the review window closes.
  • [ ] Check where data is stored and whether sub-processors are involved.
  • [ ] Give candidates a clear notice before the exam explaining what is recorded and why.
  • [ ] If candidates include minors, review your obligations under India's DPDP Act, which requires verifiable parental consent for children's data and restricts tracking and behavioural monitoring, subject to limited exemptions for educational institutions. Have counsel confirm how this applies to you.
  • [ ] Record a data-processing agreement with the vendor covering breach notification and deletion.

Accessibility and fairness

  • [ ] Test the full flow with a screen reader and keyboard-only navigation.
  • [ ] Provide accommodations: extra time, breaks, alternative ID checks, assistive technology allowed.
  • [ ] Check that behaviours linked to disability or neurodivergence (looking away, movement, speaking aloud) are not auto-flagged.
  • [ ] Confirm face detection is tested across skin tones and lighting conditions; ask the vendor for evidence.
  • [ ] Offer an alternative for candidates with poor bandwidth, no webcam or shared living space.

Vendor evaluation

  • [ ] Request a sandbox and run a pilot with real candidates before contracting.
  • [ ] Ask for security reports or certifications and read the scope, not just the badge.
  • [ ] Check LMS/SIS integration (LTI, APIs, SSO) and data export options.
  • [ ] Review uptime commitments and support during exam windows.
  • [ ] Confirm you can leave: data export, deletion certificate, no lock-in on recordings.

Red flags

  • The vendor cannot explain how flags are generated or reviewed.
  • "Cheating detected" scores with no evidence attached.
  • Indefinite retention of video by default.
  • No accommodations workflow.
  • Refusal to run a pilot or share a data-processing agreement.

How to use this

Copy the list into your evaluation document. Mark each item pass, fail or not applicable per assessment tier, and treat any failed privacy or appeals item as a blocker for high-stakes use. Repeat the review each term or whenever you change vendor or exam format.

Next step

If you would like a second pair of eyes on your proctoring setup, we can walk through this checklist against your own exams, platform and candidate base in a 30-minute call. Book a 30-minute call