Implementing Advanced Proctoring Technology at a High-Volume Student Testing Center
Designing Human-Supervised AI Proctoring for High-Volume Testing
An illustrative operating model for combining identity checks, exam controls, computer vision, human review, privacy safeguards, and student accommodations.
About this case study: This page describes a representative high-volume testing scenario and recommended implementation model. It does not present audited results from a named Web Inventix AI client. Identity, security, efficiency, fairness, and academic-integrity outcomes depend on the exam design, student population, technology, testing conditions, accommodations, data quality, human review, institutional policy, and applicable law.
Executive Summary
High-volume testing organizations need to confirm who is taking an exam, apply consistent testing rules, identify technical or security exceptions, support students who require accommodation, and preserve a defensible record when an incident is reviewed.
Technology can support those tasks, but it cannot determine academic misconduct reliably on its own. Camera signals, identity scores, browser events, object detections, audio events, and unusual movements are indicators that may require review. They are not proof that a student cheated.
A responsible design combines narrowly scoped technology with trained proctors, documented exam rules, clear student notice, accessible alternatives, privacy controls, incident review, and an appeal process.
The recommended first project is a limited human-supervised pilot. Begin with one exam type, minimize data collection, validate every automated flag, measure demographic and accessibility impacts, and retain human authority over all academic-integrity decisions.
Industry Context
Online and computer-based assessment can improve scheduling flexibility and expand access, but remote monitoring introduces additional privacy, security, fairness, accessibility, and procedural risks.
The Information and Privacy Commissioner of Ontario reviewed McMaster University’s use of Respondus Monitor and found problems with notice, use of personal information, and contractual safeguards. The decision illustrates that purchasing a widely used proctoring product does not transfer accountability away from the institution.
The Office of the Privacy Commissioner of Canada’s 2025 biometrics guidance states that organizations should identify an appropriate purpose, assess necessity and proportionality, use appropriate consent, limit collection and retention, safeguard the information, test accuracy, and provide transparency.
Face recognition performance also varies by algorithm, use case, image quality, operating threshold, and demographic group. NIST’s face-recognition evaluations have documented demographic differentials across many tested algorithms.
These issues make proctoring a governance and assessment-design problem, not only a computer-vision project.
Representative Testing Scenario
Consider a university testing centre, professional certification provider, training organization, or assessment company administering approximately 100 to 300 online or computer-based exams each day.
The organization supports several exam types with different risk levels. Some are low-stakes course assessments. Others affect certification, program progression, licensing eligibility, or access to employment.
The current operating model includes manual check-in, live or recorded video, exam-delivery software, human proctors, incident forms, email-based accommodation requests, and separate systems for student records and appeals.
The organization is experiencing several problems:
- Check-in procedures vary by proctor and exam type
- Identity documents and video are reviewed inconsistently
- Proctors monitor too many simultaneous sessions
- Automated alerts generate large numbers of low-value flags
- Head or eye movement is sometimes treated as evidence without context
- Technical failures interrupt exams and create appeals
- Students do not fully understand what is recorded or inferred
- Accommodation and alternative-testing processes are handled separately
- Incident evidence, decisions, and appeals are stored across several systems
- Management lacks reliable measures of false alerts, demographic performance, student complaints, and cost per completed exam
Operational Challenges
Identity Assurance
The organization must confirm the correct person is taking the exam without collecting more biometric and identity information than the risk justifies.
Alert Overload
Proctors receive repeated flags for ordinary movement, poor lighting, background activity, assistive technology, connectivity issues, and camera-position changes.
Procedural Fairness
Students may be affected by automated scores or inferences without understanding the evidence, decision process, or method for challenging a result.
Accessibility
Movement, gaze, speech, environment, device, and interaction rules may create barriers for students with disabilities or accommodation needs.
Privacy and Security
Video, audio, identity documents, biometric templates, screens, room images, device data, and behavioural inferences may be highly sensitive.
Weak Evidence Management
Flags, recordings, proctor notes, decisions, student responses, and appeals are not connected through a consistent case-management process.
Recommended Human-Supervised Proctoring Solution
The recommended solution is a layered assessment-integrity platform. It combines only the controls justified by the exam’s risk, delivery method, student population, and legal environment.
The first release should focus on consistent check-in, reliable exam delivery, targeted alerts, human review, accommodations, and incident management. Continuous facial recognition, gaze scoring, room scans, and audio analysis should not be enabled merely because a vendor offers them.
| Component | Purpose | Initial control | Primary measure |
|---|---|---|---|
| Exam-risk classification | Match controls to the consequence and threat level | Academic, privacy, security, and accessibility approval | Controls justified by risk |
| Identity check | Confirm the registered test-taker | Offer a non-biometric or human-review route where required | False match and false non-match rates |
| Exam delivery controls | Limit prohibited applications, resources, or navigation | Technical test and accessible alternative | Successful exam launches |
| Video event detection | Flag face absence, additional persons, or approved object categories | Every flag requires contextual human review | Confirmed-event precision |
| Live proctor dashboard | Prioritize sessions that require attention | Severity rules and proctor workload limits | Response time and missed incidents |
| Incident case management | Connect evidence, notes, student response, decision, and appeal | Role-based access and documented procedure | Decision consistency and appeal outcomes |
| Accommodation workflow | Apply approved adjustments without exposing unnecessary health information | Disability-services or authorized-office approval | Accessible exam completion |
| Privacy and retention controls | Limit collection, access, sharing, and storage | Data map, retention schedule, deletion verification, and audit | Records deleted on schedule |
Recommended operating principles
- Use the least intrusive control that can meet the defined purpose
- Do not treat automated flags as proof of misconduct
- Do not use gaze or head movement as a standalone integrity finding
- Separate camera analysis from browser and device telemetry
- Provide meaningful notice before the exam
- Offer an accessible accommodation and exception process
- Require human review before an incident affects a student
- Allow the student to understand and respond to the evidence
- Test performance across relevant demographic and accessibility conditions
- Retain only the data required for the approved purpose and appeal period
Integrity Signals and Their Limits
A responsible system distinguishes between what the technology observes and what the institution concludes.
| Signal | Possible meaning | Important limitation | Recommended response |
|---|---|---|---|
| Identity mismatch score | The check-in image differs from the stored or presented reference | Lighting, camera quality, appearance changes, disability, demographics, and threshold settings affect performance | Human identity review or approved alternative verification |
| No face detected | The student may have moved outside the camera frame | Poor lighting, camera movement, assistive positioning, or occlusion may produce the same result | Check session context and contact the student where appropriate |
| Additional face or person | Another person may have entered the testing area | Photographs, screens, mirrors, background movement, or model error can trigger a flag | Review the video segment and applicable exam rule |
| Phone or prohibited object | A device or unauthorized material may be visible | Object models can confuse similar shapes and may miss partially hidden items | Human confirmation before opening an incident |
| Head or gaze movement | The student looked away from the screen | Normal thinking, reading, disability, anxiety, room layout, and assistive technology can produce the same behaviour | Do not use alone as evidence; review only with stronger corroborating information |
| Speech or background audio | Conversation or another audio source may be present | Neighbouring rooms, accessibility needs, environmental noise, and transcription errors can cause false alerts | Use only when necessary and proportionate; review manually |
| Browser focus change | The exam window lost focus or another application opened | This comes from exam or device software, not computer vision; system notifications and assistive tools may trigger it | Review the event, permitted software, and technical logs |
| Network interruption | The student lost connectivity or the monitoring stream stopped | It does not indicate misconduct | Apply the documented technical-failure and resumption process |
| Room scan anomaly | The scan may not show the full testing area | Room scans can expose highly personal information and create accessibility barriers | Avoid by default; use a less intrusive method where practical |
An anomaly score is a queue-management tool, not a misconduct verdict. Academic decisions require evidence, context, policy, human judgement, and procedural fairness.
Representative Testing Workflows
Workflow 1: Pre-Exam Check-In
Provide advance notice
The student receives plain-language information about the exam rules, technology, data collected, automated functions, service providers, retention, accommodations, alternatives, technical requirements, and support contacts.
Run a technical readiness check
The system checks supported browser, camera, microphone if required, network, permitted assistive technology, device settings, and software conflicts before exam day.
Confirm identity proportionately
The process uses the minimum identity evidence appropriate for the exam. Biometric verification is used only when justified, tested, disclosed, and supported by an alternative route where required.
Apply accommodations and approved exceptions
The proctoring configuration receives only the operational adjustment needed, such as extra time, permitted movement, breaks, assistive software, reader support, or an alternate testing method.
Start the exam
The student sees the active controls and receives a clear way to request technical or human assistance.
Workflow 2: Live Monitoring and Alert Review
Collect approved signals
The platform collects only the video, audio, browser, identity, or device events approved for that exam type.
Prioritize an event
The system groups related events, applies severity rules, suppresses duplicates, and sends the relevant session segment to a trained proctor.
Review context
The proctor checks the exam rule, accommodation record, prior technical events, video segment, browser log, timing, and available student explanation.
Choose a proportionate response
The proctor may dismiss the flag, note it, contact the student, provide technical help, issue an approved reminder, pause the exam, or escalate a serious event.
Preserve only relevant evidence
If an incident is opened, the system stores the necessary segment, event data, proctor notes, and chain of review under the approved retention schedule.
Workflow 3: Post-Exam Incident Review and Appeal
Separate detection from decision
A trained reviewer who understands the academic-integrity policy evaluates the incident. The automated system does not assign guilt or invalidate the exam.
Verify the evidence
The reviewer confirms timestamps, identity, system reliability, relevant exam rule, accommodation, technical conditions, and whether the evidence is complete.
Notify the student
The student receives the allegation, relevant evidence or an appropriate summary, policy basis, response process, deadline, and support information.
Make a human decision
An authorized person or committee decides the outcome under the institution’s policy and records the reasons.
Support review or appeal
The system preserves the required record and tracks appeal, correction, overturn, deletion, and policy-improvement outcomes.
Workflow 4: Technical Failure and Alternate Path
Detect the failure
The system records camera, browser, network, service, authentication, or device failure without classifying it as misconduct.
Protect the student’s exam state
Where the platform supports it, the exam is paused or saved without exposing answers or extending access improperly.
Offer a documented resolution
The student may reconnect, receive live support, move to a human-proctored session, use an approved alternative, or reschedule without an automatic penalty.
Solution Architecture
Exam content, timing, question rules, permitted resources, submissions, autosave, and session status.
Human check, identity document, account authentication, one-to-one facial verification, or another approved method based on risk.
Approved presence, person-count, object, camera-state, or environmental signals. Local processing may reduce transfer but does not remove privacy obligations.
Window focus, application restrictions, display checks, copy-and-paste rules, and exam-software telemetry. These controls are separate from computer vision.
Exam-specific thresholds, duplicate suppression, accommodation exceptions, severity levels, and proctor routing.
Live session status, prioritized alerts, evidence segments, support tools, interventions, and workload management.
Approved operational adjustments without exposing unnecessary diagnostic or medical information to proctors or vendors.
Evidence, policy references, student response, reviewer notes, decisions, appeals, corrections, and retention status.
Encryption, role-based access, access logs, regional processing records, retention schedules, deletion verification, and breach response.
Technical reliability, alert quality, demographic differentials, accommodations, complaints, appeals, cost, and exam-completion metrics.
Technical support, live proctoring, accessibility support, privacy inquiries, academic review, and emergency escalation.
APIs, identity providers, learning systems, student records, assessment platforms, service-provider controls, and contract monitoring.
The architecture should keep biometric templates, identity documents, full-session recordings, short incident clips, browser events, accommodation records, and academic decisions under separate access and retention rules.
Implementation Plan
Define the exam purpose, stakes, threat model, student population, current incident process, technical environment, accommodations, alternatives, and success measures.
Consider whether open-book design, question banks, oral verification, project work, in-person testing, or other assessment methods can reduce the need for surveillance.
Complete privacy, security, human-rights, accessibility, records-management, procurement, and algorithmic impact reviews appropriate to the institution and jurisdiction.
Assess data flows, subprocessors, training-data use, biometric storage, accuracy testing, demographic performance, breach history, encryption, retention, deletion, audit rights, model changes, accessibility, support, and exit terms.
Use synthetic data, staff volunteers, or approved test sessions. Validate integrations, technical support, identity alternatives, accessibility, event definitions, evidence handling, and deletion.
Run one exam type with a limited cohort. Human reviewers validate every flag. No automated finding affects a grade, credential, or disciplinary decision.
Measure false alerts, missed events, demographic differentials, accessibility issues, technical failures, student complaints, appeal outcomes, proctor workload, and full cost.
Expand only when the institution can justify the controls, demonstrate reliable performance, provide alternatives and accommodations, support human review, and operate the privacy and incident process.
Review vendor updates, model changes, thresholds, complaints, appeals, demographic performance, retention, security, and necessity on a defined schedule. Retire controls that no longer remain necessary or proportionate.
Privacy, Biometrics, Accessibility, and Human Rights
Proctoring systems may collect identity documents, face images, biometric templates, video, audio, screens, browser activity, IP addresses, device details, room images, behavioural inferences, disability-related adjustments, and incident records.
Use the least intrusive method
The organization should define the exam-integrity purpose and test whether less privacy-invasive methods can meet it. The Office of the Privacy Commissioner of Canada’s biometrics guidance specifically emphasizes necessity, proportionality, consent, collection limits, accuracy, safeguards, openness, and accountability.
Do not assume consent solves the issue
Students may have limited practical choice when a system is required for course progression, licensing, or certification. The institution should assess the legal authority and appropriateness of the processing rather than relying only on a checkbox.
Biometric alternatives
Where biometric verification is used, provide a human or other reasonable identity-verification route when required. The biometric process should not become the only route for a student who cannot use it reliably or lawfully.
Accuracy and demographic testing
Do not claim equitable or perfect identity performance without representative evidence. Test false matches and false non-matches across relevant conditions and groups, monitor results after deployment, and investigate material differences.
Meaningful notice
Students should receive one clear, accessible source explaining what is collected, why, which automated functions are used, what is inferred, who receives the data, where it is processed, how long it is retained, how to obtain assistance, and how to challenge a result.
The Ontario IPC’s McMaster Respondus decision specifically recommended a consolidated, plain-language, accessible notice rather than requiring students to assemble information from several sources.
Accessibility and accommodation
Ontario education providers have a duty to accommodate disability-related needs to the point of undue hardship. Testing and evaluation procedures should not create discriminatory barriers.
Examples may include:
- Permitted movement or breaks
- Screen readers, magnification, speech input, or other assistive software
- Alternative camera positioning
- Reduced or disabled movement alerts
- A human-proctored or in-person alternative
- Additional setup or exam time
- Private support that does not disclose a diagnosis to the proctor
Children and youth
When students are minors, the institution should apply heightened privacy and best-interest safeguards, age-appropriate notice, limited collection, appropriate consent, strong vendor controls, and practical alternatives.
Human decision-making and appeal
An automated score should not invalidate an exam, create a misconduct finding, or impose a penalty. Students need a fair review by an authorized person and a method to correct information or appeal the decision.
Data retention and deletion
Full recordings, short clips, identity documents, biometric templates, technical logs, incident evidence, and final decisions may require different retention periods. Retain only what is necessary for the defined purpose, legal obligations, and appeal process.
Privacy, accessibility, and procedural fairness are part of exam validity. A system that creates unequal barriers or unreliable accusations can undermine the integrity it is intended to protect.
Measurement Framework
This illustrative case study does not claim an 89% reduction in cheating, 100% identification accuracy, or fixed efficiency gains. A pilot should establish transparent definitions and report both benefits and harms.
| Metric | Definition | Why it matters |
|---|---|---|
| Successful check-in rate | Students who complete identity and technical checks without staff intervention | Measures usability, not identity accuracy alone |
| Check-in time | Time from start of check-in to exam access | Shows operational friction |
| Technical failure rate | Exams interrupted or delayed by platform, device, network, camera, or authentication problems | Protects students from technology-driven disadvantage |
| Automated alert rate | Flags generated per completed exam or exam hour | Shows system sensitivity and proctor workload |
| Confirmed-event precision | Alerts that human reviewers determine require follow-up | Measures alert usefulness |
| Missed-event rate | Confirmed incidents not surfaced by the system | Prevents a false sense of security |
| False match rate | Incorrect biometric match to another identity | Measures identity risk |
| False non-match rate | Failure to match the correct student | Measures exclusion and access risk |
| Demographic performance differential | Material performance differences across relevant groups and conditions | Supports fairness review |
| Accommodation success rate | Students completing exams with approved adjustments | Measures accessibility |
| Human review time | Proctor and investigator time per session and incident | Shows actual operating cost |
| Incident decision rate | Reviewed cases resulting in a formal academic-integrity finding | Separates alerts from decisions |
| Appeal and overturn rate | Decisions appealed, corrected, or reversed | Identifies procedural and evidence problems |
| Student complaint rate | Privacy, accessibility, technical, fairness, and support complaints | Measures trust and operational harm |
| Retention compliance | Records deleted or preserved according to policy | Measures privacy operations |
| Cost per fair completed exam | Total technology, staffing, support, review, accommodation, and appeal cost divided by exams completed under the approved process | Provides a complete operating measure |
Illustrative operating-value formula
Net testing value = verified operating capacity + reduced manual administration + faster legitimate review − software − devices − integration − proctoring − support − accommodations − privacy controls − investigations − appeals − remediationDo not measure success by the number of flags, allegations, or penalties. A system can increase those numbers simply by generating more false positives.
Risks and Recommended Controls
| Risk | Example | Recommended control |
|---|---|---|
| Automated accusation | A movement score is treated as proof of cheating | Human review, corroborating evidence, student response, and no automated adverse decision |
| Demographic bias | Identity verification fails more often for a group or condition | Representative testing, threshold review, alternative verification, monitoring, and remediation |
| Accessibility barrier | Assistive technology or disability-related movement triggers alerts or prevents launch | Accommodation workflow, technical testing, accessible alternatives, and trained support |
| Excessive surveillance | The system records a student’s room, audio, screen, and behaviour without necessity | Data minimization, exam-risk tiers, less intrusive alternatives, and impact assessment |
| Biometric breach | Face templates or identity images are exposed | Template protection, encryption, separation, access controls, retention limits, and incident response |
| Weak notice | Students learn about recording or biometric processing during check-in | Advance consolidated notice in accessible plain language |
| Technical exclusion | A student lacks a compatible device, private room, bandwidth, or camera | Readiness checks, loaned equipment, testing-centre option, alternate delivery, and no automatic penalty |
| Alert overload | Proctors cannot review the number of events generated | Workload limits, severity rules, suppression, sampling, and threshold tuning |
| Evidence integrity failure | A clip lacks context or timestamps do not align | Chain of evidence, synchronized logs, complete context, audit trail, and reviewer training |
| Vendor change | The provider changes its model, subprocessors, retention, or accuracy | Change notification, audit rights, approval gates, revalidation, and termination rights |
| Security vulnerability | Monitoring software exposes the student’s device or data | Security testing, least privilege, code-signing review, patching, incident response, and alternative method |
| Purpose expansion | Exam video is later used for research, discipline, attendance, or model training | Purpose limitation, separate authority or consent, contract restrictions, and audit |
| Unfair appeal process | The student cannot see or challenge the evidence | Clear notice, access to relevant information, independent review, reasons, and appeal |
Where This Model Fits
This approach is a stronger fit when the testing organization has:
- A genuinely high-stakes or security-sensitive assessment
- A documented reason remote or technology-assisted proctoring is necessary
- Clear exam rules and incident procedures
- Privacy, security, accessibility, legal, and academic-integrity ownership
- Qualified human proctors and reviewers
- A practical accommodation and alternative-testing process
- Representative data and participants for pilot testing
- A case-management and appeal process
- Authority to control vendors, retention, and data use
- A baseline and agreed measures of reliability, fairness, and cost
It is a weaker fit when:
- The assessment is low stakes and could use a less intrusive format
- The institution wants software to replace academic-integrity judgement
- Students cannot access a suitable device, room, or connection
- No reasonable accommodation or alternative is available
- The institution cannot explain what the system collects or infers
- Vendor claims of fairness or accuracy cannot be independently evaluated
- There is no trained human review or appeal process
- The project begins with facial recognition or gaze tracking rather than a defined assessment problem
- The institution cannot protect or delete the collected data
The strongest first project is usually consistent check-in, technical readiness, proctor workflow, and incident case management. Add biometric or behavioural analysis only when the institution can demonstrate that it is necessary, proportionate, reliable, accessible, and governed.
FAQs About AI-Assisted Exam Proctoring
Can AI determine whether a student cheated?
No. AI can identify selected events or patterns for review. A misconduct finding requires a human process that considers the evidence, exam rules, technical context, accommodations, and the student’s response.
Should the system continuously recognize the student’s face?
Not by default. Continuous biometric verification is more intrusive than a check-in process and requires a specific necessity, proportionality, accuracy, consent or legal-authority, security, retention, and alternative-method review.
Can head and eye movement prove cheating?
No. Looking away can occur for many legitimate reasons. Gaze or head movement should not be used as standalone evidence and may create barriers for students with disabilities or different testing behaviours.
Can computer vision detect unauthorized browser activity?
No. Camera-based computer vision can analyze visual content. Browser focus, open applications, copy-and-paste, multiple displays, or network activity require exam software, operating-system permissions, or device telemetry.
Does local or edge processing solve the privacy problem?
It can reduce data transfer and cloud storage, but it does not remove collection, consent, notice, accuracy, security, accessibility, fairness, retention, or human-review obligations.
Must students receive an alternative?
The answer depends on the institution, jurisdiction, legal authority, disability-related needs, and the technology’s reliability. A responsible design should include accommodation and exception routes and should assess less intrusive alternatives before making biometric or invasive monitoring mandatory.
What should the first pilot include?
Use one exam type, a limited cohort, clear notice, approved accommodations, technical support, minimal data collection, human validation of every alert, no automated adverse decisions, demographic and accessibility testing, and a documented appeal process.
How should recordings be retained?
Use a documented schedule based on the purpose, legal obligations, academic-integrity process, and appeal period. Full recordings, incident clips, biometric templates, identity documents, and final decisions should not automatically have the same retention period.
Sources
- Office of the Privacy Commissioner of Canada: Guidance for processing biometrics for businesses
- Office of the Privacy Commissioner of Canada: Biometrics quick tips for businesses
- NIST: Demographic effects in face-recognition evaluation
- NIST: Effects of race, age, and sex on face-recognition software
- Information and Privacy Commissioner of Ontario: McMaster University Respondus Monitor decision
- Information and Privacy Commissioner of Ontario: AI on campus and proctoring privacy
- IPC and Ontario Human Rights Commission: Principles for the responsible use of AI
- Ontario Human Rights Commission: Accessible education for students with disabilities
- Ontario Human Rights Commission: Appropriate accommodation in education
- Information and Privacy Commissioner of Ontario: Digital Privacy Charter for Ontario Schools
- USENIX: Students’ privacy and security perceptions of online proctoring
- USENIX Security: Bias and vulnerability in remote proctoring software
- USENIX Security: Educators’ perspectives on online exam proctoring
Assess One Testing and Exam-Integrity Workflow
Web Inventix AI can review your exam process, identity controls, proctor workload, assessment platform, technical environment, privacy requirements, biometric risks, accessibility needs, incident process, vendor architecture, and success measures. The first pilot should prove a fair and reliable workflow before broader deployment.
Book an AI Proctoring Strategy CallHave a process that takes too much time?
Tell us where work gets delayed, leads get missed, or information has to be entered manually.
We’ll review your workflow and recommend a practical first step.