Candidate experience

Remote proctoring without default surveillance: a proportionality test for assessment teams

How to decide what monitoring is genuinely necessary, explain it clearly, provide alternatives and keep automated flags from becoming findings.

← All articles

Remote proctoring is often introduced as a binary choice: monitor the assessment or accept that integrity cannot be protected. That framing skips the most important design work. Monitoring ranges from a clear declaration and identity check to continuous video, screen capture, room scans, biometric matching and automated behavioural flags. Each measure changes privacy, accessibility and the candidates ability to concentrate.

Data-protection guidance from the UK Information Commissioners Office repeatedly emphasises necessity and proportionality in monitoring. Those principles are useful beyond one jurisdiction: identify the real risk, ask whether the measure addresses it, compare less intrusive alternatives and consider the effect on people. Obtain specialist legal advice for your locations and use, especially where biometric or special-category data may be involved.

Describe the integrity risk precisely

Cheating is too broad to design against. Are you concerned about impersonation, unauthorised reference material, collaboration, copying questions, external devices or assistance from another person? How likely is the behaviour, how consequential is the decision and what evidence would actually distinguish it from ordinary candidate activity?

A low-stakes diagnostic does not warrant the same controls as professional certification. Nor does every risk require observation. Question variation may reduce copying. An open-book design may remove the value of hidden notes. A short oral check can verify understanding. A test centre may be appropriate for a small group making a high-consequence attempt. Start with the assessment and threat model before shopping for technology.

Record the reasoning. State why each monitoring feature is needed, what it cannot establish and when the decision will be reviewed. If the justification is merely that the vendor enables the feature by default, turn it off.

Minimise what enters the candidates space

A home is not a test centre. A room scan can reveal family circumstances, religious objects, health information or other people. Continuous audio may capture conversations unrelated to the assessment. Screen recording can collect notifications and personal information. Require the minimum view and duration needed for the defined risk.

Give candidates time to prepare and a genuine alternative where possible. An alternative should not carry a penalty, unexplained delay or assumption of suspicion. Explain device and room requirements before booking, not moments before the timer starts. Provide a practice system check that uses the same permissions without collecting unnecessary content.

Consider data separation. Identity evidence may need a different access group and retention period from an assessment recording. Reviewers investigating a flag may not need a full government document. Support staff should not receive unrestricted video access simply because they can troubleshoot the platform.

Be careful with biometrics

Facial matching and other biometric processing can carry significant legal and ethical obligations. Accuracy may differ across populations and conditions. A mismatch can deny access or create suspicion before a candidate answers a question. Ask whether a less intrusive identity route could meet the need, such as a live human check, one-time document review or supervised centre.

If biometrics are proposed, document purpose, legal basis, special conditions, performance evidence, error handling, accessibility, retention and deletion. Test the real camera and lighting conditions candidates use. Provide a prompt human route when matching fails; repeated automated attempts are not a fair appeal process.

Do not reuse identity templates for unrelated analytics or product training. Make supplier restrictions explicit and verifiable. Deleted after processing needs a defined point, scope and evidence.

Treat automated flags as observations, not findings

A face moving out of frame, another voice, unusual gaze or application switch can have innocent explanations. A candidate may use an assistive device, read aloud, respond to a child, experience a connection delay or look away while thinking. Automated systems do not understand that context simply because they attach a risk score.

Define what each flag means and how it is validated. A trained reviewer should inspect relevant evidence, consider approved adjustments and seek corroboration. The candidate must have a fair chance to explain before an adverse conclusion. Keep the original flag, reviewer rationale and final finding separate in the record.

Measure false positives and reviewer disagreement. Look for group patterns and conditions such as skin tone, disability, language, device or bandwidth. If evidence quality is insufficient, the correct outcome is uncertainty, not a misconduct label.

Design transparency before consent screens

A long privacy notice presented after a candidate has invested in the application does not create meaningful choice. Provide a concise summary early: what will be collected, the specific purpose, whether automated flags are used, who reviews them, retention, suppliers, international processing, adjustment routes and alternatives. Link to full detail.

Do not imply that consent solves an imbalance where the person cannot realistically refuse without losing an employment or education opportunity. The lawful basis depends on context and jurisdiction. Transparency remains necessary regardless of the basis.

During the assessment, show when recording begins and ends. Make camera, microphone and screen-capture state unambiguous. At completion, confirm the session has closed. A candidate should not be left wondering whether the software is still observing them.

Plan retention around review, not convenience

Set a defined period tied to result checking and appeal. Delete recordings and derived data when that purpose ends unless a specific case requires a documented hold. Different artefacts may need different periods: an identity decision, raw video, flags and final review record are not one category.

Restrict and log access. Prevent casual downloads. Secure data in transit and storage, and test deletion across the primary service, backups and subprocessors. Contracts should state incident notification, assistance with rights requests and what happens to data when the service ends.

Protect assessment validity and accessibility

Monitoring changes behaviour. Anxiety, fear of looking away and concern about a shared room can consume attention that should be available for the task. Study whether the control affects completion and performance, not only whether it generates flags.

Test with disabled candidates and assistive technology. Keyboard navigation, screen readers, speech input, switch devices, interpreters and approved breaks can all be mistaken for anomalous behaviour if the system was designed around one narrow idea of a test taker. Adjustment information must reach the reviewer without exposing unnecessary medical detail.

Keep an unmonitored or differently monitored route where it can provide equivalent evidence. A supervised centre, live check, alternative task or later verification may be more proportionate and more valid.

A proportionality decision record

  • Define the decision, consequence and specific integrity threats.
  • List the data and access required by every monitoring feature.
  • Compare assessment redesign and less intrusive alternatives.
  • Evaluate privacy, equality, accessibility and validity impact.
  • Define human review, candidate explanation and appeal.
  • Set retention, deletion, security and supplier controls.
  • Pilot with representative candidates and measure false flags.
  • Assign review dates, stop conditions and an accountable owner.

Review the supplier demonstration differently

Ask the vendor to show failure, not only the ideal journey. What happens when a face cannot be matched, bandwidth drops, another person enters the room, an assistive technology changes focus or a reviewer disagrees with a flag? Follow one case from event to final decision and inspect the evidence available at every step.

Then ask operational questions. How quickly can a candidate reach a person? Can individual monitoring features be disabled? Are model or rule changes announced? Can your organisation export a defensible review record and verify deletion? A product that detects many events but cannot support fair resolution may increase integrity workload rather than reduce it.

Proportionate control is stronger control

Collecting more data can feel safer because it creates more material to inspect. In practice it can create noise, legal exposure, candidate distress and a queue of ambiguous flags. A narrower control tied to a defined risk is easier to explain, test and govern.

Remote assessment does not require default surveillance. Begin with the evidence the decision needs, redesign avoidable vulnerabilities and monitor only where necessity survives challenge. Candidates deserve a process that protects integrity without treating ordinary behaviour in a private space as evidence of wrongdoing.

Sources and further reading

Primary guidance used for the current facts in this article. Always confirm requirements for your jurisdiction and use case.

Topic FAQ

Questions about candidate experience

Is remote proctoring always necessary for online assessment?

No. Start with the actual integrity risk, then consider assessment redesign, question variation, oral checks or test-centre options before intrusive monitoring.

Can an automated proctoring flag prove misconduct?

No. A flag is a prompt for trained human review. It needs context, corroborating evidence and a fair process.

What should candidates be told before the assessment?

Explain what is collected, why, retention, access, likely flags, the human review process, available adjustments and any alternative route.

How long should recordings be retained?

Only for a defined period tied to review and appeal needs, followed by secure deletion. Communicate that period before collection.

Ready when you are

Turn assessment evidence into a decision you can explain.

See how the platform connects design, delivery, evaluation, publication and capability reporting.

Book a demo View sample report