2026-05-22 · 7 min read

Online Exam Security: 10 Best Practices for Institutions

A practical checklist for universities, certification bodies, and corporates to run secure, fair online exams — covering technical setup, candidate briefing, question design, and post-exam review.

Exam SecurityOnline ProctoringBest Practices

1. Verify identity before the exam begins

Require candidates to present a photo ID before the session starts. AI identity verification compares the ID photo to the webcam image in real time.

This single step eliminates proxy sitting — one of the most common forms of exam fraud in competitive recruitment and university assessments.

2. Run a system check in advance

Ask every candidate to complete a technical readiness check 24–48 hours before the exam. The check should verify camera, microphone, browser compatibility, and internet speed.

This reduces mid-exam technical failures that disrupt the candidate experience and create review workload for administrators.

3. Randomise questions and options

Use a question bank with randomised selection so each candidate receives a different subset of questions in a different order.

This makes answer sharing between candidates in the same exam session ineffective. Combined with proctoring, it dramatically reduces collusion.

4. Set appropriate time limits

Time pressure is a natural deterrent to looking up answers. Questions should be calibrated so a candidate who knows the material can complete them comfortably, but one who needs to look things up runs out of time.

5. Use a lockdown browser for high-stakes exams

A lockdown browser prevents access to other applications, browser tabs, and system functions during the exam. It is the most effective technical control against open-internet cheating.

For lower-stakes assessments, tab-switch monitoring via a standard browser extension is often sufficient and causes less candidate friction.

6. Communicate monitoring rules clearly

Publish an exam conduct policy before registration, remind candidates at the start, and explain exactly what is monitored (webcam, audio, screen activity).

Transparency reduces false positives and anxiety-driven behaviour that can resemble misconduct.

7. Set proctoring intensity to match exam stakes

Not every assessment needs the same level of monitoring. Use full AI analysis with human review for high-stakes exams, and lighter monitoring (tab-switch logging only) for formative or practice assessments.

Over-monitoring low-stakes exams wastes reviewer time and creates a poor candidate experience.

8. Review flags with a human before acting

Never automatically disqualify or penalise a candidate based on an AI flag alone. AI systems generate false positives. All flags should be reviewed by a trained reviewer who can watch the relevant video clip in context.

9. Analyse post-exam data for patterns

Review answer similarity scores across candidates, response time distributions, and flag clustering. Patterns that appear across multiple candidates in the same exam window (identical wrong answers, identical flag types) may indicate organised misconduct.

10. Store and purge data according to policy

Define upfront how long exam recordings are retained and who can access them. Compliance with India's DPDPA and international standards like GDPR requires explicit data retention policies.

Proctyx gives institutions granular control over recording retention periods and access permissions at the exam-type level.

FAQ

What is the most important thing to prevent cheating in online exams?

Identity verification combined with question randomisation addresses the two most common fraud types: proxy sitting and answer sharing. Add proctoring to deter opportunistic cheating.

How do I choose a proctoring intensity level for different exams?

Match intensity to stakes: high-stakes exams (admissions, certifications) use full AI monitoring with human review; internal assessments use light monitoring. Proctyx lets you configure this per exam type.

Want to see Proctyx in action?