What Is Online Proctoring? How It Works and What to Look For
What online proctoring actually does, the three ways to run it, which controls suit which exams, and the questions to ask before you choose a tool.

Online proctoring is supervision for an exam taken away from a test center. Software limits what the candidate can do during the attempt, and evidence capture records enough of the session for someone to review it later. The goal is a result you can defend when a candidate, an employer or a regulator asks how you know it is genuine.
That last point gets lost in vendor demos. Proctoring rarely stops a determined cheater on its own. What it does well is raise the effort required and leave a clear trail when something looks off. Treat it as a way to gather evidence for a decision, and you will configure it far more sensibly than if you treat it as a cheating detector.
What you are protecting against
Most exam integrity problems fall into four groups:
- Impersonation. Someone else sits the exam, or takes over partway through.
- Unauthorized materials. Notes, a second device, a search engine, an AI chat window in another tab.
- Outside help. A colleague in the room or on a call.
- Content leakage. Questions copied out and shared, which damages every future sitting.
Each threat needs a different control. A webcam snapshot does nothing about a question bank that leaked last month, and a large randomized question pool does nothing about impersonation. Exam design and proctoring have to work together.
Three ways to run it
| Model | How it works | Fits | Trade-offs |
|---|---|---|---|
| Live | A person watches candidates in real time and can intervene | High-stakes licensing, small cohorts | Scheduling, cost per session, limited scale |
| Record and review | The session is captured and reviewed afterwards | Medium-stakes exams with modest volumes | Heavy review workload, problems found only after the fact |
| Automated with human review | Software monitors and flags, people review flagged attempts | Certification and hiring exams at volume | Flags need judgment, false positives happen |
Programs that run exams at any real volume tend to end up on the third model. Nobody has time to watch every recording, so the software's job is to decide which attempts deserve a human's attention.
The controls, in the order a candidate meets them
Before the first question
- Access by one-time code. The candidate is invited by email and signs in with a one-time code sent to that address. On its own this is weak identity, but it ties the attempt to an inbox and stops casual link sharing.
- ID photo capture. The candidate photographs an ID document at the start. A reviewer can compare it with the webcam snapshots later if the attempt is questioned.
- Honesty pledge. It sounds like a formality. It is useful anyway: it sets expectations, and in a dispute you can point to the specific rules the candidate agreed to.
- Environment checks. Detection of external monitors, external cameras and virtual machines. Virtual machines matter because a candidate can run the exam inside one while the host machine has everything else open.
During the attempt
- Browser lockdown. Fullscreen mode, tab-switch detection, and blocked copy, paste and right-click, with each attempt logged.
- Webcam snapshots with face monitoring. Periodic images, with AI flagging frames that show no face or more than one face.
- Screen snapshots. Useful for seeing what was actually on the display when a flag fired.
- Single session and device lock. A second tab or a change of device mid-attempt is caught instead of silently allowed.
- Heartbeat monitoring. Regular pings show when the exam page went quiet, which distinguishes a sleeping laptop from a steady session.
- Microphone monitoring. Optional, and only with consent. Short clips are captured when speech is detected and can be transcribed, which is much faster to review than a full audio recording.
After submission
Idle periods and answer timings that do not fit a normal pattern are flagged, and everything above lands in an evidence trail for that attempt: event type, timestamp and the snapshot or clip behind it. That trail is the thing you will rely on when a result is challenged, so check how a reviewer actually sees it before you buy.
Decide what a violation limit means
The setting with the most impact gets the least attention: what happens when a candidate breaks a rule. Most tools let you set a violation limit. Set it too low and a candidate whose Wi-Fi hiccuped twice loses their attempt. Set it too high, or turn it off, and the rules have no teeth.
A sensible approach separates events that can happen innocently from events that almost never do. A face briefly leaving the frame or a gap in the heartbeat is worth logging for review. Opening developer tools or switching tabs repeatedly is a stronger signal. In LMS Advisor, for example, a heartbeat gap is logged as an integrity event but never ends the attempt, while reaching the configured violation limit ends it and marks it disqualified. Whatever tool you use, make sure you know which events count toward termination and which only go into the log.
Match the controls to the stakes
| Exam type | Reasonable starting point |
|---|---|
| Knowledge check inside a course | Usually no proctoring. Use question pools and retake rules instead. |
| Pre-hire skills test | Email code access, fullscreen, tab-switch and copy/paste controls, webcam snapshots with face monitoring, device lock |
| Internal role certification | All of the above plus ID photo, screen snapshots, honesty pledge and a violation limit |
| External professional certification | All of the above plus virtual machine and external monitor checks, microphone monitoring with consent, and human review of every flagged attempt |
Over-proctoring a low-stakes quiz costs you goodwill and review time for very little gain. Under-proctoring a credential that employers rely on costs you the credential's value. Decide exam by exam, not once for the whole platform.
Candidate experience and privacy
Candidates cope well with strict rules they understand. They cope badly with surprises. A few habits make a big difference:
- Tell candidates before exam day exactly what is captured (camera, screen, audio) and why.
- Offer a short practice attempt with the same settings, so camera permissions and browser issues surface before the real exam.
- Give candidates a way to report a problem during the exam, so "my camera froze" is on record at the time instead of in an angry email afterwards.
- Set retention periods for snapshots and audio and keep them short. Audio clips usually deserve a shorter window than images. You cannot leak what you no longer hold.
- Plan for accommodations. Extra time is easy. Assistive technology can conflict with lockdown controls, so agree an alternative route for those candidates in advance.
Be precise about what the AI does. Face monitoring that counts faces in a frame is different from facial recognition that identifies a person, and your privacy notice should say which one you run. In LMS Advisor the AI checks for no face or more than one face. Matching the candidate to their ID photo is a human reviewer's job.
Let question design carry some of the load
Proctoring is the visible part of exam security, but the exam itself does a lot of quiet work. Draw each attempt from a question pool larger than the exam, so two candidates comparing notes see different items. Tag questions by difficulty so every attempt stays fair even when the items differ. Consider negative marking on multiple-choice sections where blind guessing is a real problem. Retire items that are answered correctly far more often than their difficulty suggests, because that pattern often means they are circulating.
For technical roles, question types that are hard to look up help more than any camera. A coding question that runs the candidate's code against test cases, or an image hotspot where they have to click the faulty component on a diagram, gives a search engine very little to work with.
Flags are signals, not verdicts
Automated monitoring produces false positives. Poor lighting, glare on glasses, a candidate looking down at permitted scratch paper, a child wandering through the room, someone reading questions aloud to themselves. None of these is cheating. Your review process should assume a flag means "look at this", not "fail this".
Write the review process down before the first exam: who reviews, what evidence they check, what outcomes are possible (accept, retake, disqualify) and how a candidate appeals. Record the decision and the reason on the attempt. If you ever have to defend a result, that record matters as much as the snapshots.
Questions to ask before you choose a tool
- Is proctoring built into the exam platform, or a separate vendor with its own login, integration and per-attempt fees?
- Can every control be switched on or off per exam?
- Can people who are not LMS users take exams, without being enrolled in a course?
- What evidence is captured, where is it stored, and can you set how long it is kept?
- Which events count toward a violation limit, and what happens when a candidate's connection drops?
- How does a reviewer see the evidence for one attempt, and can they record a decision?
- Which third parties process candidate data, for example for audio transcription?
- What happens after a pass: is a certificate issued automatically, and can employers verify it?
Where LMS Advisor fits
We built proctoring into the Exams module rather than bolting on a separate service, and every control listed above is configured per exam. Candidates use their own exam portal with email one-time codes, so they do not need a course enrollment or an LMS account. Audio clips, where you enable them, are transcribed with OpenAI Whisper. A pass can issue a certificate with a public verification page, and exam certificates do not expire (expiry and recertification apply to course certificates, which the certificates page explains). The online proctoring feature page lists every setting, and the certification programs page shows how exams, certificates and verification fit together for a credentialing body.