Rory McCorkle, VP of Business Development
January 20, 2026
Remote proctoring has become a key component for exam delivery of many credentialing programs. While it offers clear benefits, expanded access, scheduling flexibility, and scalability, it also introduces new risks related to exam security, candidate experience, and accreditation compliance.
For accredited credentialing bodies, these risks cannot be outsourced. Even when a third-party vendor delivers the service, the responsibility for maintaining exam integrity and compliance ultimately remains with the credentialing organization itself. This principle is both a best practice in vendor governance and an expectation of accreditation frameworks.
Below are several critical areas credentialing bodies should evaluate carefully when contracting for remote proctoring services.

1. Proctor and Workforce Management
Proctor Workforce Structure
A foundational question is who is actually proctoring your exams. Are proctors direct employees of the vendor, or are they subcontracted through a third party (which is far more common)? Where does proctor management sit within the vendor’s organizational structure?
Understanding this chain of responsibility matters. The degree of control the vendor has over its proctoring workforce directly affects training quality, incident escalation, and corrective action when problems occur. Credentialing bodies should understand not only who manages proctors, but how incidents are resolved with the individual proctor involved.
Candidate Communication and Language Proficiency
If proctors communicate with candidates verbally, language proficiency becomes a security and fairness issue. Vendors should be able to demonstrate how they assess English competency for proctors who are not native speakers.
A best practice is to align proficiency requirements with the Common European Framework of Reference for Languages (CEFR), typically requiring B1 (intermediate) or B2 (upper-intermediate) proficiency in the relevant skill area (written communication, listening/speaking, or both). Clear communication is essential during check-in, rule enforcement, and incident resolution.
Subcontractor Agreements and Oversight
When subcontractors are used, credentialing bodies should ask what contractual covenants exist between the vendor and subcontractor. What recourse does the vendor have if systemic issues arise? How are proctors retrained, monitored, or removed when patterns of concern are identified?
A vendor’s answers here often reveal the maturity of their workforce governance model.
Proctor-to-Candidate Ratios
Proctor workload directly affects vigilance. Credentialing bodies should ask for both average and maximum proctor-to-candidate ratios, and how these differ between the check-in phase (which is labor-intensive) and ongoing monitoring. While these are not best practices around proctor-to-candidate ratios, high ratios may dilute a proctor’s ability to identify misconduct in real time.
Room Scans and Identity Verification
Room scans should go well beyond a simple 360-degree sweep. Proctors should examine:
- The desk and working surface
- The monitor or laptop itself (for hidden notes)
- Under the desk and peripherals
- Other likely concealment locations
Identity verification procedures should also be clearly defined. Is ID verified in advance or at session start? How does the vendor validate authenticity? These steps form the first line of defense against impersonation.
2. Remote Proctoring Software Capabilities
Lockdown Browsers
Many remote proctoring solutions rely on a lockdown browser to restrict candidate activity. Credentialing bodies should understand whether the vendor uses an allowlist or denylist approach and how frequently these lists are updated.
Blocking screen sharing, remote desktop, and remote access tools is particularly critical. Vendors should also be transparent about known limitations. No lockdown browser is foolproof, and software can be disguised or renamed at the operating-system level.
Device, IP, and Hardware Monitoring
Vendors should be able to track device fingerprints and IP addresses to identify suspicious patterns, such as repeated connections from at-risk regions or shared IPs across candidates.
Hardware detection, such as identifying multiple monitors or screen-casting devices, adds another layer of protection and should be standard in high-stakes programs.
AI and Assistive Technologies
Many vendors now deploy AI-enabled tools to flag aberrant behavior, including:
- Audio detection
- Keystroke or mouse-movement analysis
- Facial detection or recognition
- Gaze tracking
- Object detection
- Biometric authentication
Credentialing bodies should ask what technologies are used, how they are trained, and how accuracy is monitored. Importantly, vendors should be able to explain acceptable confidence thresholds and how performance varies across different candidate populations, lighting conditions, skin tones, eyewear use, and accessibility needs.
Data Forensics
Behavior can be concealed, but data patterns are far harder to mask. Robust remote proctoring programs incorporate post-session or real-time data forensics, including:
- Response similarity indices
- Speededness analysis
- Geographic or affiliation-based score anomalies
Organizations should ask whether these services are included or offered separately, what analyses are run, and whether results are normed specifically to their program or generalized across clients.
3. Incident Management and Remediation
Clear incident management processes are essential.
Credentialing bodies should understand:
- How incidents are communicated to candidates
- Whether the vendor or client takes action, and under what circumstances
- How quickly incidents and supporting evidence are shared
Vendors should also allow clients to align proctoring rules with their own security posture, typically through configurable behavioral categories and escalation pathways.
Audit practices are another critical indicator of quality. What proportion of sessions is audited? Historically, what proportion of audits uncover issues? When problems are identified, what remediation steps are taken with the proctor involved?
Most mature vendors apply tiered remediation, ranging from retraining to removal, based on severity and recurrence.
4. Data Sharing, Metrics, and Transparency
Transparency during the RFP process often predicts transparency during the partnership.
Credentialing bodies should expect regular reporting on both experience and security metrics, such as:
- Time from check-in to proctor connection
- Proctor-to-candidate ratios
- Candidate satisfaction ratings
- Session completion rates and technical failure causes
- Incidents of misconduct by category and resolution
Vendors should also support ongoing audits, not just annual reviews, and be able to describe how they “secret shop” or internally audit their own services.
Finally, contracts should clearly define KPIs or SLAs tied to service credits or corrective mechanisms. Metrics without consequences provide limited leverage when service levels fall short.
Final Thoughts
Remote proctoring can be a powerful enabler of access and growth, but only when governed with the same rigor applied to any other high-stakes assessment process. Credentialing bodies that ask detailed questions, demand transparency, and retain clear oversight are far better positioned to protect exam integrity, candidate trust, and accreditation standing; regardless of which vendor they select.