Alternatives to online proctoring work in layers: assessment design that makes copying pointless, access and network scoping, browser-level controls, and post-hoc data forensics. StudyDrome Exam Manager follows that model by design. It detects four classes of in-browser behavior and evaluates them on the server. It records no video, audio, or biometric data at all.
That is the short answer. The longer one matters. Most vendors present "alternatives to proctoring" as a single swap — cameras off, something else on. It is not. Each layer catches a different thing. The layer with the largest effect contains no software at all.
Why are universities looking for alternatives to proctoring?
Three pressures arrived at once. Each is enough on its own.
Legal exposure. In August 2022, a federal district court ruled on Cleveland State University's room scans. The university scanned each student's room before a remote exam. The court held that practice unreasonable under the Fourth Amendment. The student's privacy interest in his home outweighed the university's interest in the scan (Ogletree v. Cleveland State University, N.D. Ohio; NPR). A later ruling vacated the judgment on procedural grounds. So it is not precedent. But the exposure it described did not leave with it.
Data-protection exposure. In 2021, Italy's data protection authority fined Bocconi University €200,000 over remote proctoring software. It cited biometric processing without a legal basis and a deficient impact assessment (EDRi; Portolano Cavallo). The Court of Milan later cut the fine to €10,000. It also disputed the biometric classification. In May 2024, the Court of Cassation (decision 12967/2024) returned the case. Its holding: exam-supervision technology requires a rigorous impact assessment and documented security measures.
Measurement exposure. Woldeab and Brothen studied 631 students (International Journal of E-Learning & Distance Education 34(1), 2019). High trait test anxiety was associated with lower exam scores. The effect was strongest for anxious students sitting proctored online exams. Such a control adds construct-irrelevant variance. The exam no longer measures only what it set out to measure.
The sector has drawn its own conclusions. The University of Louisiana at Lafayette publishes an online proctoring alternatives page for its faculty. Ohio State's Arts and Sciences office publishes alternatives to proctoring exams in online classes.
What does online proctoring actually detect?
Proctoring software does not detect cheating. It detects events: a face leaving frame, a second voice, a new process. It converts them into flags for a human to review. In every system, recorded or not, a person reads a flag and decides.
Recording is therefore a collection strategy, not a decision strategy. It buys a rich event stream. It pays in three currencies:
- the legal and privacy exposure above,
- reviewer time to watch the footage,
- a duty to retain the recordings once they exist.
That tells you what an alternative must replace. Not the camera, but the evidence: enough signal to review an incident and defend a result.
What are the alternatives to online proctoring?
Five layers, ordered by how much of the problem each removes.
Layer | What it removes | What it cannot do |
|---|---|---|
Assessment design | The value of copying — an item requiring application or judgment cannot be answered from a shared file | Nothing about impersonation; a redesigned exam can still be sat by the wrong person |
Item security | The value of leakage — a large bank with random selection makes a leaked paper worth little | Nothing about live collusion during the sitting |
Access and network scoping | Unauthorized starts — per-candidate access codes, an IP allow-list, a supervised room | Identity assurance; a code proves possession of a code |
Browser-level controls | Casual opportunism — copy and paste blocking, fullscreen enforcement, window-leave detection | Anything on a second device, a phone, or another person in the room |
Post-hoc forensics | Undetected compromise — item statistics exposing a leaked question, conduct timelines, submission clustering | Prevention; every finding arrives after the exam |
No single row replaces proctoring. The stack does.
How do you design an exam that is hard to cheat?
The teaching-center guides all land on the same moves. They are the highest-yield changes you can make. They change what the exam asks, not what it watches.
Replace recall with application. An open-book question can require a judgment or a calculation based on supplied data. It can ask the student to defend a choice. No shared answer key answers it. It also tends to map more closely to your learning outcomes than the recall item. Split one high-stakes exam into several lower-stakes parts. Then no single sitting justifies the risk.
Then make the paper a moving target. Random selection from a large bank means two students rarely see the same form. Choosing an assembly strategy covers what it buys you and what it costs you in comparison. This is where item quality starts doing security work. A leaked item looks odd in the statistics: facility rises sharply relative to its history, while discrimination collapses. Strong and weak students now give the same answer. That pattern shows up in a routine item analysis. Run one today on a results export with our free item analysis tool. No account required. Item quality and item security are the same discipline. That is why writing flaw-free items belongs inside an integrity plan.
What can browser-level controls actually catch?
The honest list is shorter than the marketing category suggests. A browser-native layer sees four classes of behavior:
- leaving the exam window,
- exiting fullscreen,
- trying to copy question text,
- trying to paste into an answer field.
Two related behaviors land under those headings. A tab switch is triggered by a window-leave event. A blocked right-click counts as a copy attempt.
The hard part is not detection but avoiding false alarms. A false flag on a nervous student's record is worse than no record. Three suppressions do that work in StudyDrome Exam Manager. A blur while a file-upload dialog is open does not count. A blur where the document still reports focus does not count. And on iOS, a blur while a text input is focused does not count: that is the virtual keyboard, not a departing student. Surviving events are debounced for 500 milliseconds before the system records anything.
Two design decisions matter more than the detection list. Every control is off by default. You choose it per exam, not for the whole calendar. And the browser reports while the server decides. The server checks warning thresholds and the auto-submit decision against the published exam's settings. A student cannot change the outcome by tampering with the client.
The limit, plainly: none of this sees the room. A phone beside the laptop is invisible to a browser. So is a second machine, or a person in the room. Any vendor claiming otherwise is describing a camera.
What evidence do you have if you never record anything?
A registrar or appeals panel will ask this. The answer is concrete: an event record. It is smaller than a video and easier to defend.
Every attempt ends in one of eight categories with plain labels:
- in progress
- finished by student
- time expired
- test window expired
- terminated for violations
- finished by administrator
- abandoned or session timeout
- unknown
The seventh is the one that protects an innocent candidate. A dropped connection is filed apart from a rule breach, which is why losing internet mid-exam does not read as misconduct.
Each attempt opens onto a timeline of its violations. Each violation includes a timestamp and the sessions associated with it. Every session carries its IP address and user agent. The entire record is rendered as a PDF for the appeal bundle. Across a sitting, each attempt carries the seconds elapsed since the previous one finished. So a cluster of near-simultaneous submissions is easy to spot in the report.
Note what that last figure does not do. It applies no threshold and raises no automatic flag. The system shows the interval and does not interpret it. That is the same boundary as a proctoring flag. You reach it with an event log, not a recording of somebody's bedroom. Clustering is a prompt to look, not a finding.
The trade is straightforward. You lose sight of the room. You gain a record a panel can read in a minute. You can show it to a student without exposing their home. And it carries no retention liability for video or biometric data. None was ever collected. Our security overview covers how we handle that data.
When is online proctoring still the right answer?
Three cases, stated directly. A layered approach that overreaches is just another form of dishonesty.
Identity assurance for a portable credential. Some results become a license or certification that travels beyond your institution. Someone must then confirm the person sitting the exam is the person named on it. Access codes, device binding and network scoping do not do this. They prove possession of a code and continuity of a browser session. A test center or an identity-verifying service does.
Genuinely unsupervised, single-sitting, high-incentive exams. Sometimes the student is remote and unwatched. And the exam cannot be split into lower-stakes parts. There, the design layer is gone. The rest then carry more weight than they should.
A mandate. Some regulators and accreditors require recorded supervision. That is a compliance rule, not a teaching one. Argument does not move it.
For the record: we surveyed six exam platforms on 7 August 2026. Five sold webcam, AI, or identity-verified proctoring. If your case is one of the three above, that market exists. Use it.
A checklist for this term
- Write down what your exam protects against: impersonation, collusion, item leakage, or casual lookup. Most integrity plans blur these together. Each has a different answer.
- Audit your highest-stakes paper for items a shared file can answer. Rewrite those first.
- Check whether your bank is large enough that random selection matters. If not, that is this term's authoring priority.
- Run an item analysis on last cycle's results. Look for the leaked-item signature: facility rising sharply while discrimination collapses.
- Issue access codes per student, not shared. Scope by IP for exams sat on campus.
- Enable only the browser controls you can justify to a student. Write that reason down.
- Decide before the exam who will review flagged attempts and to what standard. An appeal tests the review policy, not the detection setting.
- Complete a data protection impact assessment. The Bocconi cases turn on that document.
Frequently asked questions
What are the alternatives to online proctoring?
Five layers, used together. Assessment design makes copying worthless. Item security uses large banks and random forms. Access and network scoping covers per-student codes and IP allow-lists. Browser-level controls block copy-paste and detect window leaves. Post-hoc forensics reads item statistics and submission timing. No single layer replaces proctoring; the combination does, for most exam types.
Is online proctoring legal under GDPR?
It can be, but not automatically. In 2021, Italy's data protection authority fined Bocconi University €200,000 over remote proctoring. It cited processing without a valid legal basis. It also cited an inadequate data protection impact assessment. Later rulings reduced the fine and disputed the biometric classification. They still held that exam-supervision technology needs a rigorous impact assessment. It also needs documented security measures before deployment.
Can you stop cheating in an online exam without a webcam?
You can greatly reduce it. You cannot remove it fully, with or without a camera. Assessment design removes the payoff from copying. Randomization from a large bank removes the value of a leaked paper. Access scoping controls who starts. No browser-based system sees a second device or another person in the room. Identity-critical exams still belong in a supervised setting.
What does a browser-based integrity system actually detect?
Four classes: leaving the exam window, exiting fullscreen, trying to copy question text, and trying to paste into an answer field. Tab switches count as window-leave events, and blocked right-clicks as copy attempts. It cannot see a phone, a second computer, or a person in the room. Any claim otherwise describes a camera rather than a browser.
Does removing proctoring make results indefensible at appeal?
No — provided you keep an evidence chain. A defensible bundle needs five things:
- the exact version of the paper the candidate sat
- item-level statistics for the disputed questions
- a reliability figure for the exam
- the standard-setting record behind the pass mark
- a conduct record showing how each attempt ended
Video is one possible input to that chain, not the chain itself.
When should a university still use proctoring or a test center?
In three cases. The result is a portable credential that needs identity assurance. A high-incentive exam truly cannot be redesigned into lower-stakes parts. Or a regulator or accreditor mandates recorded supervision. In those cases, use a test center or an identity-verifying service. Scope it to the exams that need it, not the whole assessment calendar.
Where to go next
Rebuilding an integrity policy rather than buying a product? Start with the design layer. It is free and survives every technological change. It is also the only layer that improves the exam and protects it.
Comparing platforms? The useful question is not which one watches students most closely. Ask what evidence each can put before an appeals panel. And ask what it had to collect to get there. Our comparison with ExamSoft works by accounting for that difference.