Join our Newsletter — 33% off our NHI Course
Home FAQ Governance, Ownership & Risk Who is accountable when fraud slips through an…
Governance, Ownership & Risk

Who is accountable when fraud slips through an online testing platform?

← Back to all FAQ
By NHI Mgmt Group Editorial Team Updated August 26, 2026 Domain: Governance, Ownership & Risk

Accountability sits with the platform operator, its security and trust teams, and the institutions that rely on the results. Each party needs clear controls for identity verification, review thresholds, and incident handling. When fraud occurs, organisations should be able to show that they applied proportionate safeguards and maintained evidence for investigation and remediation.

Why This Matters for Security Teams

Online testing platforms create a blended trust problem: they must verify the test-taker, protect exam content, and preserve evidence when fraud is suspected. When accountability is unclear, each party can assume another team owns the control gap, which delays containment and weakens post-incident review. That is why identity assurance, review thresholds, and auditability need explicit ownership from the start.

For security teams, the core issue is not just access control but evidentiary integrity. A platform that cannot show who authenticated, what signals were evaluated, and when a decision was made will struggle to defend its process after a dispute. NIST’s NIST SP 800-53 Rev 5 Security and Privacy Controls is useful here because it ties accountability to logging, monitoring, and controlled access rather than informal assurance. NHIMG research also shows how fragile identity governance can be in practice: only 5.7% of organisations have full visibility into their service accounts, according to the Ultimate Guide to NHIs — The NHI Market.

In practice, many security teams encounter fraud only after an appeal, a challenged result, or a regulator has already asked for the evidence trail.

How It Works in Practice

Accountability should be split by function, not blurred by vendor language. The platform operator is usually accountable for the technical controls that detect anomalous behaviour, preserve logs, and enforce review workflows. The institution that accepts the exam outcome is accountable for deciding what level of assurance is sufficient for its use case. Security, trust, and operations teams then own the specific control decisions and escalations that make those commitments real.

In a strong operating model, the platform verifies identity with layered signals, applies risk-based review thresholds, and records the full decision path. That usually includes session metadata, device and location signals, challenge outcomes, reviewer actions, and evidence retention rules. The operator should also define who can override a flagged session, who receives alerts, and who signs off on remediation. NIST control families around audit logging, incident response, and access enforcement provide the baseline structure, while policy decisions should be documented so they can be defended later.

That same discipline is reflected in NHIMG guidance on NHI governance, where weak lifecycle control and excessive privilege are recurring failure modes. The Ultimate Guide to NHIs highlights how often organisations lose visibility into identities and secrets before damage becomes visible. Even though an exam platform is not a classic NHI environment, the operational lesson is the same: identity assurance fails when credentials, session controls, and audit evidence are treated as separate problems.

  • Define who owns detection, who owns adjudication, and who owns final acceptance of risk.
  • Use proportionate identity checks based on exam sensitivity, fraud history, and legal exposure.
  • Preserve logs, reviewer actions, and challenge outcomes in a tamper-evident record.
  • Set incident handling thresholds before launch so disputes do not become ad hoc decisions.

These controls tend to break down when the platform spans multiple subcontractors, because evidence custody and decision ownership become fragmented across systems and contracts.

Common Variations and Edge Cases

Tighter identity verification often increases friction, so organisations have to balance candidate experience against the risk of impersonation and credential abuse. There is no universal standard for this yet, especially where remote proctoring, accessibility needs, and cross-border privacy rules intersect. Current guidance suggests using the least intrusive control set that still meets the institution’s assurance requirement.

Edge cases matter. A low-stakes practice exam may justify lighter controls, while licensure, certification, or academic integrity disputes require stronger evidence retention and clearer escalation paths. Where AI-assisted proctoring is used, accountability becomes more complex because model outputs are advisory, not self-justifying. The human reviewer still owns the decision, but the platform must be able to explain what the system saw and why it flagged the session.

One practical reference point comes from broader identity governance: excessive privilege, poor rotation, and weak offboarding create hidden exposure long before an incident appears. NHIMG’s Ultimate Guide to NHIs — The NHI Market notes that 97% of NHIs carry excessive privileges, which is a useful reminder that accountability fails when controls are broad but evidence is thin. For platform operators, the lesson is to make every exception measurable, time-bound, and reviewable.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

OWASP Non-Human Identity Top 10, CSA MAESTRO and OWASP Agentic AI Top 10 address the attack and risk surface, while NIST CSF 2.0 and NIST AI RMF set the governance and control requirements practitioners need to meet.

FrameworkControl / ReferenceRelevance
NIST CSF 2.0PR.AC-4Access control and accountability are central to exam fraud governance.
OWASP Non-Human Identity Top 10NHI-01Fraud detection depends on strong identity and lifecycle control for platform accounts.
CSA MAESTROGOVGovernance is needed to assign ownership across autonomous review and fraud workflows.
NIST AI RMFAI-assisted proctoring needs accountable governance and traceable decisions.
OWASP Agentic AI Top 10A1If agents assist review or triage, autonomous actions must be bounded and auditable.

Assign clear owners for detection, review, and escalation across the platform’s AI-supported workflows.

NHIMG Editorial Note
Reviewed and updated by the NHIMG editorial team on August 26, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org