See what's new

Testlify
Talent assessment
Last updated on: 10 August 202615 min read

Can technology prevent cheating in online tests?

Can technology prevent cheating in online tests?

Explore how technology combats cheating in online tests with proctoring tools, advanced algorithms, and techniques to maintain fairness and integrity during assessments.

TL;DR

  • AI tools now generate fully native-looking answers during online tests. Keystroke cadence and typing speed no longer reliably separate human responses from AI-assisted ones.
  • Gartner projects that by 2028, 1 in 4 candidate profiles across enterprise hiring pipelines will contain fabricated information. Most detection systems deployed today were not built to catch this.
  • A bad hire linked to assessment fraud costs 50 to 200% of that role’s annual salary, and most errors do not surface until the candidate is onboarded, at which point the full hiring cycle restarts.
  • Standard proctoring catches behavioural tells: tab-switching, copy-paste, and screen-sharing. It does not detect AI-generated answers, identity swap at session start, or secondary devices used outside the camera frame.
  • The most defensible detection setup uses three tiers: passive environmental controls, active role-sensitive monitoring, and post-assessment review for flagged sessions.
  • Over-proctoring carries measurable costs. Intrusive monitoring increases assessment dropout rates, and high-performing candidates with more options exit the pipeline first.

Online tests were built to bring objectivity to hiring decisions. The problem is that the threat environment in 2026 looks nothing like the one those tools were designed for.

Most standard proctoring systems flag tab-switching, copy-paste attempts, and second-screen activity. They are largely blind to AI-generated responses and proxy candidates who take the entire assessment from a separate device.

Cheating in online assessments now covers four distinct threat types: AI-generated answer injection, identity fraud and proxy substitution, environment manipulation, and post-assessment credential forgery. Each requires a different detection control, and no single layer stops all four.

Summarise this post with:ChatGPTGeminiClaudeGrokPerplexity

Cheating in online assessments: the current state

Assessment cheating in 2026 is systematic, not opportunistic. The tools candidates can access allow for repeatable fraud that standard proctoring alone cannot detect, and understanding each threat type is a prerequisite for building controls that actually work.

Traditional methods that still show up

Before addressing newer threats, the traditional ones never went away. Tab-switching, screen sharing to a helper, notes documents open in adjacent windows, and phone-based lookups still account for a significant share of detected violations in high-volume hiring pipelines.

The key difference in 2026 is that these lower-sophistication methods are now combined with AI tools rather than replaced by them. A candidate who opens a second screen is increasingly likely to run an AI query, which changes the quality and speed of the output compared to a basic search.

How AI changed the threat in 2024 to 2026

Large language models changed the economics of cheating in online assessments. A candidate with access to any major LLM can paste a technical question and receive a polished answer within seconds, then rephrase and type it naturally to avoid copy-paste detection.

More recently, tools built specifically for exam contexts have entered circulation. These tools monitor on-screen content through a secondary device and generate answers passively, without any copy-paste activity from the candidate.

Standard browser lockdown does not catch this behaviour because the secondary device operates entirely outside the controlled environment.

Cognitive ability assessments face additional complexity here since AI tools can generate plausible responses to logic and reasoning questions within typical time limits.

Identity fraud and proxy candidates

Identity fraud in remote assessments takes two forms. The first is account takeover: a candidate completes registration legitimately, then hands the live session to a more capable substitute.

The second form is deepfake impersonation: the substitute uses a synthetic video feed that matches the registered applicant’s appearance closely enough to pass a webcam check at session start. Candidates who bypass video-based identity checks using deepfake technology can sustain the deception for the duration of a standard proctored session.

Palo Alto Networks found that deepfake fraud across digital channels grew 1,300% from 2023 to 2024. Gartner projects that by 2028, 1 in 4 candidate profiles across enterprise hiring pipelines will contain fabricated information, and assessment platforms that rely on a single webcam snapshot at session start are insufficient against either method.

Build your dream team — Book a product demo

What a compromised assessment costs

A fraudulently passed assessment does not just produce a bad hire. It inserts an unverified candidate into a role where the performance gap surfaces on the job rather than in the screening process, and the cost compounds with every week the hire remains in seat.

Talent management strategies built on assessment data are only as reliable as the integrity of those assessments. Enterprise talent management programs that use assessments as a primary filter are directly exposed to fraud at the top of the pipeline.

The direct hiring cost of a bad result

SHRM estimates the cost of replacing a bad hire at 50 to 200% of that role’s annual salary, covering recruitment fees, onboarding investment, productivity loss, and manager time on performance management. In technical and senior-level positions, the figure approaches the upper end of that range.

A software engineer or finance analyst who passed a technical assessment fraudulently typically goes 60 to 90 days before the performance gap becomes actionable. At that point, the full hiring cycle restarts, and the cost of that cycle doubles against the original budget.

Most HR teams track quality-of-hire at the 90-day mark. Assessment platforms that generate auditable session logs give HR teams the evidence to identify fraud before that mark, rather than attributing poor performance to onboarding variables.

Legal exposure from unsecured assessments

Assessment security creates legal exposure in two directions. If a hiring team uses assessments that are not secure, they face negligent hiring claims when a fraudulently placed employee causes harm.

If monitoring practices are excessively invasive, they risk privacy claims from candidates in jurisdictions with strong data protection requirements. In regulated industries, the exposure is compounded: financial services, healthcare, and government contractors operate under frameworks that require documented evidence of assessment integrity for specific roles.

Detection technologies available in 2026

Detection technology in 2026 covers four main categories: identity verification at session start, behavioural analysis during the session, environmental controls on the testing device, and assessment design that limits the value of external assistance. Each category addresses a different threat vector, and effective setups use all four in combination.

Identity verification and webcam monitoring

Identity verification at session start combines document checking against a government-issued ID with liveness detection to prevent static image or video replay attacks. Continuous facial comparison throughout the session catches identity swaps that occur after login.

Webcam monitoring records the candidate’s environment and flags activity associated with forward and rear-facing secondary devices. More advanced implementations use gaze tracking to identify sustained attention shifts away from the primary screen, a pattern associated with reading from a secondary source.

Skills-based assessments that layer identity verification on top of role-specific questions produce a stronger combined signal. A candidate who passes both identity verification and a well-designed skills test has cleared two independent controls, not one.

Behavioural analysis and AI anomaly detection

Behavioural biometrics analyse typing cadence, mouse movement patterns, and answer submission timing across the full session. A candidate who types steadily for 45 minutes and then submits a complex technical answer in under 90 seconds presents a detectable anomaly.

AI-powered systems compare a candidate’s response pattern against baseline data from previous sessions for the same assessment. Responses that arrive faster than the assessed competency level would support, or that cluster around known AI output patterns, generate a review flag rather than an automatic disqualification.

Psychometric and skill assessments used in combination provide richer baseline data for anomaly detection than either type alone. A candidate who performs consistently across both types is statistically less likely to have used external assistance on either.

Environmental controls: browser, screen, location

Browser lockdown prevents candidates from switching tabs, opening new windows, or accessing clipboard content during the assessment. Screen recording supplements this by creating an auditable session record that reviewers can check against flagged behavioural events.

IP geolocation and VPN detection add a geographic layer. If a candidate’s registered location differs significantly from the session IP, that discrepancy is a signal worth reviewing.

ATS-integrated assessment platforms that log geographic signals alongside application data give hiring teams a complete evidence trail from application to hire. These controls raise the cost of fraud without claiming to eliminate it entirely.

Question randomisation and test design

Assessment design is a detection control in its own right. Question banks that randomise item selection across candidates make coordinated answer-sharing less effective, since no two candidates taking the same assessment see the same question sequence.

Adaptive question logic adds a second layer. If a candidate answers the first five questions at the top of the competency range and then struggles with a follow-up testing the same competency at a deeper level, the system flags the divergence.

This pattern is difficult to fake with generalist AI assistance because the follow-up requires contextual continuity from the previous answer. Technical skills assessments built with adaptive logic are significantly harder to game than static question sets because the system responds dynamically to the candidate’s apparent knowledge level.

Threat vs. detection: what catches what

Threat type

Detection method

Limitation

Tab-switching, new windows

Browser lockdown

Does not detect secondary device

Screen sharing to helper

Screen recording

Does not detect dictated answers

AI-generated typed responses

Behavioural biometrics, timing analysis

Requires session baseline data

Identity fraud, account takeover

Liveness detection, facial comparison

Requires real-time processing

Deepfake video impersonation

Advanced liveness detection

Hardware-dependent at highest tier

Secondary device outside camera frame

Gaze tracking, IP monitoring

Not conclusive against local proxies

Coordinated answer sharing

Question randomisation

Does not catch all organised groups

Post-assessment credential forgery

Secure result chains

Depends on issuer system integration

Where single-layer detection fails

Most assessment platforms offer proctoring as a single-layer control. Proctoring catches what it can observe: screen activity, physical movement, and environmental anomalies.

The problem is that the most prevalent cheating methods in 2026 operate outside that field of view. A candidate using a secondary device in their lap, or an AI tool on a phone below the camera frame, generates no signal that standard proctoring can detect.

Why proctoring alone is not enough

AI proctoring flags physical and environmental cues: head movement away from the screen, multiple faces in frame, unusual noise, and device activity visible within the monitored environment. It does not observe a candidate using a secondary device in their lap, a noise-cancelling earpiece connected to a helper, or an AI tool running on a phone placed below the camera frame.

The core vulnerability of single-layer detection is that it creates a known attack surface. Once candidates understand what triggers a flag, the next iteration of cheating is designed to avoid those specific signals.

CV fraud and assessment fraud often appear together: a candidate who misrepresents their background on a CV is more likely to attempt to compensate with an assisted assessment. A layered system raises the cost of both forms of fraud by requiring independent verification at multiple stages.

The candidate experience cost of over-detection

Intrusive monitoring produces a dropout effect that is measurable and asymmetric. Candidates who feel monitoring is disproportionate to the role they are applying for are more likely to abandon the session mid-assessment.

Higher-performing candidates, who hold more competing offers, are disproportionately represented in this dropout group. Assessment completion rates below 70% in a high-volume pipeline indicate either an excessive difficulty threshold or an invasive monitoring setup, and calibrating monitoring to role risk level reduces dropout without reducing detection coverage on critical roles.

A well-calibrated candidate experience and assessment integrity are not in opposition. Screening approaches that match detection intensity to role risk protect both hiring quality and the candidate pipeline from dropout at the assessment stage.

A layered assessment integrity approach

The most defensible integrity setups in 2026 use three tiers of control that activate based on role risk level rather than uniform policy. This structure reduces candidate friction on lower-risk roles while maintaining rigorous detection coverage where it matters most.

Tier 1: passive controls, always on

Tier 1 controls run on every assessment regardless of role level. These include browser lockdown, basic webcam capture, question randomization from a validated item bank, and IP-level monitoring for geographic anomalies.

These controls create no friction for compliant candidates and detect opportunistic cheating, which accounts for the majority of violations in volume hiring pipelines. No manual review is required when sessions pass without flags.

Digital hiring optimisation frameworks treat Tier 1 controls as the default layer for all assessment types. Escalation to Tier 2 happens only when the role’s criticality or access level warrants it.

Tier 2: active monitoring, role-sensitive

Tier 2 controls activate for roles where the assessment result directly determines the hiring decision. This includes real-time facial comparison, gaze tracking, behavioural biometrics, and AI anomaly detection on response timing and pattern.

The trigger for Tier 2 should be role criticality and access level, not seniority alone. A junior developer with direct access to production code warrants the same monitoring tier as a senior engineer, and hiring teams that conflate seniority with risk level consistently under-protect high-access junior roles.

Interview scorecards used alongside Tier 2 assessment results create a dual data point for hiring decisions. A candidate whose monitored assessment score diverges significantly from their interview performance warrants a closer review before an offer goes out.

Tier 3: post-assessment review protocol

Tier 3 is a human review step for sessions that generated composite anomaly flags in Tiers 1 or 2. A reviewer examines the flagged session recording, compares the anomaly against the candidate’s full response pattern, and makes a pass, re-test, or disqualification decision.

Post-assessment review prevents both false positives and false negatives. A candidate whose internet connection caused timing anomalies should not be disqualified without review, and a candidate with a perfect score whose timing pattern matches AI output should not advance without one.

This review step also serves a compliance function in regulated sectors. Organisations where job specifications include minimum assessment score requirements need documented review trails to demonstrate that thresholds were applied consistently.

How Testlify approaches assessment integrity

Testlify’s platform applies controls across all three tiers by default. Every assessment runs in a locked browser environment with question-level randomisation drawn from validated item banks.

Role-sensitive assessments activate the full proctoring stack, covering identity verification, behavioural monitoring, environment controls, and session integrity. The platform generates composite anomaly scores rather than flagging individual events, which reduces false positive rates while maintaining detection coverage on the patterns that indicate coordinated fraud.

Identity and physical verification run from session start and continue throughout the assessment. Testlify’s identity controls include:

  • Face detection
  • Photo ID verification
  • Webcam snapshots
  • Dual camera proctoring

Environment and device controls prevent candidates from accessing resources outside the assessment. Testlify’s environment controls include:

  • Full-screen mode
  • Force full-screen mode
  • Live environment check
  • System requirement check
  • Internet speed check

Behavioural monitoring flags patterns that distinguish normal test-taking from assisted or fraudulent responses. Testlify’s monitoring features include:

  • Copy/paste tracking
  • Mouse-out tracking
  • AI assistance detection
  • Focus Guard (Anti-Cheat Mode)
  • Talking prohibition
  • Live video monitoring
  • Screen recording
  • Question-level activity logs

Session integrity controls apply to the structure and administration of the assessment itself. These include question randomisation, IP proctoring, and Honesty Agreements presented to candidates before the session begins.

A single tab-switch does not trigger a review in Testlify’s system. A tab-switch combined with response timing anomalies and a geographic inconsistency does, and that composite approach separates incidental technical issues from deliberate fraud attempts.

Key Takeaway: The gap in most assessment integrity setups is not missing technology. It is the absence of a review protocol for cases that technology cannot conclusively resolve, and human review at Tier 3 is where false positives and genuine fraud get separated.

Final thoughts

Assessment integrity is not an edge case for specialist roles. It is a baseline requirement for any organisation that uses online assessments to make hiring decisions at scale.

Nearly 70% of HR professionals still report challenges recruiting for full-time positions, according to SHRM’s Talent Trends report. Assessment fraud compounds those challenges by allowing unqualified candidates to pass through filters that were designed to protect hiring quality.

Gallup’s 2026 State of the Global Workplace report shows global employee engagement at 20%, its lowest level since 2020. Every fraudulently placed hire who underperforms in role contributes to that deficit, and the compounding effect across a high-volume hiring pipeline is significant.

The fix does not require a full platform replacement. It requires adding a post-assessment review layer on flagged sessions, calibrating Tier 2 monitoring to access level rather than seniority, and confirming that your current platform uses question randomisation at the item bank level rather than at the assessment level only.

If you’re looking for a trusted skills assessment platform that actively prevents cheating and maintains assessment integrity, Testlify delivers advanced security controls at every stage of the hiring process.

Book a demo to see how Testlify helps you run fair, secure, and reliable assessments for any role.

Frequently asked questions (FAQs)

Reuben
Reuben

Content Writer

Reuben John is a B2B content writer focused on HR and recruitment. His work explores hiring trends, skills-based recruitment, talent assessment, and the technologies shaping how companies find and hire talent.

LinkedIn

Get started.

Hire on proof, not resumes.

Run your first skills-based assessment free — no credit card required.

We use cookies to enhance your browsing experience, serve personalised ads or content, and analyse our traffic. By clicking "Accept All", you consent to our use of cookies.