Skip to content
Skip to content
Securing Online Exams: A Complete Guide to Proctoring in Moodle 2026 blog illustration

Securing Online Exams: A Complete Guide to Proctoring in Moodle 2026

The online proctoring market is expanding aggressively; as of 2026, the industry is valued at $1.07 billion, with research projecting a 25.27% compound annual growth rate (CAGR) that could see the market exceed $8 billion by 2035. That growth reflects a real need: remote exams require some form of verification that the person completing the assessment is who they say they are.

But surveillance carries a cost beyond licensing fees. Student surveys and institutional reporting have repeatedly documented discomfort with webcam-based monitoring, especially around privacy, biometric processing, disability accommodations, and the stress of being watched in private spaces. Institutions should treat proctoring as a risk decision, not a default setting.

This guide gives you a clear framework for choosing the right level of security for each assessment type, implementing Safe Exam Browser step by step, meeting your legal obligations, and, where appropriate, replacing surveillance with smarter assessment design.

Understanding Your Options: Five Proctoring Approaches

1. Live Proctoring: Maximum Security, Maximum Cost

A human proctor monitors the student in real-time via webcam and screen sharing. They verify identity, conduct a room scan, and can intervene immediately if suspicious behaviour is detected.

  • When to use: Professional licensure exams, graduate admissions assessments, final exams worth 40%+ of course grade.
  • Typical cost: $6-10 per exam session. Contact vendors directly -- pricing varies significantly by volume and institution.
  • Student impact: Most intrusive. Requires scheduled appointments and full room visibility to a stranger.

2. Recorded Proctoring: Scalable Review

The entire session -- screen, webcam, audio -- is recorded. AI flags potential incidents for human review. Reviewers examine only flagged segments rather than full recordings.

  • When to use: Mid-stakes assessments with large cohorts, asynchronous exam windows spanning multiple days.
  • Typical cost: $4-7 per exam.
  • Student impact: Moderate -- recording of private space, but no real-time interaction.

3. Automated AI Proctoring: Algorithmic Monitoring Only

Facial recognition, eye tracking, audio analysis, and browser monitoring run automatically. No human reviews footage unless an instructor manually checks flagged incidents.

  • When to use: Large-scale assessments where human review is impractical.
  • Typical cost: $3-5 per exam.
  • Student impact: High privacy concern -- biometric data collection with no human judgment on flagged behaviours. Bias and accessibility concerns have been reported in automated systems, so review vendor evidence and accommodation workflows carefully.

4. Hybrid: AI Screening with Human Review

Automated monitoring during the exam, followed by human review of AI-flagged incidents. Balances scalability with accountability.

  • When to use: Programs with diverse student populations, institutions that want defensible human oversight without real-time cost.
  • Typical cost: $5-8 per exam.
  • Student impact: Moderate automated monitoring plus post-exam review.

5. Lockdown Only: Browser Restrictions Without Surveillance

Browser lockdown prevents access to other websites, applications, or keyboard shortcuts. No webcam, microphone, or identity verification.

  • When to use: Deterrence-level security for formative assessments, open-book exams with strong question design, any context where surveillance is disproportionate to stakes.
  • Cost: Free (Safe Exam Browser).
  • Student impact: Minimal technical restrictions only, no biometric data or recordings.

Proctoring Solutions That Integrate with Moodle

ProviderMoodle IntegrationCost ModelKey FeaturesPrivacy posture to verifyBest For
Safe Exam Browser (SEB)Native (Moodle 3.9+)FreeBrowser lockdown, kiosk mode, multi-quiz support, optional Screen Proctoring via SEB ServerNo webcam/audio collection in lockdown-only mode; verify SEB Server settingsBudget-constrained institutions, formative/open-book assessments
SMOWLMoodle CertifiedInstitution licenceContinuous AI monitoring, ID verification, behavioural analysisVerify DPA, EU data hosting, FERPA/GDPR documentationEuropean institutions, strict privacy requirements
ProctorULTI$6-10/exam (contact for volume pricing)Live human proctors 24/7, ID verification, room scan, session reportsVerify FERPA school-official terms, retention, and subcontractorsProfessional certifications, high-stakes graduate programmes
Respondus LockDown Browser + MonitorNative Moodle pluginCampus annual licenceDesktop lockdown + webcam recording, widely used in US higher educationVerify FERPA terms, accessibility documentation, and retentionUS universities, semester-length programmes
HonorlockOfficial Moodle pluginContact for current pricingAI + live hybrid, mobile lockdown, browser guardVerify FERPA terms, state privacy terms, and deletion controlsInstitutions wanting predictable per-student pricing
YuJa VerityLTI CertifiedInstitution licenceAutomated + live, mobile app, cross-platformVerify selected region, DPA, FERPA/GDPR documentationMulti-vendor assessment environments
ProctortrackLTITiered pricingLive/auto/hybrid, advanced ID verificationVerify FERPA terms, biometric notices, and retentionCorporate training, professional development

Pricing and vendor note: Pricing figures above are indicative public-market ranges, not quotes. Proctoring vendors change pricing, product scope, privacy terms, and data-retention commitments frequently. Before adoption, review current vendor documentation, legal history, accessibility posture, DPA terms, subprocessors, and deletion controls with your compliance team.

Online proctoring collects some of the most sensitive data categories: biometric identifiers, video of private living spaces, and behavioural patterns. You must understand your obligations before deploying any system.

This section is general operational guidance, not legal advice. Confirm the applicable law, lawful basis, notices, consent model, accommodation process, and vendor contract language with counsel before deploying online proctoring.

GDPR (EU and EEA)

GDPR applies if you enrol students in the EU or EEA, regardless of where your institution is based.

Key requirements:

  • Lawful basis and transparency: Identify the lawful basis for processing before the exam, explain the purpose clearly, and avoid relying on consent where students cannot freely decline.
  • Data minimisation: Collect only what is strictly necessary for the purpose. Browser lockdown only? Don't add webcam monitoring.
  • Purpose limitation: Proctoring data may only be used for academic integrity. Selling or repurposing it violates GDPR.
  • Right to erasure: Students can request deletion. Your vendor contract must support this.
  • Data Processing Agreement (DPA): Required with every proctoring vendor.
  • International transfers: Verify data location, subprocessors, transfer mechanisms, and retention periods with the vendor.

Penalty: Up to EUR20 million or 4% of global annual revenue, whichever is higher.

FERPA (United States)

Proctoring recordings and related logs may be education records when they are directly related to a student and maintained by, or for, the institution.

Key requirements:

  • If your vendor allows subcontractors to access recordings, you need student consent.
  • Your vendor qualifies as a "school official" only if a written agreement specifies they will not re-disclose data.
  • Parents of students under 18 have the right to inspect proctoring recordings.

Penalty: Loss of federal funding. Rarely enforced directly, but institutional reputational and litigation risk is significant.

California (CCPA/CPRA)

California privacy obligations depend on your institution type, student population, vendor role, and whether consumer privacy or student-data laws apply. Key requirements:

  • Review whether CCPA/CPRA, California student-data laws, or contract-specific institutional policies apply.
  • Disclose what automated or AI-assisted flagging does at a high level, and require vendor documentation where available.
  • Verify retention, deletion, sale/share restrictions, sensitive personal information handling, and subcontractor controls.

Regulatory exposure and private rights of action vary by statute and fact pattern. Treat California deployments as counsel-review items.

The Proportionality Principle

Match surveillance level to assessment stakes -- and always offer an alternative:

StakesRecommended approachAlternative
Low (<=10% of grade, formative)SEB lockdown or no proctoringN/A -- privacy harm exceeds benefit
Medium (15-35% of grade)Automated or recorded proctoringOpen-book format with application questions
High (>=40% of grade, certifications)Live or hybrid proctoringIn-person testing or portfolio assessment

Student Rights: Tell Students This Before Every Proctored Exam

  • What data is collected (video, audio, screen, biometric, environmental)
  • How data is used and who has access (vendor, instructors, subcontractors)
  • How long data is retained and where it is stored
  • How to request data deletion
  • What happens if technology fails during the exam
  • Alternative assessment options
  • Accommodation process for students with disabilities

How to Implement Safe Exam Browser: Step-by-Step

Safe Exam Browser is free, open-source, and natively integrated with Moodle 3.9+. Download the current release from the official Safe Exam Browser downloads page before every exam cycle. As of May 2026, the official page lists Windows 3.10.1, macOS 3.6.1, and iOS/iPadOS 3.6.2; those version numbers will change over time.

SEB Server is an optional companion application that adds Screen Proctoring -- periodic screenshot capture during exams for post-exam review, without full video recording. It is free but requires your own server infrastructure.

What SEB Does and Doesn't Do

  • Does: Lock the device into kiosk mode, disable keyboard shortcuts (Alt+Tab, Cmd+Tab, Print Screen), block other websites and files, prevent copy/paste, force full-screen, support multi-quiz sessions, and optionally capture screenshots via SEB Server.
  • Does not: Monitor via webcam or microphone, verify student identity, detect a second device, prevent in-room collaboration, or track eye movement.
  • Bottom line: SEB deters opportunistic cheating but cannot stop determined misconduct. Use it when you trust your question design more than surveillance.

Step 1: Choose Your Configuration Strategy

  • Option A: Browser Exam Key (simplest, weakest): Moodle generates a hash key to validate the browser. No SEB download required. Suitable for low-stakes quizzes only, students can potentially spoof the key.

  • Option B: SEB Client, Default Config (moderate): Students download SEB and use its default configuration. Suitable for mid-stakes assessments.

  • Option C: SEB Client with Custom Config File (strictest): You create a .seb file specifying exactly what is allowed -- whitelisted URLs, permitted tools, quit password. Students open the file to launch SEB pre-configured for your exam. Suitable for high-stakes exams.

Step 2: Configure Your Moodle Quiz

  1. Open your Quiz -> Edit settings
  2. Scroll to Extra restrictions on attempts -> Browser security
  3. Select your level: "Require the use of Safe Exam Browser" (any config) or "Require a Safe Exam Browser with exam configuration from this quiz" (your specific .seb file)
  4. If using a custom config, click "Download this quiz's Safe Exam Browser config file"
  5. For institution-wide templates: Site Administration -> Plugins -> Activity Modules -> Quiz -> Safe Exam Browser

Step 3: Create a Custom Config (Optional)

  1. Download the SEB Config Tool from safeexambrowser.org
  2. File -> New Configuration
  3. Set: quit password, allowed/blocked URLs, file upload permissions, permitted utilities
  4. Configuration -> Exam URL -- paste your quiz URL and set a Quit URL
  5. Save as a descriptive .seb file and upload to your Moodle course Files area

Step 4: Test, Communicate, and Support

Test first: Run the config yourself -- attempt to switch apps, access blocked sites, and copy/paste. Then pilot with 5-10 students across different operating systems.

Known platform issues:

  • macOS may require explicit accessibility permissions on first launch.
  • Official SEB downloads cover Windows, macOS, and iOS/iPadOS. Do not assume Android, Linux, or Chromebook support without a tested institutional path.
  • For unsupported devices, plan a Browser Exam Key fallback, managed-device lab, or alternative assessment.

Communicate 2 weeks before the exam via announcement and email:

This exam requires Safe Exam Browser (SEB) -- a free lockdown browser.

  1. Download the current SEB version for your platform from safeexambrowser.org. Official downloads cover Windows, macOS, and iOS/iPadOS.
  2. Install and launch once to confirm it works
  3. Download the exam config file: [link]
  4. On exam day, double-click the config file to begin

Also, create a no-stakes practice quiz with SEB enabled so students can verify their setup before the real exam.

On exam day: Set up a dedicated support channel. Common fixes: add SEB to antivirus exceptions if it won't launch; provide the quit password if a student accidentally closes SEB; offer Browser Exam Key mode as a fallback for incompatible devices. Log all incidents with timestamps.

Step 5: Evaluate After the Exam

  • Did SEB prevent the specific type of cheating you were concerned about?
  • Did technical issues affect any students' ability to complete the exam?
  • Would a better question design achieve the same integrity goals with less friction?

Decision Framework: Choosing the Right Approach

Question 1: What are the stakes?

  • <=10% of grade (formative, practice) -> No proctoring or SEB lockdown only
  • 15-35% of grade (midterms) -> Continue to Question 2
  • =40% of grade (finals, certifications) -> Continue to Question 3

Question 2: What is your primary concern?

  • Deterring casual cheating -> SEB lockdown (free)
  • Evidence for academic integrity cases -> Recorded proctoring with AI flagging
  • Accreditation or institutional policy compliance -> Hybrid AI + human review

Question 3: What is your risk tolerance?

  • Low -- stakes justify maximum security -> Live proctoring
  • Moderate -- balance cost and security -> Hybrid AI + live review of flagged incidents
  • Privacy-conscious institution with strong question design -> Recorded proctoring or well-designed open-book exam

Question 4: What are your compliance obligations?

  • EU/EEA students -> vendors with documented GDPR posture, DPA terms, transfer mechanisms, and suitable hosting region
  • California residents -> verify state privacy obligations, retention, deletion, and sale/share restrictions with counsel
  • Students with disabilities -> Confirm vendor supports extended time, screen reader compatibility, flexible room scan requirements

Question 5: What is your budget?

  • No budget -> SEB + smart question design
  • Per-exam budget -> Automated or recorded proctoring; compare vendors on features vs. privacy record
  • Semester/annual budget -> Campus licence (Respondus) or per-student flat rate (Honorlock)
  • Enterprise -> ProctorU Live or YuJa Verity enterprise tier

Alternatives to Proctoring: Assessment Design That Reduces Surveillance Need

Before deploying surveillance, consider whether assessment redesign achieves the same integrity goals with less privacy impact.

  1. Open-Book, Application-Focused Exams Replace "Define photosynthesis" with "A plant in a sealed dark box maintains normal CO2 levels but stops growing. A second plant in a sealed box with light grows normally. Explain the difference." Students can look up the equation -- they cannot look up the reasoning for a novel scenario.
  2. Randomised Question Pools Create a question bank with 100+ items. Configure each quiz to randomly select 20. Each student sees a different subset -- collaboration becomes impractical. Randomise numerical parameters within questions for additional variation.
  3. Time-Boxed, Open-Note Exams Design 60 minutes of content into a 60-minute window. Students can use notes and textbooks. Questions require synthesis and application rather than lookup. Time pressure exposes lack of understanding.
  4. Portfolio or Project-Based Assessment Replace a single timed exam with staged submissions (proposal, draft, final). Staged feedback makes outsourcing obvious and impractical. Instructors develop detailed knowledge of each student's work over time.
  5. Oral Examinations 15-minute synchronous video conversations with randomised questions from a question bank, or asynchronous video responses. Difficult to outsource in real-time. Instructors can ask follow-up questions to probe understanding.
  6. Honour Code with Targeted Proctoring Default to unproctored exams with an honour code. Randomly proctor 10-20% of students, or focus proctoring resources on students with prior violations. Reduces surveillance burden while maintaining deterrence.

MooDIY's Proctoring Support: Infrastructure for Exam Day

Regardless of which proctoring solution you choose, your hosting infrastructure must handle the spike loads that exam windows create. A 300-student final exam at 10:00 AM generates simultaneous quiz launches, LTI connections to proctoring services, and database writes. If your server is underpowered, exams fail, and student panic escalates.

What MooDIY provides for exam-day reliability:

  1. Concurrency planning: We scope exam-window capacity against your expected simultaneous quiz launches, LTI handshakes, and database writes.
  2. Monitoring and support: Enterprise plans can include scheduled exam-window monitoring and support commitments documented in the commercial agreement.

Ready to run your next exam on infrastructure built for it? Explore MooDIY hosting plans

Related reading: See our high-concurrency quiz guide for handling exam-day traffic, explore the best Moodle plugins for assessment tools, or review Moodle performance optimizations.

Research References

  1. Market Trends & Student Sentiment
  1. Software & Technical Specs
  1. Legal and Privacy References