The short answer: high-stakes exam programs should treat identity as a lifecycle, not a selfie taken at login. A NIST SP 800-63-4-informed workflow starts with risk assessment, selects an appropriate identity assurance level, validates identity evidence, verifies that the candidate owns it, protects remote capture from injected or modified media, records consent and retention rules, and gives trained people a way to review exceptions and suspected fraud.

NIST SP 800-63-4 is written for digital identity services, especially government systems. It is not an exam-proctoring certification. However, its risk-based concepts provide a strong vocabulary for universities, licensing bodies, certification providers, and testing centers that need defensible remote identity controls.

Identity proofing, authentication, and continuous presence are different

Identity proofing establishes that a real person is associated with a claimed identity. Authentication confirms that a returning user controls an authenticator linked to that identity. Continuous presence checks whether the same authorized candidate remains in the exam session. A secure exam may need all three, but they solve different problems.

  • Identity proofing: Is this person genuinely associated with the submitted identity evidence?

  • Authentication: Is this session being opened by the enrolled account holder?

  • Exam-session continuity: Did the same person remain present throughout the assessment?

  • Integrity review: Is there evidence that exam rules were violated even if identity remained consistent?

A one-time face match cannot answer every question. It may reduce simple impersonation at login while missing account takeover, candidate substitution after the check, replayed media, or a virtual camera feed.

Choose assurance from impact, not convenience

NIST defines Identity Assurance Levels, or IALs, as progressively stronger identity-proofing requirements. The right level depends on the harm caused by a false identity result. A practice quiz and a professional license should not use the same workflow.

IAL1 supports lower-risk contexts where identity evidence may not be required. IAL2 requires stronger evidence, validation, verification, and protections against impersonation. In Revision 4, IAL3 identity proofing is limited to on-site attended processes with stronger evidence and controlled collection. Exam owners should not market a consumer-device remote workflow as IAL3 without a valid basis.

A NIST-informed checklist for remote exams

1. Document the impact of identity failure

List the consequences if an impostor passes: admission, employment, licensing, financial eligibility, public safety, or damage to the credential. Use that impact assessment to determine how much evidence and supervision are proportionate.

2. Validate the identity evidence

Check that the document or digital evidence is genuine, current, and consistent with authoritative or reliable sources. Define which evidence types are accepted and what happens when automated validation is unavailable.

3. Verify ownership of the evidence

Confirm that the person presenting the document is the rightful holder. Depending on risk and legal context, this may involve facial comparison, knowledge or possession checks, a trained remote agent, or a combination of methods.

4. Protect remote capture from injection and modified media

NIST SP 800-63A-4 requires injection protection and modified-media controls for remote attended identity proofing at IAL1 and IAL2. For exam programs, that means thinking beyond printed-photo spoofing. Threats include virtual cameras, replayed video, deepfake overlays, emulators, rooted devices, and media inserted into the capture pipeline before it reaches the verifier.

Liveness detection is useful but not sufficient on its own. A resilient workflow correlates capture integrity, device signals, document evidence, biometric comparison where permitted, and human review of anomalies.

5. Set video quality and supervision requirements

For remote attended proofing, NIST requires video quality sufficient for evidence inspection and comparison, and trained agents able to recognize manipulation, coercion, or social engineering. Exam owners should define minimum camera, lighting, network, and fallback requirements before the test window opens.

6. Give reviewers a secure fraud-flagging workflow

Reviewers need a mechanism to flag suspected fraud without alerting an attacker during sensitive workflows. For exams, the evidence packet should preserve timestamps, relevant images or video, device events, reviewer notes, and the rule or policy involved.

7. Notify candidates and govern recording

Where sessions are recorded, NIST calls for advance notice, consent, and published retention and deletion processes. Exam programs should also define access controls, data residency, purpose limitation, and whether recordings are necessary for every exam tier.

8. Design exception and accessibility paths

Standard workflows fail for legitimate reasons: damaged documents, inaccessible capture steps, poor connectivity, name changes, young candidates, disabilities, or lack of suitable devices. NIST emphasizes documented exception handling and redress. A secure program needs an alternative path that does not quietly exclude candidates who cannot complete the default process.

9. Bind identity to the exam session

After proofing, bind the verified identity to the account and exam attempt. Use appropriate authentication at launch and continuity checks during the exam. Re-authentication triggers may be useful after a long absence, camera interruption, device change, or other takeover indicator.

10. Test the full workflow, not only the face model

Measure document failures, liveness failures, false matches, false non-matches, manual-review rates, time to resolution, accessibility exceptions, and candidate abandonment. Test with the devices, countries, documents, languages, and network conditions expected in production.

Procurement questions for identity and proctoring vendors

  • Which parts of the workflow are identity proofing, authentication, liveness, or continuous monitoring?

  • How does the system detect virtual cameras, replay attacks, injected media, and modified capture pipelines?

  • What evidence is retained for a human reviewer, and can the reviewer override an automated result?

  • Which identity documents and countries are supported, and how is document validation performed?

  • How are consent, retention, deletion, access, and data residency configured?

  • What alternative path is available for accessibility, document, device, or network exceptions?

  • Which performance metrics are reported for the customer’s actual deployment population?

  • What claims, if any, have been independently assessed, and what exactly is within the assessment scope?

How TrustExam fits into the identity lifecycle

TrustExam supports ID capture, face matching, liveness checks, continuous face presence, multi-camera monitoring, virtual-camera and device-integrity signals, and an evidence timeline for human review. Organizations can select controls according to the stakes of the exam and integrate the integrity layer with an existing LMS or testing platform.

Frequently asked questions

Is a selfie enough to verify an exam candidate?

No. A selfie is only one capture. A defensible workflow also validates identity evidence, verifies ownership, protects the capture channel from spoofing or injection, authenticates the account, and checks continuity during the exam when risk requires it.

What is the difference between liveness and injection protection?

Liveness attempts to establish that capture comes from a live person rather than a static presentation. Injection protection addresses manipulated or synthetic media inserted into the digital capture path. Strong remote proofing needs both, plus device and human-review controls.

Can remote identity proofing reach NIST IAL3?

Under NIST SP 800-63A-4, IAL3 proofing is on-site attended. Remote attended and remote unattended methods can support IAL2 when the applicable requirements are met.

Should identity data be retained for as long as exam video?

Not automatically. Each data type should have a defined purpose and retention period. Keep only what is necessary for verification, audit, fraud investigation, and appeals under the organization’s legal and operational requirements.

Sources and further reading

Orken Rakhmatulla

Head of Education

Share