
Ask an exams controller what worries them the night before a large online exam and it is rarely the servers. It is question 14 circulating on a group chat twenty minutes in, or a candidate who is not the person on the ID card. Knowing how to prevent cheating in online exams is now a core operational skill, and the honest answer is that no single tool does it. The institutions that keep their exams clean layer their defences: they design cheating out of the question bank, control the delivery environment, watch the session with AI and human eyes, and then run the numbers afterwards to catch what live monitoring missed.
Why online cheating is harder to stop than it looks
In an exam hall, one invigilator can see thirty candidates, their desks and their hands. Online, every candidate sits in a room you have never seen, on a device you do not control, with the whole internet one keystroke away. The methods have multiplied to match: a second phone propped behind the laptop, a friend on a call, answers shared between sittings, a paid stand-in, or an AI assistant in another window. Each one needs a different control, which is why bolting a webcam onto a paper-era exam rarely works.
The AI part is no longer hypothetical. The Higher Education Policy Institute's Student Generative AI Survey 2025, which polled 1,041 full-time UK undergraduates, found that 88% had used generative AI for assessments, up from 53% a year earlier, and 92% used AI tools in some form. Some 18% said they had put AI-generated text directly into their work. Those are UK figures; students elsewhere are unlikely to differ much. If your exam can be answered by pasting the question into a chatbot, assume someone will try.
One more reality check: prevention that treats every candidate as a suspect makes anxious students perform worse, raises complaints, and drowns the integrity office in appeals. The target is an exam that is hard to cheat on and calm to sit.
Start with the question bank, not the camera
The cheapest place to prevent cheating is before the exam exists. Three practices do most of the work.
Randomise questions and options. When each candidate draws questions from a moderated bank in a different order, with answer options shuffled, "what did you get for question 7?" stops being a useful message. Parallel forms matched for difficulty make sharing between a morning and an afternoon sitting pointless too.
Write questions a chatbot cannot answer cold. Recall questions are the easiest to cheat on and the easiest to generate. Questions that ask candidates to apply a concept to a scenario, read a data set shown on screen, or justify a choice are harder to outsource and better measures of learning anyway. On ExamX, faculty generate items from their own course content across 20+ question types with Bloom's-taxonomy coverage, then review them in a moderated bank before anything goes live.
Retire items each cycle. Any question a few thousand candidates have sat should be treated as public. Item analysis after each exam (more below) tells you which items to retire, so the bank stays fresh without a full rewrite every semester.
Technical controls during delivery
Once the paper is sound, the delivery environment is where most attempts are stopped in the moment. The controls below are standard on any serious online proctoring software; what varies is how well they work together.
Browser lockdown. A lockdown browser or kiosk mode keeps the exam full-screen, blocks new tabs and other applications, and disables copy, paste and screen capture. It removes the casual look-up and makes the screenshot-to-group-chat route much harder. It does nothing about a second device, which is why it never stands alone.
Identity verification. Photo-ID capture and face matching at login stop the paid stand-in and let you prove afterwards who sat the exam. Re-checks during the session catch a later swap.
AI proctoring. This is the layer that replaces the invigilator's eyes. ExamX AI proctoring uses face and gaze detection to flag repeated off-screen looks, raises real-time alerts for multiple faces in frame, device swaps and off-screen activity, and runs at 99.2% detection accuracy with under 0.1% false positives. Every flag is reviewed by a human before anything happens to a candidate; there are no automatic penalties. Our plain-English guide to proctoring covers the modes in more depth.
Time limits and question timers. A per-question timer with no back-navigation defeats the "screenshot everything, look it up, come back" pattern. For long descriptive answers a section timer is fairer.
Pre-exam environment check. A short guided check before the clock starts (camera, microphone, room, device state) fixes technical problems in time, sets the expectation that the session is monitored, and cuts mid-exam support tickets.
Use analytics to catch what proctoring misses
Live monitoring catches behaviour. It cannot see a candidate who memorised leaked answers, or a group that coordinated on a messaging app beforehand. Post-exam analytics can, and they are the most underused tool in online exam cheating prevention.
Item analysis flags questions that suddenly became easy. If an item half the cohort used to get wrong is suddenly answered correctly by nearly everyone, with no change in teaching, it has probably leaked.
Response-time analysis looks at how long each candidate spent on each item. Someone who repeatedly answers a multi-step calculation correctly in a few seconds is either brilliant or reading answers from somewhere.
Similarity analysis compares answer patterns across candidates, including which wrong options they chose and in what order they moved through the paper. Identical error patterns between candidates who sat in different rooms are hard to explain innocently. ExamX's cheating detection runs cross-candidate similarity and answer-pattern matching with time correlation as one of its seven detection layers, and packages statistical outliers into evidence reports for the review committee instead of acting on them automatically.
None of these is proof on its own; together they give the integrity office a documented starting point an appeals panel will respect.
Write an integrity policy people can actually follow
Technology enforces rules; it cannot invent them. The HEPI survey found that 80% of students agreed their institution had a clear AI policy, which sounds reassuring until you consider the one in five who did not. A usable exam integrity policy answers four questions in plain language: what counts as permitted aid for this exam, what happens when a flag is raised, who reviews it, and how a candidate can respond.
Stanford's Honor Code, in the version that applies to incidents from September 2023, is a useful model because it commits both sides. Students agree to neither give nor accept unpermitted aid in any graded work, examinations included. Instructors agree to state clearly, in the syllabus and when asked, what aid is permitted; to design assessments that encourage honesty, "including but not limited to proctoring assessments"; and not to take "unusual or unreasonable precautions" against dishonesty. That last clause matters. Proctoring is legitimate; surveillance theatre is not.
Publish the policy well before the exam, restate the exam-specific rules on the pre-exam check screen, and have candidates acknowledge them. A policy nobody read is a weak defence at appeal.
Train invigilators to read flags, not just watch screens
AI proctoring changes the invigilator's job from watching to reviewing. A flag arrives as a timestamped clip with a reason: a second face in frame, gaze off-screen again, a device change. A trained reviewer clears most of these quickly (a child walking into the room is not misconduct) and escalates the few that warrant it with the evidence already packaged. Untrained reviewers either clear everything to avoid conflict or escalate everything and bury the integrity office. A short session on what each flag means, what the policy says, and how to write up an escalation is the best-value hour in the exam calendar.
AI-assisted cheating deserves its own plan
Most of the controls above already blunt AI-assisted cheating. Lockdown blocks the chatbot tab, gaze detection catches the second device, and similarity analysis catches the twenty candidates who all pasted the same fluent, slightly wrong answer. Three additions close the remaining gaps.
First, decide per assessment whether AI is permitted, and say so. Some assessments should allow it, because using AI well is a skill worth assessing; banning it everywhere and enforcing it nowhere is the worst of both. Second, design items that need the candidate's own context: the data set on screen, the case discussed in week six, the lab result from their own group. A chatbot answers generic questions well and specific ones badly. Third, for the highest-stakes exams, use invigilated on-campus delivery on managed devices, where the environment is yours. Digital does not have to mean remote; SRM's 80,000+ exams ran on roughly 2,000 tablets across five campuses.
Before, during and after: the checklist
Put this in the exam runbook and tick it every cycle. The "before" column is the easiest to skip and the hardest to make up for once the exam has started.
Why one platform beats a stack of point tools
Every control in this article can be bought separately. The problem is the audit trail. When the question bank lives in one tool, the lockdown browser in a second, proctoring in a third and analytics in a spreadsheet, an appeal means reconstructing one candidate's session from four systems with four clocks. ExamX keeps the whole lifecycle in one place: authoring, randomised delivery on web, iPad and Android, lockdown, AI proctoring, evaluation and analytics, with one timeline per candidate from login to result. Our earlier piece on how technology secures exams makes the broader case.
The scale proof is public: SRM Institute of Science & Technology ran 80,000+ paperless exams across five campuses on ExamX, 45 days of continuous examinations at a peak of around 1,800 concurrent candidates, with zero disruptions. The details are in the SRM case study.
Two honest limits. ExamX does not offer a live human proctor watching each candidate in real time; integrity is automated, with humans reviewing flags rather than sessions. If a licensing body requires live proctoring, you need a service that provides it (we weigh the two models in automated vs live proctoring). And no platform can fully control a candidate's home, so match the delivery mode to the stakes: remote high-stakes exams carry more risk than on-campus digital exams on managed devices.
How to prevent cheating in online exams: FAQs
What is the most effective way to prevent cheating in online exams?
Layer the controls: a randomised question bank, browser lockdown, identity verification at login, AI proctoring with human-reviewed flags, and post-exam analytics, all under a policy published in advance. A webcam alone is easy to work around; five layers with one audit trail are not.
Can AI proctoring detect ChatGPT and other AI tools during an exam?
Indirectly, yes. Lockdown blocks the chatbot tab, gaze and multiple-face detection flag a second device or a helper, and post-exam similarity and response-time analysis catch answers that look pasted rather than worked out. Pair these with context-specific questions and a policy that says when AI is permitted.
Does a lockdown browser stop cheating on its own?
No. It stops the casual look-up on the exam device: new tabs, other applications, copy-paste and screen capture. It cannot see a phone behind the laptop or a helper in the room, so it is paired with identity verification and AI proctoring.
How do you prevent cheating in online exams without a webcam?
Lean harder on the other layers: randomised questions and shuffled options, parallel forms, per-question timers with no back-navigation, browser lockdown, higher-order questions, and post-exam analytics. For high-stakes exams, deliver on campus on managed devices with in-room invigilators.
What should an online exam integrity policy include?
In plain language: what counts as permitted and unpermitted aid for each exam (AI tools included), what is monitored and recorded, how flags are reviewed and by whom, what sanctions apply, and how a candidate can respond or appeal. Publish it before the exam and restate the rules on the pre-exam check screen.
What happens when AI proctoring flags a student wrongly?
On a well-run platform, nothing automatic. ExamX runs at 99.2% detection accuracy with under 0.1% false positives, and a trained human reviews every flag: they see the timestamped clip and the reason, clear it if it was innocent, and escalate with packaged evidence only when the policy warrants it.
The bottom line
Nobody prevents cheating in online exams with a single purchase. The institutions that get it right build a stack: a question bank that makes sharing pointless, a delivery environment that removes the easy options, AI proctoring that watches without punishing, analytics that catch what the camera missed, and a policy everyone read in advance. If you would rather run that stack on one platform than across four vendors, book a demo of ExamX and bring your most cheat-prone exam to the conversation.
Survey figures from the HEPI/Kortext Student Generative AI Survey 2025; policy language from Stanford University's published Honor Code. ExamX capabilities and figures as published on greatify.ai, September 2026.