# Why control should match the risk
Uniform supervision for online exams looks consistent on paper, but it treats assessments with different purposes and consequences the same way. That produces uneven confidence in results. Instead, decide how much assurance each assessment needs by asking what claim the result will support.
Start with the result and its consequence
Australia's TEQSA security guidance is a practical example: it assigns security levels to common formats and advises that low-security assessments generally should not carry substantial weighting for progression. The underlying test is simple: what would be at stake if the assurance level is wrong?
If an assessment must prove independent performance, stronger identity verification is required. If access to outside materials would change what the task measures, the testing environment needs tighter controls. If breaches must be interpreted during an event, live human oversight may be necessary rather than only later review.
Think beyond individual tasks: programme-level security
This approach has two practical benefits. First, it lets educators place stronger controls around assessments that carry real evidentiary weight while keeping lower-stakes activities lighter. Second, it makes resource allocation clearer: live invigilation, technical controls, and incident review are limited resources, so concentrate them where the programme needs the strongest evidence.
Make delivery choices preserve the design
Practical delivery tasks include reproducing identity checks, logging or live observation consistently, and ensuring incident handling processes match the anticipated scale of problems.
Remember cohort size and capacity
Candidate numbers can change the assessment risk calculus. A model that works for a small cohort may strain authentication, support, and incident handling when applied to several hundred concurrent candidates. Cohort size is part of the supervision decision and should influence choices about which controls are feasible and which need additional operational capacity.
How to apply this in practice
- Identify what claim each assessment result will support (practice, formative feedback, progression, external validation).
- Map assessment formats to security needs using a clear rubric (identity assurance, environment controls, live vs recorded oversight). TEQSA-style guidance can be a starting point.
- Apply programme-level thinking to concentrate stronger controls at deliberate assurance points rather than across every task.
- Select delivery tools that reproduce the required assurances reliably and plan for support and incident handling at the expected scale.
Matching control to risk creates a different kind of consistency: educators apply the same risk logic across comparable assessments, even when supervision arrangements differ. That produces clearer, more justifiable assurance in the results.