Institutions are being asked harder questions about how they assess: by regulators, by accreditors, by auditors, by external examiners, and by students who appeal. Answering them usually means assembling an account of a single exam from a VLE, a marking tool, a proctoring service, a similarity checker - and, not unusually, a spreadsheet and someone’s mailbox. That gets treated as a reporting problem. More often it is an architecture problem.
![]()
The report everyone read as a cheating story
In August, the UK think tank Policy Exchange published Evidence of Learning Through Assessment, a report by Professor Philip M. Newton urging universities to stop running unsupervised remote exams, arguing that the credibility of the degree itself was at stake. The figures it put on the table, drawn from Freedom of Information requests to UK universities, were striking: 78% of UK universities use online remote exams for summative assessment, only 10% use online invigilation for all such exams, and 70% plan to carry on with this type of assessment. Students who follow the rules, the report argued, risk being “punished by lower grades” against those who do not (reported in Times Higher Education, 18 August 2026).
The sector read it as an argument about cheating, and the debate that followed was the familiar one about whether to march everyone back into the exam hall. We have set out our position on that question already, and we will not rerun it here - the short version is that supervision is a legitimate tool for some exams and a poor strategy for all of them, which is why we argued for going forward rather than back.
But there was a second finding in the report that attracted far less attention, and it is the more uncomfortable one. Two-thirds of university policies for these exams - 67% - did not mention generative AI at all.
That is worth pausing on. It is not that these institutions have adopted the wrong policy. It is that two-thirds of them are working to one that is silent on the single largest change to assessment in a decade.
What that silence actually tells you
It is tempting to file this under governance failure - committees that have not met, documents that have not been updated. Some of it is that. But spend any time inside an exams office and a less comfortable explanation presents itself: it is very hard to write policy about practice you cannot see in full.
Ask a mid-sized university a question that ought to be simple. Across all summative assessment last academic year, how many exams ran unsupervised, in which departments, under what AI conditions, with what completion rates, and how many were subsequently appealed? At most institutions this is not a query. It is a project. Somebody exports a list from the assessment platform, somebody else pulls participation data from the proctoring tool, a third person reconciles the result against the student record system by hand, and often a fourth explains why the numbers do not quite agree. Six months later there is a paper for a committee, and by the time it is read it describes a world that has moved.
This is what fragmentation actually costs. Not the licence fees for four tools instead of one - that is the version of the argument vendors like us are always accused of making, and it is the least interesting part. The costlier problem is that it becomes hard for the institution to describe itself. And an institution that struggles to describe its own assessment practice will struggle to govern it, to evidence it for an accreditor, and to write policy about it that means much operationally.
The record tends to break at predictable seams. Grades are finalised in the assessment tool and usually do reach the gradebook or the student record system - but by way of an export, a re-import and somebody checking a column. That works most of the time. It is also where a mark lands against the wrong student, and nobody finds out until a transcript is queried. Participation and invigilation events - who started, who stopped, what was flagged, what a human reviewed - often sit inside a supervision tool with no straightforward route out. Marking decisions are made properly, by people applying real judgement - but the trail of who marked what against which criterion is not always retrievable in a form you would want to put in front of an appeal panel. And the mapping of identities between the SIS and everything else tends to live in one person’s head, which works right up until the year they leave.
None of these are exotic failures. They are a fairly ordinary condition of an estate that grew one procurement at a time.
The question tenders forget to ask
Assessment tenders are exhaustive documents. They ask, in enormous detail, what a platform can do: which question types, which invigilation modes, which accessibility standards, which languages, which formats. All of that matters.
What they rarely ask, with anything like the same rigour, is what the platform gives back.
The questions worth adding are not technically sophisticated, and that is rather the point. Can every operation available in the interface also be performed through a documented public API? Do final grades flow back automatically into the VLE gradebook, or does someone re-key them? Can the institution export a complete audit trail for a single exam - authorship, delivery, supervision, marking, moderation, release - as one coherent record rather than five partial ones? Are participation and integrity events available as data, or only as a screen? Will the platform accept the institution’s own identifiers, so that records match the student record system without a reconciliation step? And if the relationship ends in seven years, what leaves with you, in what format, and who pays for it?
A vendor who answers these crisply is telling you something real about their architecture. A vendor who treats them as an afterthought for the technical annexe is telling you something too.
We would put ourselves in the same frame. This is not a standard institutions should apply only to other people’s platforms.
What institutions are actually asking us for
We keep a structured record of what customers ask us to build. It is not a marketing artefact - it is the thing our product decisions are argued from. And when we look at the requests logged against integration, the pattern is not what an outsider might expect.
Institutions are, for the most part, not asking us for new assessment features. They are asking to get data out and to keep systems in step.
They ask for endpoints that expose the grade audit trail. They ask for webhooks that carry their own institutional identifiers, so events land in their systems without translation. They ask to pull final grades out of the assessment platform and display them in the VLE the department actually uses. They ask to export participation-monitor logs, individual question scores, granular rubric data, and an audit of activity. They ask for queries scoped to their own institution, and for pagination, because the exports have got big enough to matter. In the integrity tooling they ask to bring in documents that never passed through our platform at all, and to see at a glance which system each one arrived from. In one national system, the requests are almost entirely about status parity - a complaint withdrawn in the national student record should look withdrawn in the assessment platform too, without anybody touching it twice.
That is not a feature backlog. It is a sector telling its suppliers, request by request, that the value of an assessment platform increasingly lies in how well it participates in an estate rather than how much of the estate it replaces.
It also lines up with something we have argued before about readiness: institutions do not become mature by buying more platform, and there is nobody at level three waiting to be discovered. Capability is uneven by design, and the systems have to accommodate that.
How we have built for this
We built WISEflow API-first and standards-first, and the practical consequence is that the integration conversation with IT is usually short. Single sign-on through OIDC, LTI 1.3 for launch and grade passback, QTI for item exchange, OAuth2 and webhooks for everything event-driven. It sits alongside the SIS and the VLE rather than asking either of them to move over.
The more consequential design decision is a structural one. WISEflow treats the exam as its core entity rather than the class. That sounds like an abstraction until you need the record: because authoring, delivery, invigilation, marking, moderation and archiving all hang off the same object, the audit trail for an exam is one exportable thing rather than a reconciliation exercise across four tools. When an external examiner, an appeal panel or a regulator asks what happened, the answer is a query.
It also shapes how we think an institution should be allowed to start. Not every university wants a central assessment platform, and plenty have a VLE they are perfectly happy with and no intention of replacing. That is why Marking Studio exists: the same professional marking, feedback and integrity capability, delivered into Canvas, Moodle, Blackboard, Brightspace or Itslearning through LTI 1.3, with identity, gradebook and course structure staying exactly where they are today. A department can adopt it without a campus-wide decision, and the institution still gets an audit trail.
The same logic applies to integrity checking, which is where the record most easily gets separated from the exam it belongs to. WISEflow Originality attaches to either route - the dedicated platform or the LMS - and it will also run standalone against what an institution already has, so integrity checking need not wait on a platform decision, or be re-done after one. A similarity report is evidence. It belongs with the submission it describes, in the same record an appeal panel may eventually read, rather than in a separate tool with its own login and its own way out.
More than one way in, then, with integrity checking available either way or on its own - and the integration story holds across all of it. We have written before about why onboarding is a change process rather than an installation — this is the architectural half of the same conviction. The platform should adapt to the institution, not the other way round.
There is a regulatory dividend here too. The obligations arriving with the EU AI Act for high-risk assessment systems are, in large part, obligations to keep records and to demonstrate oversight. Institutions that can already produce a complete, exportable account of an exam are most of the way there; institutions assembling it by hand will find December 2027 is not a snooze button.
Consistency is not the same as consolidation
The coherence argument is usually made badly, including by vendors, and it deserves better. It is not that institutions should buy more of one thing. Standardisation that flattens genuine disciplinary difference is not a win - we have argued at length that assessment design has to stay fair, consistent and human, and that means faculties keeping real latitude over format.
What has to be consistent is the record. Every exam, whatever its format and wherever it runs, should produce the same kind of evidence: who did what, when, under which conditions, reviewed by whom. Get that right and standardisation stops being a constraint on academics and becomes the thing that lets an institution say yes to format diversity, because it can still account for the result.
That is the version of coherence worth defending. And it sets a test that is uncomfortable in the right way: a platform that makes it hard to get your data back out is asking to be trusted rather than audited. In assessment, of all places, that is the wrong trade.
A simple takeaway
Before the next assessment procurement, try answering one question about your current estate: how long would it take to produce a complete, defensible record of a single exam - from authoring through to release of the mark - without anyone opening a spreadsheet?
If the honest answer is days rather than minutes, the gap may be less in your policies than in the seams between your systems - and policy drafting alone will not close it.
We would be glad to work through that with you: where your assessment record currently breaks, what would have to be true to close it, and whether the right answer is a dedicated platform, professional marking inside the VLE you already run, or some of each across different faculties. Get in touch or request a demo - and if you would rather start with the integration questions than the feature list, so much the better. Those are the ones we like being asked.