India does not need another promise that the next high-stakes examination will be “foolproof.” No large system is risk-free. It needs controls that make leaks harder, expose unusual access quickly and give candidates a fair remedy when the system fails.

The Public Examinations (Prevention of Unfair Means) Act, 2024 creates offences and penalties. Punishment matters, but criminal law acts mainly after misconduct. Prevention requires an operational design covering question creation, printing, digital systems, transport, examination centres and incident response.

Map every place the paper can escape

Security begins with a complete data-flow map. The examination body should document every person, system and vendor that can view or move sensitive material from drafting to opening at the centre.

That includes subject experts, moderation teams, software administrators, printers, packaging staff, transport contractors, centre coordinators and emergency support teams. An unnamed subcontractor is still part of the security boundary.

For each step, record what is accessed, why access is needed, how long it lasts and which independent record proves it happened. A confidential design can protect operational details while a public assurance report explains the control categories.

Use dual control for sensitive actions

No individual should be able to retrieve, decrypt, print or replace a final paper alone. Sensitive actions should require two independently authenticated people with different roles. This is similar to the two-key principle used in financial and infrastructure operations.

Role-based access must be narrow. A printer technician may need to operate equipment but not read the full paper. A database administrator may maintain a system without being able to export readable questions. Temporary access should expire automatically.

Log every access event in an append-only system. The log should include the identity, time, device, action, approval and result. Alerts should detect bulk downloads, access outside an approved window and repeated failed attempts.

Reduce the value of a stolen copy

Different encrypted paper sets can be assigned close to examination time. Secure digital delivery can reduce long physical custody chains, but it also creates concentrated cyber risk. The choice should follow threat modelling, not marketing.

Where printing remains necessary, use tamper-evident packaging, unique package identifiers and documented handovers. Reconcile package counts at every transfer. Centres should report a broken seal through a dedicated incident channel before opening the room.

Watermarking or controlled variations may help trace a leaked set, provided they do not create unequal difficulty for candidates. Any normalization method must be tested and published in advance.

Treat vendors as part of the examination body

Outsourcing work does not outsource accountability. Contracts should require staff screening, access records, incident reporting, data deletion and independent audit rights. Subcontracting should need written approval rather than disappearing into a vendor chain.

Before appointment, vendors should undergo technical and operational assessment. During delivery, the examination body should conduct surprise checks and verify that the controls described in policy exist in practice.

A vendor’s failure should trigger consequences, but candidates should not have to chase the vendor for a remedy. The public authority remains the accountable institution.

Monitor centres without turning candidates into suspects

The NTA has used biometric authentication and other identity controls. Such measures can reduce impersonation, but they should be proportionate, accessible and governed by clear retention rules. A candidate should know what data is collected, why it is needed, how long it is stored and how to challenge an error.

Centre monitoring should focus on organized misconduct and control failures. It should not create humiliating procedures or assume every nervous student is cheating. Staff need training for disability accommodations, religious clothing, medical devices and technical failures.

Every centre should run a rehearsal before exam day. Connectivity, power backup, clocks, storage, seating, biometric equipment and escalation contacts should be tested. A checklist signed without a real test is not evidence of readiness.

Publish an incident response clock

Candidates should not wait through rumours while authorities say only that the matter is “under examination.” A public incident protocol can define deadlines:

  • acknowledge a credible report within 2 hours;
  • preserve logs, CCTV and physical records immediately;
  • publish an initial scope statement within 24 hours;
  • provide a candidate update within 72 hours;
  • publish the remedy decision with reasons and an appeal route.

These timings are a proposed service standard, not current law. The exact window can vary, but silence should not be the default.

Investigators must distinguish a local incident from a system-wide compromise. A national re-examination imposes enormous costs, while refusing a re-examination after a broad compromise can destroy fairness. The decision needs transparent evidence and a reasoned explanation.

Give candidates an automatic remedy

When the administration causes a cancellation or major delay, affected candidates should not bear every cost. A remedy framework could include automatic fee refunds, travel support for low-income candidates, free correction windows, accessible grievance handling and a fast independent appeal.

Compensation should not depend on proving personal wrongdoing by an official. It should respond to documented administrative failure. Publish eligibility rules before the next crisis, not after public pressure peaks.

Mental-health support should also be visible in candidate communications. India’s Tele-MANAS service can provide support, but a helpline must accompany institutional accountability rather than replace it.

Measure whether reforms work

An annual public assurance report should disclose enough aggregate information to test progress: number of centres audited, seal anomalies, access alerts, impersonation attempts, confirmed breaches, average complaint-response time and remedies paid.

Independent auditors should sample logs and centre records. A parliamentary committee, court-appointed body or statutory regulator could review systemic failures without publishing secrets that make attacks easier.

The measure of security is not “zero complaints.” It is whether controls detect problems early, evidence survives investigation and students receive a timely, reasoned outcome.

Sources

Students cannot personally audit an examination supply chain. That is why trust must be earned through visible controls, preserved evidence and remedies that do not make candidates pay twice for an institutional failure.