A global look at testing integrity and what China, the United States and the United Kingdom do differently
For millions of Indian students, a competitive examination is a gateway to a medical seat, a university place or a government job, which makes examination integrity a matter of public trust. Yet India has repeatedly faced questions over the security of its high-stakes examinations.
NEET-UG was administered to over 22 lakh candidates on 3 May Soon the CBI had filed a case regarding alleged irregularities and leak of the question paper in the wake of the examination (MHA, Government of India, 2026); by 27 May, it had arrested 13 people (CBI/PIB, 2026). The episode came barely two years after the NEET-UG 2024 controversy and the cancellation of UGC-NET in June 2024 (Ministry of Education, 2024).
The question is no longer why do question papers leak? It is: why does a system handling examinations at this scale remain vulnerable? A comparison with China, the US and the UK offers clues.
The scale makes examination security a systems problem
NEET-UG is one of the world’s most popular high-stakes exams.As many as 24.06 lakh candidates registered for the exam, and 23.33 lakh appeared in 4,750 centres across 571 cities in 2024. More than 2.1 lakh invigilators and 7,500 observers were deployed (NTA, 2024). A question paper passes through question setting, review, finalisation, printing, storage, transport, centre receipt, administration, collection and scoring; every handover is a potential vulnerability. A leak is therefore not simply a failure to keep a paper secret; it is a failure of chain of custody.

What other countries do differently
China: security begins before the exam
China’s Gaokao is similarly massive and important: in 2025, 13.35 million students took the exam in 7,899 sites, 355,000 rooms, with 1.05 million invigilators. Printing, transport, storage, and distribution all controlled by intelligent security gates, device checks, and real-time room monitoring (China MoE, 2025). The lesson for India is not to replicate China’s governance model, but to recognise that security cannot sit solely with the examination agency; it
must extend across printers, logistics, technology vendors, centres and personnel.
United States: a professional testing-integrity function
No single agency in the US is equivalent to NTA. Instead, ETS and other agencies conduct major tests. ETS’s Office of Testing Integrity (OTI) maintains continuous surveillance of testing,
Four systems, four approaches
investigates incidents, conducts unannounced audits, such as mystery shopper visits to centres, and implements statistical analysis to identify unusual patterns of scores that exceed expectations, with more than US$50 million spent annually on test security (ETS, 2026; ETS, 2026). The model: prevent, detect, investigate, analyse, respond- not compliance-checklist security, but independently tested security.
United Kingdom: make every handover auditable
Paper should be kept in a secure place where it is only accessible to authorised keyholders and opening a packet should always be accompanied by a recorded “second pair of eyes” check – no person can have responsibility for a critical action (JCQ, 2025–26). Ofqual reported 102 security breaches in GCSE/ AS/A-level exams in 2025 (up from 70 in 2024), 39 involving centre-staff mishandling, but zero public pre-exam leaks (Ofqual, 2025).
The lesson: a secure system is not one with zero breaches, but one where breaches are detected, contained, and acted upon.

India’s biggest vulnerability: the insider
The 2026 NEET investigation brings the issue into sharp focus
According to the CBI, a chemistry lecturer involved in the examination process on behalf of NTA had access to question papers and allegedly disclosed questions, options and answers to prospective candidates before the examination. Another NTA-appointed expert allegedly had complete access to Biology question papers, with several questions subsequently matching the examination paper (CBI/PIB, 2026; Ministry of Education/PIB, 2026).
This is not a problem that can be solved by adding another layer of frisking at the examination gate. It is an insider-access problem.
How much access does any one individual actually need?
Secure systems follow the principle of least privilege: people receive only the access necessary to perform their role.
This means isolating the process of setting, reviewing, finalising, printing, transporting, administering, and scoring examinations as much as possible. Sensitive actions must be dual-authorised, and digital access must leave an audit trail.\
The UK’s “second pair of eyes” is a simple example of this principle. ETS applies it at a much larger scale through access controls, audits, monitoring and investigations.
India has already diagnosed many of its weaknesses
India is not starting from scratch.
After the 2024 examination controversies, the Ministry of Education constituted a High-Level
Committee chaired by former ISRO chairman K. Radhakrishnan to recommend reforms in
examination processes, data-security protocols and the structure and functioning of NTA (Ministry of Education, Government of India, 2024).
The resulting report examined examination security, candidate verification, technology, centre
management and institutional restructuring (High-Level Committee Report, Government of India). India has also enacted the Public Examinations (Prevention of Unfair Means) Act, 2024, creating a statutory framework to deal with organised malpractice and unfair means in public examinations. The challenge, therefore, is increasingly one of implementation and institutional capacity. The 2026 NEET case demonstrates that having security protocols on paper is not enough.
What India should change
- A dedicated Testing Integrity Unit. NTA needs a specialised function for risk assessment,
personnel vetting, vendor audits, centre inspections, incident investigation and post-test analytics — on the model of ETS’s Office of Testing Integrity (ETS, 2026). - A digital chain of custody. Keep an audit trail of all activity: creation, review, finalisation, storage, dispatch, receipt, opening, examination, collection, scoring and capturing of all accessions to all items, when, where and by whom.
- Random, unannounced centre audits. Go beyond compliance checks to random checks as ETS does (ETS, 2026). Use exam data to detect anomalies. Routinely analyse centre-level performance, unusual score distributions and suspicious response similarities. Statistical detection cannot prove malpractice alone, but tells investigators where to look.
- Publish an annual Examination Integrity Report. Report incidents, centres affected, investigations, sanctions and audits conducted, as Ofqual does (Ofqual, 2025), turning security into a measurable accountability function.
The real benchmark is not zero leaks
It is tempting to ask which country has the fewest leaks but definitions and disclosure practices differ too much for that to be meaningful. The better question is: what happens when a security control fails? China offers whole-system coordination; the US, specialised integrity teams, audits and statistical detection; the UK, dual verification, documented custody and transparent reporting. India has many of the individual components; what it lacks is the same degree of institutional integration. It needs a system in which no single person, centre, vendor or process failure can compromise an examination affecting millions of students without leaving a trace,
from the moment a question is created until a score is reported.
Examination integrity is not about protecting a question paper. It is about protecting trust in the result.
About the Author:
Asmita Yadav is Deputy General Manager -MLE at DevInsights, a research, monitoring, evaluation, and learning (RMEL) organization that generates evidence to support informed decision-making in the social development sector.
Clear Cut Education Desk
New Delhi, UPDATED: September 28, 2026 16:00 IST
Written By: Asmita Yadav
Designation: Deputy General Manager– MLE at Devinsights
