A year ago, the Manhattan District Attorney's office indicted the operators of Valor Security Services for selling roughly 20,000 fraudulent OSHA training cards. Across the Atlantic, the Metropolitan Police were unwinding a parallel scheme inside the UK's CSCS construction-card program. The headlines were brutal. Industry associations issued statements. Regulators promised reviews. Training organizations swore the problem was a few bad actors.
Twelve months later, the data tells a different story. In an Asgard analysis of 950 online training programs across construction, healthcare, food service, financial services, oil & gas, and manufacturing — conducted between January 2024 and January 2025 — more than 90% of the training organizations reviewed issued certificates to individuals with no verification of their identity, their participation, or even their humanity.
That isn't a margin-of-error finding. It is the rule, not the exception. The vast majority of what regulated industries call compliance training is, in any defensible sense of the word, functionally fraudulent — not because the training material is wrong, but because the organizations issuing the credentials never confirmed who, if anyone, actually completed the course. The Valor case wasn't an outlier. It was a sample.
What We Mean by 'Functionally Fraudulent'
The word fraudulent is loaded, so let's be precise. We are not claiming that 90% of training organizations are knowingly running scams. We are claiming something colder and more structural: the certificates they issue cannot be defended.
A training completion record is defensible only if the issuing organization can answer four questions, on demand, to a regulator, an auditor, an insurance carrier, or a court. First, who started the course — did the organization confirm that the person at the keyboard was the same person whose name appears on the certificate? Second, who stayed in the course — did the organization verify that the same person remained present for the duration, or did someone, or something, else take over partway through? Third, was it a human at all — did the organization put any control in place to detect an AI agent, a script, or a third-party completion service doing the work unattended? Fourth, can the record be tampered with — if the organization allows timestamps, scores, or completion flags to be edited after the fact, the audit trail is fiction.
In our review, an organization had to fail only one of these four criteria to be classified as issuing functionally indefensible credentials. More than 90% failed at least one. A meaningful share failed all four. That is what fraudulent means here. Not malice on the part of the learner — a failure on the part of the organization issuing the certificate.
Why Nothing Changed After Valor
If the problem is this large, and the headlines were this loud, why didn't the market correct itself? Two reasons, and neither of them are technological.
First, the training organizations themselves are paid for completions, not integrity. Most online training providers earn revenue per seat, per course, or per certificate issued. An organization that flags a suspicious completion has to refund a customer, void a credential, or interrupt a renewal cycle. The economic gravity pulls these organizations in exactly one direction: issue the certificate, log the completion, move on. Verification is treated as a cost center. Completion is the revenue line.
Second, regulators set standards faster than they enforce them. The updated ANSI/ASSP Z490.1-2024 standard explicitly addresses learner authentication for online environmental, health, and safety training. The standards exist. The audits that would force training organizations to actually implement them, in most jurisdictions, do not.
The Regulators Who Saw It Coming
To be fair, a meaningful subset of regulators has been signaling this exact failure for years.
ANSI/ASSP Z490.1-2024 is the flagship standard for environmental, health, and safety training in the United States. The 2024 revision is explicit: online training programs are expected to authenticate learner identity and document the controls that prevent proxy completion. It is not a suggestion — it is the consensus standard the courts will reference when assigning negligence in the next workplace fatality.
Other regulators are moving in the same direction. While most have stopped short of mandating a specific authentication method, a growing number now treat unverifiable training records as the practical equivalent of no training at all. The standards bodies have done their job. The market has not.
The AI Escalation That Makes 90% an Undercount
Here is the most uncomfortable part of the analysis. The 90% figure measures the gap that training organizations have left wide open — the gap that lets a coworker, a spouse, or a paid third party complete a course on someone else's behalf and still walk away with a valid-looking certificate. That gap has existed since the first online course shipped, and the organizations issuing the credentials have known about it the entire time.
What is new — what makes the next twelve months categorically different from the last twelve — is that the proxy no longer needs to be human. Consumer-grade AI agents can now log into a training platform, watch the videos, answer the questions, complete the assessments, and generate a passing score, all without a human ever touching the device. The training organizations issuing certificates against those sessions have, in most cases, no mechanism in place to notice.
This is no longer a research demo. It is a documented behavior across multiple compliance domains, and it is being marketed openly on freelance and productivity sites under names like automated course completion and compliance assistance. An organization that fails our four criteria today fails them more catastrophically tomorrow, because the cost and friction of cheating have collapsed to near zero while the verification posture of most providers has not moved.
The 90% finding is, almost certainly, an undercount of where the real number is heading. The Valor scheme required physical card production, a fake training storefront, and a network of buyers. The next Valor needs a $20-a-month AI subscription, and a training organization that doesn't bother to check.
What a Defensible Record Actually Looks Like
The fix is not mysterious. A defensible record requires learner verification tied to a government-issued credential at enrollment and at the start of every session, low-friction continuous presence checks throughout the course, automation and AI-agent detection, and tamper-evident completion logs a regulator or court can rely on without taking the training provider's word for it.
This is what we mean by source-of-training verification — verifying not just that a certificate exists, but that the certified person actually generated the underlying training event. It is the layer the industry skipped in its first decade of going online, and the layer ANSI/ASSP Z490.1-2024 now expects. It is also the difference between a certificate that survives an audit and a certificate that becomes evidence in a lawsuit.
The Next Valor Is Already Happening
If you are a compliance officer reading this, the question to ask is not whether the next Valor-scale scandal will land in your industry. It will. The question is whether your organization's training records will be on the right side of the headline when it does.
A year ago, the industry was given a clear warning. The data says 90% of programs ignored it. The standards bodies have moved on without the market. The technology to cheat — for both humans and machines — has gotten dramatically cheaper. The technology to verify has gotten dramatically better.
The next twelve months will not look like the last twelve. The gap between the standard and the practice has become wide enough that someone — a regulator, a plaintiff's attorney, a journalist, an insurance underwriter — will close it. The only open question is which organizations will be on the wrong side of that closure when it happens.
The Path Forward
Valor was a warning. The 90% number is the receipt. The training organizations issuing online credentials were never set up to answer the question regulators, auditors, and courts are now starting to ask: who, specifically, completed this course?
For most of the industry, the honest answer from the training organization is we don't know — and the certificate we issued cannot tell you. Asgard Authenticate exists to close that gap for the organizations willing to fix it, with source-of-training verification built into the session itself rather than bolted on after the fact.
Defensibility is not a feature a training organization adds at the end. It is an architectural choice it makes at the beginning. The organizations that make that choice now will be the ones still standing when the enforcement wave the standards bodies have been promising finally arrives.
Authoritative Sources & Further Reading
- OSHA Training Requirements— Official OSHA guidelines for workplace safety training
- ANSI Standards— American National Standards Institute
Writing on training integrity, learner verification and compliance record-keeping for Asgard Authenticate.
Ready to Issue Credentials You Can Defend?
Join organizations worldwide that trust Asgard for online training credential integrity. Start your free trial today—no credit card required.
Start Free Trial