Regulatory

The Regulators Are Done Waiting: How 2026 Became the Year Governments Started Voiding Training Certificates

Asgard Editorial
6 min read

For most of the last decade, the regulatory response to online training fraud followed a predictable rhythm. A scandal would surface. A press release would follow. A working group would be formed. Three years later, a guidance document would appear. And in the meantime, the certificates kept flowing.

That rhythm has broken. In 2025 and into 2026, regulators on three continents have stopped waiting for the next scandal and started doing something far more uncomfortable for the training industry: voiding credentials that have already been issued, fining the awarding bodies that issued them, and freezing the doors on new market entrants until the existing ones can prove they know who they trained.

This is the shift the compliance industry has been quietly dreading. And it is happening faster than most training providers are prepared for.

Australia: ASQA Stops Issuing Warnings and Starts Cancelling

The Australian Skills Quality Authority has spent 2025 and 2026 systematically cancelling the registrations of Registered Training Organisations whose record-keeping cannot withstand scrutiny. Baker Ebert Pty Ltd (RTO 40958), Kingsway Institute (RTO 41374) and SPES Group (RTO 46018) have all had their authority to issue nationally recognised qualifications revoked — and crucially, ASQA has the power to retroactively void qualifications already in circulation when the issuing body cannot evidence the training actually took place.

In May 2026 the regulator went further still, imposing a twelve-month freeze on applications from new private training colleges. The reasoning published alongside the freeze is unusually blunt: the regulator no longer trusts that new entrants can be assessed against existing standards because the existing standards have not kept pace with how training is now delivered, consumed and — increasingly — faked.

For an Australian learner holding a Certificate III or IV from a cancelled RTO, the consequences are immediate. The qualification on the wall may still look identical to a valid one. The database underneath it no longer agrees.

The United Kingdom: Ofqual Goes After the Awarding Bodies Themselves

Where ASQA is targeting the providers, Ofqual has done something even more significant: it has started enforcement against the awarding bodies that sit above them.

Its Action Plan for the Prevention of Qualification Fraud, published in late 2024 and updated through March 2026, has produced real consequences. ProQual has been issued a monetary penalty. The British Safety Council has accepted a settlement notice. EAL has been served with a formal Notice of Direction. Each of these organisations is not a training provider — they are the bodies whose seal of approval makes a certificate legally meaningful in the UK workplace.

That is a categorical change in regulatory posture. For thirty years the implicit deal was that awarding bodies set standards and providers met them; if fraud happened, the provider was at fault. Ofqual has now confirmed in writing that an awarding body which fails to verify how its qualifications are being earned is itself liable. The deal has changed.

North America: The Slower Wave Finally Arrives

Enforcement in North America has been slower, more fragmented, and harder to track — but the pattern is now visible.

In Texas, Attorney General Ken Paxton filed suit against TexAM University for issuing degrees without legal authority and opened formal investigations into commercial driver's licence training schools whose graduates were repeatedly failing on-road assessments. In Michigan, a Detroit truck driving school was suspended within weeks of a local TV investigation revealing that students were receiving CDL endorsements without completing the federally mandated behind-the-wheel hours. In Ontario, the Auditor-General published findings that private career colleges were accrediting commercial truck drivers without minimum training records — and recommended retroactive review of issued licences.

And in the financial sector — historically the canary for compliance enforcement — FINRA and the SEC's January 2025 settlement with LPL Financial centred on a failure of identity verification during customer onboarding. The technical failure is identical to the one inside fraudulent online training: the institution could not prove who, exactly, was on the other end of the transaction.

The Pattern: From Reactive to Proactive

Three years ago, regulators reacted to fraud after it surfaced publicly. Operation Nightingale unwound for years before anyone moved. The Valor and CSCS card scandals required journalist investigations to reach enforcement. The pattern was: wait for the press, then act.

In 2025–26 that has flipped. Regulators are now voiding credentials already in the field, not just sanctioning future ones. They are fining the issuers rather than only the providers. They are freezing market entry until existing players can demonstrate baseline integrity. And they are publishing anti-fraud action plans that name specific enforcement mechanisms before fraud occurs.

The unifying assumption behind all of this enforcement is one the training industry has spent a long time avoiding: a certificate is meaningless if the issuer cannot prove who was actually present at the moment the learning happened.

What This Means for Training Providers and the Employers Who Rely on Them

If you are a training platform, the practical implications are straightforward and uncomfortable. The regulator does not care whether your platform recorded a completion. The regulator cares whether you can produce, on demand, evidence that the human whose name appears on the certificate is the human who completed the assessment. Completion timestamps, IP addresses and SCORM payloads do not answer that question. They never did. Until 2025 most regulators were willing to pretend otherwise. They are no longer pretending.

If you are an employer accepting third-party training certificates — for OSHA-required safety hours, for food handler permits, for healthcare credentials, for CDL endorsements — the era in which the certificate itself was sufficient defence in an audit or a courtroom is ending. The defensible record is no longer the certificate. The defensible record is the verified chain of custody from the named human, through the verified learning event, to the issued credential.

That chain of custody is what learner authentication at the moment of training actually produces. It is also, not coincidentally, what every one of the regulators above is now implicitly or explicitly requiring.

The Window Is Closing Faster Than the Industry Thinks

The reason the 2026 enforcement wave matters is not because any single action is dramatic on its own. It is because the cumulative direction of travel — ASQA freezing entry, Ofqual fining issuers, Texas suing, Ontario auditing, FINRA settling — points unambiguously at one outcome: in the next regulatory cycle, the burden of proof shifts from the regulator (who must prove fraud) to the provider (who must prove integrity).

Training providers who can produce verified learner records will quietly continue operating. Those who cannot will discover, as the Australian RTOs already have, that the question is not whether their certificates were valid yesterday. It is whether anyone is willing to accept them tomorrow.

The Path Forward

The 2026 enforcement wave is not a series of isolated actions in disconnected jurisdictions. It is the same regulatory instinct surfacing in parallel — and arriving at the same conclusion. The certificate alone is no longer sufficient. The defensible record is the verified chain from the named human through the verified learning event to the issued credential.

Asgard Authenticate provides cryptographically verified learner identity at the moment of training — the only record that survives the kind of regulatory review now happening in Australia, the UK and North America. The training providers who build that record now will quietly continue operating. The ones who don't will spend the next twelve months discovering what their certificates are actually worth.

Authoritative Sources & Further Reading

  • OSHAOccupational Safety and Health Administration
  • ANSIAmerican National Standards Institute
Asgard Editorial

Writing on training integrity, learner verification and compliance record-keeping for Asgard Authenticate.

Published

Ready to Issue Credentials You Can Defend?

Join organizations worldwide that trust Asgard for online training credential integrity. Start your free trial today—no credit card required.

Start Free Trial

Related Insights

Asgard reviewed 950 online training programs across six regulated industries. More than 90% had no way to prove the certified person actually took the course. One year after the Valor scandal, the industry hasn't changed — it's gotten worse.

Read more

A UK tutor was jailed for three years after completing online coursework and assessments for more than 100 students. Proxy completion is no longer an individual act of cheating — it is a market with prices, guarantees, and repeat customers.

Read more

Most training platforms verify identity once at signup, then assume it forever. Here's why continuous learner authentication — from enrollment to every future refresher — is the missing layer in compliance.

Read more