In February 2024, the Manhattan District Attorney's office unsealed an indictment that should have shaken every general contractor in North America. Valor Security and Investigations, a state-approved safety training school, was charged with issuing roughly 20,000 fraudulent OSHA and NYC Department of Buildings safety cards to construction workers — many of whom had never sat through a single hour of training. Across the Atlantic, the UK's Construction Skills Certification Scheme (CSCS) was simultaneously dealing with its own crisis: organized rings of test-fixers helping workers cheat the touchscreen health and safety exam that gates entry to nearly every UK construction site. Different countries, different schemes — same fundamental problem. The credentials that supposedly prove a worker is safe to be on a high-rise scaffold or near live electrical work can be bought, faked, or proxy-tested with disturbing ease.
The Valor Case: A Sham School Inside the System
According to prosecutors, Valor Security and Investigations operated as a state-approved OSHA outreach training provider in New York City — a credential that gave it the legal authority to issue Site Safety Training (SST) cards required for any worker on a major NYC construction project. Instead of delivering the mandated 40 hours of safety instruction, executives allegedly sold cards outright. ABC News reported that prosecutors believe the scheme produced approximately 20,000 fraudulent cards across multiple years. The Manhattan DA charged six individuals; a separate Brooklyn case in April 2025 sentenced another operator to six months in jail for manufacturing counterfeit OSHA and Buildings Department safety cards. The shared thread: the credential system trusted the issuer, the issuer was a fraud, and tens of thousands of workers walked onto active job sites holding documents that were technically valid in every database — but represented zero actual training.
The CSCS Problem: Cheating the Test, Not Faking the Card
The UK story plays out differently but ends in the same place. CSCS cards themselves are hard to counterfeit — they're issued centrally and verified through the CSCS Smart Check app. The exploit is upstream: the CITB Health, Safety and Environment touchscreen test that workers must pass to qualify for a card. In a Metropolitan Police investigation that concluded in 2026, three men were jailed for running a service that helped more than 70 candidates cheat the exam — using hidden earpieces, stand-in test-takers, and bribed test centre staff. A separate February 2026 operation arrested four more individuals tied to a similar scheme. As CSCS itself acknowledges in its public guidance on qualification fraud, the card on a worker's lanyard may be entirely genuine while the qualification behind it is not. That's a verification gap no on-site inspection can close.
Why Both Schemes Failed in the Same Way
Strip away the geography and the two scandals share an identical architecture. In each case, the system relied on a trusted intermediary — a state-approved training provider, an accredited test centre — to vouch for the worker's competence. Once that intermediary was compromised, the downstream credential became indistinguishable from a legitimate one. There was no biometric tie between the human who appeared on the construction site and the human (if any) who actually completed the training. CSCS Smart Check could confirm the card was real. NYC's database could confirm the SST number was issued. Neither could answer the only question that actually matters: did this specific person sitting in front of me complete this specific training? That is the verification gap that fraudsters on both continents have learned to exploit at industrial scale.
The Real-World Stakes
Construction is consistently among the most dangerous industries in both the US and the UK. OSHA attributes a significant share of US construction fatalities to the 'Fatal Four' hazards — falls, struck-by, electrocutions, and caught-in/between — every one of which is a focus of the training that fraud schemes circumvent. When a worker holding a Valor-issued SST card falls from a scaffold, or a worker holding a fraudulently obtained CSCS card mishandles a live circuit, the legal and human consequences fall on the contractor, the developer, and the worker's family — not on the people who sold the fake card. Plaintiffs' attorneys have already begun citing these scandals in negligence cases, arguing that any contractor who relies solely on card presentation — without independent verification of the training itself — is operating below the modern standard of care.
What Source-of-Training Verification Changes
Both the Valor and CSCS cases would have been structurally impossible under a source-of-training verification model. Source-of-training verification ties every certificate to a biometric record of the specific human who completed the training, captured continuously throughout the session — not just at login. A facial match at enrollment, liveness checks during the course, and tamper-proof session records mean that even if a fraudulent training provider tried to issue a card, there would be no biometric session evidence to support it. And even if a worker tried to use a proxy test-taker, the biometric mismatch would surface immediately. This is exactly the gap the recently updated ANSI/ASSP Z490.1-2024 standard targets with its Section 4.4.2 learner authentication requirement, and it's the direction UK regulators have signaled with CSCS's expanding fraud-prevention program.
What Contractors and Developers Should Do Now
First, treat any safety credential as a starting point, not an endpoint. If your subcontractors' workforce holds cards from training providers you've never independently audited, you have Valor-style exposure. Second, ask your training vendors a direct question: can you produce biometric session evidence proving the cardholder was the actual participant? If the answer is 'we have a login record,' that is not verification. Third, in the UK, integrate CSCS Smart Check into site entry workflows — but pair it with vendor-level questions about how the underlying qualification was earned. Finally, document your verification process. In post-incident litigation, the difference between 'we checked the card' and 'we verified the human behind the card' is the difference between a defensible position and a settlement.
The Path Forward
The Valor indictment and the CSCS prosecutions are not isolated stories about a few bad actors. They are evidence that the entire model of credential-based safety verification — on both sides of the Atlantic — has a structural blind spot that organized fraud is now exploiting at scale. The card on the worker's lanyard tells you a transaction happened. It does not tell you a human learned anything. Until construction adopts source-of-training verification as the baseline rather than the exception, every general contractor is one fall, one electrocution, one collapse away from discovering exactly how indefensible their training records really are.
Authoritative Sources & Further Reading
- ABC News — Manhattan DA charges Valor Security— Indictment of a sham NYC safety school accused of issuing thousands of bogus OSHA certifications
- Brooklyn DA — Counterfeit OSHA Card Sentencing— Sentencing of a Brooklyn man for making and selling fake OSHA and NYC Buildings Department safety cards
- CSCS — Types of Card Fraud— Official UK Construction Skills Certification Scheme guidance on qualification and card fraud
Writing on training integrity, learner verification and compliance record-keeping for Asgard Authenticate.
Ready to Issue Credentials You Can Defend?
Join organizations worldwide that trust Asgard for online training credential integrity. Start your free trial today—no credit card required.
Start Free Trial