Every organization running online compliance training operates on a quiet assumption: if it ever came to it, the training record would hold up. The certificate is in the system. The quiz was passed. The timestamp is there. That has to count for something.
It doesn't. It never has. A login and a completion record only prove that an account finished a course — not who was behind it. The only reason the gap got away with it for so long was that exploiting it took effort.
That has changed. AI has removed the barrier to entry on malpractice. Generative tools can now log in, consume content, and complete assessments in the enrolled learner's name without a human present. Proxy completion services advertise guaranteed passes for a few hundred dollars. Regulators have noticed — and they are making proof of both identity and participation a non-negotiable part of any defensible training record.
This is not a future problem. It is a present one.
The Questions That Actually Get Asked
After a workplace incident, the first document requested is often the training record. But the record is the beginning of the inquiry, not the end. The follow-up questions are where most programs fall apart:
How do you know the person named on this certificate is the person who took the course? Who else had access to that account? Can you show they were present for the material, not just logged in while it played? What prevented a colleague, a supervisor, or a paid proxy from completing it for them?
A username and password answers none of these. Credentials get shared constantly — written on sticky notes, saved in browsers, handed to the new hire along with the uniform. A completion record proves an account finished a course. It says nothing about who was behind the account.
This Is Not a Hypothetical
Enforcement has already moved past the certificate. In the Valor case in New York, prosecutors alleged a safety school issued thousands of OSHA certifications to construction workers who never received the training — records that looked legitimate until someone asked the follow-up questions. In Australia and the UK, regulators have begun voiding credentials and fining the issuing organizations themselves, on the basis that the issuer could not demonstrate the training actually happened.
The pattern is consistent: when the record is challenged, the burden shifts to the organization that issued or relied on it. "Our system shows they completed it" is not a defense when the next question is "show me it was them." A training program that cannot answer that question is not defensible in court, in an audit, or in the court of public opinion after an incident.
Why the Standard Tech Stack Can't Answer
Most online training platforms were designed to deliver content and track completion. Their security model is the login screen. Their evidence model is the completion report. Neither was built to establish identity.
That gap is exactly what fraud exploits. AI has removed the barrier to entry on malpractice: what once required a willing colleague or a paid proxy now takes a generative tool that can sit through the material, answer questions, and pass the assessment in the enrolled user's name. Proxy completion services still operate, but they no longer set the floor for how easy fraud can be.
Regulators have moved past warnings. In enforcement actions across several jurisdictions, the question is no longer whether a certificate was issued, but whether the issuing organization can prove the named learner's identity and participation. Identity at enrollment and presence across the course are becoming baseline expectations, not premium features.
Detection-based proctoring tries to close this gap at the assessment. But checking identity once, at the final exam, leaves the entire course unverified — and leaves honest learners flagged by a system that watches for cheating instead of confirming presence.
What a Defensible Record Actually Contains
A record that survives scrutiny needs to answer the investigator's questions before they are asked. In practice, that means four things:
Identity verified at enrollment — the person who starts the course is confirmed to be the named learner, not just the account holder. Presence re-verified throughout — the same person is confirmed across the course and at the final assessment, not checked once and trusted forever. A documented participation trail — access history, session continuity, and any integrity events, recorded in a tamper-evident form. And guidance for honest learners — when something looks off, the system steers the learner back into compliance in the moment, rather than failing them after the fact.
This is the difference between defensible training records and a stack of certificates. One is evidence. The other is paperwork.
Verification Before the Knock
The organizations that come out of these inquiries well share one trait: they can produce the verified chain from learner to credential on demand. They do not reconstruct it after the incident, because it was built while the training happened.
That is what learner identity verification is for. Asgard Authenticate verifies the learner at enrollment, re-verifies them through the course and at the final assessment, and documents the whole chain — so that when the regulator, the auditor, or the court asks who actually did the training, the answer is already in the record. Not a login. Not a timestamp. A verified person.
The Path Forward
Nobody thinks their training records will be challenged until the day they are. By then, the only thing that matters is what the record can prove — and a username and password prove almost nothing. They never did.
AI has forced the issue. What used to require coordination, access, or expense can now be automated. Regulators are responding by asking for proof of identity and participation as standard evidence, not optional extras. Training organizations that cannot produce that proof are no longer getting the benefit of the doubt.
The question is worth asking now, while it is still a choice: if an investigator opened your training file tomorrow, could you show the named person actually did the work? If the honest answer is no, the certificate is not a defense. It is a liability waiting for a date.
Asgard Authenticate was built so the answer is yes. Verify the learner, not the login.
Authoritative Sources & Further Reading
- ABC News — Manhattan DA charges Valor Security— Indictment of a sham NYC safety school accused of issuing thousands of bogus OSHA certifications
- OSHA Training Requirements— Official OSHA guidelines for workplace safety training
- ANSI/ASSP Z490.1-2024 Standard— ASSP's official page for the Z490.1 OSH Training standard
Writing on training integrity, learner verification and compliance record-keeping for Asgard Authenticate.
Ready to Issue Credentials You Can Defend?
Join organizations worldwide that trust Asgard for online training credential integrity. Start your free trial today—no credit card required.
Start Free Trial