There is a question nobody in the online safety training chain wants to answer: who is responsible for making sure the worker named on the certificate actually took the course?
Ask an employer and they will point to the provider they paid. Ask the provider and they will explain that they are an agent of the employer — the employer holds the duty, the provider simply delivers content and issues the card. Ask an inspector and they will point at the certificate in the file, which is what the framework tells them to accept.
Every party in that chain is behaving reasonably. And at no point does anyone verify that a human being participated. That is the accountability gap, and it sits almost entirely on the one party with the technical ability to close it: the training provider.
Only One Party Can Actually Verify Anything
Strip the argument back to capability and the responsibility question answers itself.
An employer cannot verify participation. They do not control the course platform, cannot see session data, and have no way to establish who was at the keyboard during a module delivered by a third party. They can require training, pay for it, and file the certificate. That is the extent of their reach.
An inspector cannot verify participation either. They arrive after the fact and review documents. The certificate is the artifact the system produces, so the certificate is what gets reviewed.
The training provider is the only party present at the moment that matters. They control enrollment, delivery, assessment, and issuance. They are the only party who can confirm that the named learner was the person who did the work — and the only party in a position to record that proof at the time it is created. Capability and responsibility are not separable here.
"We're Just the Employer's Agent" Doesn't Survive Scrutiny
The prevailing view among providers is that they are suppliers acting on instruction. The employer carries the regulatory duty; the provider's obligation ends at delivering content and issuing a credential. Under that view, investing in learner authentication is a cost with no corresponding liability, so the status quo is the rational business choice.
The problem is that the provider is not selling content. They are selling an assertion. A certificate is a statement — issued by the provider, in the provider's name, on the provider's authority — that a named individual completed a defined program of instruction. No supplier in any other industry gets to issue a conformity statement and then disclaim responsibility for whether the statement is true.
And the employer is not in a position to check the provider's work. They asked for proof of training and received a document. If that document can be produced without a human present, the provider has not supplied training. They have supplied paperwork, priced as training.
AI Removed the Last Excuse
For years the gap was theoretical enough to ignore. Bypassing a course required technical skill, patience, or a willing accomplice. The friction did the work that controls should have been doing.
That friction is gone. AI has done two things to online safety training. It has democratized old technical bypasses — console tricks and completion-code manipulation that once required a developer now circulate as copy-paste instructions. And it has created something genuinely new: AI agents that can log in, move through content, answer knowledge checks, and produce a credential with no human involvement at all.
The protections built into most safety courses were designed against a different threat. Timers that enforce a minimum seat time, activity prompts that ask whether you are still there, and voice verification — a voice enrolled at registration, expected to answer random call-ins during the course — all assume a human is present and merely distracted. None of them establish identity. A phone line is not a person. The number answers, not the learner, and a recording, a second person, or a synthetic voice satisfies it just as easily; the actual learner can go golfing for the afternoon and still return a credential. Seat-time enforcement is no stronger — it proves the page stayed open, not that anyone was there. Against an agent designed to look like an attentive learner, these controls confirm exactly the wrong thing.
This applies far beyond any single card program. The same architecture underpins OSHA-regulated online safety training across the board: confined space entry, HAZWOPER, fall protection, hazardous materials handling, radiation safety. One weakness, replicated across an industry.
The Standard Already Assigns the Duty
The most useful fact in this debate is that it has already been settled in writing.
ANSI/ASSP Z490.1-2024, Criteria for Accepted Practices in Safety, Health, and Environmental Training, addresses this directly. Section 4.4.2 requires that training providers verify the learner's identity, confirm their participation, and ensure that the verified learner — not a bot, not a proxy — completes the assessment. The obligation is placed on the provider, by name, in the consensus standard that governs how safety training is supposed to be delivered.
This is not an obscure document, and it is not foreign to enforcement. OSHA Publication 2254, Training Requirements in OSHA Standards, lists the Z490.1 standard in its appendix as a reference for accepted training practices. OSHA citations have quoted earlier editions of Z490.1 in connection with training documentation and record keeping. The standard has been treated as the benchmark for what good safety training looks like for over two decades.
What has not happened is anyone stating plainly that Section 4.4.2 applies with equal force to online delivery. That absence is not a gap in the rules. It is a gap in communication — and providers have been reading the silence as permission.
What a Provider Should Be Able to Show
If a provider wants to defend the certificates it issues, four things need to be true of every record in its system.
Identity established at enrollment, against something stronger than a self-declared email address. Presence re-confirmed across the course — not a single check at the final assessment, which leaves every preceding hour unverified and is trivially satisfied by a proxy who sits the whole thing. A participation trail that is tamper-evident, recording access history, session continuity, and any integrity events, so the record can be examined rather than merely asserted. And in-the-moment guidance rather than retrospective failure, so an honest learner who steps away from their desk is steered back into compliance instead of flagged, failed, and appealing three weeks later.
None of that is exotic, and none of it requires rebuilding a course catalogue. It requires accepting that the provider is the party responsible for the truth of the credential it issues.
The Market Will Be Realigned One Way or Another
The comfortable assumption among providers is that nothing forces a change. An employer is not going to audit a course platform, and an inspector is going to accept a certificate that looks correct.
That assumption has a short shelf life. Enforcement bodies in several jurisdictions have already begun voiding credentials and penalising the organizations that issued them, on the basis that the issuer could not demonstrate the training happened. Prosecutions over fraudulent safety cards have made the harm concrete rather than hypothetical. And a single clarification — that identity and participation verification applies to online delivery exactly as it applies in a classroom — would realign the entire market overnight, without a line of new regulation.
When that clarification arrives, the providers who invested early will have defensible records and a clear commercial advantage. The providers who waited will have a back catalogue of certificates they cannot stand behind, issued to workers whose employers relied on them.
The Path Forward
The accountability gap in online safety training is not caused by bad actors. It is caused by a chain in which every participant reasonably believes verification is somebody else's job. Employers cannot verify. Inspectors cannot verify. Providers can — and have decided they are not obliged to.
The standard disagrees. Z490.1-2024 puts identity verification, participation confirmation, and verified assessment on the training provider, and OSHA has recognised that standard as the benchmark for accepted practice for years. What changed is that AI removed the friction that made the gap survivable, and a credential issued without human participation is now trivially obtainable across OSHA-regulated online safety training.
Providers have a choice about how they arrive at the other side of this. They can build verification into what they deliver now, on their own timeline, and sell a credential that means something. Or they can wait for the clarification, the citation, or the incident that makes it somebody's job to check.
Asgard Authenticate exists for the first option: verify the learner, not the login, and issue a record that holds.
Authoritative Sources & Further Reading
- ANSI/ASSP Z490.1-2024 Standard— ASSP's official page for the Z490.1 criteria for accepted practices in safety, health and environmental training
- OSHA Publication 2254 — Training Requirements in OSHA Standards— OSHA's training requirements publication, which lists ANSI/ASSE Z490.1 in Appendix B as a reference for accepted training practices
- OSHA Training Requirements— Official OSHA guidance on workplace safety training obligations
Writing on training integrity, learner verification and compliance record-keeping for Asgard Authenticate.
Ready to Issue Credentials You Can Defend?
Join organizations worldwide that trust Asgard for online training credential integrity. Start your free trial today—no credit card required.
Start Free Trial