Skip to content
VeriV.

A result that cannot be quietly changed after it is issued

When an examination result is issued as a signed record, any later alteration becomes mathematically detectable — by the candidate, the employer, the auditor, or anyone else holding the record. We call this a Merit Passport.

The problem, stated plainly

In most examination systems, a result exists as a row in a database.

A row has no memory. It carries no evidence of what it said yesterday, who wrote it, or whether it has been touched since. If the value changes, the new value looks exactly as authoritative as the old one, because authority comes from the database itself rather than from anything inside the record.

That places the entire trust burden on whoever operates the database. Not because operators are assumed to be careless or dishonest — but because the architecture gives them no way to prove they were neither. An operator with good controls and an operator with none produce records that look identical to an outside observer.

The result is that confidence in an examination outcome rests on institutional assurance rather than on evidence anyone can independently check.

What a signed result record changes

A signed record binds three things together into one object: the result, the identity of the authorised signer, and the moment of signing.

The binding is a digital signature — ECDSA-P256, issued in the DigSig format defined by ISO/IEC 20248:2022. VeriV's implementation was built from co-research and testing with a co-author of that standard, ongoing since 2017, and its records are conformant with it and independently reviewed.

Illustrative sample
Record
SAMPLE-0000
Signer
named signer
Signed
YYYY-MM-DD · hh:mm
DigSig

VALID

Signature verifies · record unaltered

Three properties follow directly from the mechanism:

Alteration is detectable, not merely discouraged.

Change any character of a signed record — a mark, a grade, a candidate identifier — and the signature no longer matches the content. Verification fails. There is no version of the altered record that still verifies, because the signature cannot be recomputed without the signing key.

Detection does not depend on the issuer.

Verification is a mathematical check against the record and the signer's public key. Anyone holding the record can perform it, on any modern smartphone, with no app to install and no account to create. The check is read-only and runs serverless — the party verifying does not have to ask the party who issued the result whether the result is real.

Corrections leave a visible trail.

The ledger is append-only: nothing is overwritten. A legitimate amendment — a remark, a moderation adjustment, a corrected entry — is issued as a new signed record by a named signer. The earlier record remains. What was changed, by whom, and when, is part of the record chain rather than a matter of recollection.

The point is not that records become unchangeable. It is that changing them silently stops being possible.

Sealed chain of custody, where a physical stage exists

Examinations often have a physical leg: printed papers, sealed answer-scripts, transport between a centre and a marking site, storage before and after marking.

Where a physical seal matters, each package or batch can carry an NFC hardware anchor — an NXP NTAG 424 DNA chip. Each tap of the chip produces a fresh one-time code, so the tag cannot be usefully photographed, cloned or reprinted. Handovers are recorded against that anchor: who released the package, who received it, at what time, each recorded as a signed record.

This is optional. Pure-digital signed result records work with no hardware at all. The hardware anchor exists for organisations that need the paper trail and the digital trail to be the same trail.

Who signs what

Every record in the chain is signed by a named, authorised human signer at a defined gate — invigilation, collection, marking, moderation, result issue. There is no anonymous system action and no automatic approval.

AI is used only in an assistive capacity, such as flagging statistical variances for a human to examine. It signs nothing, and it approves nothing.

Records also carry a formal dispute path. A record can be disputed within a formally defined window, with an arbitration route defined at the outset. Disputes are part of the architecture rather than an exception to it — an integrity system that cannot accommodate a challenge is not an integrity system.

What this is not

This is worth stating precisely.

  • It is not surveillance. Nothing here monitors candidates, staff or behaviour. It signs records, not people.
  • It is not accusation tooling. It produces no allegations, no risk scores about individuals, and no judgements. It establishes whether a record still matches what was signed. What that means is a matter for the institution and its processes.
  • It is not a replacement for examination governance. Rules, invigilation and appeals remain exactly where they are. This changes the evidentiary properties of the record they produce.
  • It is not retrospective. Signed records prove things about results issued under signature. They say nothing about records created before.

What it is: an integrity architecture. It moves trust from the operator of the database to the mathematics of the record, so that institutions acting properly can demonstrate it, rather than simply assert it.

Maturity

The underlying record architecture runs end to end today on VeriV's live industrial platform at veriv.io, at TRL 6–7 — demonstrated in a relevant operating environment. Examination applications are at the pilot and research stage, and we describe them that way deliberately.

Start a pilot conversation

We are looking for examination bodies, institutions and research partners who want to test what signed result records do to the integrity properties of an examination pipeline. The first conversation is technical, exploratory, and carries no obligation.

Enquire about a pilot