Online school & tutoring centre operations

How to Create an Assessment Policy for an Online School: A Practical Governance Checklist

A strong online-school assessment policy makes decisions more consistent, feedback more usable, and learner evidence easier to govern. Use this practical framework and editable checklist to define assessment purposes, roles, integrity processes, access controls, retention, and review.

An academic manager reviews an online-school assessment checklist on a laptop beside visual symbols for learner work, feedback, secure access, and a review calendar.

An assessment policy is the operating agreement behind your online school’s assessment practice. It explains what assessment is for, who makes which decisions, what evidence is kept, how learners receive feedback, and what happens when a result is questioned. It is not a promise that every learner will achieve a particular grade, qualification, or outcome.

This matters especially in an online setting, where assessment activity can create a distributed trail of submissions, recordings, rubric scores, feedback comments, identity checks, platform logs, and communications. The Department for Education’s privacy notice for school attendance data collection, published on 28 August 2026, is specific to its own attendance-collection context. Still, its clear structure—what is collected, why it is used, who receives it, and how long it is kept—is a useful governance prompt for any online-school operator.

Use the framework below as a practical policy template. Adapt it to your school’s jurisdiction, learner age range, contractual commitments, and any requirements that apply to regulated qualifications or external awarding bodies.

What an online-school assessment policy should govern

Your policy should turn good teaching intentions into repeatable decisions. It should govern the school’s internal approach to assessment design, marking, feedback, review, records, and learner communication. It should also make boundaries visible: which decisions belong to teachers, academic managers, moderators, data leads, platform administrators, and external partners.

A useful policy normally covers:

  • the purposes of assessment and the decisions each type may inform;
  • assessment design, marking, moderation, and consistency checks;
  • the evidence collected to support decisions;
  • feedback, reassessment, adjustments, complaints, and appeals routes;
  • academic integrity, including declared use of AI-assisted work;
  • access to learner records, retention, deletion, and review; and
  • how the policy is approved, communicated, monitored, and updated.

Keep the policy distinct from course-level assessment briefs, marking rubrics, learner handbooks, privacy notices, and technical procedures. Those documents should align with the policy, but they can change more often and contain more operational detail.

1. Define assessment purposes before choosing tools

Start with the decision an assessment is intended to support. This prevents a common online-school failure: collecting extensive learner activity data without deciding whether it is actually needed to improve teaching, report progress, or make a progression decision.

Assessment purposeTypical questionAppropriate evidencePolicy control
DiagnosticWhere should teaching begin?Entry task, interview, baseline quizState whether results are low stakes and how they affect placement.
FormativeWhat should the learner do next?Drafts, practice tasks, teacher observations, short checksSet feedback expectations and clarify whether marks contribute to a final result.
SummativeHas the learner met stated outcomes?Project, test, portfolio, presentation, practical demonstrationDefine marking criteria, review procedures, and rules for late or missed work.
Certification or progressionWhat formal decision is being made?Verified assessment record and decision rationaleIdentify the authorised decision-maker and applicable external requirements.

For each assessment type, state the learning outcomes, method, timing, weighting where relevant, evidence standard, feedback approach, and decision owner. Do not describe a quiz, platform metric, or automated score as proof of learning unless your academic team has determined that it is suitable evidence for the intended decision.

2. Set roles, decision rights, and consistency procedures

Consistency does not require every teacher to teach identically. It requires the school to make comparable assessment decisions from comparable evidence. Define who can create assessments, who marks them, who conducts a second review, and who can alter a recorded result.

For higher-stakes internal decisions, use proportionate checks such as rubric calibration, sampled moderation, second marking, or a review of borderline cases. The aim is to identify unclear criteria, uneven interpretation, or avoidable process errors—not to remove teacher judgement. Where your school delivers regulated qualifications, check the current rules of the relevant awarding organisation and regulator; Ofqual’s handbook, for example, includes conditions on setting and delivering assessments, marking, and appeals for qualifications within its scope.

Maintain an assessment decision log for material decisions. A concise record protects both learners and staff because it shows what evidence was considered, who decided, when the decision was made, and whether a review occurred.

Editable assessment decision log

FieldRecord
Learner and assessmentName or learner ID; course; assessment title; attempt number
Decision requiredMark, progression, reassessment, adjustment, integrity finding, or appeal outcome
Evidence consideredSubmission, rubric, feedback history, meeting notes, verification record, or other relevant material
Decision and rationaleOutcome, criterion references, and concise reason
Decision owner and reviewerNamed roles, decision date, review date, and any change made

3. Build a data-and-evidence inventory

Assessment governance and data governance should meet in one practical inventory. The Information Commissioner’s Office explains that data minimisation means holding personal data that is adequate, relevant, and limited to what is necessary for the purpose. Its guidance also says organisations should document retention periods and avoid keeping personal information longer than needed. Use those principles to challenge every field, recording, and platform report you retain.

Editable data-and-evidence inventory

Evidence or data itemPurposeAuthorised accessStorage locationRetention triggerReview question
Submitted learner workMarking and feedbackTeacher, moderator, academic managerApproved learning platformCourse end or appeal windowIs the full file needed after the decision?
Rubric and marksDecision evidence and progress reportingTeaching and authorised academic staffAssessment recordDefined academic-record periodIs each field necessary and accurate?
Video or oral assessment recordingVerification or review where justifiedRestricted reviewers onlyApproved secure storageShort, documented review periodCan notes or a verified record meet the purpose instead?
AI-use declarationAcademic integrity reviewTeacher and integrity reviewerAssessment recordLinked to integrity and appeal processDoes it record only what is needed for the decision?

Access should follow roles, not convenience. The ICO’s access-control guidance recommends assigning appropriate access rights to staff who process personal information. In practice, this means removing access when staff leave or change role, limiting administrator privileges, and reviewing access periodically.

Access-review checklist

  • List each assessment system, shared drive, spreadsheet, and inbox that contains learner evidence.
  • Assign an owner for each location and document which roles need access.
  • Check that former staff, temporary staff, and external collaborators no longer have unnecessary access.
  • Confirm that sensitive assessment evidence is not being copied into unapproved personal tools or accounts.
  • Record exceptions, approvals, and the date of the next review.

4. Make feedback, reassessment, adjustments, and appeals predictable

Learners need to know what feedback they can expect, when they can expect it, and what options exist if they cannot complete an assessment as planned. Set service standards that your staffing model can realistically meet, then communicate them in course materials.

Your workflow should distinguish four routes: ordinary feedback; reassessment or resubmission; an access or reasonable-adjustment request; and an appeal or complaint about process. Define the evidence required, the decision-maker, the target response period, the escalation path, and how outcomes are recorded. Education providers have duties relating to reasonable adjustments for disabled learners in relevant contexts; obtain appropriate local legal and specialist advice when translating this into your school’s policy.

Separate an appeal about a process error from a request for a different academic judgement. An appeal process should focus on documented grounds, an independent or appropriately separated review where feasible, a written outcome, and a record of any corrective action.

5. Address academic integrity and AI-assisted work through evidence, not detection claims

An online-school policy should explain what counts as permitted collaboration, permitted tools, attribution, and unauthorised assistance. If learners may use generative AI for brainstorming, language support, coding assistance, or feedback, specify the boundaries by assessment type and require a simple declaration where appropriate.

Avoid treating an automated indicator as conclusive proof of misconduct. Instead, use a fair, evidence-led process: identify the concern; preserve relevant assessment evidence; invite the learner to respond; consider context and any declared support; make a proportionate decision; and provide a review route. Use assessment design to reduce ambiguity, for example by combining drafts, reflective commentary, oral follow-up questions, version history where available, and task-specific evidence.

6. Review the policy when the operating context changes

Annual review is useful, but it should not be the only trigger. The ICO describes a data protection impact assessment as a process for identifying and minimising privacy risks, and says a DPIA is required for processing likely to create high risk to individuals. A new proctoring approach, biometric or identity-verification feature, AI-enabled marking workflow, major platform migration, or new learner-data sharing arrangement may require privacy and legal review before implementation.

Annual policy-review calendar

Timing or triggerReview actionAccountable role
Before each academic yearApprove policy version, retention schedule, learner-facing summaries, and staff training.Academic lead and data/privacy lead
Each term or teaching cycleSample marking consistency, turnaround times, reassessments, integrity cases, and appeals.Academic manager
After a course redesignCheck purposes, rubrics, evidence requirements, and learner instructions.Course owner
Before a platform or data-practice changeMap data flows, access, retention, supplier responsibilities, and risk review needs.Platform owner and data/privacy lead
After a significant incident or upheld appealDocument lessons, assign corrective actions, and communicate changes.Policy owner

Approval record and next step

Finish the policy with an approval record: policy owner, approver, version number, effective date, next review date, staff consultation completed, learner communication completed, and linked procedures. This turns the document from a static statement into a governable operating tool.

SubSchool can help online schools reduce repetitive teaching administration while keeping teachers responsible for authorship and final educational decisions. Use this checklist as the basis for a policy workshop, then explore how SubSchool for online schools may support your assessment workflow.


Practical governance checklist: Can every assessment be linked to a stated purpose? Are decision rights clear? Is the evidence proportionate? Can authorised staff find the rationale for a material result? Do learners understand feedback, reassessment, adjustment, and appeal routes? Are access and retention reviewed? Is the policy updated when courses, systems, or data practices change?

Sources and methodology

Prepared from the supplied editorial brief and current official UK Department for Education, Information Commissioner's Office, and Ofqual materials. The article uses the DfE attendance privacy notice as a governance prompt only; it does not treat that collection-specific notice as a universal rule for online schools. Recommendations are operational policy design practices, not legal advice, and the included template fields are intended for adaptation by the school’s authorised academic, privacy, and legal decision-makers.

  1. Privacy notice: school attendance data collection
  2. A guide to the data protection principles
  3. Retention
  4. Access control
  5. Data protection impact assessments
  6. Ofqual Handbook: General Conditions of Recognition
Put the idea to work

Related tool, workflow, and guide

Free toolAI lesson plan generator

Draft an objective, teaching sequence, practice, and exit check.

Product workflowAI course creator

Turn approved sources into editable course entities.

Guide hubPractical teaching guides

Use complete, reviewable workflows rather than isolated prompts.

Continue with the next teaching step

Use the relevant SubSchool workflow while keeping the result editable and source-grounded.

Open workflow →
SubSchool Editorial Team