How to Create an Assessment Policy for an Online School: A Practical Governance Checklist
A strong online-school assessment policy makes decisions more consistent, feedback more usable, and learner evidence easier to govern. Use this practical framework and editable checklist to define assessment purposes, roles, integrity processes, access controls, retention, and review.

An assessment policy is the operating agreement behind your online school’s assessment practice. It explains what assessment is for, who makes which decisions, what evidence is kept, how learners receive feedback, and what happens when a result is questioned. It is not a promise that every learner will achieve a particular grade, qualification, or outcome.
This matters especially in an online setting, where assessment activity can create a distributed trail of submissions, recordings, rubric scores, feedback comments, identity checks, platform logs, and communications. The Department for Education’s privacy notice for school attendance data collection, published on 28 August 2026, is specific to its own attendance-collection context. Still, its clear structure—what is collected, why it is used, who receives it, and how long it is kept—is a useful governance prompt for any online-school operator.
Use the framework below as a practical policy template. Adapt it to your school’s jurisdiction, learner age range, contractual commitments, and any requirements that apply to regulated qualifications or external awarding bodies.
What an online-school assessment policy should govern
Your policy should turn good teaching intentions into repeatable decisions. It should govern the school’s internal approach to assessment design, marking, feedback, review, records, and learner communication. It should also make boundaries visible: which decisions belong to teachers, academic managers, moderators, data leads, platform administrators, and external partners.
A useful policy normally covers:
- the purposes of assessment and the decisions each type may inform;
- assessment design, marking, moderation, and consistency checks;
- the evidence collected to support decisions;
- feedback, reassessment, adjustments, complaints, and appeals routes;
- academic integrity, including declared use of AI-assisted work;
- access to learner records, retention, deletion, and review; and
- how the policy is approved, communicated, monitored, and updated.
Keep the policy distinct from course-level assessment briefs, marking rubrics, learner handbooks, privacy notices, and technical procedures. Those documents should align with the policy, but they can change more often and contain more operational detail.
1. Define assessment purposes before choosing tools
Start with the decision an assessment is intended to support. This prevents a common online-school failure: collecting extensive learner activity data without deciding whether it is actually needed to improve teaching, report progress, or make a progression decision.
| Assessment purpose | Typical question | Appropriate evidence | Policy control |
|---|---|---|---|
| Diagnostic | Where should teaching begin? | Entry task, interview, baseline quiz | State whether results are low stakes and how they affect placement. |
| Formative | What should the learner do next? | Drafts, practice tasks, teacher observations, short checks | Set feedback expectations and clarify whether marks contribute to a final result. |
| Summative | Has the learner met stated outcomes? | Project, test, portfolio, presentation, practical demonstration | Define marking criteria, review procedures, and rules for late or missed work. |
| Certification or progression | What formal decision is being made? | Verified assessment record and decision rationale | Identify the authorised decision-maker and applicable external requirements. |
For each assessment type, state the learning outcomes, method, timing, weighting where relevant, evidence standard, feedback approach, and decision owner. Do not describe a quiz, platform metric, or automated score as proof of learning unless your academic team has determined that it is suitable evidence for the intended decision.
2. Set roles, decision rights, and consistency procedures
Consistency does not require every teacher to teach identically. It requires the school to make comparable assessment decisions from comparable evidence. Define who can create assessments, who marks them, who conducts a second review, and who can alter a recorded result.
For higher-stakes internal decisions, use proportionate checks such as rubric calibration, sampled moderation, second marking, or a review of borderline cases. The aim is to identify unclear criteria, uneven interpretation, or avoidable process errors—not to remove teacher judgement. Where your school delivers regulated qualifications, check the current rules of the relevant awarding organisation and regulator; Ofqual’s handbook, for example, includes conditions on setting and delivering assessments, marking, and appeals for qualifications within its scope.
Maintain an assessment decision log for material decisions. A concise record protects both learners and staff because it shows what evidence was considered, who decided, when the decision was made, and whether a review occurred.
Editable assessment decision log
| Field | Record |
|---|---|
| Learner and assessment | Name or learner ID; course; assessment title; attempt number |
| Decision required | Mark, progression, reassessment, adjustment, integrity finding, or appeal outcome |
| Evidence considered | Submission, rubric, feedback history, meeting notes, verification record, or other relevant material |
| Decision and rationale | Outcome, criterion references, and concise reason |
| Decision owner and reviewer | Named roles, decision date, review date, and any change made |
3. Build a data-and-evidence inventory
Assessment governance and data governance should meet in one practical inventory. The Information Commissioner’s Office explains that data minimisation means holding personal data that is adequate, relevant, and limited to what is necessary for the purpose. Its guidance also says organisations should document retention periods and avoid keeping personal information longer than needed. Use those principles to challenge every field, recording, and platform report you retain.
Editable data-and-evidence inventory
| Evidence or data item | Purpose | Authorised access | Storage location | Retention trigger | Review question |
|---|---|---|---|---|---|
| Submitted learner work | Marking and feedback | Teacher, moderator, academic manager | Approved learning platform | Course end or appeal window | Is the full file needed after the decision? |
| Rubric and marks | Decision evidence and progress reporting | Teaching and authorised academic staff | Assessment record | Defined academic-record period | Is each field necessary and accurate? |
| Video or oral assessment recording | Verification or review where justified | Restricted reviewers only | Approved secure storage | Short, documented review period | Can notes or a verified record meet the purpose instead? |
| AI-use declaration | Academic integrity review | Teacher and integrity reviewer | Assessment record | Linked to integrity and appeal process | Does it record only what is needed for the decision? |
Access should follow roles, not convenience. The ICO’s access-control guidance recommends assigning appropriate access rights to staff who process personal information. In practice, this means removing access when staff leave or change role, limiting administrator privileges, and reviewing access periodically.
Access-review checklist
- List each assessment system, shared drive, spreadsheet, and inbox that contains learner evidence.
- Assign an owner for each location and document which roles need access.
- Check that former staff, temporary staff, and external collaborators no longer have unnecessary access.
- Confirm that sensitive assessment evidence is not being copied into unapproved personal tools or accounts.
- Record exceptions, approvals, and the date of the next review.
4. Make feedback, reassessment, adjustments, and appeals predictable
Learners need to know what feedback they can expect, when they can expect it, and what options exist if they cannot complete an assessment as planned. Set service standards that your staffing model can realistically meet, then communicate them in course materials.
Your workflow should distinguish four routes: ordinary feedback; reassessment or resubmission; an access or reasonable-adjustment request; and an appeal or complaint about process. Define the evidence required, the decision-maker, the target response period, the escalation path, and how outcomes are recorded. Education providers have duties relating to reasonable adjustments for disabled learners in relevant contexts; obtain appropriate local legal and specialist advice when translating this into your school’s policy.
Separate an appeal about a process error from a request for a different academic judgement. An appeal process should focus on documented grounds, an independent or appropriately separated review where feasible, a written outcome, and a record of any corrective action.
5. Address academic integrity and AI-assisted work through evidence, not detection claims
An online-school policy should explain what counts as permitted collaboration, permitted tools, attribution, and unauthorised assistance. If learners may use generative AI for brainstorming, language support, coding assistance, or feedback, specify the boundaries by assessment type and require a simple declaration where appropriate.
Avoid treating an automated indicator as conclusive proof of misconduct. Instead, use a fair, evidence-led process: identify the concern; preserve relevant assessment evidence; invite the learner to respond; consider context and any declared support; make a proportionate decision; and provide a review route. Use assessment design to reduce ambiguity, for example by combining drafts, reflective commentary, oral follow-up questions, version history where available, and task-specific evidence.
6. Review the policy when the operating context changes
Annual review is useful, but it should not be the only trigger. The ICO describes a data protection impact assessment as a process for identifying and minimising privacy risks, and says a DPIA is required for processing likely to create high risk to individuals. A new proctoring approach, biometric or identity-verification feature, AI-enabled marking workflow, major platform migration, or new learner-data sharing arrangement may require privacy and legal review before implementation.
Annual policy-review calendar
| Timing or trigger | Review action | Accountable role |
|---|---|---|
| Before each academic year | Approve policy version, retention schedule, learner-facing summaries, and staff training. | Academic lead and data/privacy lead |
| Each term or teaching cycle | Sample marking consistency, turnaround times, reassessments, integrity cases, and appeals. | Academic manager |
| After a course redesign | Check purposes, rubrics, evidence requirements, and learner instructions. | Course owner |
| Before a platform or data-practice change | Map data flows, access, retention, supplier responsibilities, and risk review needs. | Platform owner and data/privacy lead |
| After a significant incident or upheld appeal | Document lessons, assign corrective actions, and communicate changes. | Policy owner |
Approval record and next step
Finish the policy with an approval record: policy owner, approver, version number, effective date, next review date, staff consultation completed, learner communication completed, and linked procedures. This turns the document from a static statement into a governable operating tool.
SubSchool can help online schools reduce repetitive teaching administration while keeping teachers responsible for authorship and final educational decisions. Use this checklist as the basis for a policy workshop, then explore how SubSchool for online schools may support your assessment workflow.
Practical governance checklist: Can every assessment be linked to a stated purpose? Are decision rights clear? Is the evidence proportionate? Can authorised staff find the rationale for a material result? Do learners understand feedback, reassessment, adjustment, and appeal routes? Are access and retention reviewed? Is the policy updated when courses, systems, or data practices change?
Sources and methodology
Prepared from the supplied editorial brief and current official UK Department for Education, Information Commissioner's Office, and Ofqual materials. The article uses the DfE attendance privacy notice as a governance prompt only; it does not treat that collection-specific notice as a universal rule for online schools. Recommendations are operational policy design practices, not legal advice, and the included template fields are intended for adaptation by the school’s authorised academic, privacy, and legal decision-makers.
Use the relevant SubSchool workflow while keeping the result editable and source-grounded.
