Exam security investigations often involve painstaking and detailed work to uncover evidence of misconduct. But once all the questions have been answered, how do we classify the evidence? Is it clear and convincing, letting us know for certain what happened, or does it merely suggest wrongdoing? Once that’s established, how will we use the evidence? To revoke scores? To ban a candidate for future exams? And finally, do we have enough to refer the investigation to outside organizations like law enforcement or a regulatory agency? In this session we’ll look at practical ways to classify evidence from exam security investigations so you can make the most efficient and effective use of this valuable data. Using real-life case examples and borrowing closely from criminal and civil legal definitions, we’ll share a clear, repeatable framework you can apply to help make your program safer, and your adjudication process fairer and more defensible.