The Institutional Accountability Clause: What University Exam Offices Must Know
The 2026 Anti-Leak Amendment Bill extends liability to institutions and service providers, not just individuals. Here is what university Controllers of Examinations need to understand and do before it becomes law.

A Provision That Changes University Exam Risk
When the Public Examinations (Prevention of Unfair Means) Amendment Bill, 2026 was introduced in the Lok Sabha on July 27, most media attention focused on its headline penalties: ten years in prison and Rs 10 crore in fines for paper leak offenders. These numbers are significant. But for university examination administrators, the provision carrying the most immediate operational relevance is less discussed: the explicit institutional accountability clause.
This clause extends liability not only to individuals who commit examination fraud but to the institutions and service providers whose systems and processes enabled the fraud to occur. Understanding what this means in practice — and what steps reduce institutional exposure — is now a material responsibility for every Controller of Examinations, Registrar, and Vice Chancellor in India.
What the Clause Actually Says
The 2026 amendment introduces specific language making service providers and examination-conducting bodies directly accountable when a breach occurs through their systems. The exact liability thresholds will be clarified in implementing rules, but the framework represents a structural departure from the 2024 Act, which treated institutional responsibility implicitly at best.
Under the new framework, investigators can ask not only who committed the fraud but which institution or service provider created the conditions in which it was possible. The accountability is organisational, not merely individual.
For universities conducting their own examinations — particularly affiliating universities that run examination processes for thousands of students across dozens of colleges — this means examination management practices, vendor arrangements, and oversight protocols are no longer purely internal governance matters. They are potential evidence in a legal proceeding.
Which University Functions Fall Within Scope
The clause is worded broadly to cover service providers and examination-conducting bodies. Several functions that many universities currently outsource sit clearly within its likely scope.
Question paper printing and logistics. This is the highest-risk category. Any third party that handles question papers before the examination date has access to the most sensitive material in the exam cycle. If a leak traces to a printing press or courier vendor, the institution that hired them without applying adequate oversight may share liability for the breach.
Answer sheet scanning and digitisation. Vendors who scan physical answer sheets for on-screen evaluation access completed candidate work. While the fraud risk differs from question paper leaks, chain-of-custody failures — misplaced sheets, identity mismatches, unauthorised access — can become grounds for legal proceedings in which the institution's vendor management practices will be examined.
Evaluation platform hosting. Cloud providers and data centres that store examination data are third parties in the examination chain. Institutions need documented due diligence on these vendors' data security practices, particularly for the period between answer sheet receipt and result declaration.
Third-party on-screen marking systems. If your institution uses a vendor-provided digital evaluation platform, that vendor's security architecture and your contractual liability allocations matter under the new framework. Platforms without clear security certifications and contractual accountability clauses represent exposure.
What "Adequate Controls" Looks Like
Institutional liability under this kind of legislation is typically assessed against a standard of reasonable due diligence: did the institution take precautions proportionate to the risk? For examination management, this translates into four documented control categories.
Vendor selection and vetting. A formal vendor selection process with documented security criteria demonstrates that institutions applied judgment, not merely convenience, in choosing examination partners. Can you show that your question paper printing vendor was evaluated against physical security criteria at its facility? If not, document a process for doing so now.
Contractual risk allocation. Vendor contracts for examination services should include security obligations, data handling requirements, breach notification timelines, and explicit liability clauses. A vendor contract that does not address examination security is a gap that investigators will notice. Review all active contracts before the bill becomes law.
Ongoing monitoring and oversight. Documented verification of vendor compliance during the contract period — even informal visits, checklists, or correspondence confirming security arrangements — demonstrates active oversight rather than passive contracting. The absence of any such documentation is itself a risk indicator.
Incident response records. If a previous incident — a mismatched answer sheet, a missing bundle, an unauthorised access report — occurred and was escalated and investigated, those records should be preserved and accessible. Demonstrated responsiveness to prior issues is evidence of a functioning accountability system.
The 60-Day Investigation Mandate: A Practical Pressure
Alongside the institutional accountability clause, the 60-day mandatory investigation timeline creates a separate operational requirement. When a complaint is registered, investigators will need access to examination records — scan logs, evaluator assignment data, chain-of-custody documentation — quickly.
For paper-based examination records stored in physical archives across evaluation centres, retrieval within a 60-day window requires significant manual effort and coordination across multiple locations. For digital evaluation systems, the same records are searchable, exportable, and producible within hours.
This is not a marginal operational advantage. In an investigation, the ability to produce a complete digital audit trail — timestamped access logs, evaluator session records, result certification chains — is the difference between demonstrating due diligence and appearing unable to account for your own examination process.
A Compliance Checklist for Exam Offices
Before the bill passes and implementing rules are issued, examination offices should work through the following.
Vendor inventory. List every third party that currently has access to question papers, answer sheets, evaluation data, or result records. For each vendor, document what access they have, when they have it, and what contractual controls govern that access.
Contract audit. For each vendor on the list, review the current contract for security obligations, breach notification requirements, and liability clauses. Flag contracts that are silent on these points for revision.
Evidence preservation assessment. For a past examination, estimate how long it would take to produce a complete audit trail for one candidate's answer sheet — from receipt of physical script to result certification. If the answer is measured in weeks, that timeline is incompatible with effective compliance under the new law.
Process documentation. Map your current examination workflow in writing, including every handoff point, every access permission, and every oversight control. This document becomes your due diligence record if a proceeding occurs.
Digital transition planning. If your current workflow relies on paper-based answer sheet management and manual evaluation, begin scoping a transition to digital evaluation. The institutional accountability clause and the 60-day investigation mandate both create structural incentives for end-to-end digital examination management.
What the Bill Does Not Change
The institutional accountability clause does not mean that universities are liable for all examination fraud that occurs in India. It means that institutions are responsible for the examination processes they control and the vendors they hire.
Universities that maintain documented due diligence — rigorous vendor selection, security-conscious contracts, regular oversight, and digital evidence trails — have a substantive defence available under any institutional accountability framework. The clause is designed to reach negligent and reckless conduct, not to impose strict liability on examination bodies that took their responsibilities seriously.
The time to build that documentation is before an investigation begins.
Related Reading
Ready to digitize your evaluation process?
See how MAPLES OSM can transform exam evaluation at your institution.