Terms of Reference for Investigation & Demands for Disclosure

Published: 30 May 2026  |  Cashless Consumer  |  Main Article

Purpose

This document proposes a formal framework for investigating the CBSE On-Screen Marking (OSM) controversy. It is grounded in India's Right to Information Act, 2005; the Information Technology Act, 2000; the Digital Personal Data Protection Act, 2023; and internationally recognised principles of democratic oversight of digital public infrastructure.

It is not a legal document. It is a citizen's framework — one that any journalist, parliamentarian, student, parent, or civil-society body may adopt, adapt, and file.

I. Background & Scope

1.1 What happened

In February–March 2026, the Central Board of Secondary Education (CBSE) conducted Class 12 board examinations for 17,80,365 registered students. Answer sheets were graded on an On-Screen Marking platform operated by Coempt EduTeck Pvt. Ltd., a Hyderabad-based company, at cbse.onmark.co.in.

Independent security researchers disclosed critical vulnerabilities in the platform, including authentication bypass, client-side OTP validation, and unauthorised access to evaluation interfaces. OSINT analysis revealed that the vendor's own employees had published internal QA automation code on public GitHub repositories, and that the same OnMark platform serves at least 30 state boards and universities on identical infrastructure.

1.2 Why a formal investigation is warranted

  1. Scale of impact: 17.8 lakh students' exam results depend on the integrity of a single vendor's platform.
  2. Multi-board reuse: The same platform is used by state boards across India — a vulnerability or misconfiguration in one instance potentially compromises all.
  3. Procurement irregularities: Evidence suggests CBSE amended tender criteria to favour Coempt EduTeck, removing blacklist and cooling-off period requirements before awarding the contract.
  4. Vendor track record: Coempt's 2019 Telangana university evaluation contract was cancelled after grading complaints, and the company was blacklisted by the Telangana government before being cleared by courts.
  5. Data sovereignty: Answer sheets of minor students — containing personally identifiable handwritten data — are processed on a private vendor's cloud infrastructure with no publicly disclosed data-residency or data-protection audit.
  6. Leaked internal code: The vendor's own QA automation code, containing page-object models matching the live portal's DOM structure, was published on GitHub by Coempt employees — indicating poor internal security culture.

1.3 Scope of this document

This framework covers four domains:

  1. Procurement & due diligence — Was the contract awarded lawfully? Was the vendor properly vetted?
  2. Technical & security audit — Is the platform secure? Was it tested before deployment?
  3. Data protection & privacy — How are student answer sheets stored, processed, and protected?
  4. Democratic accountability & transparency — What must the government disclose, and under what legal authority?

II. Investigation Terms of Reference

2.1 Procurement & Due Diligence

#QuestionDocument / Evidence Sought
1What was the original tender specification for the OSM contract? What were the technical qualification criteria?Original tender document (2025_MHRD_858645_1), corrigenda, and all amendments
2When and why were the blacklist and cooling-off period clauses removed from the tender?Corrigendum or amendment document, internal noting file, decision-making chain
3Who approved the removal of these clauses? Was the approval documented?File notings, approval chain, minutes of relevant committee meetings
4How many bids were received? What were the technical scores of each bidder?Bid evaluation committee report, technical scoring sheets
5Was Coempt EduTeck — or its predecessor entity Globarena Technologies — declared ineligible by any government body at the time of bidding?Blacklist/greylist records from GeM, State procurement portals, Telangana government
6What due diligence was performed on Coempt's past performance, including the 2019 Telangana cancellation?Due diligence report, vendor assessment questionnaire
7What is the financial relationship between Coempt EduTeck and Globarena Technologies? Are they the same legal entity under different names?Corporate filings (MCA-21), Tofler/Zaubacorp company profiles, shareholding patterns
8What is the total contract value? What are the payment milestones?Contract document, purchase order, payment records
9Were any intermediaries, consultants, or agents involved in the procurement process?Declaration of interest forms, consultant agreements

2.2 Technical & Security Audit

#QuestionDocument / Evidence Sought
10Was a security audit conducted on the OSM platform before deployment? By whom?Audit report, auditor credentials (CERT-In empanelled?), audit scope and methodology
11Were the vulnerabilities disclosed by Nisarga Adhikary known to CBSE or Coempt before public disclosure?Internal vulnerability management records, CERT-In reporting correspondence
12What was the timeline of platform changes between mock evaluation (24 February) and live evaluation?Deployment logs, change management records, release notes
13Is the platform's source code subject to any security review by CBSE, NIC, or CERT-In?Source code escrow agreement, code review reports
14What authentication mechanisms protect evaluator access? Is multi-factor authentication enforced?Architecture documentation, security configuration records
15Are evaluator credentials shared, reused, or rotated? How are compromised credentials handled?Credential management policy, incident response procedures
16Is there rate-limiting, anomaly detection, or intrusion monitoring on the OSM portal?Security operations documentation, WAF/IDS configuration
17What infrastructure does the platform run on? Cloud provider, geographic location of servers, data residency?Infrastructure architecture document, SLA with cloud provider
18Was the platform penetration-tested by an independent third party? What were the findings?Pentest report (redacted if necessary), remediation tracker

2.3 Data Protection & Privacy

#QuestionDocument / Evidence Sought
19What categories of personal data are collected and processed by the OSM platform?Data flow diagram, data inventory register
20Answer sheets contain handwritten names, roll numbers, school names, and photographs. Are these classified as personally identifiable data under the DPDPA, 2023?Data classification policy, DPIA (Data Protection Impact Assessment)
21Where is the data stored? Is it stored within India? Is it encrypted at rest and in transit?Infrastructure documentation, encryption policy, data residency certification
22Who has access to the raw answer sheet images? Are access logs maintained?Access control matrix, audit logs (last 12 months)
23How long are answer sheet images retained after results are declared? What is the deletion policy?Data retention policy, deletion certificates
24Were students and parents informed about the use of a private vendor's platform for processing their examination data?Privacy notice, consent mechanism (if any)
25Is there a data breach notification procedure? Has any breach been reported?Incident response plan, breach notification records
26Does the contract include provisions for CBSE/NIC to audit the vendor's data practices?Contract clauses on audit rights, data access, breach notification

2.4 Democratic Accountability & Transparency

#QuestionDocument / Evidence Sought
27What is CBSE's policy on engaging private vendors for mission-critical examination infrastructure?Vendor engagement policy, risk assessment framework
28Was the Ministry of Education consulted or informed about the security disclosures?Ministry correspondence, inter-ministerial notes
29Did CBSE report the vulnerabilities to CERT-In as required under the IT Act?CERT-In reporting records, acknowledgement from CERT-In
30Is there a Business Continuity / Disaster Recovery plan for the OSM platform? Was it tested?BCP/DR documentation, test results
31What is the exit strategy if the vendor relationship is terminated? Can CBSE migrate to an alternative platform?Exit clause in contract, data migration plan, source code escrow
32Are other boards using the same OnMark platform aware of the security disclosures?Communication records with state boards
33What oversight mechanisms exist for ongoing platform security — during and between examination cycles?Governance framework, security review schedule

III. Demands for Disclosure

Demand 1: Full procurement disclosure

Under the RTI Act, 2005 (Section 4(1)(b)), CBSE must proactively disclose all tender documents, bid evaluations, and contract award decisions. We demand:

Demand 2: Independent security audit

Under Section 70B of the IT Act, 2000, CERT-In is designated as the national nodal agency for cyber security. We demand:

Demand 3: Data protection compliance disclosure

Under the DPDPA, 2023, and pending Data Protection Board rules, we demand:

Demand 4: Multi-board notification

Given that the OnMark platform serves at least 30 state boards and universities, we demand:

Demand 5: Vendor accountability

Coempt EduTeck's internal QA code was published on public GitHub repositories, containing page-object models matching the live evaluation portal. This indicates a failure of internal information security practices. We demand:

Demand 6: Parliamentary oversight

Examination integrity is a fundamental public interest. We demand:

IV. Legal Basis for Disclosure Demands

V. International Standards for Reference

While this investigation is specific to India, the following international frameworks provide useful benchmarks:

FrameworkRelevance
OECD Principles on AI (2024 update)Transparency, accountability, and security requirements for AI systems deployed in public services — including automated grading
ISO 27001International standard for information security management systems — relevant for evaluating Coempt's security posture
ISO 27701Extension to ISO 27001 for privacy information management — directly applicable to processing of student examination data
GDPR (EU)While not binding in India, GDPR's requirements for DPIA, data protection by design, and breach notification provide useful comparative standards
UN Guiding Principles on Business and Human RightsEstablishes the responsibility of business enterprises (including Coempt) to respect human rights, including the right to privacy

VI. How to File RTI Applications

Below are suggested RTI queries that citizens can file. Each query should be filed with the relevant Central Public Information Officer (CPIO) of CBSE. Queries may be adapted for state boards using the OnMark platform.

Note: RTI applications can be filed online at rtionline.gov.in for a fee of &rupee;10. The CPIO is required to respond within 30 days (Section 7(1)). Appeals lie with the First Appellate Authority and subsequently the Central Information Commission.

6.1 Suggested RTI Queries — Procurement

  1. "Please provide the complete tender document, including all corrigenda and amendments, for the On-Screen Marking (OSM) system contract awarded to Coempt EduTeck Pvt. Ltd. for CBSE Class 12 evaluation, 2026."
  2. "Please provide the bid evaluation committee's report, including technical scoring for each bidder, for the above tender."
  3. "Please provide the file notings documenting the removal of the blacklist/cooling-off period clause from the OSM tender specifications."
  4. "Please provide the due diligence report prepared by CBSE on Coempt EduTeck Pvt. Ltd. prior to contract award."

6.2 Suggested RTI Queries — Security

  1. "Please provide all security audit reports conducted on the OSM platform (cbse.onmark.co.in) prior to and during the 2026 evaluation cycle."
  2. "Please provide the timeline of platform changes (deployments, patches, configuration changes) between the mock evaluation on 24 February 2026 and the start of live evaluation."
  3. "Please provide the complete list of vulnerabilities reported to CBSE or CERT-In regarding the OSM platform, along with remediation status."
  4. "Please provide the disaster recovery / business continuity plan for the OSM platform."

6.3 Suggested RTI Queries — Data Protection

  1. "Please provide the Data Protection Impact Assessment (DPIA) for the OSM platform, covering the processing of student answer sheet data."
  2. "Please provide the data retention and deletion policy for answer sheet images processed on the OSM platform."
  3. "Please provide the privacy notice provided to students and parents regarding the processing of their examination data on the OSM platform."
  4. "Please provide the data breach notification records, if any, for the OSM platform since deployment."

VII. For Journalists & Researchers

This investigation is open-source. All evidence is archived and published:

GitHub repositories referenced in this investigation (all public as of 30 May 2026; archived locally with full git history):

Cite this document as: Cashless Consumer, "Terms of Reference for Investigation: CBSE On-Screen Marking Controversy," 30 May 2026.

Disclaimer: This document is published for public interest and journalistic purposes. It does not constitute legal advice. The suggested RTI queries are templates and should be adapted by the filer. The authors have not accessed any live evaluation system; all findings are based on passive OSINT from public sources.