The digital credentials TEQSA will accept are the ones that satisfy Standard 1.5 of the Threshold Standards: a qualification that meets the AQF, a testamur and record of results issued in line with the AQF Qualifications Issuance Policy, and a provider that can authenticate every document it has issued. The technology is not regulated. The integrity of the certification is, and blockchain does not change that requirement in either direction.
This article explains what the Standard actually asks for, what digital credential platforms and blockchain claims add to it, where fraud sits in the picture, and what I expect the regulator to require next. It draws on fifteen years of TEQSA registration work, during which certification has gone from a printing question to a systems question.
What does Standard 1.5 require of certification?
Standard 1.5 of the Higher Education Standards Framework (Threshold Standards) 2021 deals with qualifications and certification. Three things matter for digital credentials. The award must be at the AQF level it claims and carry the title the Australian Qualifications Framework permits. The testamur and record of results must be issued in accordance with the AQF Qualifications Issuance Policy, which governs what a certification document must contain and how it must be protected. And the provider must be able to verify, on request, that a document it appears to have issued is genuine.
TEQSA reads that last requirement in the present tense. An assessor asks how a provider would respond today if an employer sent through a scanned testamur and asked whether it was real. If the answer is a phone call to the registrar and a search of a spreadsheet, the standard is being met, but weakly. If the answer is a public verification page tied to the student record, it is being met well. Neither answer depends on the technology used to produce the document.
What digital credentials TEQSA sees in practice
In my experience most Australian providers now issue a digital testamur alongside or instead of paper, usually through a credentialling platform that stores a signed PDF or a badge and offers a verification link. That is a digital credential in the ordinary sense, and it satisfies Standard 1.5 provided the record of results matches, the issuance policy is followed, and the provider retains control of what is issued and revoked.
The mistake I see is a provider that adopts a platform and assumes the platform has solved compliance, which it has not. The academic board still approves the graduand list, the registrar still applies the issuance policy, and the provider still needs a register of what was conferred, when and to whom. If the platform contract ends, the provider must still be able to verify every credential issued through it. Assessors ask about that exit scenario more often than providers expect. The same discipline applies to the shorter awards discussed in our guide to micro-credentials, stackable learning and TEQSA.
Blockchain claims versus what blockchain actually does
Blockchain credentialling promises a tamper-evident record that anyone can verify without asking the issuer. That is a real property, and for cross-border verification it is useful. But the claim that a blockchain credential is therefore fraud-proof confuses two different problems. A ledger can prove that a record has not been altered since it was written. It cannot prove that the record was true when it was written, that the person presenting it is the person named in it, or that the issuer was entitled to confer the award.
Those three questions are where credential fraud actually lives, and they are answered by the provider's admission, identity, assessment and conferral processes, not by the ledger. TEQSA's interest is in those processes. A provider whose graduand approval is a formality, or whose identity verification for online students is thin, has a Standard 1.5 problem that no anchoring to a chain will fix. In fifteen years I have not seen an assessor ask which ledger a provider uses; I have seen many ask how the provider knows the graduand list is right.
Fraud, the National Register and verification
The National Register of Higher Education Providers is the public record of who may confer what, and it is the first place a careful employer or overseas authority looks. Fraud in Australian higher education takes two main forms: fake documents purporting to come from a real provider, and awards conferred in substance by someone other than the registered provider, usually through an unmanaged third-party arrangement under Standard 5.4. Digital credentials address the first. Only governance addresses the second.
Providers should also expect more scrutiny of shorter and newer qualification types, where the testamur format is less standardised and the temptation to improvise is greater. The undergraduate certificate, discussed in our article on the undergraduate certificate being permanently recognised in Australia, is one example. If a credential is an AQF qualification it must be certified as one; if it is not, the document must not imply that it is.
What I expect TEQSA to require next
I expect three developments. Verification will move from optional good practice to something assessors look for as evidence that Standard 1.5 is met in operation, because it is cheap and it directly addresses fraud. Interoperable credential formats will be adopted at sector level, driven by employers and the AQF rather than by the regulator. And third-party credentialling platforms will be examined as delivery partners under Standard 5.4, with the same questions about contracts, control and exit that apply to teaching partners.
None of that requires blockchain, and none of it is prevented by it. The digital credentials TEQSA will accept in five years will look much like the ones it accepts now, issued with more automation and verified more often. The provider that gets the underlying processes right will be ready for whatever format follows.
Download the Policy Suite Index
— a checklist of the policies a provider needs, including certification, issuance and verification, drawn from our TEQSA registration work with private providers. Get the index
Want the full article?
Enter your email for free access to the rest of this guide and our TEQSA resource library.
Frequently asked questions
Does TEQSA require digital credentials?
No. Standard 1.5 requires that qualifications are certified in accordance with the AQF Qualifications Issuance Policy and that the provider can authenticate what it has issued. Paper, PDF and platform-issued credentials can all meet that requirement if the underlying processes are sound.
Is a blockchain credential more compliant than a PDF testamur?
Not in itself. A ledger proves a record has not been altered; it does not prove the record was correct, that the holder is the graduate, or that the issuer was registered to confer the award. TEQSA assesses those processes, not the storage technology.
What must a testamur contain?
The AQF Qualifications Issuance Policy sets the required content, including the provider's name, the graduate's name, the qualification title as permitted by the AQF, the date of conferral and security features. The record of results must be consistent with the testamur.
Are credentialling platforms a third-party arrangement under Standard 5.4?
Increasingly they are read that way where the platform issues on the provider's behalf. The provider should hold a written agreement, retain control over issuance and revocation, and be able to verify every credential if the arrangement ends.
Dr Brendan Moloney is CEO of Darlo Higher Education, Australia's largest specialist TEQSA consultancy. He holds a PhD from the University of Melbourne, is a Cambridge University Press author on governance in higher education, and has advised private providers on registration and course accreditation for more than fifteen years.
