How assessment works 12 min read

Portfolio assessment explained: what "no exams" actually means for an adult learner

Portfolio assessment explained: what "no exams" actually means for an adult learner
Share this article

If you have ever looked at an online qualification and felt a flicker of doubt when you saw the words "no exams," you are not alone. For many working adults, the exam hall is the only marking system they have ever known. You sit, you write, someone marks it, you pass or fail. Clean and legible, if not always fair. A portfolio sounds, to the uninitiated, like a scrapbook. Something subjective. Something that could go any way depending on who reads it on what day.

That instinct is worth taking seriously, which is why this article explains exactly how portfolio-based, internally assessed qualifications work in regulated UK education, what quality checks sit behind them, and what you as a learner are actually expected to produce. By the end, you will be able to judge for yourself whether this mode of assessment suits the way you learn and the evidence of competence that your employer actually needs to see.

Why the question matters for adult learners in particular

Most of the people who study with The Data and AI School of London are already working. They are not eighteen and sitting in a classroom. They are managing teams, running systems, supporting infrastructure, or trying to move from an administrative role into a technical one. An exam sat at a fixed time in a fixed place is, practically speaking, out of reach for a significant proportion of that group.

Portfolio assessment was not invented as a soft alternative to make things easier. It was developed because certain skills, particularly technical and vocational skills, cannot be meaningfully demonstrated in a two-hour written paper. Whether you can configure a network, write a functioning Python script, or prepare a data set for analysis is best shown by actually doing those things and producing documented evidence of having done them. That is the logic behind the assessment model used by NCFE, the awarding organisation whose qualifications we deliver.

For a broader grounding in why regulated credentials carry weight that unrecognised certificates do not, our article on Ofqual recognition versus unrecognised certificates in the UK is a useful starting point before you commit to any programme.

What "internally assessed" actually means

When a qualification is described as internally assessed, it means the marking and judgement of your work is carried out by a qualified assessor working within the approved centre, which in our case is The Data and AI School of London, NCFE-approved centre number 11001657. The assessment does not go to the awarding organisation to be marked. Instead, NCFE sets the assessment criteria and the standard, and the centre applies that standard to your submitted evidence.

This is a well-established and tightly regulated approach. It is used across the Regulated Qualifications Framework from Level 2 through to higher technical qualifications at Level 4 and Level 5. It is not unique to digital or data subjects. It is how practical competence in construction, health and social care, engineering, and many other fields has been assessed for decades.

The phrase "no exams" is shorthand for "no timed, unseen, written examination." It does not mean no rigour, no deadlines, and no consequences for submitting work that does not meet the standard.

The role of the assessor

Your assessor is a subject-qualified professional appointed by the centre. Their role is to review the evidence you submit for each unit, make a judgement against the assessment criteria set by NCFE, and record that judgement with a written rationale. If the evidence does not meet the criteria, the assessor will tell you specifically what is missing or insufficient and give you the opportunity to resubmit within the terms of the assessment plan.

Assessors are not making free-form personal judgements. They are working against published assessment criteria that are set out in the qualification specification. Those criteria define what a learner must demonstrate to achieve each learning outcome. For a qualification such as the NCFE Level 3 Certificate in Cyber Security Practices (603/7204/0), for example, the criteria for a unit on network security will specify the depth of technical understanding that must be evidenced. Opinion does not enter into it. Evidence either meets the stated criteria or it does not.

What internal quality assurance looks like

Internal quality assurance, commonly abbreviated to IQA, is the process by which the centre monitors whether its assessors are applying the standard consistently and correctly. An Internal Quality Assurer, a separate person from your assessor, samples assessed work across cohorts and across assessors. They check that the judgements made are accurate, that the rationale recorded is sufficient, and that all documentation is in order.

If an IQA review identifies that a judgement was incorrect, the work is returned for correction before the learner's achievement is claimed with the awarding organisation. This is a routine part of quality management, not a crisis. It is the mechanism that keeps the standard stable across different assessors and different cohorts over time.

What external quality assurance adds to the picture

External quality assurance, EQA, is conducted by NCFE as the awarding organisation. NCFE appoints an External Quality Assurer who visits or connects with approved centres on a scheduled and risk-based basis. The EQA reviews the centre's IQA processes, samples assessed work directly, checks that assessment criteria are being interpreted correctly, and verifies that the centre's systems meet NCFE's requirements for centre approval.

If the EQA finds a systemic problem with how a centre is assessing, they have the authority to restrict or suspend the centre's approval to claim achievements until the issue is resolved. This is the external check that sits above everything the centre does internally. It is why the words "NCFE-approved centre" carry meaning that a PDF certificate from an unregulated provider does not.

NCFE is itself regulated by Ofqual, the Office of Qualifications and Examinations Regulation. Ofqual sets the General Conditions of Recognition that all awarding organisations must meet, and it monitors compliance. The qualifications we deliver are listed on the Ofqual register of regulated qualifications, which is a public, searchable database. Any employer can look up a qualification number and confirm its regulated status in under a minute.

What you actually submit as a learner

This is the question most people want answered and rarely find a straight answer to. The honest answer is that it depends on the qualification and the unit, but the following are the most common types of evidence you will be asked to produce across our programmes.

  • Written assignments and reports: structured responses to set briefs that require you to explain, analyse, or evaluate something within the subject area. These are not essays in the academic sense. They are practical documents demonstrating that you understand concepts and can apply them.
  • Practical tasks and projects: for coding and data units in particular, you may be asked to produce a working script, a completed data model, or a documented process. The output itself is evidence, and your commentary on what you did and why forms the rest of it.
  • Case study responses: you are given a scenario and asked to respond as a professional would. This tests applied knowledge rather than recall.
  • Reflective accounts: a structured reflection on a task you have carried out, explaining what you did, the decisions you made, and what you would do differently. These are common in units that assess professional behaviours.
  • Professional discussion records: in some qualifications, a structured conversation with your assessor, recorded and documented, can serve as evidence for certain criteria. This is particularly useful where a written account would not capture the depth of understanding you hold.

Your portfolio is the collected body of this evidence, organised against the qualification's unit structure, with your assessor's judgements and rationale recorded alongside it. It is a documented case that you meet the standard. It is not a folder of things you are proud of.

How is a Level 3 assessed differently from a Level 2?

The level of a qualification signals the complexity and depth of understanding required. At Level 2, you are expected to demonstrate knowledge and the ability to apply it in familiar contexts with some guidance. At Level 3, you are expected to demonstrate a broader and deeper range of skills, the ability to apply them in varied contexts, and some capacity for independent judgement. The evidence you produce at Level 3 will need to be more detailed, more analytical, and show a greater command of the subject.

A good example is the comparison between the NCFE Level 2 Certificate in Data Analysis (603/7192/4) and more advanced analytical work. At Level 2, you might be demonstrating that you can clean and summarise a data set using a given tool. At Level 3 and Level 4, you are expected to explain why particular approaches are appropriate, identify limitations in the data, and present findings in a way that supports decision-making. The jump is real and is built into the assessment criteria at each level.

Our guide on what data science is in a UK context gives a useful sense of the practical skills that data qualifications are designed to build, which in turn gives you a realistic picture of what portfolio evidence in this subject area looks like.

A comparison of assessment approaches

Feature Timed written examination Portfolio-based internal assessment
Flexibility for working adults Low - fixed date, fixed venue High - completed around work commitments
What is measured Recall and performance under pressure Applied competence across a range of tasks
Feedback during the process None until after results Ongoing from assessor with resubmission opportunity
Quality checks on marking Examiner marking and standardisation IQA sampling and EQA oversight by awarding organisation
Employer evidence of practical skill Limited - shows ability to answer questions Strong - demonstrates work produced to a regulated standard
Regulated status in UK Can be regulated or unregulated Can be regulated or unregulated - check the Ofqual register

The question of rigour

Key insight: Rigour in assessment is not a property of the format. It is a property of the standard being applied and the quality assurance system enforcing it. A poorly designed examination is not rigorous. A well-designed portfolio assessment, overseen by a qualified assessor, reviewed by an IQA, and monitored by an EQA appointed by a regulated awarding organisation, is. The format tells you nothing on its own. The regulatory chain tells you everything.

The reason regulated portfolio assessment is credible is precisely because of the chain described above: NCFE sets the standard, the centre's assessor applies it, the centre's IQA monitors the assessor, and NCFE's EQA monitors the centre. Remove any link in that chain and you are back to a certificate that looks convincing but carries no independently verifiable weight.

When you study a qualification that sits on the Ofqual register, every link in that chain is in place. That is what you are buying when you enrol in a regulated qualification. Not a shortcut, but a structured, monitored, and independently verified process of demonstrating competence.

Agentic AI and why portfolio assessment is the right fit for fast-moving fields

There is a practical argument for portfolio assessment that goes beyond flexibility. In rapidly evolving fields such as artificial intelligence, data analysis, and cyber security, the specific tools and techniques in use today may be materially different in eighteen months. Our article on what agentic AI is and why it matters illustrates precisely how quickly the landscape is shifting. A qualification whose assessment model asks you to demonstrate applied competence with real tasks is better positioned to reflect current practice than one that tests recall of a fixed syllabus under timed conditions.

This does not mean that portfolio qualifications are easier to keep current. The awarding organisation must update qualification specifications as the occupational standards they map to change. But the evidence model, which asks you to produce actual work, travels well. The work you submit for a data analysis or coding qualification is work of the kind that an employer would recognise as relevant, because it resembles the work they ask their teams to produce.

What this means if you are choosing a qualification now

If you are considering a regulated qualification in one of our five subject areas, the assessment model should not be a barrier. What you should look at carefully is the qualification specification, which NCFE publishes, and the assessment criteria within it. Ask the centre: what does a typical assignment brief look like for this unit? How long do learners typically take to complete each piece of evidence? What is the resubmission policy?

These are reasonable questions and a well-run centre should answer them without hesitation. We publish programme details on each qualification page, and our admissions team can walk you through the assessment structure for any programme before you enrol.

For anyone moving into technical roles from a non-technical background, the portfolio model has a particular advantage: the process of building your portfolio is also the process of building your practical skills. By the time your portfolio is assessed and your achievement is claimed, you have a body of documented technical work that you can discuss in an interview, share with a line manager, or use as the foundation for further study.

If you are interested in where coding fits into a broader data career, our article on getting started with Python for data science gives a grounded overview of the practical skills involved and how they connect to qualification content at Levels 3 and 4.

Ready to see the assessment structure for yourself?

The NCFE Level 3 Certificate in Cyber Security Practices (603/7204/0) is one of our most popular programmes for professionals moving into or consolidating a technical security role. It is delivered entirely online, assessed by portfolio, and sits on the Ofqual register of regulated qualifications. The qualification page sets out the unit structure, what each unit covers, and how the programme is delivered.

If data analysis is your focus, the NCFE Level 2 Certificate in Data Analysis (603/7192/4) is designed for professionals who want a regulated, evidenced foundation in working with data, without prior technical experience being required for entry.

Review the qualification page, read the unit structure, and if you have questions about what portfolio assessment would look like for your specific circumstances, contact us directly. We will give you a straight answer.

View the Level 3 Cyber Security qualification

Found this useful? Share it

Before you pay for a course

A free guide: how to check in five minutes that a qualification is genuinely regulated, the seven questions to ask any provider including us, and what your fee should actually buy. Enter your email and we will send you a confirmation link. Confirm it and the guide is yours, along with an email whenever we publish something new. No spam, unsubscribe any time.