Trusted Research
International collaboration drives scientific breakthrough and enhances the real-world impact of our research. At Queen Mary University of London, we actively champion global partnerships.
However, because the UK higher education sector is world-leading, it is also a prime target for hostile actors seeking to exploit our culture of openness. Academic institutions are increasingly targeted to gain research data, personal data, and intellectual property to advance foreign economic, commercial, or military interests.
Trusted Research is a UK-wide framework designed in partnership with the National Protective Security Authority (NPSA) and the National Cyber Security Centre (NCSC) to safeguard the integrity of international collaborations. It is not about restricting research and partnerships, it is an active commitment to Responsible Research and Innovation (RRI). Having an awareness of the risks involved, allows researchers to protect our academic freedom, shield their personal reputation, and ensure their discoveries are used safely and ethically.
- Why Protect Your Work?
- The Risk Environment: Who Wants Your Research?
- Core Principles of Trusted Research (The NPSA Framework)
- The Embedded Lifecycle Process
- Related Legal Frameworks & Regulations
Why Protect Your Work?
Failing to secure your research early can have professional and institutional implications:
- Reputational Damage: Partnering with institutions linked to foreign military bodies, state surveillance, or human rights abuses can critically damage your professional standing and compromise the university's core values.
- Loss of Credit and Publication Rights: If your preliminary findings, software code, or data models are inappropriately accessed, foreign entities can fast-track their own technological capabilities. You risk losing the ability to publish first or commercialise your own intellectual property.
- Legal and Criminal Liability: Certain research activities are subject to statutory requirements, including export control legislation. Breaches may result in regulatory enforcement action against both the University and individuals, including substantial fines and, in serious cases, criminal prosecution and imprisonment. Researchers should seek advice whenever there is uncertainty regarding compliance obligations.
- Institutional Trust: Major funding bodies (including UKRI) enforce strict Trusted Research conditions. If the data or assets your research depends on, are compromised or poorly protected, Queen Mary risks losing access to critical data streams and future grant allocations.
The Risk Environment: Who Wants Your Research?
While all research at Queen Mary is valued, certain fields face highly sophisticated scrutiny. Hostile actors routinely look to exploit academic openness through a variety of methods:
- Vulnerable Research Areas: Applied research aiming to solve specific engineering, computational, or life-science problems is particularly vulnerable. Aimed at STEM subject areas. Commercially sensitive research, emerging sectors (like advanced materials, quantum computing, and autonomous systems), and artificial intelligence face the highest rates of state backed interference.
- Methods of Exploitation: Hostile actors rarely rely on traditional methods. Instead, they leverage open joint ventures, academic exchange programs, informal peer-to-peer digital sharing, and complex international funding arrangements to bypass traditional security protocols.
Core Principles of Trusted Research (The NPSA Framework)
To ensure global projects remain resilient, Queen Mary aligns with the NPSA’s core pillars of academic security. These operational principles are built into every project:
1. Partner Suitability & Motivation
Before confirming an international research arrangement, you must clearly understand your partner's true intent. Ask foundational questions:
- What is their specific commercial or strategic interest in your project?
- How do they intend to apply the resulting research in their home country?
- Do they have underlying structural links to foreign military, police, or state-directed security entities?
2. Securing Information & Knowledge Sharing
Open collaboration requires safe boundaries. We provide the infrastructure to help you control how data moves:
- Workplace Segregation: Ensure appropriate digital and physical segregation between different research programmes. Restricting network and platform permissions to those with a valid approval, prevents unauthorised lateral access across sensitive projects.
- Data Integrity: Implement information security measures to ensure that research files and communication channels are fully protected from outside access or unauthorised data extraction.
3. Protecting Intellectual Assets
Securing your long-term research means establishing clear operational structures before any transfer of information begins. This means managing conflicts of interest transparently, safeguarding your intellectual property (IP), and maintaining a firm hold on your right to publish independent, peer-reviewed findings without foreign government interference.
The Embedded Lifecycle Process
Managing these considerations should not add an administrative burden to your day-to-day work. Research security assessments are embedded into our institutional workflow, ensuring that all necessary due diligence happens as your project progresses:
1. Early Assessment - Grant Development Stage
Academics should work with local teams during the initial proposal phase to highlight international considerations. The project profile should flag research that involves sensitive technologies or includes high-risk jurisdictions.
2. Due Diligence - Pre-Award Review
Where potential risks are identified, the project should be reviewed and assessed. The Research Security team is here to support researchers. Please get in touch at the earliest opportunity to arrange due diligence and the team can feedback the risk assessment to enable to researcher to be informed of the potential risks involved and any next steps.
3. Post Award - Contracting Phase
Before any agreement is signed, the university embeds robust IP protection and confidentiality clauses into collaboration contracts, securing rights to publish. Further due diligence can be carried out at this stage.
Related Legal Frameworks & Regulations
While Trusted Research provides the overarching protective framework for international collaborations, it sits alongside specific legal and operational regulations:
- Export Controls: Legal restrictions governing the physical or digital transfer of sensitive dual-use items, software, and technical "know-how" outside the UK. Compliance is a statutory requirement separate from due diligence.
- National Security and Investment (NSI) Act: Statutory rules granting the UK Government intervention rights regarding acquisitions of control over sensitive intellectual property and entities within 17 sensitive areas of the economy.
- Academic Technology Approval Scheme (ATAS): A mandatory government vetting scheme managed by our HR and Admissions teams for specific international staff and students entering sensitive STEM fields.
Depending on the nature of a project, additional legal and regulatory requirements may also apply.
The Trusted Research and Compliance Board
The Queen Mary Trusted Research and Compliance Board is the governing body responsible for monitoring institutional performance, providing structural oversight, and ensuring that our research security policies continue to champion academic freedom while maintaining full regulatory compliance.
- Get in Touch: For expert advice on international partnership risks, contact the central due diligence team at vp-trustedresearch@qmul.ac.uk.
- Official Framework Guidance: NPSA Trusted Research for Academia
What Should Researchers Do?
- Know your collaborators and funding sources
- Consider how research outputs could be used
- Protect data, intellectual property and research materials
- Seek advice where risks or uncertainties exist
- Complete due diligence where required
|
Please contact the Research Security team at: |
|---|
Note: Research Security policies and guidance documents are available on the Policies, Guidance and Training page.