TRAFEED

Research Integrity and Research Security: A Complete Guide to the Regime That Went Live in FY2026

Published2026-07-24Ryuta Hamamoto

A single map of research integrity and research security, built from the regime that actually started operating in FY2026. It sets out how the two concepts differ, which laws apply where, why compliance became a condition of research funding, what changes inside the lab, and what other countries are doing, then points to the detailed articles.

Research Integrity and Research Security: A Complete Guide to the Regime That Went Live in FY2026
シェア

Hello, this is Ryuta Hamamoto from TIMEWELL.

Over the past year, the questions arriving from universities and research institutes have changed in character. They used to be vocabulary checks. "Research integrity is basically about research misconduct, right?" Now they are operational. "What does my lab need to have in place before next year's application round?"

The reason for the shift is not mysterious. A set of ideas turned into a set of procedures. For four and a half years after the government's 2021 policy, this area lived at the level of principle. Panels, position papers, roadmaps. Then within about twelve months it moved into operation and landed on research funding application guidelines, which is where abstractions go to become someone's Tuesday afternoon.

I wrote this article to put the whole picture on one map. The concepts and how they relate. The laws involved. Why operation started when it did. What changes inside the lab. What other countries are doing. The details belong in the individual articles, and I link to each of them as I go. What I want you to have by the end is a reliable sense of where everything sits. If the export control side is what worries you, running our free export control self-check first will make the second half of this piece a lot more concrete.

Start by putting the two terms in the right relationship

Vocabulary first, because teams that get this wrong end up arguing past each other for months.

The Cabinet Office procedures manual defines both terms precisely. Research integrity is "the awareness and behaviour that research institutions and researchers are required to observe in order to maintain the soundness, fairness and transparency of research activities," and it covers all research activities. Research security is "the awareness and behaviour required of research institutions and researchers in order to protect research activities from risks that threaten national and economic security," and it covers research activities that the state or the research institution has determined should be protected1.

The scope difference is the whole ballgame. MEXT then adds the order of operations: establish research integrity thoroughly as the foundation, and build research security measures on top of that2. A base layer that applies everywhere, and a narrow protective layer sitting on it. Once you hold that shape in your head, every other piece of the regime has somewhere obvious to go.

There is a second premise I want to establish early, because it gets lost quickly. This regime does not aim for zero risk. The manual says that demanding it would make "research institutions and researchers excessively restrained about international joint research, adversely affecting the research environment. If this ends up impeding research, it defeats the purpose"1. MEXT writes that aiming for zero risk or restricting a broad range of research is neither effective nor free of consequences, and would damage research capability and innovation2. The purpose is to reduce risk within a sensible boundary so that international collaboration can keep moving in good health. Not to slow it down.

Then there is the sentence the government documents keep repeating. There must be no discriminatory treatment on grounds of nationality, race, religion or culture12. I do not treat that as ornamental wording. It sits in the load-bearing structure of the regime, and if I had to pick one line from the manual to put on the wall of every research administration office, it would be that one.

If you want the concepts explained more gently before going further, start with What Are Research Integrity and Research Security?.

Why everyone is talking about it now

Five reasons, and this section is the core of the guide.

First, the manual arrived and became a condition of funding. The Cabinet Office expert panel published the Procedures Manual for Ensuring Research Security in December 20251. Its subject is the "Specified Research and Development Program," meaning competitive research funds premised on public disclosure of results that a supervising ministry has designated, in consultation with the funding agency, as potentially involving technologies on the critical technology area list and as particularly needing protection against technology leakage from an economic security standpoint. That definition then walked straight into live call documents. Five CREST research areas under JST's Strategic Basic Research Programs were designated, applying from new projects selected in fiscal 20263. The Acquisition, Technology and Logistics Agency's security technology research promotion programme came into scope from its fiscal 2026 call. There are now areas where not responding affects whether you can apply and whether you get selected. I go through the mechanics in Research Security Became a Funding Condition in FY2026.

Second, the day-to-day running of a lab changes. Due diligence does not stop at the principal investigator. It reaches the Co-PI at each partner institution, and research participants belonging to the lead institution, and research participants include students1. Among the listed mitigation measures is strengthening governance by concluding an employment contract where a research participant is a student. Asking a student to help with an experiment, one of the most ordinary things that happens in a university, now has a procedural layer attached to it. Honestly, this is where I expect the most friction, and it is a large part of why the topic has become noisy. I have written up the practical side in Onboarding Students and RAs Under Research Security.

Third, the timing collided with the 7th Science and Technology and Innovation Basic Plan. The government had been preparing the manual with the intention of aligning this work with the plan starting in April 2026. Several waves of reform arrived at the same beach.

Fourth, it became an admission ticket for international collaboration. The manual positions itself this way: by showing the international community that you operate under these measures, you build mutual trust with G7 members and other like-minded countries, and international joint research proceeds more smoothly1. MEXT lists among its target categories those programmes involving international joint research with countries sharing common values, where equivalent measures are expected of the partner2. So this is less about Japanese domestic preference and more about a partner university abroad asking whether you have an equivalent framework. If the answer is no, you become a less attractive collaborator.

Fifth, tightening export controls in the United States and China have reached universities. For years the conversation was limited to security trade control under the Foreign Exchange and Foreign Trade Act. Preventing the leakage of critical technologies became an economic security concern in its own right, and list-based controls together with rules that follow ownership and capital relationships now touch the screening of a university's research partners and subcontractors. Universities that assumed export control was a corporate problem have found themselves inside the frame. In July 2026, for instance, measures by China's Ministry of Commerce added European universities to a control list. Listing is a regulatory designation under a specific legal instrument. It is not a statement about the quality or conduct of the institutions concerned, and it should not be read as one.

Replace siloed classification work with AI.

METI's FY2024 data shows 52% of foreign exchange law violations stem from classification errors. Download the TRAFEED product catalog covering features and rollout.

The map: which law bites where

This area is not governed by a single statute. Several regimes overlap, and holding the whole set in view keeps individual questions from getting lost.

Regime What it protects Detail
Policy on Ensuring Research Integrity (27 April 2021) Disclosure, conflicts of interest and conflicts of commitment Research Integrity and Economic Security at Universities
Research Security Procedures Manual (December 2025) Risk management for Specified Research and Development Programs The manual and its 13 due diligence checks
Foreign Exchange and Foreign Trade Act, security trade control Export of goods and technology, deemed export What Are Dual-Use Items?
Economic Security Promotion Act Specified critical technologies (K Program), patent non-disclosure K Program, patent non-disclosure system
Act on Protection and Use of Critical Economic Security Information Security clearance Japan's security clearance system
Unfair Competition Prevention Act Protection of trade secrets Trade secret protection

Seen from a university, the top two rows probably look like "the research security thing" and the bottom four like "the economic security thing that has been around for a while." In practice they run continuously into each other. The 2021 policy adopted by the Integrated Innovation Strategy Promotion Council is the origin point of the top half, and even that document already asked METI to provide information and respond to consultations on cases of concern, such as joint research with institutions absent from Japan's End User List but subject to restrictions abroad4. Five years ago the government was already saying that checking one national list is not enough.

The connection is more explicit than that. The manual's due diligence items include whether a person is a non-resident or falls under the deemed export specific categories1. The determination logic of the Foreign Exchange and Foreign Trade Act is embedded inside the research security procedure. You cannot run one competently while treating the other as somebody else's department. Export control practice for universities is a topic in its own right, and I cover it separately in export control for universities.

What the work actually is: four steps and 13 items

The risk management the manual asks for consists of four procedures. Risk identification, risk assessment, risk mitigation, and follow-up1. As a flow, that is simple enough.

At the centre sits due diligence, the process of confirming the suitability of the institutions and researchers taking part, and the manual lists 13 items to verify. Academic background. Research and employment history. Research funding received. Non-funding support received. Authorship on published papers. Patent filings. Participation in foreign talent recruitment programmes. Disciplinary history. Whether the person appears on a list. Whether the person belongs to a listed institution. Whether the person has relationships with researchers at listed institutions. Status under security trade control, meaning non-resident status or the deemed export specific categories. And anything else the funding agency considers necessary. Items three to eight, plus ten and eleven, have to cover the past three years including the year of application1. You are building a history, not taking a photograph.

The item that makes the workload heavy is not number nine or ten, the "are they on a list" questions. It is number eleven: relationships with researchers at listed institutions. The person is on no list. Neither is their institution. You still have to establish whether following the co-authorship trail leads to a researcher at a listed institution. Name matching does not answer that. You have to traverse a network of people, papers, patents and organisations, and do it for every PI, every Co-PI and every research participant, three years deep, each time a proposal goes out. A research administration office of three or four people cannot do that by hand. The arithmetic simply does not close.

The manual seems aware of this. It names the tools to use for due diligence, listing academic paper databases, research databases, intellectual property databases, METI's End User List and the United States consolidated screening list. Then it adds that "where the information gathered using these tools is insufficient for adequate due diligence, using commercial information analysis tools or commissioning investigations from firms may also be considered"1. A government document explicitly anticipating commercial tooling is not a throwaway line. I read it as an acknowledgement of the volume of work involved.

The individual pieces of practice are split across separate articles. For handling the questionnaires funding agencies send you, see How to Complete a Research Security Questionnaire. The day-to-day declaration work sits in COI and COC declarations in practice. Concrete measures such as access rights and research location are covered in implementing risk mitigation measures. For the order in which to build the institutional framework as a whole, see the research institution readiness roadmap.

The vocabulary of the risk side, and where other countries stand

To understand why the checks are shaped the way they are, it helps to know the vocabulary of what the regime is trying to catch. Undisclosed foreign funding. Undeclared dual affiliations. Unreported participation in foreign talent recruitment programmes. Unintentional technology transfer. Insider risk. Leakage through a research partner or a subcontractor. Those are the scenarios sitting behind the 13 items. I cover them in undisclosed foreign funding and dual affiliations.

Care is required here too. The regime was not built to cast suspicion on people from particular countries or with particular attributes. METI states, in writing, that the deemed export specific categories are "simply a typological grouping of cases requiring individual verification during screening, and falling under a specific category does not mean the person is regarded as posing a security concern"5. A procedural classification, not an assessment of a person. When you explain any of this to a lab, that sentence has to travel with it, every time. Otherwise the explanation does damage that no amount of policy language repairs later.

Internationally, Japan is a follower here rather than a leader. The G7 published common values and principles on research security and research integrity in June 2022, advancing the idea of shared responsibility: no single organisation can carry this alone, so every part of the research community needs to understand its own role1. The United States built on NSPM-33 and the CHIPS and Science Act, with NSF introducing its TRUST framework. The United Kingdom runs its Trusted Research Guidance with RCAT as an advice line. Canada publishes a sensitive technology list and a named research organisation list. France protects designated laboratories as restricted zones under its regime for the protection of scientific and technical potential. Germany implements through DFG recommendations12. A country-by-country comparison sits in research security regimes around the world.

The shared principles are "small yard and high fence" and "as open as possible, as closed as necessary"1. Keep the fenced area small, and precisely because it is small, everything outside it can stay confidently open. That idea is the spine of the whole design.

The gap I see right now, and what we are trying to do about it

Let me finish with the thing I think will define the next two or three years in practice.

The regime, as designed, goes out of its way to prevent overreaction. No zero risk. A narrow scope. An explicit ban on discriminatory treatment. What happens on the ground is different. Criteria stay vague, decisions get made person by person with no shared basis, and caution compounds. There is a gap between the design intent of the regime and how it actually operates in the building. In that gap, "stop everything, just in case" starts to look like the safest available move, and blaming the administrator who makes that call solves nothing. They are not being obstructive. They cannot assemble the basis for a decision, so they cannot make one.

That, I think, is why demand for support in this area is picking up. What institutions need is a way to assemble the information the checks require, completely, with sources attached, in a workable amount of time. The knowledge graph of more than 200 million records that we have built for export control at TRAFEED, roughly 90 million papers, roughly 100 million patents and roughly 300,000 researchers, together with national control lists, maps onto the manual's verification items almost item for item. Walking co-authorship and co-filing networks is a hard problem on paper and a tractable one in a graph. We are extending the same base into shareholder and capital relationship research alongside researcher information.

None of that means handing the judgment to a machine. In export control, the final classification decision belongs to the responsible officer at each organisation. In research security, risk assessment and the choice of mitigation measures belong to the research institution. That is what the manual asks for, and I have no interest in blurring it. Our job is narrower and, I would argue, more useful: assemble the material, and leave a record that can explain afterwards why the conclusion was what it was.

  • Research integrity is the foundation and covers all research activities. Research security is a narrower additional layer, applied only to research designated for protection. In MEXT's framing, integrity comes first
  • From fiscal 2026, five CREST areas under JST and the ATLA programme were designated as Specified Research and Development Programs, which makes compliance with the manual a condition of applying
  • Due diligence has 13 items, most covering three years. Research participants including students are in scope
  • The regime does not demand zero risk, and it states explicitly that there must be no discrimination by nationality or race
  • The heaviest part of the work is not list matching. It is tracing relationships through co-authorship and co-filing

This subject usually gets discussed as a defensive one. Read the manual and the intent looks close to the opposite. By narrowing what you protect and getting the procedure around it right, you earn the ability to keep everything else open without apologising for it. Keeping the yard small takes an accurate read of where the fence belongs, and that read is not something intuition and goodwill produce reliably. My prediction is straightforward: over the next few years, the institutions that can draw that boundary with evidence will pull away from the ones that cannot, and the gap will show up in who gets invited into international projects.

If you are working out how to structure your institution's response, or just where to begin, talk to our TRAFEED team. The research security features are still being built, so hearing what is actually causing pain on the ground helps us as much as it helps you.

References and primary sources

Footnotes

  1. Expert Panel on Ensuring Research Security and Research Integrity, "Procedures Manual for Ensuring Research Security," December 2025 (Cabinet Office) https://www8.cao.go.jp/cstp/kokusaiteki/integrity/yushikisha/guidelines_v1.pdf 2 3 4 5 6 7 8 9 10 11 12 13

  2. MEXT, Science, Technology and Innovation Policy Bureau, "Direction of Concrete Measures on Research Security in MEXT-Related Programmes for Universities and Other Institutions," 18 December 2024 https://www.mext.go.jp/content/20241218-mxt_kagkoku-000039402_1-1rrr.pdf 2 3 4 5

  3. Japan Science and Technology Agency (JST), "FY2026 Strategic Basic Research Programs (CREST, PRESTO, ACT-X) Call for Proposals" https://www.jst.go.jp/kisoken/boshuu/teian/koubo/2026youkou.pdf

  4. Integrated Innovation Strategy Promotion Council, "Policy on Ensuring Research Integrity Against New Risks Accompanying the Internationalisation and Opening of Research Activities," adopted 27 April 2021 https://www8.cao.go.jp/cstp/kokusaiteki/integrity/integrity_housin.pdf

  5. METI, Trade Control Department, Security Export Control Policy Division, "On the Clarification of Deemed Export Management" https://www.meti.go.jp/policy/anpo/law_document/minashi/meikakukanitsuite2.pdf

52% of FY2024 export-control violations stem from classification errors. Is your team covered?

METI FY2024 data shows over half of violations stem from classification. Start with a free 5-question light check (~2 min, no email), then continue to the full 10-question report.

Share this article if you found it useful

シェア

Newsletter

Get the latest AI and DX insights delivered weekly

Your email will only be used for newsletter delivery.

無料診断ツール

輸出管理のリスク、見えていますか?

まず5問(約2分・メール不要)のライト診断。必要なら10問本編で詳細レポートまで。

Talk with us about export-control operations

Share your screening, classification, or compliance workflow. We will map where TRAFEED can help—via our contact form (no cold booking).

Related Articles