Hello, this is Ryuta Hamamoto from TIMEWELL.
"A research security questionnaire arrived. How exactly are we supposed to answer this?"
Of everything people have brought to me over the past few months, that question is the most concrete and the most urgent. Explainers about the regime itself have multiplied. Almost nothing has been written about what to put in the boxes on the form in front of you. And the timing is awkward by design: the questionnaire reaches you from the funding agency after your project has been shortlisted. It arrives when you have no slack left.
So this piece is about the operational work. What gets asked, where each answer's raw material comes from, what to do when it does not come, and how to think about the items that feel uncomfortable to answer. I will follow the Cabinet Office procedures manual and stay as specific as I can. For how research security became a condition of application in the first place, see Research Security as a Funding Condition, and for the wider picture, the complete guide. If you also want a quick read on where your own export control arrangements stand, our export compliance self-check starts at five questions.
When the questionnaire arrives, and who receives it
Let me set the premises straight first, because a lot of anxiety comes from assuming the wrong ones.
The questionnaire does not go to everyone who applies to a Specified Research and Development Program. Reading JST's application guidelines, it is sent separately to the principal investigator of a shortlisted project that has been made subject to risk management1. The sequence runs: application, shortlisting, confirmation that the project is in scope, then the questionnaire.
Submission comes with conditions attached. The PI submits by the stated deadline, having obtained the agreement of the main co-investigators and confirmation from the responsible departments at both the PI's institution and the co-investigators' institutions1. This is where the time actually goes. It is not a form you can fill in and send on your own.
If several partner institutions are involved, you need to reach the right department at each of them. And if a partner has no department that owns research security, your first task is finding a counterpart at all. Work backwards from the deadline and you reach an uncomfortable conclusion: starting only when the questionnaire lands may not leave enough time. That is the single point I most want to get across in this article.
Submission is not the end either. JST and MEXT review the responses and may request additional risk mitigation measures where they consider them necessary1. Build your schedule assuming at least one round trip.
What gets asked: the 13 verification items
Funding agencies design their own form, but the substance comes from the Cabinet Office procedures manual. The manual lists 13 items that the lead institution should verify for the PI, for research participants belonging to that institution, and for Co-PIs2.
| # | Item to verify | Past three years |
|---|---|---|
| 1 | Academic background, including supervisors where relevant | — |
| 2 | Research and employment history | — |
| 3 | Research funding received | ● |
| 4 | Support other than research funding received | ● |
| 5 | First, corresponding and co-authors on published papers | ● |
| 6 | Patent filings, including co-inventors and co-applicants | ● |
| 7 | Participation in foreign talent recruitment programmes | ● |
| 8 | Disciplinary history under the guidelines | ● |
| 9 | Whether the person appears on a list | — |
| 10 | Whether the person belongs to a listed institution | ● |
| 11 | Whether the person has relationships with researchers at listed institutions | ● |
| 12 | Status as a "non-resident" or under a "specific category" in security export control | — |
| 13 | Anything else the funding agency deems necessary | — |
Items 3 through 8, plus 10 and 11, cover the past three years, including the fiscal year in which you apply2. That column is the part worth staring at. The manual is not asking for a single-year snapshot. It is asking for a history, and histories are much harder to reconstruct after the fact than current status is.
The population in scope deserves attention too. It is not only the PI and Co-PIs. Research participants belonging to the lead institution are included, and research participants include students2. Depending on how your lab is staffed, the headcount can be several times what people first assume. The contractual side of including students is something I cover separately in Taking On Students and RAs Under Research Security.
Replace siloed classification work with AI.
METI's FY2024 data shows 52% of foreign exchange law violations stem from classification errors. Download the TRAFEED product catalog covering features and rollout.
Where the information for each item comes from
Here is the core of it. Splitting the 13 items into three groups by the nature of their source makes the work far easier to organise.
Items filled in by self-declaration (1 to 4, 7, 8, 12)
Academic background, research and employment history, research funding and non-funding support received, participation in foreign talent recruitment programmes, disciplinary history, and status under the deemed export rules. These are things only the individual really knows. You rely on declaration.
This is where accumulated routine work pays off. The manual treats collecting information declared by researchers on the basis of a research integrity checklist as one of the measures institutions should carry out as ordinary, day-to-day practice, and it categorises that as "necessary"2. In other words, the information you have already been gathering under the research integrity framework is meant to become the raw material for the questionnaire. The inverse is also true. If your integrity declarations have quietly become a box-ticking exercise, this is where you will grind to a halt. Honestly, that is the situation at more institutions than people admit out loud.
Item 4, support other than research funding, is the one most often missed. The government's 2021 policy defines it as receiving research facilities, equipment, instruments or services free of charge3. No money needs to have moved. Borrowing an instrument at no cost, or having analysis done for you as a favour, can fall inside it. When I raise this in conversation, the reaction is usually a pause, then a "wait, does that count?" It does.
On item 12, the deemed export specific categories, I have written about the underlying concepts in What Are Dual-Use Items?. The sentence I would keep close at hand is METI's own: falling under a specific category does not mean the person is regarded as posing a security concern4. It is a procedural grouping of cases that require individual verification during screening, nothing more. When you ask a researcher to confirm their status, attach that sentence. Whether the request reads as "we are checking a procedural classification" or as "we suspect you" changes everything about how it is received on the ground, and the difference costs you nothing to get right.
Items you can confirm from public sources (5, 6, 9, 10)
Authorship on published papers, patent filings, listing status, and affiliation with a listed institution. For these, declaration can be cross-checked against public information.
The manual names the tools to use for due diligence: academic paper databases, portals such as Google Scholar, research databases such as e-Rad and researchmap, IP databases such as J-PlatPat, METI's End User List, and the United States consolidated screening list2.
Two things about lists are worth saying plainly before anyone starts matching names. Appearing on a control list is a regulatory designation. It reflects how a government has categorised an entity for licensing and screening purposes, and it is not a finding that the institution or the individual did anything wrong. Treat items 9 and 10 as classification questions, not character questions, and the whole exercise stays proportionate.
The manual then adds something reassuring. Due diligence is to be carried out "using self-declared information, open source information and other information that each lead institution can ordinarily obtain"2. Nobody is asking you to run an investigation. The standard is what you can ordinarily obtain, and it is written down in the manual, which means you can point to it when an internal discussion starts spiralling into "but what if we missed something."
The item you cannot answer without tracing relationships (11)
Then there is item 11, which behaves differently from all the others.
Whether the person has relationships with researchers at listed institutions. The manual defines what "relationships" means here: conducting joint or commissioned research, writing and publishing co-authored papers, and appearing as a named co-presenter at conferences and similar events2. Being billed as a co-presenter counts, even where no paper came out of it.
Items 9 and 10 are matching problems. Compare a name or an institution name and you have your answer. Item 11 is not that. The researcher in front of you appears on no list. Their institution appears on no list. You still have to work out whether following their co-authors leads to a researcher at a listed institution. Across three years. Covering co-authored papers, joint research, and named conference presentations.
Name matching will not get you there. You have to walk a network of people, papers, patents and organisations. Then do it for every PI, every Co-PI and every research participant including students, every time a proposal goes out. For an institution whose research administration office has a handful of staff, calling that workload unrealistic is not an exaggeration.
The manual anticipates this. Right after listing the tools, it adds that "where the information gathered using these tools alone makes adequate due diligence difficult, using commercial information analysis tools or commissioning investigations from firms may also be considered"2. My reading is that a government document explicitly contemplating commercial tooling is a direct consequence of what item 11 asks for. Nothing else on the list has that shape.
When the information does not arrive, and when an item does apply
Two situations come up in practice every single time. Both are addressed in the manual, and both are widely misread.
When you cannot gather the information. The manual states that for individuals where adequate due diligence is difficult because the necessary information cannot be obtained, implementing risk mitigation measures as needed is desirable2. Not proceeding with a blank field. Not excluding the person as a matter of policy. You acknowledge what could not be confirmed and cover that gap with measures. A researcher who has just arrived from overseas, or whose previous employment records are hard to obtain, is a real and frequent case. The answer there is access rights design, not exclusion.
When an item does apply. This is the biggest misunderstanding of all. A co-author works at a listed institution. Someone participated in a foreign talent recruitment programme. Neither of those means you cannot apply. What the manual asks for is reasonable handling proportionate to the degree of risk, and the mitigation measures it offers as examples are modest: managing access rights to facilities and equipment, securing off-campus or otherwise separated research locations, considering who attends meetings based on the sensitivity of what is discussed, strengthening governance through employment contracts where the research participant is a student, training, managing access rights to research data, and hardening against cyberattack2. Falling under an item is an entrance, not an exit.
The manual also states that, in judging whether a counterpart is a trustworthy partner, there must be no discriminatory treatment on grounds of nationality, race, religion, culture or the like2. MEXT writes the same thing5. When the regime itself has been designed to prevent overreaction, there is no reason for the people operating it to be stricter than the design. If I had to pick one place where institutions do damage to themselves, it is here: an internal rule invented out of caution that goes beyond what the government asked for, and quietly makes the institution a worse place to collaborate with.
Sort out the personal data handling before you collect anything
One last thing, and it belongs at the start of your work rather than the end of this article.
The information you collect from researchers for the questionnaire is personal data. It may also be provided to third parties, namely the funding agency and relevant government bodies. In light of Japan's Act on the Protection of Personal Information, the manual states that institutions should require a consent form when receiving declarations of personal data from researchers2.
The manual also spells out what the consent form should cover. First, that the researcher declares the personal data to the institution for the purpose of risk management aimed at ensuring research security, and that the institution uses it only for that purpose. Second, that the institution may provide that personal data to third parties for that purpose2.
A written declaration is required alongside it: that the personal data declared is, to the signatory's knowledge, current as at the time of declaration, and contains no false content and no omissions2.
Preparing those two documents before you start collecting is the correct order. Collect first and go back for consent afterwards and you have doubled your own work while spending goodwill you will need later. JST's application guidelines also state that personal data provided may be used within the necessary scope by JST, MEXT, the Cabinet Office and other government bodies1, so I would build your explanatory material to cover that too. Researchers are far more cooperative when they can see the whole path their information takes.
Making this run in practice
Let me reorder everything above into the sequence I would actually work in.
Prepare the consent form and the written declaration first. Take stock of what you already collect through the research integrity checklist and map it against the 13 items, so you know which boxes are already filled and which are empty. For the empty ones, particularly items 5, 6, 10 and 11, decide now how you will confirm them from public sources. Get the contact details for the responsible department at each partner institution before you apply, not after. And decide how you are going to handle the relationship check in item 11. Five things.
That item 11 carries a disproportionate share of the load should be clear by now. The knowledge graph of more than 200 million records we have built for export control at TRAFEED, roughly 90 million papers, roughly 100 million patents and roughly 300,000 researchers, together with national lists, maps almost directly onto items 5, 6, 9, 10 and 11. Walking co-authorship and co-filing edges one hop, then two, and surfacing whether a path reaches a listed institution is something a graph structure handles as computation rather than as manual labour. Alongside researcher information, we are extending into shareholder and capital relationship research on partner organisations.
What goes on the questionnaire, though, is decided by the research institution. The manual assigns risk assessment and the choice of mitigation measures to the institution, and that is the right place for them. Our job is to assemble the material and to leave it in a form that can explain, later, why a conclusion was reached. Building an audit-ready trail is something we designed in from the start on the export control side, and it transfers to this work more cleanly than I expected.
What to take away
- The questionnaire goes to the PI of a shortlisted project that has been made subject to risk management. It is not sent to every applicant
- Submission requires the agreement of co-investigators and confirmation from the responsible departments at both institutions. Starting only when it arrives may not leave enough time
- The substance is the manual's 13 verification items. Items 3 to 8, plus 10 and 11, cover the past three years. Research participants, students included, are in scope
- Due diligence is to be done with information you can ordinarily obtain, and the manual says so explicitly
- Where information cannot be gathered, the answer is mitigation measures, not exclusion. Falling under an item is not a ground for exclusion either
- Prepare the consent form and written declaration before you collect anything. Getting the order wrong costs you twice
As paperwork, the questionnaire is tedious. I will not pretend otherwise. But read the items one by one and something else shows through: what is being asked is that you can explain who you work with, what you work on, where your support comes from, and how the collaboration is structured. That is research transparency. It is the kind of thing you ought to be able to answer whether or not anyone asks. Reframing it that way makes the form noticeably lighter to pick up.
So here is my recommendation, and it is deliberately narrow. Do not wait for a questionnaire to arrive before touching any of this. Write the consent form and the written declaration this quarter, run one PI through the 13 items as a dry run, and see where you get stuck. Whatever breaks in that rehearsal is exactly what would have broken later, on a deadline, with a funding decision attached.
If you are working out where to start at your own institution, talk to our TRAFEED team.
References and primary sources
Footnotes
-
Japan Science and Technology Agency (JST), "FY2026 Strategic Basic Research Programs (CREST, PRESTO, ACT-X) Application Guidelines" https://www.jst.go.jp/kisoken/boshuu/teian/koubo/2026youkou.pdf ↩ ↩2 ↩3 ↩4
-
Expert Panel on Ensuring Research Security and Research Integrity, "Procedures Manual for Ensuring Research Security," December 2025 (Cabinet Office) https://www8.cao.go.jp/cstp/kokusaiteki/integrity/yushikisha/guidelines_v1.pdf ↩ ↩2 ↩3 ↩4 ↩5 ↩6 ↩7 ↩8 ↩9 ↩10 ↩11 ↩12 ↩13 ↩14
-
Integrated Innovation Strategy Promotion Council, "Policy on Ensuring Research Integrity Against New Risks Accompanying the Internationalisation and Opening of Research Activities," 27 April 2021 https://www8.cao.go.jp/cstp/kokusaiteki/integrity/integrity_housin.pdf ↩
-
METI, Trade Control Department, Security Export Control Policy Division, "On the Clarification of Deemed Export Management" https://www.meti.go.jp/policy/anpo/law_document/minashi/meikakukanitsuite2.pdf ↩
-
MEXT, Science, Technology and Innovation Policy Bureau, "Direction of Concrete Measures on Research Security in MEXT-Related Programmes for Universities and Other Institutions," 18 December 2024 https://www.mext.go.jp/content/20241218-mxt_kagkoku-000039402_1-1rrr.pdf ↩
