TRAFEED

Taking On Students and RAs Changes Under Research Security: Employment Contracts, Confidentiality and Sworn Statements

Published2026-07-24Ryuta Hamamoto

Risk management under Japan's research security regime reaches research participants, students included. This piece works through how a lab's intake practice changes, following the Cabinet Office procedures manual: employment contracts for research assistants, confidentiality, consent forms and sworn statements, and access design, plus how to run all of it without making people anxious.

Taking On Students and RAs Changes Under Research Security: Employment Contracts, Confidentiality and Sworn Statements
シェア

Hello, this is Ryuta Hamamoto from TIMEWELL.

There is a moment in almost every conversation about research security when a faculty member's expression shifts. It comes when I say, "Students are in scope as well."

As a statement about the rules, that is one line. What it implies is heavy. A master's student helps run your experiments. An international student joins the lab. Someone new arrives halfway through the year. Procedure now reaches into the ordinary rhythm of a research group. Of everything in this regime, this is the part that hits the ground hardest, and frankly it is also the part that draws the most pushback.

So this piece works through how intake practice actually changes. It also covers how to run it without making people anxious, because the regime was written to prevent overreaction, and losing that in the way an institution implements it would be the most wasteful failure available. For the whole picture there is the complete guide, and for filling in the paperwork itself there is the questionnaire guide.

Start with scope. Not every student is covered

Get the boundary right first. If it stays vague, procedure spreads into places that never needed it, and the people doing the work lose faith in the whole exercise.

Japan's Cabinet Office procedures manual names three groups subject to risk management. The PI, who bears responsibility for the research as a whole. Any Co-PI participating as the representative of a partner institution. And research participants belonging to the lead institution. For that third group the manual gives a definition: "researchers scheduled to participate in the Specified Research and Development Program (including students, and excluding the PI and Co-PI)"1.

The load-bearing words sit in the first half of that definition. Risk management under the manual applies to Specified Research and Development Programs, meaning competitive research funds premised on public disclosure of results that a supervising ministry has designated, in consultation with the funding agency, as potentially involving technologies on the critical technology area list1. Not everything running in your lab qualifies.

Read precisely, then, the people in scope are students scheduled to participate in a designated program. Not every student on the roster. Operationally that gap is enormous. Try to push every student in the group through the procedure and the system collapses under its own weight, and nobody asked you to do that in the first place. Where designation becomes visible in practice is in the funding agency's call documents2, and I have set out how that played out this year in research security as a condition of funding.

That said, if a student does take part in a designated program, that student is in scope. And the reality of running a lab is that people rarely divide cleanly into "works only on this project" and "works on everything else." A student runs a measurement for one project on Tuesday and a different one on Thursday, using the same instrument and sitting in the same weekly meeting. That messiness, not the paperwork, is the real difficulty. If you want a quick read on how your institution's export control practice stands before you start drawing lines, our free export compliance check is a reasonable place to begin.

What an employment contract actually buys you

Among the risk mitigation measures the manual offers as examples, there is this line.

(Where a research participant is a student, for example) strengthening governance by concluding an employment contract1

Why a contract? The reason is plain. Without one, you have a weak basis for imposing obligations at all.

In relation to the university, a student is an enrolled learner. Even when they are doing research in your lab, if no employment relationship exists there is no vehicle for imposing confidentiality duties or rules on handling information as contractual terms. Work rules do not apply to them either. Put a research assistant employment contract in that gap and you can state, as contract terms, confidentiality, the handling of research data, access to equipment, and the obligation to return materials on departure.

If I had to pick the single clause that makes the paperwork worth it, it would be the last one. Departure is where things go wrong. People leave with a laptop full of raw data and no clear rule about what happens to it, and years later nobody can reconstruct who held what. An RA contract fixes that in advance, and it is useful whether or not research security is in the picture.

This is not an obligation. The manual's wording is that it "gives examples," and it goes on to say that measures need only be reasonable and proportionate to the degree of risk1. There is no rule requiring you to hire every student as an RA. For students touching the sensitive parts, use a contract to establish governance. For everything else, handle it through access design. That kind of calibration is exactly what the manual anticipates.

The footnotes carry one more practical warning. Where a research participant is a secondee from another institution, a dispatched worker, or an employee of a contractor, it is necessary to check the content of the contract covering their participation in the research1. This is not only about students. Whenever someone works on the research without an employment relationship with your own institution, you need to go and read the contract that does govern them.

Replace siloed classification work with AI.

METI's FY2024 data shows 52% of foreign exchange law violations stem from classification errors. Download the TRAFEED product catalog covering features and rollout.

The manual also sets out procedure for the moment you gather information from a student. The order matters here, and it is easy to get backwards, so let me be careful.

Information obtained from researchers for risk identification and risk assessment includes personal information, and that information may be provided to third parties. In light of Japan's Act on the Protection of Personal Information, the manual therefore requires that when a research institution receives a declaration of personal information from a researcher, it obtain a signed consent form1.

The contents are specified. First, that the researcher declares the personal information to the institution for the purpose of risk management aimed at ensuring research security, and that the institution uses it only for that purpose. Second, that for that same purpose the institution provides the personal information to third parties1. Third parties here include funding agencies and relevant government bodies.

A sworn statement is required as well. It states that the personal information declared is, to the best of the signer's knowledge, current as of the time of declaration, and that it contains no falsehood and no omission1.

In practice, have both documents finished before you start collecting. Going back for consent after the fact is rework, and with students it costs you something harder to recover than time. When the person on the other side is a student, pairing the form with an explanation of why it exists is not a nicety, it is the whole thing. Hand over paperwork and ask for a signature with no context, and the only impression that survives is being watched.

There is one sentence I would attach to that explanation every time. On the deemed export specific categories, Japan's Ministry of Economy, Trade and Industry states that they are "simply a typological grouping of cases requiring individual verification during screening, and falling under a specific category does not mean the person is regarded as posing a security concern"3. It is a procedural classification, not an assessment of the person. Whether or not that premise is shared changes the atmosphere in a lab completely, and I have watched it go both ways.

Mid-year additions, and new hires

Lab membership moves during the year. Everyone knows this. The manual accounts for it.

Where research participants are added as the research progresses, conducting due diligence on that participant is necessary1. Each addition triggers procedure. There is no annual snapshot that lets you stop thinking about it until next April.

For new recruitment, the manual says it is desirable to collect the information used for due diligence from candidates at the open call stage1. Not after they arrive. Build it into the recruitment process itself. I think that is sound design. It avoids the situation where someone has already started and the information you need will not come, and it is fairer to candidates, who get to see the conditions before they apply rather than after they have moved cities.

There is also a procedure for errors. Where an error is discovered in information declared by a researcher, the institution must promptly report it to the funding agency and carry out due diligence again on the basis of the corrected information1. Report it, redo it. No ambiguity there, and I would rather have a rule this clear than one that leaves people guessing whether a correction counts as a problem.

"So wouldn't it be safer just not to take international students?"

Raise this topic and the reaction arrives on schedule. If the procedure is burdensome, why not narrow who we accept in the first place?

The regime answers that directly. That is not what is being asked for.

In judging whether a counterpart is a trustworthy partner, the manual states that "there must of course be no discriminatory treatment on grounds of nationality, race, religion, culture or the like"1. MEXT's document says the same, that discrimination by race or nationality is unacceptable, and it goes further: aiming at zero risk, or placing restrictions across broad areas of research, is not effective and has an adverse effect on research capability and on the creation of innovation4.

The manual's reasoning for refusing zero risk is written out plainly. Demanding it "would require enormous labour and cost to verify information about counterparts, or would make research institutions and researchers excessively restrained about international joint research and the like, adversely affecting the research environment. If this ends up impeding research, it defeats the purpose"1.

The regime, in other words, is designed all the way through to preventing overreaction. So when a chilling effect shows up anyway, the cause is not the rules. It is the inability to assemble a basis for judgment. With no evidence in hand, "stop it just to be safe" looks like the safest available answer to whoever has to sign. Blaming that person solves nothing, because the problem is structural. I expect this to be the live practical issue for the next two or three years, and I would rather institutions treat it as an information problem than a courage problem.

I have covered the intake of international students and researchers itself in the risks and background checks, and the conclusion there is identical. Do not judge by attribute. Verify what needs verifying, and take measures proportionate to the risk. Nothing more, nothing less. Appearing on a government list is a regulatory designation applied to an institution or a person, and it is not a statement that the institution or person has done anything wrong.

Making it work in a real lab

Last, the practical split. Assume the work divides between the research support office and the lab itself, and start here.

Who What to do
Research support office Draft the consent form and sworn statement templates. Add confidentiality and research data handling clauses to the RA employment contract. Change recruitment so due diligence information is collected at the open call stage
Lab Establish who is participating in the designated program. Decide who has access to sensitive information and equipment, and record it

The three items on the support office side are not things each lab should be inventing. Build them once at the institution level and reuse them everywhere. If nobody centrally owns the templates, every group ends up drafting its own consent form, which is a poor use of researchers' time and produces wording that varies from lab to lab.

The lab side is scope and access design. First establish who is actually participating in the designated program. Then decide who reaches the sensitive information and the sensitive equipment. The mitigation measures the manual lists are these: managing access rights to facilities and equipment, securing off-campus research locations where appropriate, considering who attends meetings based on the sensitivity of what is handled, managing access rights to research data and other information, and strengthening countermeasures against cyberattack1. Read that list and the shape becomes obvious. The centre of gravity is permissions and places, not capital spending. Nobody is asking you to build a secure facility.

Mitigation measure the manual gives What it looks like in a lab
Access rights to facilities and equipment Card access on specific rooms and instruments, reviewed when membership changes
Off-campus research locations Running a sensitive portion at a separate site rather than the shared lab floor
Meeting attendance by sensitivity Splitting the weekly meeting so the sensitive agenda has a smaller room
Access rights to research data Folder-level permissions, with a record of who was granted what and when
Cyberattack countermeasures Ordinary hardening, applied to the machines that actually hold the data

What remains after all of that is the due diligence itself. Once the population extends to students, the number of people to verify grows, and it grows fastest in exactly the labs that take on the most people. Item 11 in the manual, verifying relationships with researchers at listed institutions, is the one that breaks manual effort. It reaches co-authored papers and named joint conference presentations across the past three years, so it is not a matter of comparing names and getting an answer. The manual itself acknowledges the limit, noting that where the information gathered with public tools is insufficient, using commercial information analysis tools or commissioning investigations from firms may also be considered1.

The knowledge graph we built at TRAFEED for export control maps onto this verification almost directly. It holds more than 200 million records, roughly 90 million papers, roughly 100 million patents and roughly 300,000 researchers, alongside national lists. Traversing co-authorship and co-filing networks is a computation rather than a manual search once the data is held as a graph. Beyond researcher information, we are extending into research on the shareholders and capital relationships of collaborating organisations. The determination itself belongs to the research institution, always. What we take on is assembling the material and leaving it in a form that can explain, later, why a conclusion was reached.

The short version

  • Scope is "research participants scheduled to participate in a designated Specified Research and Development Program," and that includes students. It is not every student in the lab
  • An employment contract is an example of a mitigation measure, not an obligation. Reasonable measures proportionate to the risk are enough
  • Have the consent form and sworn statement ready before you collect anything. With students, the explanation of why matters as much as the form
  • Mid-year additions are in scope. For new hires, collecting information at the open call stage is described as desirable
  • Deciding intake by nationality is something the regime explicitly rejects. Zero risk is not being asked for either
  • The centre of the work is permissions and places, not equipment budgets

I will say the honest thing: this regime puts a load on labs. That is true and there is no point pretending otherwise. But read what is actually being asked, and it converges on a single sentence. Decide who has access to what, and how far, and keep a record of it. That is not only a research security requirement. You will need it for research data management, and you will need it again when someone has to work out who owns which piece of intellectual property from a project that ran four years ago. Seen that way, my view is that the arrival of these rules is a decent excuse to design it properly once, rather than a tax to be minimised.

If you are weighing up where your own organisation should start, talk to our TRAFEED team.

References and primary sources

Footnotes

  1. Expert Panel on Ensuring Research Security and Research Integrity, "Procedures Manual for Ensuring Research Security," December 2025 (Cabinet Office) https://www8.cao.go.jp/cstp/kokusaiteki/integrity/yushikisha/guidelines_v1.pdf 2 3 4 5 6 7 8 9 10 11 12 13 14 15

  2. Japan Science and Technology Agency (JST), "FY2026 Strategic Basic Research Programs (CREST, PRESTO, ACT-X) Call for Proposals" https://www.jst.go.jp/kisoken/boshuu/teian/koubo/2026youkou.pdf

  3. METI, Trade Control Department, Security Export Control Policy Division, "On the Clarification of Deemed Export Management" https://www.meti.go.jp/policy/anpo/law_document/minashi/meikakukanitsuite2.pdf

  4. MEXT, Science, Technology and Innovation Policy Bureau, "Direction of Concrete Measures on Research Security in MEXT-Related Programmes for Universities and Other Institutions," 18 December 2024 https://www.mext.go.jp/content/20241218-mxt_kagkoku-000039402_1-1rrr.pdf

52% of FY2024 export-control violations stem from classification errors. Is your team covered?

METI FY2024 data shows over half of violations stem from classification. Start with a free 5-question light check (~2 min, no email), then continue to the full 10-question report.

Share this article if you found it useful

シェア

Newsletter

Get the latest AI and DX insights delivered weekly

Your email will only be used for newsletter delivery.

無料診断ツール

輸出管理のリスク、見えていますか?

まず5問(約2分・メール不要)のライト診断。必要なら10問本編で詳細レポートまで。

Talk with us about export-control operations

Share your screening, classification, or compliance workflow. We will map where TRAFEED can help—via our contact form (no cold booking).

Related Articles