TRAFEED

Undisclosed Funding and Dual Affiliation: Reading the Research Security Verification Items Through the Regime That Produced Them

Published2026-07-24Ryuta Hamamoto

Undisclosed foreign funding, dual affiliation, participation in foreign talent recruitment programmes, unintended technology leakage, insider risk. This is a careful walkthrough of what those phrases actually mean in Japan's regime and why they became verification items, worked out from primary sources including the Cabinet Office procedures manual and the G7 common principles. It also sets out how explicitly the regime prohibits discrimination.

Undisclosed Funding and Dual Affiliation: Reading the Research Security Verification Items Through the Regime That Produced Them
シェア

Hello, this is Ryuta Hamamoto from TIMEWELL.

Open a research security document for the first time and the unfamiliar vocabulary arrives in a rush. Undisclosed foreign funding. Dual affiliation. History of participation in foreign talent recruitment programmes. Unintended technology leakage. Insider risk. Every one of those phrases lands with a slight chill the first time you read it.

Let me settle one thing before anything else. None of this vocabulary was created to cast suspicion on people from a particular country, or on people with a particular attribute. The regime goes to considerable lengths to head off overreaction, and it says so in writing. Even so, the words travel faster than the documents they came from, and I have watched more than a few institutions tighten up far beyond anything the government asked for.

What follows is an attempt to take that vocabulary apart. What each term actually refers to in Japanese practice, and why it ended up on a verification list, traced from the way the regime was built. If export control is new to you, running our free export compliance self-check first will give you a rough sense of where your organisation sits and make the rest of this easier to absorb. The wider picture is in the complete guide.

Translating the threat vocabulary into Japanese administrative terms

Start with the words themselves. Leave them fuzzy and the discussion turns emotional within minutes.

Phrases like "undisclosed funding" and "undisclosed affiliation" circulate widely in the international research security conversation. Read Japan's primary documents, though, and those exact phrases are nowhere to be found. What the regime uses is drier and more bureaucratic.

The "Procedures Manual for Ensuring Research Security," published by the Cabinet Office in December 20251, lists 13 matters to be verified during due diligence. Due diligence here means the process of confirming the appropriateness of the institutions and researchers taking part in a project. Undisclosed foreign funding maps onto item 3, the history of research funding received, and item 4, the history of support other than research funding received. The manual takes care to define item 4: remuneration and salary, scholarships, donations, the conferral of honorary positions, and the status of concurrent employment1.

So this is not only about money. Being given an honorary title counts. Holding a concurrent post counts.

How it is phrased internationally The expression used in Japan's regime Verification item
Undisclosed foreign funding History of support other than research funding received (remuneration and salary, scholarships, donations, conferral of honorary positions, and concurrent employment) 3, 4
Dual affiliation All current affiliations and positions, including concurrent work and unpaid roles such as emeritus professorships with no employment contract 2, 4, 10
Participation in foreign talent recruitment programmes History of participation in foreign talent recruitment programmes 7
Leakage via collaborators or subcontractors Whether relationships exist with researchers at listed institutions; due diligence on collaborating institutions 5, 6, 11
Insider risk Leakage in a form not intended by the research institution or the researcher The purpose of the regime as a whole

Having read all of the primary material end to end, there is one observation I want on the record. The manual, the MEXT document2, METI's explanatory material3, the Japanese translation of the G7 common principles4, the 2021 government policy5, and the MEXT-commissioned casebook of near-miss incidents6. Across all six, not one names a country as the source of the threat. The manual's chosen phrasing is "certain organisations or actors" and "malicious organisations or actors." The near-miss casebook goes further still, anonymising every one of its 23 cases: countries become "Country B" and "Country C," institutions become "University α" and "University β"6.

Even the teaching material the government produced for practitioners withholds the country names. I do not read that as squeamishness. I read it as design. It keeps the habit of drawing lines by attribute out of the room from the very beginning.

Why these became verification items

Understanding what the words mean is not the same as accepting why anyone is asking. Trace the lineage of the regime in three stages and the reasoning comes into view.

The starting point is 27 April 2021, when the Integrated Innovation Strategy Promotion Council adopted its policy on ensuring research integrity5. The statement of purpose in that document is worth reading closely. It notes concern that the new risks accompanying the internationalisation and opening of research activities may damage openness and transparency, the values that underpin the research environment, and that there is a danger of researchers falling unintentionally into conflicts of interest and conflicts of commitment5.

A conflict of interest is a state in which a researcher's personal financial interests could collide with the responsibilities they owe their institution. A conflict of commitment is a state in which the responsibility owed to a primary employer and the responsibility taken on for another organisation can no longer both be met. Neither is a synonym for misconduct. Both are surfaced first, then managed.

The word to sit with is "unintentionally." This policy was not built to catch researchers behaving badly. It was built the other way round, to protect researchers who might otherwise find themselves squeezed between two obligations without ever having noticed it happening, and the tool chosen was transparency. That is why the policy asked for declaration of all applications for and receipt of research funding whether domestic or foreign, of concurrent work and participation in foreign talent recruitment programmes, and of all affiliations and positions including emeritus professorships carrying no employment contract5. Not suspicion. Disclosure. That was the first instrument reached for.

The second stage is the clarification of deemed export management, in force from May 2022. "Deemed export" describes the idea that you can be treated as having exported something without shipping anything abroad, because handing over technology inside the country can itself trigger the rules. Japan's Foreign Exchange and Foreign Trade Act makes two things subject to licensing: the provision of technology across a border, and the provision of technology from a resident to a non-resident. Under the earlier practice, though, a foreign national who had been in Japan for more than six months, or who worked at an office in Japan, was treated as a resident, so providing technology to that person fell outside the controls3. There was a gap in the route that runs through people rather than through goods. The concept of "specific categories" was introduced to close it. For the underlying export control concepts, What Are Dual-Use Items? is the companion piece.

The third stage runs through MEXT's document of 18 December 20242 to the procedures manual of December 20251. This is where an additional layer appears, narrowed to critical technologies. MEXT writes that in ensuring research security, what matters first is that researchers themselves and universities carry out research integrity measures thoroughly: securing transparency in research activities and managing risk autonomously2. Integrity as the foundation, security built on top. That order is the skeleton of the whole design. The manual draws the same distinction in terms of scope, noting that research integrity covers "all research activities" while research security covers "research activities that the state or the research institution has judged should be protected"1.

Scope is where most of the misreading happens, so let me be precise about it. The manual's framework does not apply as written to all research. It applies to competitive research funding premised on public disclosure of results, where the ministry with jurisdiction, in consultation with the funding agency that distributes the money, has designated a programme as potentially involving technologies on the list of critical technology areas. Those are called Specified Research and Development Programs1. The people subject to verification are the principal investigator, co-investigators, and research participants belonging to the lead institution. Students count as research participants1. If you supervise, that is worth sharing with your group before anything else.

The actual footprint is still narrow. In JST's FY2026 application guidelines, the only things designated as Specified Research and Development Programs within the Strategic Basic Research Programs are five CREST research areas. PRESTO and ACT-X are outside the scope. It applies from newly adopted FY2026 projects onward. The Acquisition, Technology and Logistics Agency's security technology research promotion programme also came into scope from its FY2026 call. So the picture of questionnaires suddenly landing on every researcher's desk is not the one to have in your head.

The manual also declines to ask for zero risk. What it asks for is to "limit the technologies in scope and handle them reasonably in proportion to the degree of risk"1. The method is set out as four steps: risk identification, risk assessment, risk mitigation measures, and follow-up1. Rather than scrutinising everything to the same standard, you put effort where the weight is. The design philosophy leans firmly that way.

Put together: first ask for disclosure, then close the statutory gap, then add a layer for critical technologies only. Three stages of accumulation, arriving on your desk today as 13 items on a questionnaire. How this became a condition of application is covered in Research Security as a Funding Condition.

Replace siloed classification work with AI.

METI's FY2024 data shows 52% of foreign exchange law violations stem from classification errors. Download the TRAFEED product catalog covering features and rollout.

Dual affiliation and "specific categories." Falling under one is not a verdict

Of the 13 items, the one that makes people most tense is item 12, status as a non-resident or under a specific category in security export control. Get this one wrong and you will invent boundaries nobody asked for.

Broadly, the specific categories cover three situations. A person under the control of a foreign government or foreign corporation by contract. A person who receives, or has promised to receive, significant benefit from a foreign government or equivalent body. And a person who receives instructions or requests from a foreign government or equivalent body concerning their conduct in Japan. METI's explanatory material gives concrete examples of what this looks like at a university: faculty and staff holding concurrent posts at a foreign university, students receiving study funding from a foreign government, and researchers participating in a foreign government programme who receive substantial research funding or living expenses in a personal capacity3.

Most readers will tighten up at this point. Which is exactly why the next sentence in the same document has to be read alongside it.

Specific categories are no more than a grouping of the cases that need to be verified individually during screening, and falling under a specific category does not mean that the person is regarded as posing a security concern3

That sentence appears twice in the same METI document. Once on the page addressed to universities and research institutions, once on the page addressed to companies. Placing the same caveat twice is a deliberate repetition. When an administrative document repeats a sentence, it is usually because the drafters know how easily that point gets misread.

The regime does not ask for intrusive background investigation either. For students not under the institution's direction, visiting faculty and similar cases, it is enough to confirm status from the contractual documents you would ordinarily obtain under normal commercial practice, and where those documents do not make the status clear, no further investigation is required3. What is criticised is only the case where the status was plainly apparent and technology was handed over anyway.

Dual affiliation follows the same logic. Cross-appointment, where a researcher holds a position at more than one institution with an employment contract at each, is ordinary research practice. So is teaching part-time at an overseas institution. What creates a problem is not the arrangement. It is the arrangement going undeclared, leaving the institution without the material it needs to make a judgement. The MEXT-commissioned near-miss casebook includes the case of a professor invited to serve as a part-time lecturer by an overseas university. The letter of appointment described roughly two hours once a month. The draft contract that arrived afterwards listed at least one month of work per year, publication of multiple papers, and an obligation to jointly apply for an international programme6. The two documents did not say the same thing. The professor read the draft and asked for it to be amended.

There is no bad actor anywhere in that story. The whole thing turns on whether someone noticed that two pieces of paper disagreed. To my mind that case captures the substance of the dual affiliation question better than any definition does.

Unintended leakage, insider risk, and the omitted declaration

The last piece of vocabulary, insider risk, does not strictly appear in the manual at all. It is defined in the common values and principles produced by the G7 SIGRE working group in June 2022, and the Japanese translation puts it this way.

Insider risk can arise from persons who know or have access to an organisation's infrastructure and information, and from persons who may obtain unauthorised access to research inputs, processes and knowledge for illegitimate purposes, whether deliberately or through carelessness4

"Whether deliberately or through carelessness" is the decisive clause. The document goes further, noting that in many cases such individuals have little or no formal espionage training and are often using relatively open tools, consciously or otherwise4. It adds that risk also comes from personnel who are not involved in illegitimate knowledge transfer at all, but who fail to observe adequate security measures or who mistakenly provide unauthorised access4.

Even in the international framing, the figure being described is not the spy from the film. Carelessness carries a great deal of the weight.

The manual's counterpart expression is leakage "in a form not intended by the research institution or the researcher"1. The near-miss casebook expands the phrasing from the 2021 policy into "the danger of researchers falling unintentionally into conflicts of interest, conflicts of commitment and technology leakage"6. The wording shifts by source. What is being pointed at does not.

The same casebook carries a researcher-facing case called "unintended co-authorship." A professor co-wrote a paper with a professor at an overseas university on research that raised no export control questions whatsoever. The other party was the corresponding author. Our professor checked their own section and left the remaining process to the counterpart. Later it emerged that among the co-authors was a researcher belonging to an institution that had attracted regulatory attention. It was picked up in the press. The casebook records that the professor had never met that researcher, had no history of joint research with them, and that the situation came "entirely out of the blue"6.

For the avoidance of doubt, an institution appearing on a list or drawing regulatory attention is a matter of regulatory categorisation. It is not a finding that the institution, or the researchers who work there, did anything wrong. What the casebook is pointing at is not the merits of the counterpart either. It is the single fact that the professor did not know what their own name was attached to.

Because that can happen, checking co-authors became an item. Read the other way round, the verification items are not an expression of suspicion. They are a guard rail against being swept into something you never chose.

Now the part I most want to land. An omitted declaration is not necessarily an act of bad faith. And the regime itself is built on that assumption.

Four things support this. First, the wording of the written declaration set out in the manual is that "the personal data declared is, to the signatory's knowledge, current as at the time of declaration and contains no false content and no omissions"1. That is not a demand for infallibility. Second, what triggers a government response is limited to cases where "an intentional false declaration or deliberate concealment has been made"1. Third, the remedy when an error surfaces is correction rather than penalty: the research institution reports promptly to the funding agency, and due diligence is carried out again on the corrected information1. Fourth, on leakage that occurs despite adequate measures having been taken, the manual states plainly that "in that case, the research institution and the researcher do not bear responsibility"1.

Obligations also fall on the side collecting the data. What you need before collecting is a consent form and a written declaration, and the consent form must limit the purpose of use and specify the scope of any provision to third parties1. You do not repurpose what you collected. That promise is built into the regime itself. Where there has been an intentional false declaration, the consequences are handled as improper receipt under the "Guidelines on the Proper Execution of Competitive Research Funding" and can lead to restrictions on future applications1.

Correction rather than sanction. Honesty rather than perfection. That is the straightforward reading of how the framework is put together. Simply attaching those four points to the declaration form when you circulate it changes how researchers receive the whole exercise.

Collaborators and subcontractors: the route that is hard to see

The final piece of vocabulary is leakage through a collaborator or a subcontractor. This is the hardest one in practice, because securing your own perimeter does not address it.

When the manual defines a "collaborating institution," it explicitly includes not only institutions conducting research jointly but also institutions to which part of the research has been subcontracted1. Subcontractors sit inside the same frame. The G7 document likewise addresses supply chain attacks, where partners and suppliers of a research institution are targeted as a way of reaching the intended victim4. Attackers go where the defences are thinnest. That is as true in export control as it is in cybersecurity.

Among the verification items, item 11 is the one that covers this route. It asks whether relationships exist with researchers at listed institutions, and the manual defines "relationships" as conducting joint or commissioned research, writing and publishing co-authored papers, and appearing as a named co-presenter at conferences and similar events1. It does not end with the simple name matching that items 9 and 10 involve. The reason is structural: neither the individual nor their institution appears on any list, and you still have to work out whether following the chain of co-authorship arrives at a researcher at a listed institution. The window is three years including the year of application. Of the 13 items, numbers 3 through 8 plus 10 and 11 all carry that same "past three years including the year of application" window1.

Written out like that it sounds hopeless, but nobody is being asked to play detective. Due diligence may be carried out "using self-declared information, open source information and other information that each lead institution can ordinarily obtain"1. The tools it names are all publicly accessible: academic paper databases, portals such as Google Scholar, researcher databases such as e-Rad and researchmap, IP databases such as J-PlatPat, METI's End User List, and the United States consolidated screening list. It then adds that "where the information gathered using these tools alone makes adequate due diligence difficult, using commercial information analysis tools or commissioning investigations from firms may also be considered"1. Build it in house or bring in outside help. That call is left to each institution.

Checks on supporters are included as a "desirable" measure. For individuals and organisations providing grants, donations or goods, you confirm the nature of the support, its purpose and conditions, the financial position and capital structure, and whether they appear on any list. On purpose and conditions, the manual notes that you might check whether anything is being asked for in return1. On the contractual side, four confirmations are treated as the minimum: the nature of the cooperation, access to research data, the treatment of intellectual property, and the content of confidentiality obligations1.

Let me say a little about our own work here. What we have built at TRAFEED is an AI agent for Japan's security export control regime, covering both list controls, which decide whether an item is caught based on its specifications, and catch-all controls, which decide whether verification is needed based on the end use and the parties to the transaction. We believe it is the first AI agent of its kind in this field, based on our own research as at March 2026. Underneath it sits a knowledge graph of more than 200 million records, a database that holds people, organisations, papers and patents as connected edges, comprising roughly 90 million papers, roughly 100 million patents and roughly 300,000 researchers, alongside corporate registries and national sanctions lists. In a joint demonstration with Okayama University, we confirmed AI determination accuracy of over 95% against roughly 30,000 historical screening records (our own study). We hold Japanese Patent No. 7862062 and have been adopted by more than 20 organisations.

The graph structure fits an item like 11 without much translation. You pull affiliations, funding and co-authorship relationships across public sources and surface only the differences against what the researcher declared. Rather than a human reading every record, attention goes to the places where two accounts disagree, or where there is a good chance the researcher does not know either. The "unintended co-authorship" case above is precisely the kind of thing that difference report catches. Alongside researcher information, we are extending into shareholder and capital relationship research on collaborating organisations.

To be clear about where this stands: the features aimed specifically at research integrity and research security are an area we are still building out. And more importantly, the final determination belongs to the research institution, or in a corporate setting to each company's export control officer. What we can carry is the assembly of the material and leaving the basis for a conclusion in a form that can be explained afterwards. The mechanics of the due diligence process itself are covered in Research Security Due Diligence.

What to take away

  • Undisclosed foreign funding and dual affiliation are, in Japan's regime, matters of disclosure: "history of support other than research funding received" and "all current affiliations and positions." This is not an enforcement framework
  • The items exist because of a three-stage accumulation: ask for disclosure, close the deemed export gap, then add a layer for critical technologies
  • Falling under a specific category is not a verdict. METI placed the same caveat twice to make sure that lands
  • The international definition of insider risk includes "whether deliberately or through carelessness." Spies are not the only scenario being modelled
  • An omitted declaration is not necessarily bad faith. The "to the signatory's knowledge" wording, the intent requirement, the correction route and the express relief from responsibility are the four grounds for reading it that way
  • Subcontractors sit in the same frame as collaborators. Checking relationships does not end with matching names
  • The manual applies as written to funding designated as a Specified Research and Development Program, and the population verified covers PIs, Co-PIs and research participants including students
  • The manual does not ask for zero risk. It asks you to limit the technologies in scope and handle them in proportion to the risk, and the investigation stays within publicly available information you can ordinarily obtain

How you present a regime genuinely changes the atmosphere in which it operates. The manual, the MEXT document and the G7 principles all reject discrimination on grounds of nationality or race, and all decline to ask for zero risk. Yet if the people running it apply more pressure than that, the open research environment the regime set out to protect is the first thing to break. That is the failure mode I would least like to see.

So there is one thing I would ask of anyone circulating a declaration form or a questionnaire. Put a sentence at the top saying, in plain words, that this is not an accusation. That one line changes the quality of what comes back.

If you are working out where to start at your own organisation, talk to our TRAFEED team.

References and primary sources

Footnotes

  1. Expert Panel on Ensuring Research Security and Research Integrity, "Procedures Manual for Ensuring Research Security," December 2025 (Cabinet Office) https://www8.cao.go.jp/cstp/kokusaiteki/integrity/yushikisha/guidelines_v1.pdf 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22

  2. MEXT, Science, Technology and Innovation Policy Bureau, "Direction of Concrete Measures on Research Security in MEXT-Related Programmes for Universities and Other Institutions," 18 December 2024 https://www.mext.go.jp/content/20241218-mxt_kagkoku-000039402_1-1rrr.pdf 2 3

  3. METI, Trade Control Department, Security Export Control Policy Division, "On the Clarification of Deemed Export Management" https://www.meti.go.jp/policy/anpo/law_document/minashi/meikakukanitsuite2.pdf 2 3 4 5

  4. G7 SIGRE Working Group, "G7 Common Values and Principles on Research Security and Research Integrity" (Japanese translation), June 2022 https://www8.cao.go.jp/cstp/kokusaiteki/integrity/g7_sigre_values_jpn.pdf 2 3 4 5

  5. Integrated Innovation Strategy Promotion Council, "Policy on Ensuring Research Integrity Against New Risks Accompanying the Internationalisation and Opening of Research Activities," 27 April 2021 https://www8.cao.go.jp/cstp/kokusaiteki/integrity/integrity_housin.pdf 2 3 4

  6. FY2024 MEXT Commissioned Project, "Casebook of Research Integrity Near-Miss Incidents (Casebook of Risks in Research Activities at Universities and Other Institutions, Focusing on Ensuring Research Integrity)," March 2025 https://www.mext.go.jp/content/20250331-mxt_kagkoku-000019002_1.pdf 2 3 4 5

52% of FY2024 export-control violations stem from classification errors. Is your team covered?

METI FY2024 data shows over half of violations stem from classification. Start with a free 5-question light check (~2 min, no email), then continue to the full 10-question report.

Share this article if you found it useful

シェア

Newsletter

Get the latest AI and DX insights delivered weekly

Your email will only be used for newsletter delivery.

無料診断ツール

輸出管理のリスク、見えていますか?

まず5問(約2分・メール不要)のライト診断。必要なら10問本編で詳細レポートまで。

Talk with us about export-control operations

Share your screening, classification, or compliance workflow. We will map where TRAFEED can help—via our contact form (no cold booking).

Related Articles