03 · What You Need to Know
How to Respond When the Problem Is Discovered After Data Collection
First, Confirm That Approval Really Was Required
Do not begin by assuming either guilt or exemption. Establish the project's actual status under the rules that applied when the research was conducted.
The activity might have required full or expedited review. It might instead have qualified for exemption, fallen outside the applicable human-participant research definition, or been governed by another institutional process.
The appropriate determination should come from the body authorized by your institution rather than from a retrospective internet search or a colleague's informal opinion.
Why This Step Matters
Researchers often use “no ethics approval” to describe several different situations:
| Situation |
What It May Mean |
| No application was submitted |
The study may have required approval, may have been exempt, or may have fallen outside the relevant framework |
| Researcher assumed exemption |
The study may satisfy an exemption, but the institution may have required an authorized exemption determination |
| Project was initially classified as evaluation |
The original classification may have been correct, or the project may later have developed a research component |
| Data were believed to be anonymous |
The actual information collected may or may not satisfy the applicable standard for nonidentifiability |
| Research was conducted without required approval |
The institution may need to assess noncompliance and determine corrective action |
These situations should not be treated as interchangeable.
If Required Approval Was Missing, Do Not Try to Rewrite the Timeline
Preserve the dates on which recruitment, consent, data collection, analysis, and institutional decisions actually occurred.
Do not backdate an approval letter, alter consent dates, relabel the project after the fact, or change protocol documents to imply that a prospective process occurred when it did not.
An accurate chronology gives the institution the information needed to distinguish misunderstanding, administrative error, unapproved research, and other forms of noncompliance.
Watch Out
A documentation problem should not become a research-integrity problem. Keep the record accurate even when the chronology is uncomfortable.
Pause Activities That Could Compound the Problem
Although primary data collection may be complete, other research activities may still be underway. Follow-up contacts, participant validation, additional record extraction, linkage with other datasets, secondary questionnaires, interventions, or recruitment at another site may still be planned.
Pause unapproved participant-facing or otherwise covered activities as appropriate and seek institutional instructions before continuing.
If an immediate participant-safety issue exists, address that first and notify the relevant institutional authorities promptly.
Secure the Existing Data
Do not treat the dataset as ordinary approved research material while its status is unresolved.
Restrict unnecessary access. Preserve audit trails where available. Avoid additional sharing, linkage, analysis, or dissemination beyond what is needed to assess and protect the records. Maintain appropriate security for identifiable or sensitive information.
If a confidentiality or data-protection breach also occurred, separate privacy or institutional reporting requirements may apply.
Do Not Automatically Delete the Dataset
Deleting everything can feel like the cleanest ethical response. It is not always the correct first step.
The institution may need the records to establish how many participants were involved, what information was collected, whether consent existed, what risks arose, and what corrective action is appropriate. Other legal, regulatory, contractual, or research-integrity requirements may also affect record retention.
Secure the data and obtain instructions before deciding their final disposition.
Document What Happened Before Memory Becomes the Dataset
Create a factual account while the details are still recoverable. Include the project's purpose, dates, participant population, recruitment method, consent process, procedures, data collected, identifiers, risks, data access, and how the missing approval was discovered.
Also document why the research team believed approval was unnecessary or why the requirement was missed. That explanation does not erase the event, but it helps the institution understand whether the problem arose from misunderstanding, poor training, workflow failure, deliberate bypassing of review, or another cause.
Report Through the Appropriate Institutional Channel
The relevant contact might be the REC, IRB, Human Research Protection Program, research-compliance office, research integrity office, institutional research office, or another designated authority.
Under the U.S. HHS framework, institutions maintain procedures for prompt reporting of serious or continuing noncompliance and other specified events. OHRP's published compliance determinations include research conducted without required IRB review or approval as a recognized category of noncompliance.
The institution, rather than the investigator alone, should determine how the incident is classified.
Do Not Minimize the Problem Before It Has Been Assessed
“It was only an anonymous survey,” “there were only twelve participants,” or “nobody was harmed” may be relevant facts, but they are not substitutes for an institutional assessment.
Risk, participant number, consent, identifiability, intent, duration, and recurrence can all affect how an incident is evaluated. An isolated low-risk error and deliberate conduct of a high-risk unapproved study are plainly different, but both should be characterized from evidence rather than researcher reassurance.
The Institution May Need to Assess Noncompliance
Under U.S. HHS requirements, research covered by the regulations must receive the appropriate IRB review and approval before it is conducted. OHRP has published compliance determinations specifically identifying covered research conducted without required IRB review or approval.
Whether a particular incident is serious or continuing noncompliance depends on the circumstances and applicable institutional process. Researchers should report the facts rather than assigning themselves the most favorable classification.
Participant Harm and Regulatory Noncompliance Are Different Questions
A study can involve no apparent participant injury and still have been conducted without a required procedural protection. Conversely, an incident involving missing approval can coincide with actual harm or a confidentiality breach.
Participant impact
What risks, burdens, harms, or rights-related consequences participants actually or potentially experienced.
Compliance status
Whether the research followed the applicable ethics-review and institutional requirements.
Both matter, but one should not be used to erase the other.
The Institution May Decide That Participants Need Further Protection
Depending on what occurred, participants may need additional information, follow-up, re-consent for a future use, clinical support, privacy notification, or another corrective response.
Do not contact participants with an improvised explanation unless immediate safety requires action. Coordinate with the appropriate institutional authority so that any communication is accurate and does not create additional problems.
Later Approval Is Not the Default Remedy
The instinctive request is often: “Can the committee approve the study now?” But retrospective ethics approval generally cannot recreate the prospective review that was missing.
The ethics body may instead review future activities, determine the status of the existing data, assess the incident, or issue another form of institutional determination appropriate to its authority.
What if the Study Would Have Qualified for Exemption?
This can materially change the analysis. If the project satisfies an exemption category, the institution may determine that ordinary ethics approval was not required, although its policies may still have required an exemption determination before research began.
That is why researchers should not jump directly from “no approval letter” to “unethical study.” The first task is to determine who had authority to determine exemption and what process applied at the time.
What if the Data Were Existing or Public?
Secondary research can also create classification confusion. If the study used existing records, the institution may need to determine whether investigators obtained identifiable private information and whether an exemption applied.
If the information was genuinely public, the analysis can be different again. Neither existing data nor publicly available information should be classified solely from their labels.
What if the Research Was a Student Project?
A student may discover the issue while preparing a thesis defense or manuscript. Academic deadlines do not change the institutional response, and an adviser's approval of the project does not necessarily substitute for REC or IRB authorization.
Students should involve their supervisor while also following the institution's formal research-ethics process. The objective is to establish what happened and correct it, not to find wording that will make the thesis examiner stop asking questions.
Publication Should Wait Until the Ethics Status Is Resolved
If you discover the missing approval while preparing or submitting a manuscript, resolve the institutional ethics issue before representing the study to a journal as compliant.
ICMJE's current recommendations advise authors reporting human research to seek approval from an independent review body. Editors also retain their own judgment concerning whether the research was conducted appropriately.
Accordingly, an institutional decision about the dataset and a journal's willingness to publish are related but separate questions.
Correct the Process, Not Just the Current Manuscript
A useful institutional response should ask why the problem happened and how recurrence can be prevented.
Possible corrective actions may involve training, clearer approval workflows, better documentation, changes to supervision, automated controls preventing survey activation, protocol tracking, or clearer distinctions among research, evaluation, and exempt activities.
If the only lesson is “next time hide the spreadsheet better,” the research-governance problem remains impressively undefeated.