Legal & Ethical Governance
Code: GOVERN
Consider research ethics throughout project lifecycles and include information and guidelines on good research conduct and governance that follow all legal and ethical requirements or policies.
GOVERN 1.0.0 Ethical governance foundations
Ethical governance ensures user research protects participants, organisations and researchers. It requires continuous reflection on risks, consent, safeguarding, legal frameworks and appropriate review mechanisms.
GOVERN 1.1.0 Continuous ethical governance responsibilities
GOVERN 1.1.1
Continuous Ethical Governance
Ethics must be reviewed before, during and after research. This includes risk assessment, meaningful consent, safeguarding, and clear escalation routes. Ethical governance is not a one-off task but an ongoing obligation.
GOVERN 1.1.2
Understanding Relevant Legislation
Researchers must understand and apply relevant legislation including:
- GDPR & Data Protection Act
- Equality Act (2010)
- Accessibility Regulations for public sector bodies
- UKRI-ESRC or equivalent organisational research ethics frameworks
Legal considerations must be embedded into planning, recruitment, facilitation and data handling procedures.
GOVERN 2.0.0 Internal ethics review & operational compliance
As research maturity increases, formal ethics reviews and operational compliance procedures become essential. These ensure risk is understood, documented and mitigated.
GOVERN 2.1.0 Framework for Internal Ethics Review
GOVERN 2.1.1
Internal Ethics Review Requirements
Some studies require formal ethics review depending on topic sensitivity, participant vulnerability or organisational risk.
- Establish an ethics committee including legal, data protection and research specialists.
- Define criteria for when review is mandatory.
- Use standard ethics application forms documenting purpose, risks, safeguards and data handling.
- Define predictable review timeframes to avoid delivery delays.
- Store decisions and conditions for organisational learning.
GOVERN 2.1.2
Operational GDPR & Compliance Procedures
Compliance must be embedded throughout research activity.
- Standardise consent models and secure storage.
- Include compliance checklists in research plans.
- Define protocols for capture, transfer, storage, sharing and disposal.
- Conduct periodic audits of research projects.
- Maintain an incident response plan for data breaches involving research data.
GOVERN 3.0.0 Bias, fairness & research risk
Research must proactively identify and mitigate sources of bias, protect fairness and manage potential risks to participants, researchers and the organisation.
GOVERN 3.1.0 Bias Management & Fairness Practices
GOVERN 3.1.1
Managing Bias & Fairness in Research
Bias may arise at any stage of research. Organisations must provide tools and training to identify and reduce it.
- Provide bias awareness training.
- Encourage diversity in research teams.
- Peer review topic guides and instruments.
- Ensure inclusive recruitment and monitor representation gaps.
- Audit studies periodically for fairness issues.
GOVERN 3.1.2
Research Incident Handling & Risk Mitigation
Research can expose participants or researchers to risks if poorly planned.
- Require study-level risk assessments.
- Document foreseeable risks and safeguards.
- Provide clear guidance for distress, safeguarding or disclosures.
- Use an incident log to support organisational learning.
- Review and update risk procedures annually and after incidents.
Glossary & Definitions
- Ethics Committee
- A group responsible for reviewing high-risk studies to ensure ethical and legal safeguards are in place.
- Lawful Basis
- A GDPR requirement defining the legal justification for processing personal data.
- Safeguarding
- Measures that protect participant welfare and prevent harm, particularly for vulnerable groups.
- Research Incident
- An unplanned event during or after research that affects participant safety, legal compliance or data security.
- Bias
- Systematic distortion in design, delivery or interpretation of research.
Templates & Artefacts
Change History
| Version | Date | Summary of Changes | Author / Owner |
|---|---|---|---|
| 0.1-draft | 2025-12-11 | Converted to unified A1 numbering; nested structure corrected; reformatted content into 1.0.0/1.1.0 pattern; added skos metadata throughout; aligned with ENVIRO template structure. | ResearchOps Governance Team |