03 · What You Need to Know
Why Ethical Research Can Still Fail an Institutional Rule
Ethics, Institutional Permission, and Legal Compliance Are Three Different Questions
Researchers often collapse several forms of authorization into one idea. Keeping them separate makes disagreements easier to understand.
Ethical defensibility
Asks whether the research can be justified in light of relevant ethical principles, rights, risks, burdens, benefits, fairness, and responsibilities.
Institutional permission
Asks whether the research satisfies the policies, procedures, access conditions, and governance requirements of the organization under whose authority or resources it will be conducted.
Legal and regulatory compliance forms another layer. A project may therefore need to be ethically defensible, legally permissible, and institutionally authorized before it can proceed.
Passing one layer does not automatically satisfy the others.
Institutions Can Adopt Requirements That Are More Protective Than Regulatory Minimums
The distinction is not merely theoretical. The U.S. Office for Human Research Protections explains that institutions may apply Common Rule protections to research even when that research does not otherwise fall under the Common Rule, and institutions can implement policies and procedures that are more protective than regulatory requirements.
An institution might therefore require internal review for research that does not independently require a particular form of federal review. It might impose stronger data-security standards, require particular consent procedures, restrict certain recruitment practices, or establish additional safeguards for particular populations.
Those institutional choices do not necessarily mean that every less restrictive alternative would be unethical. They mean the institution has established the conditions under which it is willing to authorize research within its system.
Institutions Regulate More Than Participant Ethics
Research institutions have responsibilities and interests extending beyond the ethical evaluation of a single protocol.
They may need to manage information security, legal liability, insurance, clinical operations, student records, staff workload, intellectual property, contractual commitments, use of facilities, reputational risks, cybersecurity, conflicts of interest, biosafety, or relationships with external organizations.
A restriction may therefore originate from an office other than the research ethics committee.
For example, an ethics committee might consider a data-collection plan acceptable from the perspective of participant risk, while the institution's information-security office prohibits storing the data on a particular cloud service. The disagreement is not necessarily about research ethics. Different institutional responsibilities are being applied to the same project.
Institutional Rules Often Standardize Decisions That Could Otherwise Be Made Case by Case
Ethical judgment is highly contextual. Institutional administration often needs standardized procedures.
An institution may therefore adopt a broad rule because evaluating every case individually would be impractical, inconsistent, expensive, or difficult to monitor. Such a rule may prohibit some individual cases that a researcher could plausibly defend ethically.
That does not automatically make the rule unreasonable. Nor does it prove the rule is optimal.
The important distinction is between asking whether one specific study could be ethically justified and asking what policy an institution should apply consistently across many researchers, projects, and circumstances.
An Institution May Apply Research Protections More Broadly Than External Regulation Requires
OHRP notes that many institutions voluntarily apply Common Rule provisions to all of their human-participant research regardless of funding source. Institutions may do this through formal assurances or internal policy.
This means a project that falls outside a particular federal regulatory requirement can still be subject to institutional research review.
A researcher should therefore avoid reasoning, “This is not federally regulated, so my institution cannot require review.” External regulatory scope and internal institutional policy are different sources of authority.
Exemption From a Regulation Does Not Necessarily Mean Exemption From Institutional Process
Another common confusion involves the word exempt.
In regulatory systems, exemption ordinarily means exemption from specified regulatory requirements under defined conditions. It does not necessarily mean that researchers may independently begin the project without any institutional determination or procedure.
OHRP, for example, has long recommended that investigators not independently determine that their own human-subject research is exempt because of the potential conflict of interest, although institutions may establish their own processes for making exemption determinations.
Researchers should therefore distinguish “this activity qualifies for a regulatory exemption” from “my institution requires no review, registration, or determination.”
Ethics Committee Approval May Not Override Other Institutional Authorities
Researchers sometimes assume that favorable ethics review is the highest institutional permission a study can receive.
That is not necessarily how research governance works.
An institution may require approval from several bodies. A hospital research project might need ethics review, departmental permission, data-governance approval, site authorization, pharmacy review, radiation safety review, or other clearances depending on the research.
An ethics committee's approval ordinarily applies within its remit. It does not automatically compel every other institutional unit to authorize the project.
This is another reason ethics committee approval should not be treated as universal clearance.
Institutional Restrictions Can Sometimes Protect Researchers as Well as Participants
Some rules exist partly to protect participants, but others also protect researchers from taking on responsibilities they may not recognize.
A prohibition against storing sensitive research data on personal devices, for example, may reduce participant risk while also protecting the researcher from accidental disclosure. A rule requiring supervisory approval before student researchers recruit vulnerable populations may provide additional expertise and accountability.
Institutional bureaucracy is easy to experience as an obstacle when a deadline is approaching. Occasionally, however, the annoying form is guarding a problem that would be much more annoying after the data breach.
Institutional Rules Can Also Be Overly Restrictive
The fact that an institution has authority to create rules does not establish that every rule is ethically ideal.
A policy may be outdated, drafted for a different kind of research, applied inconsistently, or more restrictive than necessary. A rule intended to protect a population might inadvertently exclude that population from research relevant to its needs. A blanket prohibition might prevent low-risk research that could have been managed safely through proportionate safeguards.
Ethical scrutiny can therefore be directed at institutional policy itself.
The appropriate conclusion, however, is not that individual researchers may simply disregard rules they consider misguided. Institutional policies usually provide mechanisms for interpretation, exception, appeal, revision, or escalation. Researchers should use those mechanisms where available.
Disagreement With a Rule Is Different From Permission to Ignore It
A researcher may have a persuasive argument that an institutional restriction is unnecessary. That argument can support a request for reconsideration. It does not automatically create authorization to proceed.
Quietly violating the policy may create additional ethical and integrity concerns, particularly if the researcher conceals the deviation from participants, supervisors, collaborators, funders, or the institution.
Research ethics includes accountability for how research is conducted within legitimate systems of oversight. Disagreement should therefore be made visible and addressed through appropriate channels.
Institutional Rules Can Conflict With Ethical Considerations
The more difficult case arises when following a rule itself appears to create an ethical problem.
Suppose an institutional data-retention policy requires retaining identifiable information longer than a researcher believes is necessary, potentially increasing privacy exposure. Or imagine a blanket exclusion policy that prevents a population from participating in research directly relevant to it.
The researcher should first determine whether the apparent conflict is real. Policies are sometimes more flexible than their informal summaries suggest.
If the conflict remains, researchers can document the ethical concern, consult the responsible office, propose an alternative safeguard, request an exception if a mechanism exists, or seek formal policy reconsideration.
The broader question of what to do when ethical considerations point in different directions also applies when governance structures create competing responsibilities.
Different Institutions Can Reach Different Policy Decisions
Two universities may regulate identical low-risk research differently. One may require full institutional submission, another a brief registration, and another may place the activity outside its ethics-review system.
This variation does not necessarily prove that one institution understands ethics and the other does not. Differences can reflect regulatory environments, institutional risk tolerance, available resources, organizational history, research portfolio, local law, or governance philosophy.
Researchers working across institutions should identify which organization's requirements apply rather than assuming the rules of their home institution automatically govern every collaborating site.
Institutional Permission Is Not Proof of Ethical Perfection Either
The distinction works in both directions.
An institution may permit a study, but researchers remain responsible for recognizing ethical issues that arise during its actual conduct. Institutional authorization does not turn every permissible choice into the ethically preferable one.
This parallels the broader distinction between ethical justification and formal compliance. Authorization matters, but researchers still have to think.