Guide — Research Security
The disclosure was already in the file.
Federal research security enforcement rarely turns on facts nobody knew. It turns on facts an institution had written down, in its own systems, that never reached the certification it signed. That is a reconciliation problem — and reconciliation is a records problem.
- Foreign affiliation
- Recurring review
- Decision evidence

Decision before access
Intake, screening, review, approval gate, and evidence export stay on one record.
August 31, 2026
Two things happened on the same day
Thirty U.S. academic institutions faced a Department of War deadline to report the results of an ordered review of their academic, financial, and research collaborations with foreign entities of concern — including institutions named under Section 1286 of the FY19 NDAA and organizations associated with rebranded Confucius Institutes. Institutions were directed to assess exposure of sensitive and export-controlled research and to produce mitigation plans.
On that same date, a public settlement agreement was executed between the Department of Justice — acting for NASA and the National Science Foundation — and a major public research university, resolving civil claims for $2.1 million in restitution. The United States contended that the university failed to disclose foreign affiliations and foreign government funding held by researchers working on federal grants. The university denies the allegations, and the agreement is expressly not an admission of liability.
Read together, the two documents describe the same week from opposite ends. One tells institutions to go find these relationships. The other shows the cost when an institution already had them.
Pattern
The failure mode is reconciliation, not discovery
The detail that matters most in the settlement is not that a relationship was hidden. According to the agreement, the researcher’s guest, adjunct, visiting, and advisory positions with foreign universities and state-run research organizations were reported on annual faculty activity reports submitted to his own department — since at least 2014.
The institution held the information for roughly a decade. What the United States contended is that it never reached the grant applications or the requests to draw down grant funds. Two systems of record inside one organization, never compared.
A second gap in the same document is about elapsed time rather than linkage. The agreement recites that the university learned of a foreign talent program participation in September 2019 and disclosed it to the funding agencies in 2023. Knowing something and owing someone that knowledge are different events, and the interval between them is itself reviewable.
Neither gap is a screening failure. No watchlist would have closed either one. Both are failures of a record: nothing joined the internal disclosure to the external certification, and nothing started a clock when the obligation attached.
Scope
This is not only a university problem
The same structure appears wherever an organization collects affiliation information once and certifies something to the government later. A cleared contractor onboards a foreign national and records their prior employer. A national laboratory approves a visiting researcher and notes their home institution. Two years on, that person is working under a different contract, in a different area, against a different set of representations — and nothing re-examined the affiliation that was captured on day one.
The exposure is not hypothetical. The settlement described above released only common-law claims; it reserved False Claims Act liability, criminal liability, individual liability, and administrative remedies such as suspension and debarment. A payment resolves a civil claim; it does not necessarily end the matter.
Self-assessment
Four questions to ask about your own file
- Where does affiliation live? If foreign affiliation is captured as free text on an onboarding or intake form and never normalized, it cannot be compared to anything. A field you cannot query is not a control.
- What re-examines it? A point-in-time check answers a question about the day it ran. An affiliation that was true in 2014 and still true in 2019 only resurfaces if something looks again on a schedule.
- Can you prove what you knew, and when? The hardest question in a retrospective review is reconstructing your own timeline. If that reconstruction depends on email threads and spreadsheets, it is an argument rather than a record. An append-only, tamper-evident log answers it as a fact.
- Did you record why you proceeded? Most relationships reviewed in an audit are legitimate and continue. Counsel guidance in this area often emphasizes documenting the basis for continuing a lower-risk relationship — not merely the decisions to terminate. An undocumented approval and an unexamined one look identical two years later.
Product fit
How Regulated Access maps to this
Regulated Access is pre-access decision infrastructure. It structures the decision to grant a person access to a controlled area or controlled data, and it produces the record of that decision. Three parts of it bear directly on the failure mode described above.
- An append-only decision record. Every decision, note, information request, and screening result writes to a hash-chained audit log that is append-only at the database trigger level — updates and deletes are blocked. It carries identifiers, codes, and timestamps rather than personal data. It answers “what did we know, and when” without relying on anyone’s recollection.
- Scheduled re-review. For configured pilots, active approvals are re-screened on a schedule, and each run links back to the screening history that preceded it, so an approval is a maintained position rather than a one-time event.
- Recorded basis for proceeding. Reviewers resolve screening matches against a fixed set of resolution codes, and overrides are captured with a reason code and an actor. The record shows the judgment, not only the outcome.
What it does not do, stated plainly: Regulated Access does not manage faculty disclosure programs, conflict-of-commitment workflows, or grant certifications, and it does not reconcile institutional forms against federal filings. Denied-party screening runs for configured pilot organizations rather than by default. It is not a substitute for a research security or export compliance program, and nothing here is legal advice — license determinations, disclosure obligations, and final access decisions remain the organization’s own.