Research security as part of funding applications ‒ experiences and lessons from the first application round

21 Sep 2026

In recent years, research security has become an increasingly central aspect of the responsible planning and conduct of science and research. The amendment to the Act on the Research Council of Finland, which came into force in July 2025, required the RCF to ensure that research security and the associated risks are taken into account appropriately in RCF-funded projects. However, this change does not restrict researchers’ right to choose their research topic and methods. The new procedures were introduced in the calls for applications for Academy Project and Academy Research Fellowship funding over the past year. Initial experience suggests that research security can be smoothly integrated into the funding process, but identifying risks will continue to require collaborative learning and open discussion between researchers, organisations and funders.

The Academy Project and Academy Research Fellowship calls together form the RCF’s largest annual funding call. The call launched in autumn 2025 marked a significant turning point at the RCF in terms of research security: for the first time, applicants were required to include a self-assessment addressing research security in their applications and, where necessary, a risk management plan. Applicants were asked to assess the project’s collaborators and the sensitivity of the topic from a security perspective.

The aim of the reform was to incorporate the security perspective right from the application stage and to support researchers in identifying the associated risks. The reform places the emphasis on the applicants’ ability to identify and manage the risks. At the same time, the aim was to enhance the ability of the decision-making bodies to obtain sufficient information on security risks and their management, in order to facilitate reliable and equitable decisions.

First round with new research security appendix

We received more than 2,700 applications for Academy Project and Academy Research Fellowship funding, accounting for more than half of the applications we typically receive in a year. All applicants completed the required appendix.

Yes, there were still some technical hiccups, as around 200 applications required closer research security scrutiny after the call had closed. However, it soon became clear that this was mainly because the appendix had been saved in the wrong format and therefore could not be processed automatically.

Just over 60 applicants were asked to correct their appendices, but not a single application was rejected solely on the grounds of a technical shortcoming.

Research security as part of funding decisions

As the applications progressed from the review stage to the decision preparation stage and the actual decision-making, the security assessments – that is, the self-assessments and risk management plans – were examined once again. If the official, decision-maker or reviewer who had processed the applications had noted any clarity issues relating to a particular matter, the applicant was asked to provide further clarification at this stage.

However, the final assessment of the adequacy of the supplementary information and the acceptability of the risks associated with the research was carried out by the RCF’s scientific councils responsible for making funding decisions on the calls in question. The scientific councils also used research security considerations in the justifications for their funding decisions.

This is an important point: the assessment and management of research security risks are not merely an additional requirement at the application stage, but an integral part of the responsible planning and conduct of research and thus also of the funding decision-making process.

Considerable variation in the drafting of risk management plans between disciplines

The highest number of risk management plans were drawn up in applications addressed to the Scientific Council for Natural Sciences and Engineering. In the applications assessed by two evaluation panels in particular, more than 90% of applicants drew up a risk management plan. These were related to robotics, automation and production planning, as well as telecommunications technology and electronics.

This raised the question of whether there could be research projects in these disciplines that do not concern critical technologies or do not have dual-use potential, or whether the issue was, in fact, that not all applicants had understood the questions on the form.

The fewest risk management plans relating to research security were drawn up in applications submitted to the Scientific Council for Social Sciences and Humanities. Of course, in these fields of research too, we must continue to consider risks associated with research security.

Impact of research security on international cooperation

As regards international collaborators, the leading countries mentioned in the calls remained the same as before: The EU member states, Switzerland, the Nordic countries, the United States and the United Kingdom were the main partners.

Cooperation with China, on the other hand, has been steadily declining since 2023, and the introduction of the new research security appendix does not appear, at least judging by the first round, to have accelerated this decline any further. This was a positive observation, as the purpose is not to reduce cooperation with, for example, China, but to ensure that cooperation – with whichever country it may be – is conducted responsibly.

Mostly positive feedback

In light of the new requirement, the RCF anticipated a lively debate on how to describe the risk management.

In preparation for the reform, we organised an information session during the application stage, focusing specifically on research security. In addition, we prepared to respond to questions raised by individual applicants; however, our staff ultimately received very few such enquiries: just over 5% of all enquiries received during the call concerned research security issues.

The results of the feedback survey conducted after the call showed that the majority of applicants (67%) had found the instructions clear. Many had also received support from their own organisation: more than 60% of those who had drawn up a risk management plan said they had received help from their site of research. This shows the important role played by research services in supporting research security.

What can we do better?

Research security is a constantly evolving topic. As a new topic, not all members of the scientific and research community are familiar with it.

Guidelines have been updated – what's next?

Based on the feedback we received from applicants and sites of research, we revised the appendix and guidelines on research security in the summer of 2026. The guidelines now make it clearer than before that a duly completed appendix is a prerequisite for funding. The revised guidelines place greater emphasis on:

  1. links to critical technologies
  2. possible dual-use potential
  3. risks associated with political influence
  4. potential misuse of results contrary to EU values.

In addition, the guidelines now provide examples for each topic area, as well as clarification on how research security is addressed in relation to the data management plan and other aspects of risk management.

The next step is to ensure that research security is also taken into account in project monitoring and reporting. The RCF plays an active role in international networks in the field of research security and strives to strengthen the cooperation both in Finland and internationally.

More information

Do you have questions or feedback for us?