Self-assessment of research security

All applications must include a research security appendix that contains a self-assessment of research security, a description of risk factors and, if necessary, a risk management plan. The assessment must be prepared using the template provided. Identifying and evaluating the risks related to research security and presenting an adequate risk management plan, if necessary, at the application stage are prerequisites for the granting of funding. Insufficient risk identification and assessment may lead to the application being inadmissible or rejected.

The appendix will not be peer-reviewed, but it is available to the reviewers as part of the application. The appendix can be completed in Finnish, Swedish or English. The consortium PI shall submit the research security appendix for the entire consortium.

Template in Finnish (PDF)

Template in Swedish (PDF)

Template in English (PDF)

Save the appendix in PDF format. Do not “print to PDF” as it makes it more difficult to process the attachment. Name the appendix as follows: research security_application/project number_year_yoursurname.pdf.

The research security appendix is a public document unless it contains information that is secret under the Finnish Act on the Openness of Government Activities. Such information includes, for example, data from the research plan. Learn more: Publicity of applications.

Research security risks

The risks assessed with the research security appendix may concern national or EU security, including both military and financial security, but also the researcher and their research. Such risks include:

  • risks associated with the transfer of critical knowledge and technology in a way that could jeopardise national security through the military, intelligence or other uses of such information. Critical information refers to data related to research projects, research results and other project-related information (e.g. plans, methods), including the knowledge and know-how held by researchers and organisations, the misuse, leaking, or uncontrolled sharing of which could cause harm to individuals, organisations, society or national security.
  • risks associated with harmful influence on research: using research as a tool to spread disinformation or to induce self-censorship among students and researchers, thereby violating academic freedom and the integrity of research
  • risks associated with violations of research ethics, where knowledge and technology are used to undermine fundamental rights or violate EU values.

Risks other than those related to research security are described as part of the research plan. These include scientific risks and risks related to the implementation of the project, such as methodological risks and project management risks.

Research security appendix

Section A of the appendix consists of four yes/no questions.

  1. Are there any collaborators (individuals or organisations) involved in the project that cause security risks?
    • An example of a security risk may be cooperation with or ties to (significant funding, affiliations) with the armed forces or governments of non-EU countries in a way that jeopardises research security.
    • The independence of collaborators owned or controlled by a foreign state may be limited in a way that increases the risk of unwanted knowledge transfer to foreign governments, armed forces or other actors.
    • Risks may also arise from individuals participating in the project, particularly if they have ties to foreign governments or armed forces. The laws of some countries require organisations and individuals to act under government direction and, upon request, to disclose information such as research data or technology.
    • The risks may also be linked to other partners of the collaborator. They can be identified, for example, by looking at the collaborator’s publication list (co-authors, funding sources).
    • The organisation often offers support services to investigate the backgrounds of collaborators. At the application stage, it is sufficient to clarify affiliations to the extent described above. The comprehensive “know your partner” (due diligence) procedure used by some organisations may be conducted after the funding decision has been made, depending on the guidelines of the site of research.
  2. Does the project fall within the critical technology sector?
    • See the definitions on the technological areas critical to the EU's economic security here: Commission Recommendation on critical technology areas for the EU's economic security for further risk assessment with Member States (PDF).
    • If the project falls within the field of critical technology, or if critical technologies are mentioned in the application, the risk management plan must describe whether the project involves the development of such technology and whether this poses a risk of critical information being transferred to collaborators outside the EU. In addition, the risk management plan must address whether the publication of research results, data or methods could pose research security risks, and how any such risks will be managed.
    • If the application mentions critical technologies but does not involve research or development into those technologies (e.g. use of artificial intelligence as an analytical method), the risk management plan must describe the project’s relationship to the critical technology. In addition, it should be described whether the project involves the development of new knowledge related to critical technologies, the unwanted transfer of which could pose risks to research security. If the research represents fundamental research, describe it in the risk management plan.
  3. Do the results and outputs of the project have dual-use potential, or does the project use equipment with dual-use potential?
    • Dual use means suitability for military purposes in addition to normal civilian use. See the EU Commission recommendation on research involving dual-use items, which includes examples of research that may trigger export control of dual-use items:
      • multispectral imaging camera sensors for data collection of crops
      • prototype drone with spraying system for combatting Eastern equine encephalitis virus
      • autonomous scientific underwater vessel that collects data automatically in deep sea regions.

            In addition, the recommendation provides examples of
            research scenarios that can trigger export controls, such
            as teaching, consulting, collaborating or working on research
            involving dual-use items with visiting foreign researchers
            inside the customs territory of the Union.

    • The dual-use potential should be assessed in terms of both the project’s results and the possibilities for their further development. In addition, consideration should be given to whether the research data used or collected in the project has dual-use potential.
    • If the research represents fundamental research, describe it in the risk management plan. The EU dual-use recommendation defines basic scientific research as experimental or theoretical work undertaken principally to acquire new knowledge of the fundamental principles of phenomena or observable facts, not primarily directed towards a specific practical aim or objective.
  1. Are there any other identifiable risks related to research security in the application? Especially in relation to collaborators’ countries of origin or countries of work.
    • Other risks to research security may relate, for example, to restrictions of academic freedom or the use of research for political influence. The risk may arise in situations where research or research results are used to legitimise misleading information, where research findings are distorted to spread disinformation, or where researchers and students are subjected to pressure, threats or intimidation that leads to self-censorship. Self-censorship can manifest, for example, as a request from a collaborator to modify the research topic or to omit parts of the findings from publication.
    • There may also be risks associated with the use of research results in a way that restricts fundamental rights or otherwise violates EU values. According to Article 2 of the Treaty of Lisbon, the values of the EU are: respect for human dignity, freedom, democracy, equality, the rule of law and respect for human rights, including the rights of persons belonging to minorities. Examples of the use of research results that restricts fundamental rights or violates the EU’s values include:
      • use of facial recognition, biometric or location-tracking technology for the large-scale monitoring of citizens
      • collection or analysis of personal data in a manner that violates privacy or freedom of speech
      • discriminatory algorithms that favour or discriminate against people based on, for example, their ethnic background, gender, religion, age or disability
      • use of artificial intelligence or algorithms to spread disinformation, manipulate elections or smear political opponents.

                       See also prohibited uses of artificial intelligence as defined
                       in the EU Artificial Intelligence Act.

        • In addition, data falling under special categories of personal data (e.g. health data, political opinions) or sensitive data (e.g. critical infrastructure, security of supply, genetic data) may pose risks not only to information security but also to research security. Examples of such risks include the unwanted transfer of critical knowledge to third countries or the disclosure of data belonging to special categories of personal data to parties that could use it in a way that restricts fundamental or human rights, such as for surveillance or profiling.
        • The assessment can be supported by using indicators such as the Academic Freedom Index, the Corruption Perceptions Index, the Human Freedom Index and the Rule of Law Index, as well as by examining the possible affiliations of the individuals participating in the research.

      Section B of the appendix contains a description of the risk factors and a risk management plan. Applicants must justify their answers to the questions in section A.

      If the self-assessment questions identify security risks in the project, the applicant must describe the identified risks in more detail, assess their impact and probability, and draw up a risk management plan. The risks should be considered for the duration of the project. However, it is also good to consider the period after the project. The use of published research findings is no longer within the researcher’s control, so it is worth considering the publication of results and outputs from this perspective as well.

      In section B, you must also explain the “No” answers given in section A. In such cases, you must explain why, in your assessment, no risks are posed, particularly if the application mentions critical technologies or dual-use items or technologies, or if the project involves collaborators from countries where the government seeks to influence research and the topic is politically sensitive.

      When preparing the appendix, you can use the information and lists published on the websites accessible via the links above. Please note, however, that the RCF is not responsible for ensuring that the information presented on these external websites is accurate, comprehensive or up to date. The assessment to be attached to the application must be based on the situation at the time of application.

      Research into critical technologies or dual-use potential related to such research do not preclude a project from receiving funding. However, if the research does address these themes, it is particularly important to pay attention to collaborators operating outside the EU. Collaborators outside the EU do not constitute a security risk as such; rather, the key factors in the assessment are the collaborator’s affiliations, operating environment and the nature of the information or technology generated by the project. Furthermore, from the perspective of the possible dual use of research results, it is necessary to examine issues related to export control.

      Relationship with data management plan and description of responsible science

      The research security risk management plan covers some of the same issues as the data management plan, particularly with regard to the protection of sensitive data. The research security appendix is intended to address, in particular, the unwanted transfer of data to collaborators. Examples of this include access to systems and sharing data with collaborators. General issues related to the storing and protection of data are addressed in the data management plan. By default, all research data and materials produced with RCF funding are openly available. The degrees of data openness may justifiably vary, ranging from fully open to strictly confidential. If the research data cannot be made openly available in full, the metadata must be stored in a Finnish or international data finder. The risk management section of the research security appendix should describe which parts of the data cannot be open access for security reasons. The data management plan describes the publication of metadata.

      Research security also overlaps to some extent with responsible science. For example, if the research involves the monitoring of emotions or other sensitive behaviour, or if the project involves dual-use items, the principal investigator or the person in charge must describe in sufficient detail how these factors have been taken into account. These aspects should be described as part of the description of good scientific practice in the research plan’s section ‘Responsible science’ (or in some cases with a separate appendix). However, the research security appendix should pay particular attention to dual-use items and related issues.

      After the funding decisions

      If changes that occur during the course of a funded project alter the previous assessment of research security in the project, the appendix must be refilled and submitted to the RCF in accordance with the standard terms for funding. Such changes may include, for example, a new collaborator or changes in the geopolitical situation. Failure to notify the changes may result in suspension of payment and recovery of funds.

      What we expect from the site of research

      The site of research undertakes to ensure that the risks associated with research security and the management of those risks are described in the application and taken into account appropriately in the research and cooperation carried out in the project, as well as in the utilisation of the research results. The responsibility for research security lies with the project PI and the site of research. The site of research should therefore be involved in making the risk assessment and drawing up the risk management plan.

      More information

      Read more: Research security.

      Do you have questions or feedback for us?