Blue Logo for ACUA with the text Journal Articles

Research Security Training: Four Questions Every Auditor Should Ask

Publication Date: October 2, 2026

By Muwen Huang

For decades, university research security focused primarily on export controls and classified research. However, federal agencies have grown increasingly concerned about undisclosed foreign affiliations, foreign talent recruitment programs, and inaccurate disclosure of outside support. The risk has shifted from the potential for espionage in the traditional sense to a lack of transparency about research relationships and commitments.

Recent legislation requires universities receiving more than $50 million a year in federal research to develop and operate a research security program. Providing research security training to covered personnel is one of the program’s required elements. Federal agencies now require universities to certify that their researchers completed that training during the proposal phase.

Internal audit departments can add value to their research programs by confirming that research security training is occurring as designed and meets the federal and sponsor guidelines. This article walks through the background of the training requirement, the agency deadlines that enforce it, and the four questions every auditor should ask of their research administration.

Where the requirement comes from

The National Security Presidential Memorandum – 33 (NSPM-33), issued in January 2021, created the program obligation. It directed federal research agencies to require covered institutions to certify that they operate a research security program.

Issued in August 2022, Section 10634 of the CHIPS and Science Act of 2022 requires each federal research agency to establish a research security training requirement for federal research award personnel. Each covered individual listed on a federal research and development application must have completed research security training within the preceding year, and the applicant institution must certify completion. Section 10634 also defines who is a covered individual and the topics to be included in the training.

The Office of Science and Technology Policy’s (OSTP) July 9, 2024 guidelines standardized how agencies implement the program. The guidelines set the covered institution threshold at $50 million and established the four required program elements: cybersecurity, foreign travel security, research security training, and export control training. The guidelines required federal research agencies to submit implementation plans by January 9, 2025. Each agency then published its own notice and set its own effective date. The table below provides a link to the policy instrument and the effective date for the major research agencies.

Table 1. Federal agency research security training implementation

AgencyPolicy instrumentEffective date
Dept. of Energy (DOE)Financial Assistance Letter 2025-02May 1, 2025
NSFImportant Notice No. 149Dec. 2, 2025
USDASecretary’s Memorandum SM 1078-014 and general award terms and conditionsDec. 31, 2025
NIHNOT-OD-26-017May 25, 2026
NASAGrant Information Circular 26-02Aug. 5, 2026
Dept. of Defense (DOD)PendingAnticipated Oct. 1, 2026

As a result, universities have been rolling out research security trainings to meet these sponsor obligations. When auditing these programs, auditors should focus on the following questions.

Question #1: Is the university’s training program current and complete?

Per the CHIPS Act and sponsor guidelines, the following seven topics should be included in the training modules, tailored to the unique needs of covered individuals and students:

  • Cybersecurity
  • International collaboration and international travel
  • Foreign interference
  • Proper use of funds
  • Disclosure requirements
  • Conflict of commitment
  • Conflict of interest

Universities may choose their method of training from four practical options. The NSF, NIH, DOE, and DOD developed their own online research security training modules that run for about an hour each. The NSF-funded SECURE Center then condensed those four modules into a one-hour consolidated module, which NSF, NIH, DOE, DOD, and USDA all recognize as compliant, plus a 30-minute annual refresher. Commercial providers such as CITI deliver both versions inside an existing subscription.

Universities may elect to develop their own research security training courses that cover the required materials and offer guidance on disclosing potential issues. Benefits to developing an in-house training course include saving researcher time with a shorter duration course, including university-specific procedures, and integrating the completion records with existing training and research software.

When auditing this topic, internal auditors should consider taking the course. Completing it produces firsthand knowledge of the content and a completion record that shows how the system captures evidence. Auditors may also request the underlying training script and materials and build a crosswalk mapping each federal content area to the materials or use AI to assist with the analysis. Auditors should also evaluate whether the content still matches current criteria.

Question #2: Have all key personnel taken the training?

Each agency defines its own covered population, and the definitions are similar but not identical. NSF applies the requirement to “senior/key personnel.” DOE covers individuals who “contribute in a substantive, meaningful way” to a project and names the covered roles in each funding opportunity. NASA covers “any principal investigator or co-principal investigator at any level of effort, plus co-investigators committing 10 percent or more of their time.” The same researcher can fall inside one agency’s population and outside another’s.

Your research department has likely determined which roles require this training. Examples of applicable roles may include principal investigators, clinical research coordinators, post-doctoral research associates, fellows, and other key participants. Auditors should review the list of roles for inclusion, then request a list of current researchers on Federal projects with those critical roles for completeness testing.

Delivery and recordkeeping may span more than one system. Most universities assign the course through their learning management system that serves employees. Training may also be offered on student platforms for post-doctoral research associates, and there may be separate training completion records for independent contractors and visiting scholars. Auditors should request the training completion records from all sources for the past 12 months, then match the covered individuals against the training completion records and identify any individuals with missing or overdue training.

Large research universities often import or populate training records into their research modules within their ERP systems. Auditors should also verify training completion records agree with the completion data in the research module. This test would identify any unrecorded completions and detect any manual overrides where no training records exist.

Question #3: What controls are in place to ensure training is completed timely?

Universities are required to certify to sponsors that research security training has been completed within the past 12 months for all covered personnel at the time of the proposal submission. This is often documented within each researcher’s biographical sketch documents and on the university’s other support information proposal forms.

Universities may employ a mix of manual and systemic controls to encourage and monitor training completion. Initially, a rollout campaign assigns the course to the known population and sets a completion deadline, and completions are often monitored and followed up by research administration. During the proposal phase, a system control may be in place to identify covered individuals with no current completion records on file. An effective hard system edit blocks a project from entering the award phase if any covered individuals still have no valid record of training completion.

Auditors should inquire about the controls used by their university and assess their effectiveness. This may be performed by viewing a project in the proposal phase and viewing an error message when trying to move it to the award phase without completed training. Research administration may be able to set up a test project to verify hard stops are in place. A manual approach to testing is to select a sample of recently awarded projects and ensure completed training records were on file with the covered researchers at the time of the proposal.

Question #4: Is ongoing training occurring?

Every current agency policy measures training completion using a rolling 12-month period preceding each submission, and several agencies impose additional requirements. The DOE requires covered individuals working on active awards to complete training annually and newly added covered individuals to complete training within 30 days. USDA requires annual recertification for the duration of the award and requires project members to complete training within 60 days of appointment. NASA also requires institutions to certify research security training compliance when submitting annual progress reports due on or after August 5, 2026. Universities need to set up rolling reminders for researchers to complete their training. Internal audit can quantify which researchers are overdue, ensure automatic reminders are being employed, and inquire whether ongoing monitoring is taking place.

Institutions are also encouraged to perform additional training in response to an actual or potential security incident. Examples include researchers failing to disclose foreign investors, export control violations, and collaborating with certain foreign workers. Re-training is typically performed on a case-by-case basis. There should be a designated employee who manages tips and sponsor inquiries regarding research security threats. Auditors should inquire about these re-training procedures and request examples of action taken to mitigate the risk of research security violations.

Conclusion

Federal research security mandates have moved from guidance to enforcement, and every certification an institution files carries False Claims Act exposure. While research security is a broad topic, internal audit can add value by focusing on the research security training requirement. This topic is the narrowest piece of the research security program and is easily testable as it produces dated, system-generated evidence that is measurable against published federal criteria. Identification of any missing training topics, overdue training, or control deficiencies are easily correctable.

About the Author

Muwen Huang
Author Muwen Huang

Muwen Huang is a staff auditor in the Office of Internal Audit at the University of North Carolina at Chapel Hill. Muwen began his career as an auditor at KPMG and transitioned to corporate accounting prior to starting university auditing. He earned a Master of Accountancy from the University of Massachusetts Amherst.