External Research Services & Service Providers

Overview

Researchers routinely use external laboratories, testing and sequencing services, data analysis services, computing and research platforms, consultants, and other third-party service providers to support University research.

Most external research services do not require additional review by the Office of Research Security (ORS). However, additional requirements may apply when a service provider will receive, process, store, analyze, or access research information, data, samples, materials, software, technology, or other research resources.

Research security considerations may depend on the service provider and its ownership or affiliations, where the services will be performed, what will be provided to or accessed by the service provider, and applicable export control, sponsor, contractual, information protection, cybersecurity, or other requirements.

REQUEST A RESEARCH SECURITY REVIEW

SCHEDULE A CONSULTATION

CONTACT ORS


Contact ORS Before You

Contact ORS before using an external research service when you:

  • Will send or provide access to export-controlled technology, technical information, software, source code, equipment, or materials.
  • Will provide government, proprietary, confidential, controlled-access, or otherwise restricted research information.
  • Will send research samples, materials, equipment, software, technology, or technical information outside the United States.
  • Will use a foreign service provider or a service that may be performed, processed, stored, or accessed outside the United States.
  • Are working with an unfamiliar foreign company or organization or have concerns about a service provider's ownership or affiliations.
  • Are subject to sponsor, contractual, data use, cybersecurity, or other requirements that may limit where or by whom research information, data, samples, materials, or technology may be accessed or processed.
  • Are asked to agree to export control, end-use, end-user, citizenship, nationality, or other research security-related certifications or restrictions.
  • Are uncertain whether research security, export control, information protection, sponsor, or other institutional requirements apply.

Key Considerations

Before using an external research service, researchers should understand which legal entity will provide the service and where the work will actually be performed.

The organization issuing a quote, invoice, or agreement may not necessarily be the organization or location that performs all aspects of the service. Service providers may use affiliates, laboratories, data centers, subcontractors, or personnel in other locations, including outside the United States.

When relevant, researchers should understand:

  • The legal entity providing the service.
  • Where samples or materials will be sent.
  • Where testing, analysis, processing, or other work will occur.
  • Where research information or data will be stored or processed.
  • Whether personnel outside the United States may access research information, software, technology, or other project resources.
  • Whether affiliates, subcontractors, or other third parties will participate in providing the service.

ORS can assist in evaluating research security considerations associated with the service provider and locations involved.

External service providers may require Restricted Entity Screening before research information, data, samples, materials, software, technology, or other research resources are provided.

U.S. government restrictions may apply not only to organizations specifically identified on a restricted party or entity list, but in certain circumstances to other entities based on their ownership by listed or restricted parties.

ORS conducts appropriate screening and research security due diligence based on the parties and circumstances involved. Researchers are not expected to independently determine corporate ownership structures or the applicability of ownership-based federal restrictions.

Contact ORS when a proposed service involves a foreign provider, an unfamiliar organization, or another party that may present restricted entity or ownership concerns.

Consider what research information or data the service provider will receive, store, process, analyze, or otherwise access.

Additional requirements may apply to:

  • Controlled Unclassified Information (CUI) or Federal Contract Information (FCI).
  • Proprietary or confidential research information.
  • NIH Controlled-Access Data.
  • Export-controlled technology or technical information.
  • Sponsor-controlled or contractually restricted information.
  • Unpublished research information subject to specific access, use, storage, or security requirements.
  • Other research information requiring enhanced safeguards.

Providing research information to an external service provider may also require review of the provider's computing, storage, security, access, or data-handling arrangements.

ORS coordinates with appropriate DoIT/SBM-IT, Research Computing & Informatics, privacy, contracting, and other offices when additional review is needed.

External services may require researchers to send biological samples, chemicals, research materials, specimens, equipment, prototypes, or other physical items to the service provider.

International shipments or transfers may be subject to U.S. export controls, economic sanctions, customs, shipping, biological material, or other requirements.

Researchers should determine where samples and materials will be sent and whether they may subsequently be transferred to another laboratory, affiliate, subcontractor, or location.

Contact ORS before sending potentially export-controlled research materials or other items requiring research security review outside the United States.

Providing a service provider with software, source code, designs, specifications, technical information, technology, or access to research systems may create requirements that are different from those associated with sending ordinary research data.

Under U.S. export control regulations, certain shipments or transmissions outside the United States and certain releases of controlled technology or source code to foreign persons may constitute exports.

ORS can determine whether the proposed service involves export-controlled software, technology, technical data, or other items and whether authorization or additional safeguards are required.

A service provider's U.S. address, U.S. subsidiary, U.S. contracting entity, or U.S. billing location does not necessarily mean that all aspects of the service will occur within the United States.

Research information, data, samples, materials, software, or technology may be transferred to or accessed from other countries through affiliated laboratories, personnel, subcontractors, data centers, or other service arrangements.

Before using an external service for research involving restricted or controlled resources, researchers should understand where the service will be performed and whether research resources may be transferred to or accessed from outside the United States.

ORS can review proposed international transfers and determine whether export control, sanctions, research security, sponsor, or other requirements apply.

Federal awards, industry-sponsored research agreements, data use agreements, nondisclosure agreements, and other research agreements may establish requirements affecting the use of external service providers.

Requirements may address:

  • Where research information or data may be stored or processed.
  • Who may access project information or technology.
  • Use of subcontractors or third-party providers.
  • Cybersecurity or information protection standards.
  • Export control or citizenship requirements.
  • Geographic or foreign access restrictions.
  • Confidentiality and data use.
  • Approval or notification before using an outside provider.

Researchers should not assume that a commercially available service is permitted for a particular research project simply because the service is generally available.

ORS can assist in identifying research security-related requirements and coordinate with Sponsored Programs, contracting offices, DoIT/SBM-IT, Procurement, Legal, or other University offices as appropriate.


Related Guidance

Guidance Description
Restricted Entity Screening Learn how organizations and individuals are screened against U.S. government restricted party and entity lists before certain research activities.
International Transfers (Shipments, Hand-Carry & Electronic Transmissions) Guidance for shipping, mailing, hand-carrying, or electronically transferring research equipment, materials, software, technology, technical information, or research information internationally.
Sharing Research Information Guidance for sharing research information, data, software, technology, technical information, and other research outputs with external parties.
Working with Proprietary & Confidential Research Information Guidance for receiving, accessing, using, storing, sharing, and protecting proprietary or confidential research information received from sponsors, collaborators, companies, universities, and other external organizations.
Working with Government Information Guidance for receiving, accessing, using, storing, sharing, and protecting government information, including CUI, FCI, Government-Furnished Information (GFI), and other government-controlled information.
Working with NIH Controlled-Access Data Guidance for requesting, accessing, receiving, storing, using, and sharing controlled-access data obtained through NIH repositories.
Sponsor & Agreement Requirements Guidance for reviewing and complying with research security, export control, information protection, publication, and other project-specific requirements contained in sponsor solicitations, award terms, and research agreements.
Purchase of Research Equipment, Materials, Software & Technology Guidance for purchasing research equipment, materials, software, technology, chemicals, biologics, and other items that may require research security or export control review.

Frequently Asked Questions

Do all external research services require ORS review?

No. Most routine external research services do not require ORS review.

Additional review may be appropriate when a service provider will receive or access controlled or restricted research resources; when samples, materials, information, software, or technology will be transferred internationally; when a foreign or potentially restricted organization is involved; or when sponsor, contractual, information protection, cybersecurity, or other requirements apply.


Why does it matter where the service is performed?

The location of the service can affect export control, sanctions, sponsor, information protection, cybersecurity, contractual, and other requirements.

A company may contract with the University through a U.S. entity while performing some services, data processing, storage, or technical work at another location. Researchers should understand where research resources will actually be sent, processed, stored, or accessed when those resources are subject to restrictions.


Does using a U.S. company mean the service does not require international research security review?

Not necessarily.

A U.S. company may have foreign parent companies, affiliates, laboratories, subcontractors, personnel, or data-processing locations. The relevant considerations depend on the particular service, the parties involved, where the work occurs, and what research resources will be provided or accessed.

ORS can assist when these circumstances may affect research security or export control requirements.


Why does ORS review the ownership of some service providers?

Certain U.S. government restrictions may extend to entities based on ownership by listed or restricted parties, even when the service provider itself does not appear by name on a restricted party list.

ORS may therefore conduct additional ownership and affiliation due diligence when appropriate. Researchers are not expected to perform this analysis themselves.


Can I send research samples to an overseas laboratory for testing or analysis?

Possibly. The answer depends on the samples or materials, destination, recipient, intended use, applicable export controls or sanctions, sponsor and agreement requirements, and other circumstances.

Contact ORS before sending potentially controlled research materials or other research resources requiring review outside the United States.


Can I upload research data to an external analysis, computing, cloud, or research platform?

It depends on the information and the platform.

Research information subject to government, sponsor, contractual, export control, data use, cybersecurity, or other protection requirements may only be permitted in environments that meet applicable requirements. International storage, processing, or access may also create additional considerations.

Consult the applicable Research Information Protection & Cybersecurity guidance or contact ORS when you are uncertain whether an external service is appropriate for the research information involved.


When should I contact ORS?

Contact ORS when an external research service may involve controlled or restricted research information, international transfers, foreign or restricted organizations, export-controlled technology or materials, sponsor requirements, or other research security considerations.

Early consultation can help identify applicable requirements before research resources are provided to the service provider.


Need Assistance?

Contact ORS when an external research service may involve restricted entities, foreign ownership or affiliations, international processing or access, controlled or restricted research information, international transfers of samples or materials, export-controlled technology, sponsor requirements, or other research security considerations.

ORS can identify applicable research security and export control requirements and coordinate with Procurement, Sponsored Programs, contracting offices, IT and information security, Legal, and other University offices when appropriate.

REQUEST A RESEARCH SECURITY REVIEW

SCHEDULE A CONSULTATION

CONTACT ORS