Research integrity offices need repeatable steps, not improvised email chains, so this checklist covers intake, early actions, and closing the loop.
Intake checklist
- Written allegation / concern received
- Conflict-of-interest check on handlers
- Scope defined (authorship, plagiarism, data, images, peer review)
- Interim risk assessed (patient safety, ongoing submissions)
Written allegation / concern received means written before anything else happens. Concerns often arrive in a corridor, a phone call, or a meeting about something else. When that happens, write a dated note of what you were told, in the words the person used rather than your summary of them, and send it back to them to confirm it is accurate. Record the date received, who received it, what documents came with it, and give the case a reference that goes on every file and every email from that point. Anonymous concerns still get recorded and still get assessed — you weigh the evidence supplied, not the identity of the person supplying it, though an anonymous source limits what you can go back and ask. What goes wrong here is mundane: a concern sits in one person's inbox for three weeks, that person goes on leave, and nobody can reconstruct what was promised to whom.
Conflict-of-interest check on handlers happens before anyone reads the substance, not after. The test is not "do I feel able to be fair"; it is whether a reasonable outsider looking at the relationship would think the outcome was settled in advance. Check for co-authorship, shared grants or applications, the same department or unit, past or present supervision, line management, personal or family relationships, financial interests, and any existing dispute with either party. Write the check down even when it is clean — an empty conflict record is still a record, and it is the one you will need if the finding is challenged. Name substitute handlers in your policy in advance, so a recusal moves the case sideways instead of stalling it for a fortnight. The classic failure is a case handled by the head of the respondent's own department: the conclusion may be entirely right and still unusable.
Scope defined means writing one or two sentences that say what is alleged, about which outputs, involving whom, over what period — and what you are not examining. Allegations rarely arrive sorted. A complaint framed as an authorship grievance often has a data concern underneath it; a similarity concern about one paper often turns out to point at a pattern across several. Decide which strands you are actually opening. Then attach identifiers to each: DOIs, manuscript numbers, dataset and repository names, protocol or ethics approval references, grant numbers, and the filename, version and date of every document you were sent. Two failures are equally common — quietly widening the case until it never closes, and narrowing it to the strand that is easiest to resolve while leaving the serious question unasked.
Interim risk assessed is a separate question from whether the allegation is true, and you answer it before you know. Ask: if this were true, what harm is continuing today? Work informing clinical care or a live trial. Manuscripts under review, grant applications in progress, or a thesis about to be examined that rests on the disputed material. Participant or animal welfare. Anything hazardous. Interim measures are protective rather than punitive: proportionate, time-limited, written down with the reason, and reviewed on a set date rather than left running by default. If the concern touches patient safety, it does not wait for your process — tell the people with authority to act on it today, in parallel.
Early actions
- Preserve data and correspondence
- Notify affected authors appropriately
- Pause related submissions if needed (coordinate with journals)
- Follow institutional policy + COPE-aligned expectations
Preserve data and correspondence comes first for a reason: notification is the moment material starts disappearing, sometimes innocently. Take copies through IT, under your policy, of the relevant accounts and storage rather than asking the respondent to send you a selection they have chosen. Capture raw instrument files with their metadata, lab notebooks whether paper or electronic, analysis code and its version history, the submission-system correspondence, and the email threads on all sides. Remember the things people forget: shared-drive edit histories, electronic notebook audit logs, calendar entries, and the peer review correspondence held by the journal — ask the publisher to retain their side too. Suspend any routine deletion or account-closure schedule on the affected accounts, which is the most common way evidence is lost when a respondent leaves. Note who took each copy, when, and from where.
Notify affected authors appropriately is carrying a lot of weight in one word. The respondent ordinarily learns that a concern exists and enough detail to answer it meaningfully — but after preservation, and on the timing and in the form your policy and the applicable law require, not the timing that feels kindest. Co-authors who are not the subject of the concern are in a different position: they may need to know because they carry the consequences, but they are not accused of anything, and telling them too early or too widely does real damage to people who did nothing. Keep circulation to those with a genuine need to know. Whatever you send, say what stage the process is at, what happens next, and roughly when — silence after a notification is what turns a manageable case into a grievance.
Pause related submissions if needed (coordinate with journals) is a decision with a cost, and the cost lands hardest on early-career co-authors whose next post depends on that paper. Weigh it, then ask the practical question: is a journal about to make a decision it would make differently if it knew? If a manuscript under review rests on the disputed data, the editor is unknowingly deciding on your behalf. You can tell a journal that a matter is under review at the institution and ask them to hold, without sharing names, evidence or conclusions beyond what is needed. Editors handle this routinely and will usually pause rather than reject. Ask, in writing, what they will do with what you have told them and who else at the publisher will see it.
Follow institutional policy + COPE-aligned expectations because they answer different questions and you need both. Your institutional policy — together with the regulatory framework where you operate and your funders' terms — governs process: who decides, what the threshold is for moving from assessment to investigation, what the respondent is entitled to, how appeals work, and what timelines you owe. COPE's guidance governs how you deal with the published record and with journals: what editors expect from an institution, and what you can reasonably ask of a publisher. Where they pull in different directions, process follows your policy; note the mismatch in the file and raise it when the policy is next revised. Where your policy is simply silent, record the gap at the moment you hit it. That log of gaps is the most useful document you will produce, because it is what the next version of the policy gets built from.
Reference: COPE Core Practices Explained
Common case types — first links
- Authorship: Disputes guide
- Similarity: Similarity screening
- Reviewer fraud: Fake peer review
Routing matters because the three types need different first moves.
Authorship concerns are frequently not misconduct at all. Most are a disagreement about criteria that were never written down, applied by people who each remember the arrangement differently. Start by asking what authorship criteria the journal actually required, whether contributions were recorded while the work was happening or reconstructed afterwards, and whether anyone was added or removed late. If nothing was recorded contemporaneously, say so plainly in the file; it changes what you can conclude. Many of these resolve through a facilitated conversation, and resolution is a better outcome than a finding. Where a name was added or removed without the person's knowledge, or a byline was used to trade favours, you are no longer in dispute territory.
Similarity concerns need the report read, not the number. Ask where the matched text sits: methods boilerplate and standard instrument descriptions carry different weight from a matched results paragraph or a discussion. Check whether the matched source is the authors' own earlier work, whether the citation is present but the quotation marks are missing, and whether the matches are scattered fragments or one continuous block lifted intact. Then ask the question the software cannot: does a reader end up believing something about the origin of this text that is untrue?
Reviewer fraud usually shows up in the metadata rather than the prose. Suggested reviewers reachable only at generic webmail addresses that do not match the named person's institution, reviews returned unusually fast and uniformly positive, the same recommended names recurring across a set of submissions, or a real researcher who says they never received the invitation. The evidence here is split: the journal or publisher holds the submission system records, and you hold the employment relationship. Neither side can finish the case alone, so open the channel early and agree in writing what each of you is examining.
A worked example
A postdoc writes to you about a paper from a group in another faculty. Two panels in a published figure look, to them, like the same field of cells at different magnifications, labelled as separate conditions. They ask you not to use their name.
Intake: you write it up as received, record the date, open a reference, and note that the source has asked for confidentiality but has supplied specific, checkable material — so the concern is assessed on that material. Conflict check: one of your two assessors sits on a grant panel with the senior author, so they step out and the named substitute steps in, and both facts go in the file. Scope: image duplication in one named figure of one named paper, with the DOI attached. You note explicitly that you are not, at this stage, examining the rest of the group's output, and that you will revisit that if duplication is confirmed. Interim risk: the work is not clinical, but the same figure appears in a grant renewal due next month, so you flag it.
Early actions: before anyone is contacted, you secure the original acquisition files, the imaging system logs and the manuscript correspondence. Notification then goes to the corresponding author, describing the concern precisely enough to answer and asking for the unprocessed originals with their metadata.
Two outcomes are common, and they are not the same case. The originals exist, show two genuinely different fields, and the duplication turns out to be a figure-assembly error at the last revision — that is a correction, and a lab process problem. Or the originals cannot be produced at all. The second answer is not a milder version of the first. The absence of the underlying files is itself the serious finding, and it is rarely confined to one figure.
Closing the loop
- Outcome documented
- Journal notified when the published record needs action
- Training gaps identified for prevention
Outcome documented means a record a stranger could follow without asking you anything. It should state what was alleged and by whom (or that the source was anonymous), the scope you set, who handled it and what their conflict position was, what evidence was gathered and how it was preserved, what the respondent said in response, what standard you applied, what you found — and, just as important, what you did not find. Record the not-upheld cases with the same care as the upheld ones. Someone who has been the subject of an allegation and cleared is entitled to a document that says so, in writing, that they can point to later. Then apply your retention rules to the file rather than leaving it wherever it was assembled.
Journal notified when the published record needs action rests on a division of labour worth stating plainly: the institution establishes what happened, the publisher fixes the record. You cannot correct a paper and they cannot investigate your staff. Write to the editor with the article identified, which part of the record is affected, what you established, what you recommend — correction, expression of concern, or retraction — and whether the authors agree with that. Send what the editor needs in order to act, not your full investigation report. Give a named contact and an institutional address that will still be answered in two years, because the file may reopen after everyone involved has moved on.
Training gaps identified for prevention is the item that gets skipped, and it is the only one that reduces next year's caseload. Almost every case points at a condition rather than a person: an unwritten authorship convention, no data retention practice, a supervisor who never saw a raw file, or nobody knowing how to raise a concern except through their own line manager. At closure, write one anonymised paragraph — what made this possible — and hand it to whoever runs induction, supervisor training and the research office's own guidance. Keep those paragraphs together. Read across a year of them and the pattern is usually obvious and usually fixable.
If you are building this from scratch
Do it in this order. Write the intake form and the case reference scheme first, because they cost nothing and they are what you will wish you had at the worst moment. Name your substitute handlers now, while there is no live case to make the choice look political. Agree with IT, in advance and in writing, how preservation is done and who authorises it, so the first request is not also the first negotiation. Draft the standard notification letters — respondent, co-author, journal — while you are calm, because otherwise every one of them gets written under time pressure by whoever is available. And write down where your policy is silent as you go. None of this takes long, and all of it is far easier before the first case than during it.
More resources: Directive Academy
Frequently asked questions
What is a research integrity office checklist?
It is a repeatable list of steps an institution works through whenever a written allegation or concern about research conduct arrives. The checklist covers intake, early actions, common case types and closing the loop, so handling does not depend on improvised email chains. Each item is something the office records rather than something it decides case by case.
What should a research integrity office do first when an allegation comes in?
Record that a written allegation or concern has been received, then run a conflict-of-interest check on the people who will handle it. Define the scope of the concern across authorship, plagiarism, data, images and peer review. Finally assess interim risk, including patient safety and any ongoing submissions.
How do you preserve evidence in a research misconduct case?
Preserve the underlying data and the related correspondence as an early action, before notifying anyone who is affected. Notify affected authors appropriately and pause related submissions if needed, coordinating that pause with the journals involved. Keep the whole sequence aligned with institutional policy and COPE-aligned expectations.
What types of research integrity cases does this checklist cover?
The checklist points to first links for the most common case types an office sees. Authorship concerns start from the disputes guide, text similarity concerns start from similarity screening, and reviewer manipulation starts from the material on fake peer review and reviewer fraud. Scope is set at intake so the right route is chosen early.
What should we do next after an investigation closes?
Document the outcome so the record of the case is complete. Notify the journal when the published record needs action, since the correction sits with the publisher rather than the institution. Then identify the training gaps the case exposed and use them for prevention.