To audit an ABA research integrity and participant protection system, lock complete cohorts of activities, determinations, protocols, participants, consent and assent records, recruitment, data uses, incidents, contributions, publications, corrections, and closed studies. Trace approved work forward into practice and actual work back to authority. Test participant access, privacy, protocol adherence, reporting, and research-record integrity, then keep unresolved findings visible until independent validation.

Define Idris's governed activity and unit

A research audit compares the activity people actually conduct with the reviewed purpose, protocol, participant protections, data path, and released scientific record. Teams asking how to audit an ABA research integrity and participant protection system need the exact activity, people, purpose, design, data, site, sponsor, funding, institutional scope, authority, current version, participant protections, and unresolved facts before work begins.

Build Idris's research-integrity and participant-protection audit

Idris defines units before sampling: activity, determination, site, protocol version, participant, consent encounter, recruitment message, data release, deviation, adverse event, unanticipated problem, allegation, contributor agreement, publication, correction, or closure action. The audit reconciles intake, IRB and institutional records, consent versions, enrollment, clinical records, data queries, access logs, repositories, analysis code, adverse-event logs, amendments, training, disclosures, author records, presentations, publications, corrections, retention, and deletion. It samples bypass channels and closed projects as well as active studies.

Protect participants and ordinary care in Idris's workflow

Idris's sixty classification, review, consent, data, protocol, incident, contribution, and publication controls must preserve client dignity, ordinary clinical access, voluntary choice, privacy, communication and AAC, authorized decision-making, safety response, equitable treatment, complaints, and freedom from retaliation. A research label, consent signature, payment, supervisor approval, or publication goal cannot expand a role or erase a required protection.

Work through Idris's fictional example

Idris audits 60 control rows. Forty-nine align with current authority and evidence. Eleven exceptions appear: three stale consent or protocol versions, two data-access gaps, two late deviation records, one recruitment discrepancy, one contribution gap, one unresolved correction, and one incomplete closure. Eight close after validation; three remain open. Preserve every proposed, classified, reviewed, approved, exempted, enrolled, changed, reported, published, corrected, held, withdrawn, and closed state with its original version, owner, date, conditions, and validation.

Use Idris's denominator carefully

Initial control integrity is 49 of 60, or 81.7%. Validated integrity after eight closures is 57 of 60, or 95%. The three open rows remain in the original cohort and aging report. Complaint count alone cannot establish participant protection or research validity.

Assign Idris's decisions to authorized owners

Idris's auditor identifies evidence and exceptions. The IRB, institution, investigator, clinical leader, privacy, safety, data, legal, research-integrity, employment, sponsor, journal, and participant-access owners decide remediation within their authority. Audit staff do not substitute attestation for observable evidence.

Address Idris's main interpretation risk

A file review may miss recruitment language, actual consent communication, local spreadsheets, unlogged exports, protocol workarounds, abandoned analyses, and public presentations. Follow both records and real workflows.

Verify Idris's research control in practice

Idris retests each closure through the failed control, such as observing the accessible process, reconciling data access, checking timestamps, rebuilding an analysis, tracing a correction, or confirming deletion. Owner sign-off accompanies rather than replaces validation.

Place Idris's project inside organizational accountability

Idris's research-integrity and participant-protection audit uses the CASP Organizational Guidelines public overview only for high-level business, clinical-operations, and risk-management scope in autism service organizations. CASP sells the detailed guidelines. The workflow here is Finni's editorial governance model, not a CASP research protocol, regulatory determination, or institutional approval.

Apply the BACB research duties to Idris's covered roles

Idris's role review uses the current BACB Ethics Code, which applies to BCBA and BCaBA certificants and people who completed an application. Its research section addresses applicable review, participant welfare, informed consent, confidentiality, competence, conflicts, integrity, authorship, publication, and corrections. BACB has no separate organization or corporation jurisdiction, so institutional and legal controls remain necessary.

Anchor Idris's federal scope to the current HHS rule

Idris's federal analysis starts with the HHS 45 CFR 46 page, reviewed in February 2025, which identifies the 2018 Requirements and added subparts for specified populations. Applicability depends on funding, conduct, assurance, institution, activity, and other facts. The page is an authoritative starting point, while the current rule and responsible institution control the determination.

Use the OHRP decision charts as aids for Idris

Idris's reviewer may use the OHRP 2018 Requirements decision charts to organize research, human-subject, exemption, continuing-review, and consent-waiver questions. OHRP calls the charts generalizations and directs users to the full applicable text. They support intake and discussion; they do not authorize an investigator to self-approve a project.

Classify quality improvement carefully for Idris

Idris's project label follows the OHRP Quality Improvement Activities FAQs. OHRP explains that intent to publish is insufficient to decide whether QI is research and that some QI can be nonexempt human-subjects research. Purpose, design, activity, coverage, and an authorized determination matter more than the label chosen by the project team.

Separate HIPAA research permission for Idris

Idris's privacy review uses HHS research guidance under HIPAA, which explains that covered entities may use or disclose PHI for research with individual authorization or through limited rule-defined paths without authorization. Common Rule consent, IRB action, HIPAA authorization or waiver, data-owner approval, and contract terms remain separate decisions even when one document combines information.

Treat informed consent as a process for Idris

Idris's communication plan draws on the OHRP Informed Consent FAQs. OHRP flags that the FAQ predates the 2018 Requirements and 2024 conforming changes, while retaining general nonbinding guidance. Use the current regulation and review decision. The FAQ describes prospective, legally effective, voluntary information exchange with questions and a real choice to join, continue, or withdraw.

Apply child-research requirements precisely for Idris

Idris's child-participant route uses current 45 CFR 46 Subpart D, amended in October 2024. The IRB determines adequate provisions for parental or guardian permission and for child assent when the child is capable, subject to the rule's conditions and possible waivers. Clinical assent policies and research assent determinations should be recorded separately.

Distinguish adverse events and unanticipated problems for Idris

Idris's incident logic uses OHRP guidance on unanticipated problems and adverse events. The guidance explains that only a subset of adverse events are unanticipated problems and describes unexpectedness, relation or possible relation, and increased risk as the three-part analysis. Use the current protocol, institution, and rules for actual reporting decisions and deadlines.

Scope research-misconduct handling for Idris

Idris's integrity route recognizes the 2024 final rule revising 42 CFR Part 93. The rule became effective January 1, 2025, and its regulatory requirements apply beginning January 1, 2026, to covered Public Health Service research-misconduct matters. Allegations received before that applicability date generally follow the 2005 rule unless the institution and respondent elect the new rule in writing. The current rule addresses fabrication, falsification, and plagiarism and excludes honest error or differences of opinion. Other sponsors, institutions, journals, employers, and laws can use different processes; preserve allegations as allegations until the authorized process decides them.

Make Idris's participation process accessible

Idris's access plan uses DOJ effective-communication guidance for covered title II or title III entities. The appropriate aid or service depends on the interaction's nature, length, complexity, context, and the person's usual communication method. Apply the actual entity and rule, preserve AAC and authorship, and test consent, recruitment, questions, incident notices, and withdrawal routes in the formats participants use.

Choose Idris's next review trigger

Repeat on schedule and after a new institution, sponsor, study type, data platform, adverse event, noncompliance pattern, allegation, publication correction, regulatory change, or control bypass. Record the changed fact, affected people and records, immediate protection, governing source, decision owner, reporting or amendment route, deadlines, communication, and validation result.

Close Idris's record with accountable evidence

Review the research-integrity and participant-protection audit with Idris, investigators, qualified clinicians, the institution or reviewing body, participant representatives as applicable, and the specialists named in the manifest. Confirm that service, QI, evaluation, research, review, consent, privacy, safety, data, employment, authorship, publication, and misconduct routes remain distinct; all conditions are traceable; access is tested; and unresolved work has an accountable endpoint. Keep this page draft and noindex until every required review is complete.

Related resources

Sources