UK Concordat on Open Research Data (UKRI)
Evidence request list. 23 controls, 23 carrying auditor artefact guidance. Generated from the compliance knowledge graph on 12 September 2026. Published by The Art of Service.
Concordat Principles
Research data should be made openly available unless there are legitimate reasons to keep it closed, such as personal data, commercial sensitivity, or national security considerations.
- Institutional open research data policy referencing the Concordat
- Default open posture statement in research data management policy
- Exception register listing datasets withheld and justification
- Funder alignment matrix (UKRI, Wellcome, NIHR)
- Board or research committee minutes endorsing the open-by-default position
- Researcher handbook section on open data defaults
- Policy exists but does not declare open as the default position
- No documented exception process
- Funder requirements not mapped to institutional policy
Funders, institutions, publishers, researchers, and infrastructure providers each have defined responsibilities in delivering the open research data agenda.
- RACI chart covering funder, institution, researcher, repository, publisher roles
- Open Research Steering Group terms of reference
- Annual stakeholder report on Concordat progress
- Memoranda of understanding with external repositories
- Researcher responsibility statement signed at induction
- Vice Chancellor or Pro VC research sponsorship evidence
- No clear ownership at executive level
- Researcher responsibilities not communicated
- External repository MOUs missing
Use recognised community standards for data formats, metadata, identifiers, and documentation so research data is intelligible and reusable.
- Approved list of discipline-specific metadata standards (Dublin Core, DataCite, DDI, ISA-Tab)
- Persistent identifier policy (DOI, ORCID, ROR)
- File format guidance promoting open and non-proprietary formats
- Metadata schema templates for repository deposit
- Training records for FAIR data practice
- Quality assurance checklist for dataset deposit
- No DOI minting for datasets
- Inconsistent metadata across deposits
- Proprietary formats used without open alternatives
Data and supporting metadata should be discoverable through trusted catalogues, registries, and search services so others can find and evaluate research outputs.
- Institutional data repository listed in re3data or FAIRsharing
- Catalogue export feeds to aggregators (CORE, OpenAIRE, B2FIND)
- Search engine optimisation evidence for repository landing pages
- Dataset-level metadata harvesting via OAI-PMH
- Sample DOI landing page screenshots
- Indexing coverage report
- Repository not registered in trusted directories
- Metadata not exposed via OAI-PMH
- Landing pages noindex blocked
Data producers, curators, and contributors should receive appropriate citation and acknowledgement when their data is reused.
- Data citation policy with recommended format
- Author guidelines requiring data citations in publications
- Repository-generated citation strings on landing pages
- ORCID linking for dataset authors
- Sample citations in recent institutional outputs
- Acknowledgement template for funded research data
- Citation strings missing from landing pages
- No ORCID enforcement for dataset authors
- Author guidance does not mention dataset citation
Open data practices should be recognised in researcher assessment, career progression, and reward structures.
- Promotion and progression criteria referencing open data contributions
- Researcher development framework mapped to open practice
- Annual review templates including data-sharing achievements
- DORA signatory status
- Recognition scheme entries for open data work
- Communications celebrating open data exemplars
- Promotion criteria silent on open data
- No DORA alignment
- Reward decisions still dominated by journal impact factor
The costs of making data open and preserving it long term should be recognised as a legitimate research cost and provided for in funding arrangements.
- Data management plan (DMP) cost lines in grant applications
- Institutional charging policy for repository storage above thresholds
- Five-year sustainability plan for the institutional data repository
- FEC (Full Economic Costing) entries for data management
- Service-level agreement with external preservation provider
- Annual cost report for open data services
- No costing in DMPs
- Repository running on unfunded goodwill
- Long-term preservation costs not modelled
Openness must be balanced with legitimate restrictions such as protecting personal data, commercial interests, national security, and ethical considerations.
- Decision matrix for open, restricted, controlled, or closed datasets
- Data Protection Impact Assessment templates for research data
- Ethical review records covering data sharing
- Commercial sensitivity review workflow
- Export control screening for sensitive datasets
- Managed access procedure for restricted data
- No managed access process for restricted data
- DPIAs not completed for sensitive research
- Export control screening missing
Data should be deposited in trusted repositories that provide preservation, access control, and curation services aligned with community expectations.
- Approved repository list with selection criteria
- CoreTrustSeal or nestor seal certification for institutional repository
- Repository service description document
- Preservation policy with bit-level and logical preservation commitments
- Repository disaster recovery test results
- Access control configuration evidence
- Repository not certified
- No documented preservation policy
- Disaster recovery not tested
Researchers and support staff should have access to the skills, training, and support needed to manage and share data effectively.
- Annual training calendar covering DMP writing, FAIR data, repository deposit
- Researcher training completion records
- PGR (postgraduate researcher) mandatory data skills module
- Data steward role descriptions and competency frameworks
- Library and IT data champion network records
- Post-training evaluation reports
- Training optional and poorly attended
- No data champion network
- PGR programme silent on data skills
Constraints on Openness
Personal data in research must be processed lawfully and shared only with appropriate safeguards such as anonymisation, controlled access, or participant consent.
- Anonymisation standard operating procedure
- Pseudonymisation key management evidence
- Five Safes framework implementation for trusted research environments
- Participant information sheets covering data sharing
- DPIA records for personal data research projects
- Trusted research environment access logs
- Anonymisation done ad hoc
- No Five Safes equivalent for restricted access
- Participant consent silent on future sharing
Sensitive research data must be protected by proportionate security controls covering storage, transfer, and access.
- Data classification scheme mapped to research data tiers
- Trusted research environment ISO 27001 certificate
- Encryption standard for data at rest and in transit
- Access provisioning workflow with manager approval
- Penetration test summary of repository and TRE
- Incident response runbook for research data breaches
- TRE uncertified
- Encryption not enforced for transfer
- Access logs not reviewed
Culture, Equity and Collaboration
Open research data activity should align with international principles and support cross-sector partnerships with industry, public bodies, and civil society.
- EOSC (European Open Science Cloud) alignment statement
- GO FAIR initiative participation evidence
- Cross-sector data sharing agreements
- International transfer assessments where applicable
- Industry collaboration data sharing protocol
- Public engagement records on open research data
- No EOSC or GO FAIR engagement
- Industry agreements override Concordat defaults without review
- International transfer assessments missing
Open research data practice should consider equity of access, indigenous data sovereignty, and the inclusion of underrepresented voices in data infrastructures.
- EDI in open research statement
- CARE Principles alignment evidence for indigenous data
- Accessibility audit of repository interfaces (WCAG 2.2)
- Language and translation policy for metadata
- Community engagement records with patient or public groups
- Co-production protocols for data with community partners
- Repository fails WCAG checks
- CARE Principles not considered
- Community partners not credited
DMP
Per UK Concordat on Open Research Data (UKRI): Data Management Plan. Source-grounded summary control covering authoritative framework structure + key obligations. See manifest + log for detailed mapping.
- Authoritative source-grounded evidence for UKCONCDATA-1
- see authoritative source for detailed gap analysis
Data Management Planning
Every funded research project should have a current data management plan describing how data will be collected, stored, shared, and preserved.
- Institutional DMP template aligned to funder requirements
- DMP register linked to grant management system
- DMP review records from data stewards or librarians
- Sample completed DMPs from active projects
- Mid-project DMP refresh evidence
- End-of-project data deposit reconciliation against DMP
- DMPs written once and never updated
- No central register of DMPs
- No reconciliation between DMP and final deposits
Research data should be retained for periods appropriate to its value, funder requirements, and disciplinary norms, typically at least ten years from last access.
- Research data retention schedule
- Disposition records for time-expired datasets
- Funder retention requirements mapped to institutional schedule
- Preservation action logs (format migration, integrity checks)
- Retention exceptions register
- Repository retention metadata
- No retention schedule
- Datasets deleted before minimum retention reached
- Disposition decisions undocumented
Research software, scripts, and code underpinning data should be shared under open licences alongside the data wherever feasible to support reproducibility.
- Research software policy referencing FAIR4RS principles
- Approved code repositories (GitHub, GitLab, institutional Git)
- Zenodo or Software Heritage archive links for released code
- Citation file format (CITATION.cff) templates
- Container image registry usage evidence
- Sample reproducibility packages
- Code not archived alongside data
- No software citation guidance
- Containers not preserved
Equity
Per UK Concordat on Open Research Data (UKRI): Equity, Collaboration, Monitoring. Source-grounded summary control covering authoritative framework structure + key obligations. See manifest + log for detailed mapping.
- Authoritative source-grounded evidence for UKCONCDATA-3
- see authoritative source for detailed gap analysis
Licensing, Publication and Monitoring
Open data should be released under clear, permissive licences that enable reuse while respecting attribution and any necessary constraints.
- Approved licence list (CC BY 4.0, CC0, Open Government Licence, ODbL)
- Repository licence selection workflow
- Sample dataset licence statements
- Legal review records for non-standard licences
- Licence reuse statistics report
- Researcher guidance on choosing a licence
- All-rights-reserved by default
- Conflicting licences across files in same dataset
- No researcher guidance on licence choice
Institutions should monitor open research data activity and report progress to senior leadership, funders, and the wider community.
- Annual open research data dashboard
- Deposit and download metrics by discipline
- Funder compliance audit reports
- Researcher engagement survey results
- Open Research Steering Group annual report
- Public Concordat self-assessment statement
- No KPIs for open data
- No public self-assessment
- Reports go to operational only, not executive
Institutions should work with publishers and journals to align data availability statements, supplementary data, and peer review of data with Concordat principles.
- Guidance on writing data availability statements
- Sample compliant data availability statements from recent papers
- Read and publish agreement schedule referencing data sharing
- Mandate compliance dashboard at article level
- Peer review of data process for selected journals
- Author workflow integrating repository deposit with submission
- Data availability statements vague or missing
- No alignment between OA agreements and data sharing
- No deposit prior to submission
Open Data
Per UK Concordat on Open Research Data (UKRI): Open Data, Licensing, Citation. Source-grounded summary control covering authoritative framework structure + key obligations. See manifest + log for detailed mapping.
- Authoritative source-grounded evidence for UKCONCDATA-2
- see authoritative source for detailed gap analysis
Assembled from the framework’s own control set, so this list is regenerated rather than written and stays current as the graph does.