Skip to content

Evidence request lists

UK Concordat on Open Research Data (UKRI)

Evidence request list. 23 controls, 23 carrying auditor artefact guidance. Generated from the compliance knowledge graph on 12 September 2026. Published by The Art of Service.

Concordat Principles

CONCORDAT-P1
Principle 1: Open as Default

Research data should be made openly available unless there are legitimate reasons to keep it closed, such as personal data, commercial sensitivity, or national security considerations.

Artefacts an auditor will ask for
  • Institutional open research data policy referencing the Concordat
  • Default open posture statement in research data management policy
  • Exception register listing datasets withheld and justification
  • Funder alignment matrix (UKRI, Wellcome, NIHR)
  • Board or research committee minutes endorsing the open-by-default position
  • Researcher handbook section on open data defaults
Where this commonly fails
  • Policy exists but does not declare open as the default position
  • No documented exception process
  • Funder requirements not mapped to institutional policy
CONCORDAT-P10
Principle 10: Stakeholder Roles and Responsibilities

Funders, institutions, publishers, researchers, and infrastructure providers each have defined responsibilities in delivering the open research data agenda.

Artefacts an auditor will ask for
  • RACI chart covering funder, institution, researcher, repository, publisher roles
  • Open Research Steering Group terms of reference
  • Annual stakeholder report on Concordat progress
  • Memoranda of understanding with external repositories
  • Researcher responsibility statement signed at induction
  • Vice Chancellor or Pro VC research sponsorship evidence
Where this commonly fails
  • No clear ownership at executive level
  • Researcher responsibilities not communicated
  • External repository MOUs missing
CONCORDAT-P2
Principle 2: Standards and Best Practice

Use recognised community standards for data formats, metadata, identifiers, and documentation so research data is intelligible and reusable.

Artefacts an auditor will ask for
  • Approved list of discipline-specific metadata standards (Dublin Core, DataCite, DDI, ISA-Tab)
  • Persistent identifier policy (DOI, ORCID, ROR)
  • File format guidance promoting open and non-proprietary formats
  • Metadata schema templates for repository deposit
  • Training records for FAIR data practice
  • Quality assurance checklist for dataset deposit
Where this commonly fails
  • No DOI minting for datasets
  • Inconsistent metadata across deposits
  • Proprietary formats used without open alternatives
CONCORDAT-P3
Principle 3: Discoverability via Metadata

Data and supporting metadata should be discoverable through trusted catalogues, registries, and search services so others can find and evaluate research outputs.

Artefacts an auditor will ask for
  • Institutional data repository listed in re3data or FAIRsharing
  • Catalogue export feeds to aggregators (CORE, OpenAIRE, B2FIND)
  • Search engine optimisation evidence for repository landing pages
  • Dataset-level metadata harvesting via OAI-PMH
  • Sample DOI landing page screenshots
  • Indexing coverage report
Where this commonly fails
  • Repository not registered in trusted directories
  • Metadata not exposed via OAI-PMH
  • Landing pages noindex blocked
CONCORDAT-P4
Principle 4: Acknowledgement and Citation

Data producers, curators, and contributors should receive appropriate citation and acknowledgement when their data is reused.

Artefacts an auditor will ask for
  • Data citation policy with recommended format
  • Author guidelines requiring data citations in publications
  • Repository-generated citation strings on landing pages
  • ORCID linking for dataset authors
  • Sample citations in recent institutional outputs
  • Acknowledgement template for funded research data
Where this commonly fails
  • Citation strings missing from landing pages
  • No ORCID enforcement for dataset authors
  • Author guidance does not mention dataset citation
CONCORDAT-P5
Principle 5: Career Recognition

Open data practices should be recognised in researcher assessment, career progression, and reward structures.

Artefacts an auditor will ask for
  • Promotion and progression criteria referencing open data contributions
  • Researcher development framework mapped to open practice
  • Annual review templates including data-sharing achievements
  • DORA signatory status
  • Recognition scheme entries for open data work
  • Communications celebrating open data exemplars
Where this commonly fails
  • Promotion criteria silent on open data
  • No DORA alignment
  • Reward decisions still dominated by journal impact factor
CONCORDAT-P6
Principle 6: Cost Recovery and Sustainability

The costs of making data open and preserving it long term should be recognised as a legitimate research cost and provided for in funding arrangements.

Artefacts an auditor will ask for
  • Data management plan (DMP) cost lines in grant applications
  • Institutional charging policy for repository storage above thresholds
  • Five-year sustainability plan for the institutional data repository
  • FEC (Full Economic Costing) entries for data management
  • Service-level agreement with external preservation provider
  • Annual cost report for open data services
Where this commonly fails
  • No costing in DMPs
  • Repository running on unfunded goodwill
  • Long-term preservation costs not modelled
CONCORDAT-P7
Principle 7: Legitimate Constraints on Openness

Openness must be balanced with legitimate restrictions such as protecting personal data, commercial interests, national security, and ethical considerations.

Artefacts an auditor will ask for
  • Decision matrix for open, restricted, controlled, or closed datasets
  • Data Protection Impact Assessment templates for research data
  • Ethical review records covering data sharing
  • Commercial sensitivity review workflow
  • Export control screening for sensitive datasets
  • Managed access procedure for restricted data
Where this commonly fails
  • No managed access process for restricted data
  • DPIAs not completed for sensitive research
  • Export control screening missing
CONCORDAT-P8
Principle 8: Trusted Repositories

Data should be deposited in trusted repositories that provide preservation, access control, and curation services aligned with community expectations.

Artefacts an auditor will ask for
  • Approved repository list with selection criteria
  • CoreTrustSeal or nestor seal certification for institutional repository
  • Repository service description document
  • Preservation policy with bit-level and logical preservation commitments
  • Repository disaster recovery test results
  • Access control configuration evidence
Where this commonly fails
  • Repository not certified
  • No documented preservation policy
  • Disaster recovery not tested
CONCORDAT-P9
Principle 9: Skills and Training

Researchers and support staff should have access to the skills, training, and support needed to manage and share data effectively.

Artefacts an auditor will ask for
  • Annual training calendar covering DMP writing, FAIR data, repository deposit
  • Researcher training completion records
  • PGR (postgraduate researcher) mandatory data skills module
  • Data steward role descriptions and competency frameworks
  • Library and IT data champion network records
  • Post-training evaluation reports
Where this commonly fails
  • Training optional and poorly attended
  • No data champion network
  • PGR programme silent on data skills

Constraints on Openness

CONCORDAT-PERSONAL
Protecting Personal Data in Research

Personal data in research must be processed lawfully and shared only with appropriate safeguards such as anonymisation, controlled access, or participant consent.

Artefacts an auditor will ask for
  • Anonymisation standard operating procedure
  • Pseudonymisation key management evidence
  • Five Safes framework implementation for trusted research environments
  • Participant information sheets covering data sharing
  • DPIA records for personal data research projects
  • Trusted research environment access logs
Where this commonly fails
  • Anonymisation done ad hoc
  • No Five Safes equivalent for restricted access
  • Participant consent silent on future sharing
CONCORDAT-SECURITY
Security for Sensitive Research Data

Sensitive research data must be protected by proportionate security controls covering storage, transfer, and access.

Artefacts an auditor will ask for
  • Data classification scheme mapped to research data tiers
  • Trusted research environment ISO 27001 certificate
  • Encryption standard for data at rest and in transit
  • Access provisioning workflow with manager approval
  • Penetration test summary of repository and TRE
  • Incident response runbook for research data breaches
Where this commonly fails
  • TRE uncertified
  • Encryption not enforced for transfer
  • Access logs not reviewed

Culture, Equity and Collaboration

CONCORDAT-COLLAB
International and Cross-Sector Collaboration

Open research data activity should align with international principles and support cross-sector partnerships with industry, public bodies, and civil society.

Artefacts an auditor will ask for
  • EOSC (European Open Science Cloud) alignment statement
  • GO FAIR initiative participation evidence
  • Cross-sector data sharing agreements
  • International transfer assessments where applicable
  • Industry collaboration data sharing protocol
  • Public engagement records on open research data
Where this commonly fails
  • No EOSC or GO FAIR engagement
  • Industry agreements override Concordat defaults without review
  • International transfer assessments missing
CONCORDAT-EQUITY
Equity, Diversity, and Inclusion in Open Data

Open research data practice should consider equity of access, indigenous data sovereignty, and the inclusion of underrepresented voices in data infrastructures.

Artefacts an auditor will ask for
  • EDI in open research statement
  • CARE Principles alignment evidence for indigenous data
  • Accessibility audit of repository interfaces (WCAG 2.2)
  • Language and translation policy for metadata
  • Community engagement records with patient or public groups
  • Co-production protocols for data with community partners
Where this commonly fails
  • Repository fails WCAG checks
  • CARE Principles not considered
  • Community partners not credited

DMP

UKCONCDATA-1
Data Management Plan

Per UK Concordat on Open Research Data (UKRI): Data Management Plan. Source-grounded summary control covering authoritative framework structure + key obligations. See manifest + log for detailed mapping.

Artefacts an auditor will ask for
  • Authoritative source-grounded evidence for UKCONCDATA-1
Where this commonly fails
  • see authoritative source for detailed gap analysis

Data Management Planning

CONCORDAT-DMP
Data Management Planning

Every funded research project should have a current data management plan describing how data will be collected, stored, shared, and preserved.

Artefacts an auditor will ask for
  • Institutional DMP template aligned to funder requirements
  • DMP register linked to grant management system
  • DMP review records from data stewards or librarians
  • Sample completed DMPs from active projects
  • Mid-project DMP refresh evidence
  • End-of-project data deposit reconciliation against DMP
Where this commonly fails
  • DMPs written once and never updated
  • No central register of DMPs
  • No reconciliation between DMP and final deposits
CONCORDAT-RETENTION
Retention and Preservation Periods

Research data should be retained for periods appropriate to its value, funder requirements, and disciplinary norms, typically at least ten years from last access.

Artefacts an auditor will ask for
  • Research data retention schedule
  • Disposition records for time-expired datasets
  • Funder retention requirements mapped to institutional schedule
  • Preservation action logs (format migration, integrity checks)
  • Retention exceptions register
  • Repository retention metadata
Where this commonly fails
  • No retention schedule
  • Datasets deleted before minimum retention reached
  • Disposition decisions undocumented
CONCORDAT-SOFTWARE
Research Software and Code Sharing

Research software, scripts, and code underpinning data should be shared under open licences alongside the data wherever feasible to support reproducibility.

Artefacts an auditor will ask for
  • Research software policy referencing FAIR4RS principles
  • Approved code repositories (GitHub, GitLab, institutional Git)
  • Zenodo or Software Heritage archive links for released code
  • Citation file format (CITATION.cff) templates
  • Container image registry usage evidence
  • Sample reproducibility packages
Where this commonly fails
  • Code not archived alongside data
  • No software citation guidance
  • Containers not preserved

Equity

UKCONCDATA-3
Equity, Collaboration, Monitoring

Per UK Concordat on Open Research Data (UKRI): Equity, Collaboration, Monitoring. Source-grounded summary control covering authoritative framework structure + key obligations. See manifest + log for detailed mapping.

Artefacts an auditor will ask for
  • Authoritative source-grounded evidence for UKCONCDATA-3
Where this commonly fails
  • see authoritative source for detailed gap analysis

Licensing, Publication and Monitoring

CONCORDAT-LICENSING
Licensing and Reuse Terms

Open data should be released under clear, permissive licences that enable reuse while respecting attribution and any necessary constraints.

Artefacts an auditor will ask for
  • Approved licence list (CC BY 4.0, CC0, Open Government Licence, ODbL)
  • Repository licence selection workflow
  • Sample dataset licence statements
  • Legal review records for non-standard licences
  • Licence reuse statistics report
  • Researcher guidance on choosing a licence
Where this commonly fails
  • All-rights-reserved by default
  • Conflicting licences across files in same dataset
  • No researcher guidance on licence choice
CONCORDAT-MONITOR
Monitoring and Reporting

Institutions should monitor open research data activity and report progress to senior leadership, funders, and the wider community.

Artefacts an auditor will ask for
  • Annual open research data dashboard
  • Deposit and download metrics by discipline
  • Funder compliance audit reports
  • Researcher engagement survey results
  • Open Research Steering Group annual report
  • Public Concordat self-assessment statement
Where this commonly fails
  • No KPIs for open data
  • No public self-assessment
  • Reports go to operational only, not executive
CONCORDAT-PUBLISH
Publisher and Journal Alignment

Institutions should work with publishers and journals to align data availability statements, supplementary data, and peer review of data with Concordat principles.

Artefacts an auditor will ask for
  • Guidance on writing data availability statements
  • Sample compliant data availability statements from recent papers
  • Read and publish agreement schedule referencing data sharing
  • Mandate compliance dashboard at article level
  • Peer review of data process for selected journals
  • Author workflow integrating repository deposit with submission
Where this commonly fails
  • Data availability statements vague or missing
  • No alignment between OA agreements and data sharing
  • No deposit prior to submission

Open Data

UKCONCDATA-2
Open Data, Licensing, Citation

Per UK Concordat on Open Research Data (UKRI): Open Data, Licensing, Citation. Source-grounded summary control covering authoritative framework structure + key obligations. See manifest + log for detailed mapping.

Artefacts an auditor will ask for
  • Authoritative source-grounded evidence for UKCONCDATA-2
Where this commonly fails
  • see authoritative source for detailed gap analysis
Assembled from the framework's own control set. Every line traces to a control in the graph, so this pack is regenerated rather than written, and stays current as the graph does.

Assembled from the framework’s own control set, so this list is regenerated rather than written and stays current as the graph does.