---
name: research-ethics-and-consent-design
description: >
  Designs the ethical arrangements for a study before fieldwork: informed consent
  that participants actually understand, consent for recording and for AI
  processing, data minimisation, anonymisation and re-identification risk,
  protections for vulnerable participants, duty of care and distress protocols on
  sensitive topics, incentives without undue inducement, withdrawal rights and
  their real limits, and the judgement that some research should not be conducted
  at all. Use when someone says "write a consent form", "is this research
  ethical", "can we interview children or patients", "do we need consent to use
  AI on this", "how do we anonymise this", "our sample is too small to be
  anonymous", "what incentive is appropriate", or "the topic is sensitive".
category: 13 Research Quality, Ethics and Governance
ref: "13.05"
tier: 1
inherits: [K2, K3, K4, K5]
---

# Research Ethics and Consent Design

## 1. One-line description
Designs and documents the ethical arrangements of a study before it goes to field, covering consent, data minimisation, identifiability, vulnerability, duty of care, incentives and withdrawal, and reaching a judgement on whether the research should be conducted at all.

## 2. What this skill is used for

**The research problem it solves.** Research ethics fails in a characteristic way: not through cruelty but through paperwork. A consent form exists, is legally competent, is four hundred words of clause-dense text, and is agreed by a participant who did not read it and could not have restated a single element of it. **Consent that is not understood is not informed consent**, whatever it establishes contractually. Everything else follows from that gap. Data is collected because the platform had a field for it. Recordings are made under a permission that covered a note-taker. A quote is published with a role, a sector and a market attached, and it identifies exactly one person to anyone in that industry. An employee is interviewed about their manager through a route their manager arranged. A participant in financial difficulty is asked about their debts by a moderator with no protocol for what to do when they start crying.

Two things have made this sharper. Identifiability has become easier: the specificity that makes qualitative research valuable is the same specificity that identifies people, and small specialist samples make a role plus a market plus a sector a name. And AI processing is now routine in studies whose consent predates anyone thinking about it, which means data is being sent to systems under permissions that did not contemplate them.

This is a **design-time** discipline. Almost every ethical failure is cheap to prevent at design and impossible to repair afterwards, because the participant has already been recruited, the data has already been collected, and the consent has already been given for something else.

**Where it sits.** Before fieldwork, always, and alongside design. It is a precondition of collection rather than a stage of it. It also runs again before reporting, because identifiability is a reporting decision as much as a collection one.

**Typical use cases.**
- Designing consent, participant information and withdrawal arrangements for a new study.
- Assessing whether a proposed study involves vulnerable participants and what additional protections apply.
- Designing a distress protocol and escalation route for research on a sensitive topic.
- Working out whether findings from a small or specialist sample can be reported without identifying people.
- Establishing whether existing consent covers a new use, including AI processing.
- Setting an incentive that recognises participants' time without becoming an inducement.
- Reaching and recording a judgement that a piece of research should not be conducted as proposed.

**Who uses it.** Research designers and project leads; qualitative researchers working on sensitive topics; anyone recruiting through a gatekeeper with authority over participants; client-side commissioners who carry the accountability; and teams building AI-moderated or AI-assisted studies, where the consent questions are newest and least settled.

## 3. When to use it

- Before any study involving people, at design stage, as a matter of course rather than escalation.
- The topic touches health, money, employment, family, immigration status, sexuality, belief, bereavement, addiction, safety or any other area where disclosure carries risk to the participant.
- Participants are children, patients, employees discussing their employer, service users discussing the service they depend on, or people in financial or personal distress.
- Recruitment runs through anyone with power over the participant: an employer, a clinician, a teacher, a caseworker, a landlord, a benefits administrator.
- The sample is small, specialist, or defined by an attribute that few people share, so that a role plus a market plus a sector identifies one person.
- Recording, transcription, biometric capture, screen capture or observation is proposed.
- AI will process participant data at any step, including transcription, coding, summarisation or moderation.
- Personal data collected for one purpose is being reused for another.
- An incentive is being set, particularly a large one, or one aimed at a population for whom the amount is materially significant.
- Findings could be used to the disadvantage of the group they came from.

## 4. When NOT to use it

- **A definitive answer on the law is what is needed.** This skill designs research ethics and applies the general principles of applicable data protection law: lawful basis, purpose limitation, minimisation, retention, participants' rights, additional protection for special categories of data, and restrictions on transfers. **Requirements differ by jurisdiction, and legal advice is not a research judgement.** Where the question is whether a specific processing operation is lawful in a specific jurisdiction, in a regulated sector, or across a border, it goes to qualified legal advice. Equally, **a lawyer's clearance is not an ethics approval**: lawful research can be unethical, and a legal sign-off does not answer whether the study should be done.
- **A formal ethics committee or institutional review board has jurisdiction.** Where a study falls under an institutional, clinical or regulatory review process, that process governs and this skill prepares the submission rather than substituting for it. Do not use a well-designed internal ethics assessment as a reason to skip a review that applies.
- **The question is instrument wording rather than participant treatment.** Whether a question is leading, intrusive in phrasing or badly ordered is **02.04 Question Bias Detection** and **02.01 Survey Questionnaire Design**. This skill governs whether the question may be asked of this person at all, which is a different judgement.
- **The question is operational governance of AI rather than participant consent.** What may be sent to which system, disclosure to clients, audit trails, sign-off records and model version control are **13.06 AI Research Governance**. The two meet at consent for AI processing, which is designed here and operated there.
- **The question is whether the findings are accurate.** Methodological soundness is **13.01 Research Quality Review** and bias is **13.04 Bias Detection**. A study can be ethically immaculate and methodologically worthless, and the reverse.
- **Fieldwork has already run and the question is retrospective cover.** Where data has been collected and someone wants a consent arrangement written to cover it, that is not consent design. Say so plainly. The available options are to obtain consent now for the actual use, to restrict the use to what the original consent covered, or to delete. Backdating an arrangement is not among them.
- **The intent is to find the wording that makes an unacceptable study permissible.** Where the request is to draft consent language that will secure agreement to something a participant would refuse if they understood it, refuse, per K4 §9, and say what the honest version would have to disclose. Comprehension is the standard, and a form engineered to be agreed rather than understood fails it by design.

## 5. Required inputs

**Required.**
- **What will actually happen to a participant**, step by step: how they are found, what they are told, what they are asked, how long it takes, what is recorded, and what happens afterwards. Ethics attaches to the sequence, not to the method's name.
- **What data will be collected**, field by field, including free text, metadata, recordings and anything the collection route captures incidentally.
- **Who the participants are**, including any characteristic that makes them vulnerable, dependent on a gatekeeper, or identifiable in a small population.
- **What the data will be used for**, by whom, for how long, and who will see it in identifiable form. Vagueness here becomes vagueness in the consent, which is where consent fails.
- **The recruitment route**, and specifically whether anyone in it holds power over the participant.

**Optional, and what each one adds.**
- **The analysis plan (01.07).** Makes real data minimisation possible: every field is justified by a named analysis or it is not collected. Without it, minimisation becomes a preference rather than a procedure.
- **The reporting plan and the intended attribution format.** Lets the re-identification assessment run at design stage, when the sample can still be broadened or the attribution string shortened, rather than at report stage when neither is available.
- **Existing consent wording**, where participants have been recruited or data already exists. Determines what the current permission actually covers, which is nearly always narrower than assumed.
- **The organisation's data protection position**: lawful basis, retention schedule, transfer arrangements, and the named person accountable.
- **Any applicable sector code, professional standard or client policy.** These frequently impose requirements above the legal baseline, particularly on incentives, on children and on health topics.
- **The moderator's or interviewer's training and experience on this topic.** Determines whether a duty-of-care protocol is realistic in practice or is a document nobody can execute.

## 6. Questions to ask before starting

1. **What is the worst realistic outcome for a participant from taking part?** Determines the whole shape of the arrangements. *Default if unanswered:* work it out explicitly, naming the harm and who it reaches. If the answer is genuinely nothing, the arrangements are light and that conclusion should be recorded rather than assumed.
2. **Is anyone in the recruitment or participation chain in a position of power over the participant?** Determines whether consent can be voluntary at all. *Default:* if a gatekeeper is involved, assume the power question is live and design around it.
3. **How many people share the participant's defining attributes?** Determines re-identification risk and therefore what may be reported. *Default:* estimate the population; where it is small or unknown, design for identifiability.
4. **Will AI process participant data, at which steps, and does the consent contemplate it?** Determines whether new consent is needed. *Default:* if the consent does not mention it, it does not cover it.
5. **What happens if a participant becomes distressed, discloses harm, or asks for help?** Determines the duty-of-care protocol and the escalation route. *Default:* no study on a sensitive topic proceeds without a written protocol and a named human to escalate to.
6. **How long is the data kept, by whom, and what triggers deletion?** Determines retention and the honesty of the consent. *Default:* the shortest period the analysis requires, stated as a period rather than as "as long as necessary".
7. **Could the findings be used against the group they came from?** Determines reporting arrangements and, occasionally, whether the study proceeds. *Default:* ask it explicitly; it is the question that most often changes a design and least often gets asked.

## 7. Step-by-step methodology

**Step 1. Answer the prior question: should this research be done at all?** Before designing arrangements, establish that there is something to arrange. Four tests, and a study only needs to fail one.

**Necessity.** Can the question be answered without asking these people this? Existing data, a less intrusive design, a smaller sample, or a question already answered elsewhere (10.01) all remove the justification. Research burden is a cost borne by participants for someone else's benefit and it needs a reason.

**Proportionality.** Is the burden and risk proportionate to what will be learned? A twelve-minute survey on brand preference needs almost no justification. A ninety-minute interview about a bereavement, informing a marketing decision, is a different calculation and it is frequently made badly, because the researcher weighs the value to the commissioner rather than to anyone else.

**Harm to the group.** Could the findings be used against the people who provided them? Research identifying a group as less profitable, higher risk or less worth serving is research whose participants contributed to their own disadvantage. This does not automatically prohibit the study, and it changes what is reported, at what aggregation, and to whom.

**The refusal test.** Would a reasonable participant, understanding fully, agree? If the design depends on them not fully understanding, the design is the problem and no consent wording repairs it.

**Some research should not be conducted, and saying so is a legitimate output of this skill.** Record the judgement and the reasoning, route it to a human per K5 §2.4, and where the study proceeds against the assessment, record that too. *Correct result:* a written proceed, proceed-with-changes, or do-not-proceed judgement with its reasoning, made before any arrangements are drafted.

**Step 2. Map the participant journey and attach the ethical requirement to each stage.** Recruitment, screening, consent, participation, incentive, data handling, analysis, reporting, afterwards. Ethics is a property of the sequence, not a form at the start. At each stage ask what the participant knows, what they can still decline, what is being captured, and who can see it. Two stages are routinely skipped. **Screening** collects personal data (often health, income or household data) from people who are then not recruited, and it needs its own lawful basis, retention rule and deletion trigger. **Afterwards** holds withdrawal, retention, secondary use and reporting, and it is the part participants are told least about.

**Step 3. Design consent that a participant could restate.** Informed consent has six elements, and each has to be present, specific, and comprehensible.

- **Purpose.** What the research is for, in concrete terms. "To improve our services" is not a purpose; it is a category. Where the commissioner cannot be named, say what kind of organisation it is and why the name is withheld.
- **What is collected.** Including recording, transcription, screen or observation capture, metadata, and anything the platform captures incidentally. Participants consistently underestimate this.
- **How it is used.** Analysis, reporting, quotation, and specifically whether verbatim words may be published and in what form.
- **Who sees it.** In identifiable form, and separately in de-identified form. This is the element participants care most about and forms disclose least.
- **How long it is kept, and what happens then.** A period and a deletion trigger, not "as long as necessary".
- **The right to withdraw**, with its real limits, per step 8.

**Comprehension is the standard, not disclosure.** The test is whether a participant could restate the six elements in their own words afterwards, and it is worth testing on a handful of people from the actual population, particularly where literacy, language or condition affects reading. Design for it: short sentences, plain words, the participant's language, active voice, no clause stacking, no defined terms. **Layer it:** a short, complete summary carrying all six elements, with full detail offered rather than buried. A layered form is not a shortened one, and the summary omits nothing that would change a decision.

**Consent is a process rather than a moment**, with re-consent wherever reality diverges from what was agreed: a topic going further than described, unanticipated recording, a new use, a follow-up. **Two consents need separate treatment.** Recording is consented to separately, with what happens to the recording stated and participation still possible if it is declined wherever feasible. And **AI processing is consented to specifically**: if a system will transcribe, code, summarise, moderate or analyse their words, participants are told so, told what kind of processing, and told what a human does with the result. Consent that predates AI processing does not cover it, and de-identification does not remove the obligation, because participants care about what reads their words and are entitled to know (13.06).

**Step 4. Minimise the data, field by field.** The discipline is procedural, not attitudinal. Take the collection instrument and, for every field, name the analysis that will use it. Fields with no named analysis are not collected. This removes, reliably: demographic detail collected out of habit, precise ages and dates of birth where a band would do, full postcodes where a region would do, names where an identifier would do, employer names where a sector would do, and open-text fields that exist because the template had one.

Three traps. **Free text is an uncontrolled collection channel:** participants put names, addresses, account numbers, health details and third parties' information into open ends, and the study collects them whether it asked or not. Plan a screening pass before analysis and a redaction rule. **Metadata is data:** timestamps, device details, location, contact and engagement logs. **Third parties are participants who did not consent:** someone describing their partner's illness or a colleague's conduct has supplied personal data about a person who was never asked, needing the same minimisation and a retention rule of its own.

Minimisation is also the strongest protection available, because data not collected cannot be breached, re-identified, subpoenaed, or reused under a consent that did not cover it.

**Step 5. Assess identifiability properly, and design reporting around it.** Three states, routinely confused. **Anonymised** means the individual cannot be identified by anyone, by any reasonably available means, including by combining with other data. It is a high bar and it is achieved far less often than claimed. **Pseudonymised** means direct identifiers are replaced with a code and a key exists somewhere; this is personal data still, with all the obligations attached. **De-identified in the output** means the report does not name them, which says nothing about whether they are identifiable from it.

The operative risk is combination. **A role plus a market plus a sector identifies one person.** "Head of procurement, mid-size logistics firm, Nordic market" is a name to anyone in that industry, and the industry is exactly who reads the report. Run it as a design-stage step: write the attribution string you intend to publish and ask how many people in the world it describes. If the answer is one, or a handful, the string is a name.

The responses, in order of preference: **broaden the attribution** (sector band rather than sector, region rather than market, seniority rather than title); **aggregate** to theme and prevalence with no attribution; **paraphrase instead of quoting**, labelled as the analyst's summary rather than the participant's words (K4 §2.2); **seek specific consent to be identifiable**, legitimate where the participant genuinely understands the audience and consequences; or **do not report it**. What is not available is publishing the identifying string and calling it anonymous.

Two additional cases. **Small quantitative subgroups** identify too: a cell of four crossed with an attitudinal answer can expose individuals in a client's own base, so set a minimum reporting cell size at design stage. And **employee research** is the highest-risk case in commercial work, because the report's audience is the employer and the attribution string is a department and a tenure band.

**Step 6. Identify vulnerability and apply the protections it requires.** Vulnerability is situational rather than a property of a person, and it comes from three sources: capacity to consent, dependence on someone in the chain, and exposure to harm from participating.

**Children and young people.** Consent from the person with parental responsibility plus the child's own assent, which is a real veto and not a formality. Materials at the child's actual reading level. An appropriate adult present or reachable where the topic warrants. Age-appropriate limits on topic, duration and recording. Requirements and age thresholds differ by jurisdiction and sector and must be checked, not assumed.

**Patients and people with health conditions.** Never recruit through the treating clinician in a way that implies participation affects care, and state explicitly that it does not. Consider capacity, including fluctuating capacity, and account for fatigue and treatment burden in session length. Health data attracts additional protection under applicable data protection law almost everywhere, and it is present as soon as a condition is mentioned, whether or not the study is about health.

**Employees reporting on their employer.** The commonest unrecognised vulnerability in commercial research: livelihood is at stake, the employer commissioned the study and will read it, and recruitment usually runs through management. Protections: recruitment management does not control or observe; a true statement of what the employer will and will not see; reporting thresholds preventing identification by team, site or tenure; no verbatim from small units. Where none can be guaranteed, the honest position is that the study measures what people are willing to say to their employer, which is a different construct and is reported as one.

**People in financial or personal distress.** Protections: an incentive that does not become the reason for participating, freedom to skip and to stop with no consequence to the incentive, a distress protocol, and topic limits that hold even when the participant volunteers more.

**Any participant recruited through a power-holder** (employer, clinician, teacher, caseworker, landlord). The question is whether declining is genuinely available and genuinely private. Design so the gatekeeper does not know who took part.

**Step 7. Write a duty-of-care protocol for sensitive topics, and make it executable.** A protocol nobody can execute is worse than none, because it transfers responsibility to a document. It contains: the **stop rule** (what the moderator does when a participant becomes distressed, which begins with stopping rather than continuing gently); the **disclosure rule** (what happens if a participant discloses harm to themselves or others, decided and stated in the consent beforehand, since a promise of confidentiality that cannot be kept is worse than an honest limit); the **signposting** (support information prepared in advance and appropriate to the market, without the researcher acting as a counsellor); the **escalation route** (a named human, reachable during fieldwork hours, with authority to stop a session or a study); and the **researcher's own support**, since exposure to distressing material accumulates on interviewers and analysts.

**Where any part of collection is AI-moderated, human escalation is mandatory and designed rather than assumed.** An automated moderator cannot reliably recognise distress, judge capacity, exercise a stop rule with judgement, or take responsibility. Required: a low-threshold escalation trigger, a route to a real person, a visible and always-available exit, and a clear statement that the participant is speaking to a system and how to reach a human (K5 §2.4). A sensitive-topic study that cannot provide human escalation is not run AI-moderated.

**Step 8. Set incentives that respect time without inducing.** An incentive recognises time and cost. It becomes an inducement when it is large enough that someone accepts a risk or discomfort they would otherwise decline, and that depends entirely on circumstances: a token to one population is a week's food to another. Four rules. **Proportionate** to time and burden, benchmarked against the participant's situation rather than the study's budget. **Unconditional on content**, never contingent on a particular answer or on completing every question. **Paid even where the participant stops early**, at least pro rata, or the right to withdraw is not real. **Stated up front**, because an incentive revealed late is a retention device.

**Step 9. Design withdrawal, and be honest about its limits.** Withdrawal during a session is absolute and straightforward. **Withdrawal afterwards has real limits, and they belong in the consent rather than in an email six months later.** Data can be removed from a dataset up to the point analysis is run; once a report is published, a contribution cannot be extracted from an aggregate and a published quote cannot be recalled. **So the consent states the deadline**, as a date or an event, after which withdrawal can no longer remove the contribution from outputs already produced. It also states what withdrawal still delivers after that point: deletion of identifiable records and recordings, no further use, and no inclusion in anything not yet produced. That is a real right, and promising more than it is undermines it. The right to a copy is designed the same way: what a participant receives, in what form, and how long it takes.

**Step 10. Record the ethics decisions, and route the judgements that need a human.** The record is short and it is what makes the design defensible: the step 1 judgement with its reasoning; the vulnerability assessment; the identifiability assessment with the intended attribution format; the lawful basis and retention position; the AI processing position and how it is consented to; the duty-of-care protocol and named escalation contact; the incentive rationale; and the withdrawal deadline. Then route to a named human, per K5 §2.4 and §3.1: any do-not-proceed or proceed-with-changes judgement; any study involving children, patients, employees reporting on their employer, or people in distress; any unresolved identifiability; and any reuse under a consent that did not anticipate it. **These are ethical judgements with professional accountability attached and they are not delegable to a system** (K5 §2.8).

Finally, design the **reporting obligation to participants**: what they are told about what was found, in what form, and when. It need not be a report; a short summary, a link or an offer will do. Where nothing will be shared, say so at consent rather than leaving the impression that something will.

## 8. Analytical framework

Two frames. The first is the assessment sequence, which is strictly ordered because a failure at one level makes the next irrelevant:

    Should it be done? → Can consent be genuinely voluntary?
        → Is consent genuinely informed? → Is the data minimised?
            → Are participants identifiable? → Is there a duty of care,
              and can it be executed? → Are the rights afterwards real?

The second is the harm frame, applied at each stage:

    Who could be harmed → How → How likely → How severe
        → What removes it → What remains, and who accepts it

**Applying it.** Never begin at consent. Beginning at consent is what produces well-documented studies that should not have been run, because a consent form can be written for anything and the writing of it feels like the ethical work. The first question is whether the research should exist, and it is answered before any arrangements are drafted.

**The comprehension test governs the whole of consent.** Not what the form says, but what the participant could restate afterwards. Any consent process can be evaluated against it, and most fail.

**And the residual-risk rule:** every harm that cannot be removed by design is named, and a person accepts it. Unnamed residual risk is not absence of risk; it is risk nobody has taken responsibility for.

## 9. Output format

**A. Ethical assessment.** The step 1 judgement (proceed, proceed with changes, do not proceed), the four tests with their answers, and the reasoning. Written even when the answer is straightforward, because the record of a low-risk study having been assessed is what distinguishes a considered design from an unconsidered one.

**B. Participant journey with ethical requirements**, stage by stage, including screening and afterwards.

**C. Participant information and consent**, layered: a short summary carrying all six elements in plain language, and the full detail. Separate, explicit consents for recording and for AI processing. Written at the population's reading level, in their language, and comprehension-tested where feasible.

**D. Data minimisation schedule.**

| Field | Why collected (named analysis) | Identifiable? | Retention | Deletion trigger |
|---|---|---|---|---|

Fields with an empty second column are removed rather than justified.

**E. Identifiability assessment.** The intended attribution string, how many people it describes, the reporting rule that follows (minimum cell size, attribution format, quote policy), and the treatment of free text and third-party data.

**F. Vulnerability assessment and protections**, per group, with the recruitment route and how power in it was addressed.

**G. Duty-of-care protocol.** Stop rule, disclosure rule, signposting, named escalation contact with hours, AI escalation trigger where applicable, and researcher support.

**H. Incentive rationale**, with the proportionality reasoning and the partial-completion rule.

**I. Rights and their limits.** Withdrawal, including the deadline and what withdrawal delivers after it; access to a copy; and the reporting-back arrangement.

**J. Review points**, per K5 §3, naming the decision, the person, and what turns on it.

**When the evidence is thin.** Where a risk cannot be assessed (an unknown population size, an unclear recruitment route, an unspecified secondary use), the output says so and **defaults to the protective assumption** rather than to the convenient one: assume identifiability, assume the gatekeeper has power, assume the consent does not cover the new use. Where a required arrangement cannot be provided (no human escalation available, no way to prevent gatekeeper knowledge of participation), the honest output is that the study cannot proceed in this form, with what would change that. **"This should not be conducted as designed" is a complete and legitimate output**, and it is more useful than arrangements that document a risk nobody removed.

## 10. Quality checks

Run before fieldwork. K4 §8 runs anyway.

1. Was the should-it-be-done judgement made and recorded before any consent wording was drafted?
2. Could a participant from the actual population restate the six consent elements in their own words?
3. Are recording and AI processing consented to separately and explicitly, rather than folded into general participation?
4. Does every collected field have a named analysis behind it, and were the rest removed?
5. Is there a plan for personal and third-party data arriving in free text, including a screening pass and a redaction rule?
6. Has the intended attribution string been tested for how many people it describes?
7. Is a minimum reporting cell size set for quantitative subgroups?
8. Does the recruitment route prevent a gatekeeper from knowing who took part, wherever a power relationship exists?
9. Where the sample includes a vulnerable group, are the specific protections for that group present rather than a general statement of care?
10. Is the duty-of-care protocol executable by the actual moderator, with a named human reachable during fieldwork hours?
11. Where any collection is AI-moderated, is the escalation trigger designed, is the exit always visible, and is the participant told they are speaking to a system?
12. Is the incentive proportionate to this population's circumstances, unconditional on content, and payable on partial completion?
13. Does the consent state the withdrawal deadline and what withdrawal delivers after it, rather than promising more than can be honoured?
14. Is the retention period a period with a deletion trigger?
15. Are the K5 §2.4 judgements routed to a named human, and is the decision recorded?
16. Is the reporting-back arrangement stated, including where the answer is that nothing will be shared?

## 11. Common failure modes

| Failure | How to recognise it | How to prevent it |
|---|---|---|
| **Consent as paperwork** | A legally competent form nobody could restate | Comprehension is the standard. Test it on the actual population |
| **Beginning at the form** | A well-documented study that should not have been run | Step 1 before any drafting. Should-it-be-done precedes how |
| **Purpose stated as a category** | "To improve our services" | Concrete purpose, concrete audience, concrete use |
| **Collection by template** | Fields present because the platform had them | The minimisation schedule. No named analysis, no field |
| **Free text as a blind spot** | Names, account numbers and third parties in open ends | Screening pass and redaction rule designed in advance |
| **Anonymity asserted** | "All responses are anonymous" alongside role, sector and market attribution | Write the attribution string and count how many people it describes |
| **The identifying small cell** | A subgroup of four reported in a client's own employee study | Minimum cell size set at design stage |
| **Gatekeeper-arranged consent** | Employees recruited by managers who then know who took part | Recruitment route the power-holder cannot observe |
| **Vulnerability unrecognised** | Employees, patients or people in distress treated as general public | Explicit vulnerability assessment, with protections per group |
| **The unexecutable protocol** | A distress protocol with no named contact and no hours | Name the person, state the hours, confirm the moderator can execute it |
| **AI moderation without escalation** | An automated interview on a sensitive topic with no route to a human | Mandatory escalation trigger, visible exit, disclosed system status |
| **Inducement disguised as incentive** | An amount large relative to the participant's circumstances | Benchmark against the population, not the budget |
| **The unlimited withdrawal promise** | "You can withdraw at any time" with a published report already out | State the deadline and what withdrawal delivers after it |
| **Retrospective consent** | A form written to cover fieldwork already conducted | Not available. Re-consent, restrict the use, or delete |
| **AI: fluent form, unchanged substance** | A readable consent form that still omits who sees the data and for how long | Check the six elements are present and specific, not that the prose is clear |
| **AI: jurisdictional confidence** | A specific legal requirement asserted for a specific country | State principles generically; specific legal questions go to qualified advice |

## 12. AI guardrails

Universal prohibitions are inherited from K4. K5 §2.4 governs the routing of every ethical judgement in this skill.

1. **Never draft consent wording designed to secure agreement rather than understanding.** Where a form has been engineered so that a participant would not object, it fails the standard by construction, whoever requested it (K4 §9).
2. **Never state a specific legal requirement for a specific jurisdiction.** Applicable data protection law is described in principle: lawful basis, purpose limitation, minimisation, retention, participants' rights, additional protection for special categories, restrictions on transfers. Naming a threshold, an age, a period or a mechanism as legally required in a country is outside what this skill may assert, and it goes to qualified legal advice.
3. **Never treat a legal clearance as an ethics approval, or an ethics assessment as legal advice.** They answer different questions and neither substitutes for the other.
4. **Never assert that data is anonymised.** State what identifiers were removed and what re-identification risk remains, given the sample size, the attribution format and the audience.
5. **Never design an AI-moderated study on a sensitive topic without a human escalation route, a low escalation threshold, and a visible exit.** This is not a configurable parameter.
6. **Never treat consent given before AI processing was contemplated as covering it.** Silence is not permission, and de-identification does not remove the obligation to say what reads a participant's words.
7. **Never write a retrospective consent arrangement for data already collected.** The options are re-consent, restriction to the original purpose, or deletion.
8. **Never resolve an ethical judgement without routing it to a named human** where it involves children, patients, employees reporting on their employer, people in distress, unresolved identifiability, or reuse beyond the original consent (K5 §2.4, §2.8).
9. **Never promise a right that cannot be delivered**, including unlimited withdrawal, absolute confidentiality where a disclosure rule exists, or anonymity in a sample too small to provide it.
10. **Never let commercial urgency change an ethical assessment.** A deadline is a reason to decide quickly, never a reason to decide differently, and where a study proceeds against the assessment, the assessment stays on the record.

## 13. Best-practice principles

1. **Consent that is not understood is not informed consent.** Everything in this skill follows from that sentence. Disclosure is not the standard; comprehension is.
2. **Ask whether the research should exist before designing how it will run.** A consent form can be written for anything, and writing one feels like doing the ethical work.
3. **Data you do not collect cannot be breached, re-identified, subpoenaed or reused.** Minimisation is the strongest protection available and the cheapest.
4. **Specificity is what makes qualitative research valuable and what identifies people.** These are the same property, and the reporting decision is where the trade-off actually gets made.
5. **Write the attribution string and count the people it describes.** Five seconds of work that prevents the most common identification failure in commercial research.
6. **Vulnerability is situational.** A senior professional discussing their employer to a study their employer commissioned is a vulnerable participant, and almost nobody treats them as one.
7. **Design so that declining is invisible to the person with power.** A right to decline that the gatekeeper can observe is not a right to decline.
8. **A protocol nobody can execute is worse than none**, because it transfers responsibility to a document and leaves the moderator alone in the room with the actual situation.
9. **Say what withdrawal cannot do.** The honest limit is a real right; the unlimited promise is a right that fails at exactly the moment it is exercised.
10. **Consent is a process with re-consent points**, not a signature. The moment the reality diverges from what was described, the consent has expired.
11. **Assume the consent does not cover the new use.** It almost never does, and the cost of asking again is small compared with the cost of having been wrong.
12. **Tell participants what was found.** It costs very little, it is what they most often ask for, and a research practice that takes from people and reports nothing back is corroding the thing it depends on.
13. **Some research should not be done, and a discipline that cannot say so has no ethics in it.** Record the judgement, route it to a human, and if it is overridden, keep the record.

## 14. Worked example

*Fictional scenario, used for illustration only. The organisation, participants and arrangements below are invented for the purpose of demonstrating method.*

**INPUT.** A healthcare provider group wants qualitative research with patients managing a chronic condition, to understand the experience of a newly introduced remote monitoring service. Proposed: 30 depth interviews, recruited by the clinical teams from their own patient lists, recorded and transcribed, with AI transcription and AI-assisted first-pass coding, and verbatim quotes in a report circulated internally and used in a conference presentation. Incentive proposed: a payment substantially above the local norm, "to ensure recruitment".

**PROCESS.**

*Step 1, the prior question.* Necessity: the experience question is not answerable from service usage data, which shows what patients did and not why. Proportionality: an interview about living with a condition is meaningful burden on people managing fatigue, but the research directly concerns a service they use and the findings could improve it. Harm to the group: a possible finding is that a subgroup engages less with monitoring, which in a provider context could translate into being deprioritised. That does not stop the study; it changes reporting, and it is recorded as a constraint. Refusal test: a patient understanding the arrangements would plausibly agree, provided two things are true, that participation cannot affect their care and that their clinician does not learn what they said. Judgement: **proceed with changes**, with four required.

*Step 2 and 6, recruitment and vulnerability.* Recruitment by the treating clinical team is the first required change. Two vulnerabilities compound: patients are a protected group, and their clinician holds power over their care and would know who took part. The redesign has clinical teams issue a general invitation with no individual approach and no record of who responds, with all subsequent contact through the research team, and an explicit written statement that participation is unknown to the clinical team and cannot affect care. The provider's initial objection is that this will slow recruitment. It will. The alternative is consent that is not voluntary.

*Step 3, consent, and the AI judgement call.* The six elements are drafted in plain language at a short summary length, with detail layered behind. Two separate consents are added: recording, and AI processing. The provider's position is that AI transcription is an internal processing detail patients need not be told about. The assessment disagrees: patients are being asked to describe their health, and what reads their words is exactly the kind of thing they care about. The consent states that a system transcribes and produces a first pass of coding, that a researcher reviews it, that the recordings and transcripts are not used to train any system, and that a human is responsible for what appears in the report. The wording is comprehension-tested with four patients from a support group, and two elements are rewritten after two of them cannot restate who would see their words.

*Steps 4 and 5, minimisation and identifiability, and the second judgement call.* The screening instrument collects diagnosis date, medication list, and household composition. Only condition duration band has a named analysis; the medication list and household composition are removed. Health data is present throughout and attracts additional protection under applicable data protection law, which is stated in the design without a jurisdictional claim.

The identifiability assessment is the harder problem. The intended attribution format is condition, age, treatment stage and site. Written out, "male, 62, on the advanced pathway at [named site]" describes a handful of people at that site and is a name to the clinical team who will read the report. Responses applied in order: attribution broadened to condition and a decade band only, with site removed entirely; a rule that no quote may combine more than two attributes; a minimum of five participants per site before any site-level observation is reported; and, for the conference presentation, paraphrase rather than verbatim on anything describing a specific clinical interaction, labelled as the analyst's summary (K4 §2.2).

*Step 7, duty of care.* The topic reaches deterioration, fear and, for some, mortality. Protocol written: stop rule; a disclosure rule stating in the consent that anything indicating immediate risk of harm will be passed to a named clinical contact, so confidentiality is bounded honestly rather than promised absolutely; signposting to the provider's own support service and an independent one; a named escalation contact reachable during interview hours; and a debrief arrangement for the two interviewers. AI moderation is considered for a second phase and rejected for this topic on the escalation ground.

*Step 8, the incentive.* The proposed amount is well above the local norm and is being used to overcome recruitment difficulty caused by the flawed route. Once recruitment is redesigned, the amount is set proportionate to a 60-minute session plus travel, payable in full if the participant stops early, and stated at invitation.

*Step 9, withdrawal.* The consent states that data can be removed up to the analysis lock date, which is given as an actual date; that after it, contributions cannot be extracted from aggregate findings or from a published report; and that withdrawal after that date still means deletion of recordings and identifiable records and no further use.

**OUTPUT.** An ethical assessment recording proceed-with-changes and the four required changes; a redesigned recruitment route that removes the clinician from the consent chain; layered participant information with separate recording and AI consents, comprehension-tested and revised; a minimisation schedule that removed two collection areas; an identifiability assessment with a broadened attribution rule, a two-attribute limit, a five-participant site threshold and a paraphrase rule for the external presentation; a duty-of-care protocol with a bounded confidentiality statement and a named clinical escalation contact; a proportionate incentive payable on partial completion; a stated withdrawal deadline; and a reporting-back arrangement offering participants a plain-language summary of findings. `RESEARCHER SIGN-OFF REQUIRED` per K5 §3.1 and §2.4 on the identifiability rules before any external presentation, since the audience for the conference includes clinicians who could recognise their own patients.

## 15. Advanced usage

**Reuse of existing data.** The governing question is whether the original consent contemplated this use, and the honest answer is usually no. Assess three things: whether the new purpose is compatible with the stated one, whether the participants would recognise it as what they agreed to, and whether the data can be sufficiently aggregated that the question of individual consent no longer arises. Where reuse cannot be justified, the options are re-consent, aggregation, or not doing it. A repository whose entries carry their consent scope as a field makes this answerable in minutes rather than by argument (14.03).

**Longitudinal and panel research.** Consent given at wave one degrades: the study evolves, the participant's circumstances change, and the accumulated dataset becomes far more identifying than any single wave. Design re-consent points, review identifiability at each wave as the linked record grows, and set a retention rule for the linked dataset rather than for each wave separately.

**Research in low-trust or high-risk settings.** Where participation itself carries risk (research with people in insecure circumstances, on stigmatised topics, or under authorities with an interest in the answers), written consent can be the highest-risk artefact in the study, because it is the document that proves who took part. Recorded verbal consent, or witnessed consent with no participant record retained, may be the protective option. This is a case for expert advice and a named accountable human, not for a general rule.

**When the standard approach does not fit.** Where the required protections make the study unviable (identifiability cannot be resolved, human escalation cannot be provided, gatekeeper power cannot be removed), do not proceed with weakened protections. Redesign the question so it can be answered from a less exposing source, aggregate to a level where individuals are not at stake, or say the study cannot be done as specified. **The output "not in this form" is the point at which this skill is doing its job**, and it is the output most likely to be resisted and most worth holding.

## 16. Skill chain

**Recommended previous skills:**
- **01.04 Research Method Selection** and **01.05 Research Plan.** Hand over the design whose participant journey this skill maps. Feasibility is not permission, and a method chosen without this assessment may not be usable.
- **01.06 Sampling Strategy** and **02.06 Screener and Quota Design.** Hand over the sample definition and screening data, which drive both the identifiability assessment and the minimisation schedule.
- **03.01 Recruitment and Sample Sourcing.** Hands over the recruitment route, which is where power relationships and gatekeeper problems are found.

**Recommended next skills:**
- **02.01, 02.02 and 02.03**, which write the instrument within the topic limits and consent scope this skill sets.
- **03.02 AI-Moderated Interview Design**, which must build the escalation trigger, the visible exit and the system disclosure this skill requires.
- **13.06 AI Research Governance**, which operates the AI consent position across the project: what may be sent where, disclosure, and the audit trail.
- **07.04 Quote and Evidence Extraction** and **12.03 Research Report Compilation**, which apply the attribution rules and minimum cell sizes at reporting.

**Runs well alongside:**
- **03.05 Incentive and Participation Design**, for the operational side of the incentive judgement.
- **13.01 Research Quality Review**, where an ethical constraint changes what the study can claim, and **13.04 Bias Detection**, where a protection (an excluded group, a limited topic) introduces a distortion that must be recorded.
- **K5 §2.4**, which defines the ethical judgements this skill routes to a human, and **K4 §7**, for the disclosure obligations that follow AI-performed steps.

---
A Yazi Supplied Skill and resource.
