566. Exempt Review and Approval
Updated August 31, 2026
All human research in which University or affiliate faculty or staff are engaged must be approved or acknowledged by the University Research Integrity & Security or IRB. The University allows certain categories of research to be exempted from Department of Health and Human Services (DHHS) requirements for IRB review and approval (i.e., the Common Rule).
Research activities in which the only involvement of human participants is in one of the DHHS categories exempted at 45 CFR 46.104 or that meet the criteria for Exempt Review under the University’s IRB-Flexibility policy may be submitted for Exempt Review.
The University grants exclusive authority to Research Integrity & Security for review and approval of exempt research. This authority allows qualified Research Integrity & Security staff and IRB members to review applications for exempt research.
Requirements for Exempt Review
In no case will a research project be reviewed by an individual with a real or perceived conflict of interest relevant to that project.
The University’s Research Integrity & Security office requires exempt research to be consistent with the ethical principles described in the Belmont Report (in accordance with the IRB policy for a summary of the Report) as exemplified by the following:
- Risk to participants is no greater than minimal.
- Participant selection is equitable.
- Recruitment and consent procedures are designed to be free from coercion and undue influence.
- For research involving interaction with participants, participants are told the activity involves research and that participation is voluntary, are provided with a description of the research procedures, and are given the researcher’s name and contact information.
- The research is designed to minimize harms to participants and maximize research benefits.
- Individual privacy is protected.
- Provisions are adequate to maintain the confidentiality of the data. There are adequate provisions to maintain the privacy interests of participants.
Reviewers also assess for compliance with applicable federal, state, and local laws (including HIPAA, FERPA, and PPRA as described below), and state-mandated requirements for reporting abuse and communicable diseases.
Reviewers use the Exempt Review Worksheet to assess projects submitted for Exempt Review.
Reviewers should be familiar with laws, regulations, codes, and guidance governing the research, organizational policies, and the nature of the research to make sound judgments. An exemption determination may not be made solely by the researcher, or someone with a conflict of interest in the research.
Reviewers may seek clarification from the investigator or request additional information, changes, or researcher forms before making an exempt determination. Reviewers will apply the DHHS/FDA regulations regarding exempt categories and/or University’s Flexibility Policy to determine exempt status. The assigned reviewer completes the review in IRBNet by making a recommendation, adding the review worksheet and notes (if any), and marking the review complete. Research Integrity & Security will communicate the exempt review results to the Principal Investigator (PI) and research team members promptly, usually within two to ten business days of receiving a complete submission.
Exempt Review Results
Exempt reviews result in one of five outcomes:
- Project does not constitute human subject research.
- Project meets requirements for exempt determination.
- Information is needed before exempt determination may be granted.
- Project requires Expedited Review.
- Project requires Full Committee Review.
Exempt determinations are for the life of the project. Exempt research is not required to undergo renewal. However, Research Integrity & Security will conduct an annual campaign verifying the active status of research projects determined to be exempt.
Documentation of Exempt Review and Approval
For projects that meet the requirements for exempt determination, the reviewer or a staff member will complete the project in IRBNet by:
- Selecting Exempt Review for Review Type
- Selecting Exempt for Project Status
- Selecting Exempt for Action
- Noting the date, the exempt determination was finalized as the Effective Date
- Leaving the Expiration Date field blank
- Ensuring Minimal Risk is selected for Project Risk Level
- Noting the applicable exempt category (i.e., one of six DHHS categories) within the exempt review worksheet in Reviewer notes.
Notifications of Exempt Research Determinations
Research Integrity & Security staff will generate and publish an exempt determination letter in IRB. The PI and contact person (if applicable) will be notified that the letter is available for review. Exempt notification letters specify the exempt category.
For projects that do not meet the requirements for exempt determination, Research Integrity & Security staff will notify the investigators either the project was acknowledged and may proceed as “not human subjects research” or the project requires Expedited or Full Committee Review.
Information about exempt determinations is available to IRB members and institutional authorities upon request.
Limited Institutional Review Board Review
Limited IRB review requires that certain exempt research be reviewed by an IRB chair or IRB member designee for privacy and confidentiality under requirements in 45 CFR §46.111(a)(7) or §46.111(a)(8). IRB members conducting limited IRB review may not disapprove research.
The regulations at §46.111(a)(7) state, “When appropriate, there are adequate provisions to protect the privacy of subjects and to maintain the confidentiality of data,” and §46.111(a)(8) states “… (iii) If there is a change made for research purposes in the way the identifiable private information or identifiable biospecimens are stored or maintained, there are adequate provisions to protect the privacy of subjects and to maintain the confidentiality of data.” The purpose of limited IRB review is to ensure privacy/confidentiality protections are in place with exempt research that involves the collection or use of sensitive, identifiable data. This process is only applicable to certain new provisions in the exempt categories 2 and 3. The IRB has not adopted exempt categories 7 and 8.
The protocol must contain sufficient information to determine whether the proposed research fulfills the relevant criteria for approval required under limited IRB review. Documentation should provide adequate protections for privacy interests of participants and the confidentiality of identifiable data. Continuing review is not required for studies that qualify for a limited review. IRB retains the authority to suspend or terminate approval of research approved with a limited review.
Informed Consent Considerations for Review of Exempt Research
If the researcher will be interacting with participants, there is an agreement to participate that discloses adequate information for participants to make a voluntary decision regarding whether to participate in the research. This may include:
- Statement or explanation that the activity involves research.
- Description of the procedures and time commitment.
- Statement of risks and benefits.
- Statement that participation is voluntary.
- Statement that there are adequate provisions to maintain the privacy and confidentiality interests of participants.
- Name and contact information of the researcher.
- Contact information for reporting questions, concerns, or complaints about the research to Research Integrity & Security.
Situations for Reviewer Discretion to Request
For exempt research involving children or that will take place outside of the US, the designated reviewer may require the PI to submit the Population: Children or Research: International researcher forms, respectively.
Is Online Research Eligible for Exempt Review?
Research Integrity & Security will assess minimal risk online research on a case-by-case basis to determine the appropriate level of review, either Exempt or Expedited Review.
- With adequate protections for ensuring individual privacy and data confidentiality, online research may be exempt under DHHS category 2 or 3.
Is Research Involving Audio or Video Recordings, or Photography Eligible for Exempt Review?
Research Integrity & Security will assess minimal risk research involving audio or video recordings, or photographs on a case-by-case basis to determine the appropriate level of review, either Exempt or Expedited Review.
- With adequate protections for ensuring individual privacy and data confidentiality, research involving recordings or photography may be exempt under DHHS category 2 or 3.
How Do HIPAA, FERPA or PPRA Regulations Apply to Exempt Research?
- Exempt research involving medical records must comply with HIPAA requirements.
- Exempt research involving educational records must comply with FERPA requirements.
- If minimal risk, non-federally funded research involving surveys or interviews with children meets the criteria for exempt review, the research must comply with PPRA requirements.
NOTE: Researchers are advised to contact Research Integrity & Security before submitting an exempt application for research involving children.
Amendments to Exempt Research
Once qualified Research Integrity & Security staff or IRB members have granted an exempt determination for the initial review of the study, investigators are permitted to implement certain amendments without additional review by Research Integrity & Security. This is permissible so long as the changes do not alter the study aims, study population, study risks, privacy and confidentiality provisions, FERPA, PPRA, or HIPAA determinations, and remain within the exempt categories originally approved.Changes to federal funding status should always be reported to Research Integrity & Security.
Examples of such revisions include the following:
- Addition or removal of study team members (Note: change in PI is not permissible)
- PI must verify team members’ current CITI training
- Change in enrollment numbers
- Change in study timeline (i.e. timeline to study closure)
- Changes in study interventions that do not alter the study provisions listed above. (i.e. minor changes within benign behavioral interventions, revisions to survey/interview questions or , minor changes to data points collected, etc.)
- Changes to recruitment materials or new recruitment materials so long as all information is consistent with the originally approved protocol and recruitment materials.
- Expanding so long as the study population remains the same as originally approved.
- Minor revisions to time commitments of subjects so long as they stay within the same day.
- Minor changes to compensation. (i.e. SONA credit vs. gift card/prolific credit)
- Grammatical edits to study documents
PIs to document within their study’s regulatory files any amendments adopted outside of IRB review.
Should investigators wish to make amendments that either they are unsure fit the criteria listed above or that fall outside the list, they are required to consult with senior Research Integrity & Security staff before implementing to ensure the exemption status and the protocol documentation are appropriate and compliant with federal regulations and University policy. In some instances, an amendment or new project may need to be submitted to the IRB.
Umbrella Protocols for Exempt Research
The University IRB recognizes that there is a need within its research community to allow umbrella protocols in some circumstances. An umbrella protocol framework allows a single overarching protocol to support multiple related sub-studies under one defined structure while ensuring regulatory compliance, consistency, and appropriate oversight. The University IRB will review umbrella protocols on a case-by-case basis, and only allow umbrella protocols for projects that share a similar purpose and fit within the same exemption category or combination of categories. The umbrella protocol can only cover a single PI’s lab initiatives and cannot cross over multiple labs within a department.
Exclusions: Umbrella protocols and sub-studies cannot involve:
- Any research activity deemed greater than minimal risk;
- Vulnerable populations;
- Federal funding;
- FERPA, HIPAA, or PPRA requirements; or
- Multiple labs within a department.
The umbrella protocol and supporting documentation must provide sufficient information on how the study team will manage the data and track the conduct of all sub-studies under the protocol. Example recruitment materials should start with the umbrella protocol title hyphenated by the sub-study title for ease of tracking. Furthermore, the consent form must provide sufficient information and clarity for participants enrolling in any of the sub-projects to understand what is being asked of them for .
Notifying Research Integrity & Security of Closure of an Exempt Research Project
Investigators may notify Research Integrity & Security of a closed exempt project by submitting a closure request via IRBNet.
Research Integrity & Security Closure of Exempt Research Projects
Exempt studies do not have a set expiration date. However, Research Integrity & Security will conduct an annual campaign of verifying the active status of research projects determined to be exempt more than 12 months prior to the campaign. Research Integrity & Security will contact Principal Investigators to ask if their protocol is still active. Protocols will be closed if 1) the PI confirms the protocol can be closed; or 2) Research Integrity & Security receives no response from the PI after two attempts; or 3) Research Integrity & Security determines that the PI is no longer eligible to serve in that capacity (e.g., as a result of having left the institution or retired).