Skip to main content
Joint Research Management Office

Research Security Visitor Guidance

Queen Mary University of London welcomes researchers, collaborators and visitors from around the world. International collaboration is fundamental to our research excellence, and effective visitor management helps protect our people, research, facilities and information while enabling research to take place safely and responsibly.

The following provides guidance for researchers and professional services staff who are hosting visitors involved in research activities. It brings together the key research security considerations that should be addressed before, during and after a visit.

It is intended to help researchers and professional services staff identify and manage research security considerations. In the context of research-related visits, using a proportionate and risk-based approach.

Roles and Responsibilities

Researchers, hosts and visitors all have responsibilities for ensuring visits are conducted safely, securely and in accordance with University requirements.

Hosts remain responsible for ensuring appropriate approvals, due diligence, supervision and access arrangements are in place before a visitor begins their activities and for the duration of their visit.

Visitors are responsible for complying with University policies, immigration requirements, information security requirements and any conditions relating to their visit.

Research security should be considered before confirming any research-related visit. Hosts should consider the sensitivity of the research, any international collaboration risks, relevant legal obligations and whether additional due diligence may be required. Guidance is available on Trusted Research, Export Controls, NSIA and related research security requirements.

This section includes:

  • Trusted Research principles and risk awareness.
  • Export Controls and National Security and Investment Act (NSIA) requirements.
  • International collaboration risk management.
  • Data protection and information governance.
  • Higher-risk jurisdictions information.

Higher-Risk Jurisdictions

Where a visitor is travelling from, travelling to, or collaborating with organisations in a higher-risk jurisdiction, additional security measures and due diligence may be required.

Some international collaborations may require additional consideration because of legal, regulatory, security or geopolitical factors. Where such risks are present, enhanced due diligence or additional safeguards may be appropriate.

Researchers and hosts should consider:

  • Whether additional Research Security due diligence is required.
  • Export Control or National Security considerations.
  • Information and cyber security risks.
  • The sensitivity of the research being undertaken.
  • Whether enhanced supervision or access restrictions are appropriate.
  • Travel security requirements where QMUL staff are visiting higher-risk countries.

Researchers should familiarise themselves with the University's guidance before undertaking travel or hosting visitors connected with higher-risk jurisdictions.

Further guidance

Visitors should only be granted access to facilities, laboratories, systems and information that are necessary for the agreed purpose of their visit. Access arrangements should be proportionate, appropriately supervised and removed when no longer required.

Potential controls may include:

  • Restricting physical access to buildings, laboratories and specialist facilities.
  • Limiting access to networks, shared drives and research systems.
  • Time-limited access permissions.
  • Supervision requirements.
  • Visitor credentials.
  • Estates and Security Office guidance.

Research visitors may be given access to information, datasets or digital systems as part of their activities. Hosts should ensure visitors understand and comply with University information security requirements and that access is restricted to the minimum necessary for the visit.

Visitors must comply with the University's Information Security and Cyber Security requirements including:

  • Handling confidential or sensitive information.
  • Research data.
  • Secure systems and datasets.
  • Personal devices.
  • Removable media.
  • Information governance.
  • Additional controls for sensitive research.
  • IT Services guidance.

Where visitors are travelling from overseas, hosts must ensure that appropriate immigration permissions are in place before the visit begins.

Some international researchers and visitors working in sensitive subject areas may require an Academic Technology Approval Scheme (ATAS) certificate before undertaking research activities in the UK.

  • Immigration requirements.
  • Visa requirements.
  • Academic Technology Approval Scheme (ATAS).
  • International researchers.
  • Immigration guidance.
  • Research Security due diligence.

Hosts should not provide access to relevant research areas until immigration, ATAS (where applicable) and Research Security due diligence requirements have been completed.

Research visits may involve access to confidential information, unpublished research findings or intellectual property. Appropriate arrangements should be in place before information is shared, including confidentiality agreements where necessary and consideration of publication and commercialisation requirements.

This requires consideration of:

  • Intellectual Property.
  • Confidential information.
  • Publication drafts and conference presentations
  • Commercialisation.
  • Non-Disclosure Agreements (NDAs).
  • Legal Services guidance.

The visitor process explains the actions required before, during and after every research visit. Please access complete guidance using link: Trusted Research Guidance for Hosting International Visitors [PDF 167KB]

Before the Visit

  • Nominate a host.
  • Complete the Visitor Request Form.
  • Gather visitor information.
  • Complete due diligence where required.
  • Confirm immigration and ATAS requirements.
  • Arrange physical and digital access.

During the Visit

  • Ensure appropriate supervision.
  • Monitor access to facilities and systems.
  • Ensure compliance with University policies.
  • Report any security concerns.

After the Visit

  • Remove building access.
  • Disable IT accounts and system access.
  • Recover University property.
  • Complete offboarding activities.
  • Retain records in accordance with University procedures.

 

Due diligence should be undertaken before confirming a research-related visit. The level of review should be proportionate to the nature of the visit, the visitor's affiliation, the access being requested and the sensitivity of the research involved. Where concerns are identified, advice should be sought from the Research Security Team.

A proportionate due diligence process  will consider :

  • The purpose and scope of the visit.
  • The visitor's background and affiliation.
  • The level of physical, digital and intellectual access required.
  • Sensitive research areas.
  • Export Controls.
  • Trusted Research.
  • Dual-use technologies.
  • Jurisdictions of concern.
  • Escalation to the Research Security Team.

Please contact the Research Security team at:

vp-trustedresearch@qmul.ac.uk 

Back to top