Applying for U.S. government funding: What Waterloo researchers should know

U.S. government funding agencies

University of Waterloo researchers applying for U.S. federal research funding that is subject to the Risk-based Security Review Process should know that proposals are no longer evaluated on scientific merit alone; they are also screened for national security risks, especially related to foreign influence, affiliations and transparency. This includes the following U.S. government funding agencies:

The Risk-based Security Review Process

As part of the review, agencies examine disclosures from “covered individuals” (e.g., principal investigators and senior/key personnel), including foreign affiliations, appointments, funding sources, talent recruitment program participation, conflicts of interest or commitment, and collaborations with entities or organizations that may pose security concerns. 

What the "risk-based security review" evaluates

During the risk-based security review process, “covered individuals” are the primary people whose backgrounds, affiliations, and activities are scrutinized for security risks. Typically, this includes (but is not limited to):

  • Principal investigators (PIs).
  • Co-investigators (Co-PIs).
  • Any Co-investigator (Co-I) proposing to spend ten percent or more of their time in any given year on a NASA-funded award.
  • Senior/key personnel listed on the proposal.
  • Project directors or managers and other research staff contributing significantly to the research project. 
  • In some cases: 
    • Postdoctoral researchers
    • Graduate students

Although details vary by funding agency, common risk factors include:

Foreign affiliations and relationships

  • All current and past positions, including adjunct or honorary appointments abroad.
  • Foreign funding sources (both disclosed and undisclosed).
  • Institutional ties to governments or state-linked entities. 

Talent recruitment programs

  • Mandatory disclosure of participation in Foreign Talent Recruitment Programs (FTRPs).
  • All “covered individuals” will need to show certification that they are NOT involved in “Malign” Foreign Talent Recruitment Programs (MFTRPs).
    • Certification of non-participation in MFTRPs: Covered individuals must certify at proposal submission and, where required, annually thereafter that they are not participating in a Malign Foreign Talent Recruitment Program. This certification is typically completed through the Biographical Sketch Common Form submitted via agency-approved systems such as SciENcv and is supported by disclosures of affiliations, appointments, funding sources, and participation in foreign talent recruitment programs.

Collaborations and co-authorships

  • Partnerships with institutions or individuals tied to Foreign Countries of Concern (FCOCs) or restricted entities (see list in the DoD section above or in the additional information section below).

Conflicts of interest and commitment

  • Disclose overlapping obligations and conflicts of interest (e.g., dual employment, hidden funding).
  • Disclose other commitments that could affect your project’s research integrity. 

Export control and sensitive research areas

  • Work in dual-use or sensitive technologies such as AI, quantum, semiconductors, etc. may face stricter scrutiny.

Required disclosures (Information critical for Canadian researchers)

Information critical for Canadian researchers

You should expect to provide full and transparent disclosure of:

All academic, professional, and institutional affiliations worldwide

  • All sources of research support (active and pending)
  • Participation in talent programs or foreign government initiatives
  • Foreign collaborations, contracts, or agreements
  • In some cases, detailed supporting documentation (contracts, appointment letters) 

Failure to disclose, even unintentionally, can:

  • Lead to proposal rejection
  • Trigger investigations or sanctions
  • Affect future eligibility

New compliance obligations

Canadian researchers should be aware of the following new mandatory requirements:

  1. Research security training

Under Section 10634 of the CHIPS and Science Act of 2022 (42 U.S.C. §19234), and NSPM 33 (2021), all “covered Individuals” are required to complete the National Science Foundation (NSF) Research Security Training for Individual Users modules. Links to these training modules can be found on Waterloo's Safeguarding Research web pages.

Please note: Training must be renewed annually for the duration of the project.

  1. Institutional certification

Waterloo’s Safeguarding Research team ensures compliance with formal Research Security Programs. The University is required to provide a signed certification.

To support this certification, the Safeguarding Research team will conduct due diligence screening of all UW researchers identified as “covered Individuals” to confirm that:

  • Information submitted in support of the proposal is current, accurate, and complete; and
  • No “covered individual” participating in the proposed project:
    • Is participating in a Malign Foreign Talent Recruitment Program (MFTRP); or
    • Is actively collaborating on fundamental research with a prohibited entity, or an employee of a prohibited entity, as defined by current Department of Defense research security policy. 

Please note:

  • Annual certification on talent program participation will be required.
  • Updates required if circumstances change.
  1. Verification of existing relationships 

The Safeguarding Research team will meet one-on-one with each “covered individual” to review and verify any existing affiliations, collaborations, or relationships relevant to the certification requirements outlined in Section (b) above.

*Once all three steps (a-c) have been completed, the certification document will be signed off.
 

The funding agency review process flow

Step 1: Scientific merit review

  • Proposal evaluated normally (peer review)

Step 2: Security/risk assessment

  • Conducted after selection or in parallel, depending on funding agency.
  • Uses risk matrices, analytics, and disclosure checks, as outlined above. 

Step 3: Risk outcomes

Possible outcomes:

  • Low risk: No significant security concerns are identified, and the proposal can proceed with funding without additional requirements.
  • Moderate risk: Some security concerns are identified, and the researcher or institution must implement mitigation measures before the award can proceed.
  • High risk: Significant security concerns are identified that cannot be adequately mitigated, and the proposal may be deemed ineligible for funding.

Mitigation could include:

  • Limiting access to data: Researchers should be aware that access to sensitive research data, systems, materials, and results may be limited to authorized personnel to protect research assets and prevent unauthorized disclosure or misuse, or transfer of information to individuals or organizations that may present security concerns.
  • Adjusting team composition: Researchers may be required to adjust team roles, participation, or oversight arrangements to address conflicts of interest, conflicts of commitment, or foreign influence risks.
  • Adding compliance controls: Institutions may need to implement additional safeguards, such as enhanced disclosures, security training, cybersecurity measures, monitoring, and compliance reviews, to ensure ongoing adherence to research security requirements.
     

Practical steps to stay compliant

Before submitting:
✅ Compile a complete list of all affiliations and funding.
✅ Review whether any collaborator is on restricted/denied entity lists.
✅ Confirm no involvement in prohibited talent programs.

During proposal:
✅ Disclose everything, even if it seems minor.
✅ Align disclosures across CV, Biosketch, and “current & pending support.”

If flagged:
✅ Be ready to provide documentation.
✅ Work with your institution on a mitigation plan.