Skip to main content
v2026.11,610 entries · CC-BY 4.0
LAC HealthLaboratory & ResearchLab & research supplies.Reagents, consumables, PPE & instruments — documented, fast, chain-of-custody shipping.Shop lac.us lac.us

How to Write a Research Protocol for IRB Submission

How to draft the protocol narrative itself for IRB submission: section order, how much risk/benefit detail reviewers expect, common reasons it gets sent back, and how it differs from a funded grant proposal’s research plan.

Writing a research protocol and preparing an IRB application are related but different tasks. CASRAI’s guide to what a research protocol is covers the concept generally, across funders, disciplines, and registries; the guide to the IRB application covers the full submission packet — consent forms, recruitment materials, HIPAA paperwork, and why applications get sent back. This guide is narrower than either: it’s about drafting the protocol narrative itself so that it holds up under IRB review — what order to put sections in, how much detail the risk/benefit section actually needs, the recurring problems that get a protocol narrative (as opposed to the consent form) sent back for revision, and how writing for an IRB differs from writing a research plan for a funder.

None of this substitutes for your own institution’s protocol template or your IRB office’s current instructions — templates and required sections vary by institution and by electronic submission system. Confirm the current template before drafting; this guide covers what almost every template asks for and why, not a specific institution’s form.

What the protocol narrative has to do for a reviewer

An IRB (or, outside the US, a Research Ethics Committee) cannot approve a study on the strength of its scientific promise alone. Before it can approve, exempt, or refer a study to full board review, the reviewer has to be able to make a specific set of affirmative findings, most of them set out at 45 CFR 46.111: that risks to participants are minimized, that remaining risks are reasonable in relation to anticipated benefits (or the knowledge expected to result), that participant selection is equitable, and that informed consent will be sought and documented appropriately. A protocol narrative that reads well as a piece of scientific writing but doesn’t give the reviewer what they need to make those specific findings will come back for revision regardless of how sound the science is. Writing for IRB submission means writing so a reviewer — who may not be a specialist in your particular sub-field, and who is evaluating participant protection rather than scientific merit — can find the answer to each of those questions without having to infer it.

Section order and what each section needs to contain

Most institutional protocol templates ask for the same core sections, roughly in this order. The order matters less than making sure each one is actually present and answers what it’s supposed to answer.

Background and rationale

A short statement of what’s known, what gap the study addresses, and why it’s being done now — written for a reviewer who is not a specialist in the field. This section justifies why the study should happen at all, which is the first input into the risk/benefit weighing the reviewer has to do later.

Objectives, specific aims, or research questions

Stated specifically enough that a reader could tell in advance what result would answer the question. Vague objectives make the risk/benefit analysis later in the protocol harder to evaluate, because the reviewer can’t tell what the study is actually risking participants for.

Study design and setting

The overall design (randomized trial, observational cohort, qualitative interview study, secondary data analysis, and so on), where it takes place, and — for anything beyond a single, simple procedure — a brief description of why that design was chosen.

Subject population and eligibility criteria

Inclusion and exclusion criteria stated as concrete, checkable rules, not general descriptions. If the study involves a population that triggers additional protections under 45 CFR 46 — children (Subpart D), pregnant women or neonates (Subpart B), or prisoners (Subpart C) — the protocol needs to say so explicitly and describe the additional safeguards, not leave it for the reviewer to notice from the eligibility criteria. The same applies more generally under the Common Rule’s broader vulnerable-subjects criterion at 45 CFR 46.111(b), which requires additional safeguards whenever subjects are likely to be vulnerable to coercion or undue influence, not only for the three named subparts.

Procedures, in the order participants actually experience them

This is the section reviewers spend the most time on, and it’s worth writing as a literal walk-through — what happens at the screening visit, what happens at each subsequent visit or contact, in what order, using what instruments. Two things reviewers specifically look for here: first, whether the procedures described match what the consent document tells participants to expect (a mismatch between the two is one of the most common reasons a submission is sent back); second, which procedures are being done for the research as opposed to procedures that would happen anyway as part of standard clinical or educational practice. That distinction is what lets the reviewer isolate the actual incremental research risk, rather than weighing risks the participant would face regardless of the study.

Risk assessment and risk minimization

Covered in more detail below, since this is usually where a first-draft protocol is thinnest relative to what a reviewer needs.

Anticipated benefits

Benefits to the individual participant (if any — many studies offer none directly to the participant) stated separately from benefits to society or to the field generally. Compensation for participation is not counted as a benefit in this analysis; it’s evaluated separately, under the Common Rule’s voluntariness/undue-influence standard, as a possible source of coercive pressure rather than as an offsetting benefit.

Data management, privacy, and confidentiality

How identifiable data is collected, stored, who has access, how long it’s retained, and how (or whether) it will be de-identified. Where the study touches protected health information at a HIPAA-covered institution, this section needs to be consistent with whatever HIPAA authorization or waiver request accompanies the application — the two are legally separate requirements reviewed under different standards, and describing them inconsistently across the protocol and the HIPAA paperwork is a common source of a returned application.

Statistical or analytical plan

Proportional to the study: a full pre-specified analysis plan for an interventional trial, a shorter description of the analytic approach for a qualitative or exploratory study. The IRB is generally not evaluating the statistical plan’s rigor the way a funder or journal would, but a study whose sample size or analysis plan is so unclear that the reviewer can’t tell what risk is being taken on for what expected knowledge gain will still draw a query.

The informed consent document itself is prepared as a separate document within the application, not folded into the protocol narrative — see CASRAI’s guide to informed consent in research and the informed consent dictionary entry for what the required elements are and how the consent process is reviewed alongside the protocol.

How much detail the risk/benefit section actually needs

This is the section reviewers most often send back for being too thin, because it’s the one doing the most regulatory work. Under 45 CFR 46.111(a)(1), the IRB has to find that risks to subjects are minimized “by using procedures which are consistent with sound research design and which do not unnecessarily expose subjects to risk” — including using a procedure already being performed for diagnostic or treatment purposes where that’s appropriate, rather than adding a redundant research-only procedure. Under 46.111(a)(2), risks that remain after minimization have to be reasonable in relation to anticipated benefits to subjects and the importance of the knowledge expected to result.

In practice, a risk/benefit section that clears review usually does three things a vaguer one doesn’t:

  • Names each specific risk — physical, psychological, social, legal, economic — rather than a general statement that “risks are minimal.” A blood draw, a survey asking about a stigmatized behavior, and a breach of confidentiality are three different kinds of risk with three different mitigation strategies; naming them separately lets the reviewer evaluate each on its own terms.
  • States the minimization step actually taken for each risk — not just that risk exists, but what specifically reduces its probability or severity (a validated screening instrument instead of an ad hoc one, a certificate of confidentiality for sensitive data, a stopping rule for an intervention study).
  • Makes an explicit claim about where the study falls relative to “minimal risk,” and supports it. Under 45 CFR 46.102(j), minimal risk means the probability and magnitude of harm anticipated in the research are not greater, in and of themselves, than those ordinarily encountered in daily life or during routine physical or psychological exams. A protocol that asserts minimal risk without describing what the comparison to everyday risk actually looks like for the specific procedures involved is asking the reviewer to take the conclusion on faith rather than evaluate it.

Illustrative example, not an actual study: a protocol proposing a 45-minute survey about medication adherence for adults with a chronic condition, versus one proposing the same survey plus a request to access participants’ pharmacy fill records. The survey alone is a comparatively easy minimal-risk case to state briefly. Adding pharmacy-record access changes the risk profile — now the protocol needs its own paragraph on how those records are secured, who can see them, and how a breach would be handled — even though the added participant burden (an additional consent element, not additional time) is small. The level of narrative detail should track the actual complexity of the risk, not the length of the procedures list.

Common reasons a protocol narrative specifically gets sent back

CASRAI’s IRB application guide covers the recurring issues across the whole submission packet — consent-form readability, recruitment materials, training records. Within the protocol narrative itself, the recurring issues are narrower and mostly about specificity and internal consistency:

  • Eligibility criteria stated too loosely to apply consistently — “adults with anxiety,” for example, rather than a checkable diagnostic or screening threshold.
  • Procedures section and consent form describing the study differently — a different number of visits, a different set of measures, or different compensation than what’s in the consent document.
  • Research procedures not distinguished from standard-of-care or standard-practice procedures — leaving the reviewer unable to isolate what risk the research itself is actually adding.
  • A general assertion of “minimal risk” without the supporting comparison described above.
  • Vulnerable-population protections not addressed where the eligibility criteria clearly include children, pregnant women, prisoners, or a population otherwise likely to be vulnerable to coercion or undue influence, without the corresponding safeguards described in the protocol itself.
  • A data section that doesn’t match the actual sensitivity of the data being collected — for example, a generic data-security paragraph attached to a protocol that collects identifiable substance-use or mental-health information, where the reviewer would expect a security and access plan proportional to that sensitivity.

How this differs from a grant-proposal research plan

Researchers who already have a funded grant proposal often start from that document when drafting a protocol, and parts of it transfer directly — the background, the design, much of the methodology. But the two documents are written for different readers answering different questions, and a protocol that’s simply the grant’s research plan reformatted usually needs real rework, not just trimming.

A grant proposal’s research plan — an NIH Specific Aims page or Research Strategy section, for example — is written to persuade a funder’s scientific review panel that the work is significant, innovative, and feasible, and that the investigator and environment can execute it; it’s competing against other proposals for a limited pool of money, and its job is to make the strongest possible case for funding. An IRB protocol is not competing against anything and isn’t trying to persuade the reviewer the science is exciting — it’s providing the specific factual basis for a set of regulatory findings about participant risk, consent, and equitable selection. A reviewer doesn’t need to be convinced the work is important to approve it; they need enough detail about procedures and risk to make the 45 CFR 46.111 findings. Significance and innovation framing that reads well in a grant application is, at minimum, unnecessary in a protocol, and at worst crowds out the procedural and risk detail the reviewer actually needs.

The other structural difference is audience: a scientific review panel is typically staffed with content-area experts and can handle a technical research plan; an IRB is a mixed body that, by design, includes non-scientist and community members alongside scientific members. Most institutional protocol templates specifically ask for the study to be described in plain, non-technical language for this reason — jargon and abbreviations that would be normal in a grant application often need to be spelled out or removed in the protocol.

Practical drafting notes

  • Start from your institution’s current template, not a generic outline. Electronic IRB systems increasingly use smart-form questions that generate different required sections depending on how earlier questions are answered (does the study involve minors, an investigational product, more than minimal risk), so a template downloaded even a year ago may be out of date.
  • Write procedures as a walk-through, in participant order, not as a categorized list of instruments and measures. Reviewers evaluate risk sequentially, the way a participant would experience it.
  • Check the protocol against the consent form line by line before submitting — same number of visits, same measures, same compensation, same risks described. This single check catches one of the most common reasons for a returned submission.
  • Write the risk section in proportion to the actual risk, not the length of the rest of the document. A one-sentence minimal-risk survey study and a multi-visit intervention study should not have risk sections of similar length.
  • Say explicitly when a procedure is being done only for research purposes, versus one that would happen anyway as part of standard care or practice — this is one of the specific things reviewers are trained to look for and one of the easiest things for a first-time protocol author to leave implicit.

Frequently asked questions

Does the IRB protocol have to match the funded grant proposal exactly?

Not exactly, and it usually shouldn’t be a straight copy. The core science — design, population, procedures — needs to be consistent with what was funded, since funders track whether the work matches the funded plan. But the protocol should drop the significance/innovation framing aimed at a funding decision and add the risk, consent, and data-protection detail an IRB actually needs, which a grant application typically doesn’t include in the same depth.

How long should a research protocol be for IRB submission?

There’s no fixed page count set by regulation; length depends on the study’s complexity and the institution’s template. A short survey study with minimal risk can be a few pages; a multi-site interventional trial with several procedures and a vulnerable population can run much longer. The length should track how much the reviewer needs to evaluate, not a target word count.

Can I submit my protocol before the consent form is finished?

No — the consent document is submitted as part of the same application and is reviewed alongside the protocol, and the two need to describe the study consistently. Drafting them together, rather than the protocol first and the consent form as an afterthought, is one of the more reliable ways to avoid the mismatch that’s a common reason for a returned submission.

What’s the difference between a protocol amendment and a protocol deviation?

An amendment is a documented, prospectively IRB-approved change to the protocol itself, made before the change takes effect. A deviation is an unplanned departure from the already-approved protocol, documented after the fact and assessed for whether it affected participant safety or data integrity. Both need to be tracked; only one (the amendment) is planned in advance.

Does a protocol for an exempt study still need a risk/benefit section?

Yes, in substance. Even where a study qualifies for exempt or expedited review, the reviewer making that determination still needs enough description of the procedures and any risk involved to confirm the study actually meets the relevant exemption or expedited category — the level of formality can be lighter than a full-board protocol, but the underlying information the reviewer needs doesn’t disappear.

Related CASRAI resources

See also: What Is a Research Protocol?, The IRB Application, IRB/REC Approval Process, Informed Consent in Research, Preregistration of a Study Protocol, Components of a Grant Proposal, Common Rule (45 CFR 46), Belmont Report, Informed consent.

Referenced across the research world

University of Cambridge logoColumbia University logoCrossref logoUniversity of Edinburgh logoHarvard University logoUniversity of Oxford logoPrinceton University logoStanford School of Medicine logoUniversity College London logoORCID logoUniversity of Cambridge logoColumbia University logoCrossref logoUniversity of Edinburgh logoHarvard University logoUniversity of Oxford logoPrinceton University logoStanford School of Medicine logoUniversity College London logoORCID logo
  • University of Cambridge logo
  • Columbia University logo
  • Crossref logo
  • University of Edinburgh logo
  • Harvard University logo
  • University of Oxford logo
  • Princeton University logo
  • Stanford School of Medicine logo
  • University College London logo
  • ORCID logo

View CASRAI adoption →