Skip to main content
v2026.11,610 entries · CC-BY 4.0
LAC HealthLaboratory & ResearchLab & research supplies.Reagents, consumables, PPE & instruments — documented, fast, chain-of-custody shipping.Shop lac.us lac.us

The Institutional Official (IO): One Role Across IACUC, Research Security, and Misconduct Oversight

The Institutional Official (IO) is the senior signatory who binds a research institution to its federal assurances and certifications across IACUC/animal research, misconduct oversight, and research security — distinct from the RIO, DIO, and Research Security Officer roles that report to it.

Most research-compliance titles map to one regulatory scheme: an IACUC chair oversees animal-use protocols, a Research Integrity Officer (RIO) administers misconduct inquiries, a Research Security Officer runs a foreign-influence-disclosure program. The Institutional Official (IO) is different — it is the single senior signatory who binds the institution itself, by name and signature, across several of these regulatory relationships at once. The same person (or, at some institutions, different named individuals holding the title under different regulatory schemes) is who the federal government actually holds accountable when an assurance is signed, a misconduct finding is certified, or a research-security program is attested to.

This guide pulls the IO role together as a single cross-cutting subject: what makes someone the Institutional Official under each regulatory scheme that uses the term, what the IO can and cannot do relative to the committees and officers who report to them, and how the role differs from adjacent, easily-confused titles — the Designated Institutional Official (DIO) in graduate medical education, the Research Integrity Officer (RIO) in misconduct cases, and the Research Security Officer under NSPM-33.

What makes someone an “Institutional Official”

“Institutional Official” is not one federally defined job description with a single controlling regulation — it is a role-function that recurs across at least three separate compliance frameworks, each of which independently requires an institution to name a senior official with authority to sign on the institution’s behalf. Operationally, an individual is functioning as an IO for a given framework when all of the following are true:

  • Institution-wide signing authority. The IO signs documents that legally obligate the institution as a whole — not a single department, lab, or program — to the terms of a federal assurance, certification, or attestation.
  • Seniority sufficient to commit institutional resources. The role is held by someone senior enough (a vice president for research, provost, or equivalent) to direct that the institution actually provide the space, funding, staffing, and corrective action a compliance program requires — the assurance being signed is a promise of institutional capacity, not just a formality.
  • A defined accountability relationship to a federal body. The IO is who the relevant federal office (OLAW, ORI, a funding agency’s research-security office) holds responsible if the institution fails to meet the terms it signed up for.
  • Receives, rather than performs, day-to-day oversight. The IO does not review protocols, conduct misconduct inquiries, or screen disclosures personally — that work is done by a committee or officer (the IACUC, the RIO, the Research Security Officer) that reports findings and periodic assurances of compliance up to the IO.

Because it is a function repeated across frameworks rather than one office, a mid-size research institution may have the same individual serving as IO for IACUC and misconduct purposes, or may split the title across two or three different senior administrators depending on how compliance is organized — both are common and both are compliant, provided each framework’s specific signing/accountability requirement is actually met.

IO responsibilities under IACUC and PHS Policy (animal research)

The clearest, most codified use of “Institutional Official” is in animal-research oversight. Under the PHS Policy on Humane Care and Use of Laboratory Animals, an institution’s Animal Welfare Assurance — the document that establishes the institution’s animal-care-and-use program to the NIH Office of Laboratory Animal Welfare (OLAW) — must be signed by the Institutional Official, and the Assurance, along with the institution’s annual report and any reports of noncompliance, is submitted to OLAW through the IO. A parallel signing relationship exists under the Animal Welfare Act (AWA) and its implementing regulations (9 CFR 2.31), which require the research facility’s CEO to appoint the IACUC; in practice the IO frequently is, or acts on behalf of, that appointing authority.

Two mechanics of the IACUC/IO relationship are worth being precise about, because they define the actual limits of the IO’s authority rather than leaving it open-ended:

  • The IO cannot approve what the IACUC has not approved. Protocol-level scientific and animal-welfare review sits entirely with the IACUC; the IO has no authority to authorize an activity involving animals that the IACUC has withheld approval for.
  • The IO can restrict or disapprove what the IACUC has already approved. The reverse is not true — the IO retains final authority to disapprove, restrict, or terminate an activity even after IACUC approval, most often exercised where broader institutional, financial, or reputational considerations bear on a decision that pure animal-welfare review would not capture.

That asymmetry — approval flows up from the IACUC, veto flows down from the IO, never the reverse — is the structural point most worth remembering about the role in this context. The IACUC also keeps the IO informed on an ongoing basis: PHS Policy requires the semiannual program review and facility inspection report to go to the IO, and any serious or continuing noncompliance, serious deviation from the Guide for the Care and Use of Laboratory Animals, or IACUC-ordered suspension of an activity must be reported to OLAW by the IO. See IACUC training requirements and the IRB vs. IACUC and AAALAC vs. IACUC comparisons for how this committee structure sits alongside the IO.

IO responsibilities in research misconduct oversight

42 CFR Part 93 — the PHS regulation governing research misconduct (fabrication, falsification, plagiarism) in PHS-funded research — separately defines several institutional-official roles, and the terminology here is easy to conflate with the animal-research usage above precisely because it reuses the phrase “institutional official” inside its own definitions:

  • Institutional Certifying Official (42 CFR 93.217) — the institutional official responsible for assuring, on the institution’s behalf, that the institution has written policies and procedures for addressing research misconduct allegations consistent with Part 93, and for certifying the institution’s required annual compliance report to the Office of Research Integrity (ORI).
  • Institutional Deciding Official (42 CFR 93.218) — the senior official who receives the investigation committee’s report and the RIO’s recommendation and makes, or reviews, the institution’s final determination on a misconduct finding and resulting institutional actions, separate from the RIO who administers the process procedurally.
  • Research Integrity Officer (RIO) (42 CFR 93.233) — explicitly distinct from both roles above: the RIO is defined as “the institutional official responsible for administering the institution’s written policies and procedures for addressing allegations of research misconduct,” i.e. the process administrator, not the certifying or deciding authority.

The practical pattern at most institutions: the RIO runs the inquiry/investigation process day to day, while the IO — sometimes formally distinguishing between the Certifying Official and Deciding Official functions above, sometimes holding both as one senior administrator — is who signs the institution’s compliance certifications to ORI and who owns the final institutional decision once an investigation concludes. See how a research misconduct investigation actually works, the consequences of research misconduct, and research misconduct for the fuller process this role sits at the top of.

IO responsibilities in research-security oversight

Research security is the newest of the three domains and the least standardized in its use of “Institutional Official” specifically — NSPM-33 and its implementing agency guidance more often use “Senior/Institutional Official” or agency-specific titles rather than a single fixed term, and day-to-day program administration is typically run by a designated Research Security Officer, not the IO personally. But the same underlying pattern holds: federal research-security program requirements and agency-level attestations (foreign-talent-program disclosures, malign-foreign-talent-recruitment-program certifications, current-and-pending-support disclosures) are, at the institutional level, certified by a senior official the agency can hold accountable — functionally the same signing-authority role the IO plays for IACUC assurances and misconduct compliance reports, applied to a newer regulatory domain. See NSPM-33’s four required research-security program elements and research security for the full program requirements this signing role sits on top of.

IO vs. adjacent titles that are easy to confuse

Because “Institutional Official” recurs across frameworks and sounds like several other titles, keeping the distinctions explicit matters more here than for most compliance roles:

  • IO vs. Designated Institutional Official (DIO). The DIO is a formally defined ACGME graduate-medical-education accreditation role — institution-wide authority over every residency/fellowship program a Sponsoring Institution sponsors. It is governed entirely separately from the IACUC/misconduct/research-security IO uses above (different regulator, different accreditation framework), and the two titles are frequently held by different people at the same institution.
  • IO vs. RIO. The RIO administers the misconduct process procedurally; the IO (in its Certifying/Deciding Official capacities) signs the institution’s compliance certification and makes or reviews the final institutional decision. One runs the process, the other owns the outcome.
  • IO vs. Research Security Officer / Attending Veterinarian. Both are subject-matter program administrators — the Research Security Officer runs day-to-day disclosure screening and training, the Attending Veterinarian holds delegated program authority for veterinary care under the IACUC — while the IO is the accountable signatory above both, receiving reports rather than performing the underlying compliance work.

A useful shorthand for research administrators working across these domains: whenever a federal document says an institution must have someone sign, certify, or assure something on the institution’s behalf, look for the IO. Whenever a document describes who runs a compliance program day to day, that is a different, subject-matter-specific role that reports to the IO, not the IO itself.

Frequently asked questions

Can one person hold the Institutional Official title across IACUC, misconduct, and research security simultaneously?

Yes, and at many mid-size institutions the same senior research-administration officer (commonly a vice president or vice provost for research) does hold IO-type signing authority across all three, since each framework separately requires only that a sufficiently senior, accountable official exists — none require a dedicated, framework-exclusive officeholder. Larger institutions more often split the function across two or three named individuals as the compliance portfolio grows.

Does the Institutional Official need to be a scientist or physician?

No federal requirement under PHS Policy, the AWA regulations, or 42 CFR Part 93 specifies a professional credential for the IO role in any of these three domains — the requirement is institutional seniority and signing authority, not scientific expertise. (This mirrors the adjacent GME DIO role, where ACGME likewise does not require the DIO to be a physician.)

Is the Institutional Official the same as an institution’s Signing Official in eRA Commons?

Not necessarily the same title, though the functions rhyme: an eRA Commons Signing Official (SO) holds the system role permission to submit certain grant-related transactions on an institution’s behalf, which is a related but distinct administrative-systems designation from the assurance-signing IO roles described in this guide. Institutions vary in whether the same individual holds both.

What happens if an institution doesn’t have a properly designated Institutional Official?

The institution cannot hold a valid PHS Animal Welfare Assurance, cannot meet 42 CFR Part 93’s institutional-certification requirements for PHS-funded research, and cannot meet the signing-authority expectations built into research-security attestations — in each case, an unsigned or improperly authorized assurance/certification puts the institution’s eligibility for the underlying federal funding or accreditation at risk.

For the surrounding compliance architecture this role sits inside, see the integrity & compliance pillar.

Referenced across the research world

University of Cambridge logoColumbia University logoCrossref logoUniversity of Edinburgh logoHarvard University logoUniversity of Oxford logoPrinceton University logoStanford School of Medicine logoUniversity College London logoORCID logoUniversity of Cambridge logoColumbia University logoCrossref logoUniversity of Edinburgh logoHarvard University logoUniversity of Oxford logoPrinceton University logoStanford School of Medicine logoUniversity College London logoORCID logo
  • University of Cambridge logo
  • Columbia University logo
  • Crossref logo
  • University of Edinburgh logo
  • Harvard University logo
  • University of Oxford logo
  • Princeton University logo
  • Stanford School of Medicine logo
  • University College London logo
  • ORCID logo

View CASRAI adoption →