Skip to main content
v2026.11,610 entries · CC-BY 4.0

IRB Protocol: Worked Example of a Full Submission

A complete, annotated, illustrative IRB protocol narrative — section by section — showing what a full submission looks like and why each part is written the way it is.

Ask about IRB Protocol: Worked Example of a Full Submission

Answers are drawn from this guide and the rest of the CASRAI corpus, with a link to every source.

Answers are AI-generated from CASRAI’s own published pages and can be wrong, so check the linked sources before relying on one; your question is logged without personal data — never sold, never used to train a third-party model — to show us what CASRAI is missing, so please do not type personal or confidential details. How we use this

This page walks through a complete, illustrative IRB protocol narrative from start to finish, section by section, with notes on what each part is doing and why. CASRAI’s guide to writing a research protocol for IRB submission covers the drafting principles in general terms; the guide to the IRB application packet covers everything else that goes in alongside the protocol narrative — consent forms, recruitment materials, HIPAA authorization. This page is different from both: it shows one worked example of the protocol narrative itself, annotated, so you can see what the guidance in those other pages actually looks like when it’s applied to a specific study.

The example below is a synthesized, illustrative protocol for a fictional minimal-risk behavioral study. It is not a real submission, is not attributed to any real investigator or institution, and should not be copied as a template — your institution’s IRB has its own required template and section order, and the example is deliberately generic to illustrate structure and reasoning rather than to match any specific system.

What a “full submission” means here

A full IRB submission is normally more than the protocol narrative alone: it typically also includes an informed consent document, recruitment materials (flyers, email scripts, screening scripts), any data collection instruments, and — for research involving protected health information in the US — a HIPAA authorization or waiver request. CASRAI’s IRB application guide covers that full packet. This page focuses on the document reviewers spend the most time with: the protocol narrative that describes what will actually happen to participants and why it is scientifically and ethically justified. Where the example below references a companion document (a consent form, a flyer), it says so, but doesn’t reproduce the whole packet.

The illustrative example: a minimal-risk behavioral study

The example study is a single-site, minimal-risk feasibility study: a brief mindfulness-based intervention for sleep quality in adults with type 2 diabetes, delivered by phone and measured with self-report surveys. It was chosen because it is realistic and common in institutional research (behavioral/survey research is one of the most frequent protocol types IRBs see) without requiring fabricated clinical data, drug information, or device specifics that would be irresponsible to present as real. Every fact below — the study itself, its numbers, its procedures — is invented for illustration.

1. Title and overview

Protocol title: Feasibility of a Brief Telephone-Delivered Mindfulness Intervention for Sleep Quality in Adults with Type 2 Diabetes
Study type: Single-site, non-randomized feasibility pilot
Anticipated enrollment: 40 adult participants
Anticipated risk level: Minimal risk

Why this works: The title alone tells a reviewer the population, the intervention, the delivery mode, and the outcome of interest — enough to route the file to reviewers with relevant expertise before anyone reads further. Stating the anticipated risk level and study type up front (feasibility pilot, not an efficacy trial) sets the reviewer’s expectations for how much design rigor and statistical power to look for later in the narrative; a feasibility study is evaluated differently than a powered efficacy trial, and saying so early avoids the reviewer wondering why the sample size looks small.

2. Background and significance

Illustrative excerpt: “Sleep disruption is common among adults with type 2 diabetes and is independently associated with poorer glycemic control. Brief, low-cost behavioral interventions delivered remotely could extend access to sleep-focused support beyond what is feasible in specialty sleep clinics, but telephone-delivered mindfulness interventions have not been tested specifically in this population. This study will assess feasibility and acceptability as a precursor to a future, adequately powered efficacy trial.”

Why this works: Two to three paragraphs is normally enough. The reviewer isn’t grading the literature review — they’re checking that the study has a genuine, stated rationale, and that the investigator has correctly scoped the current study (feasibility, not efficacy) against what would need to happen next. A background section that overpromises what a small feasibility study can show is a common, avoidable problem: if the objectives section later claims the study will “demonstrate effectiveness,” that mismatch is exactly the kind of thing that gets a protocol sent back for revision.

3. Objectives and research questions

Illustrative excerpt: “Primary objective: assess the feasibility of remote recruitment and 6-week retention for a telephone-delivered mindfulness intervention. Secondary objective: obtain preliminary, non-inferential estimates of change in self-reported sleep quality (Pittsburgh Sleep Quality Index) from baseline to week 6.”

Why this works: The objectives are written at the scale the study can actually support — feasibility and retention as the primary question, with the sleep-quality measure explicitly labeled “non-inferential” so the reviewer doesn’t read this as an underpowered efficacy claim. Naming the specific validated instrument (rather than “a sleep survey”) lets the reviewer confirm it’s an appropriate, previously validated measure for this population without having to ask.

4. Study design and procedures

Illustrative excerpt: “Eligible participants will complete a baseline telephone survey (approximately 20 minutes), followed by six weekly 15-minute telephone sessions with a trained interventionist delivering a structured mindfulness protocol, and a follow-up survey at week 6 (approximately 20 minutes). No study procedures involve in-person contact, biological specimens, or investigational products.”

Why this works: This section answers the question a reviewer is actually trying to answer while reading it: exactly what will happen to a participant, in what order, and for how long. Stating explicitly what the study does not involve (no in-person contact, no specimens) is a small addition that closes off follow-up questions before they’re asked — it tells the reviewer the risk profile is bounded, which the risk section will then quantify in more detail.

5. Subject population and eligibility criteria

Illustrative excerpt: “Inclusion: adults aged 18–75 with a physician-confirmed diagnosis of type 2 diabetes; self-reported sleep disturbance (score greater than 5 on the Pittsburgh Sleep Quality Index); access to a telephone. Exclusion: current enrollment in another behavioral sleep intervention study; diagnosed sleep apnea requiring active treatment; cognitive impairment that would prevent completion of study surveys, per participant or referring clinician report.”

Why this works: Each criterion is tied to a stated reason a reviewer can evaluate — sleep apnea is excluded because it needs its own treatment pathway, not because of an unexplained blanket exclusion. Criteria phrased this specifically are also easier to operationalize for the study team and easier for the IRB to check for unnecessary exclusion of otherwise-eligible groups, which is one of the things reviewers are specifically asked to consider under the Common Rule’s equitable-selection-of-subjects principle.

6. Recruitment methods

Illustrative excerpt: “Participants will be recruited via flyers posted in outpatient endocrinology clinic waiting areas (Attachment C) and a study-team email sent to patients who have previously consented to be contacted about research opportunities through the institution’s research recruitment registry. No clinician will recruit their own current patients directly; clinic staff will only post approved materials.”

Why this works: Naming the specific recruitment channel and, importantly, addressing the potential conflict of a treating clinician recruiting their own patients (a classic undue-influence concern in clinic-based recruitment) heads off a question the reviewer would otherwise have to ask. Referencing the recruitment flyer as a lettered attachment shows the reviewer where to find the actual material rather than making them take the description on faith.

7. Consent process

Illustrative excerpt: “A member of the study team will review the consent document with each potential participant by telephone, allow time for questions, and obtain verbal consent, which will be documented by the study team member and confirmed by a follow-up email summary sent to the participant. A waiver of documentation of signed consent is requested because the only link between the participant and the research would be the signed form itself, and the research presents no more than minimal risk of harm from a breach of confidentiality.”

Why this works: Requesting a waiver of signed-consent documentation is common for remote, minimal-risk research, but it has to be justified against the specific regulatory criteria for that waiver, not just asserted. This excerpt states the actual reason (removing the signed form removes the only document linking participant identity to study participation) rather than simply writing “consent will be obtained verbally,” which is a frequent reason this kind of request gets sent back for more detail.

8. Risks, discomforts, and risk-benefit assessment

Illustrative excerpt: “The primary foreseeable risk is the time burden of six 15-minute calls plus two 20-minute surveys, and the possibility that survey questions about sleep and mood could cause minor emotional discomfort. This risk is comparable to what a participant might experience discussing sleep habits with a primary care provider. There is a small risk of a confidentiality breach if study data were disclosed; this is mitigated by the data security measures described in Section 10. No physical, legal, or financial risks are anticipated.”

Why this works: This is the section most likely to get returned if it’s vague, so the excerpt does the specific thing reviewers are trained to check for: naming each category of risk, giving a concrete comparison to an everyday-risk equivalent (rather than just asserting “minimal risk”), and pointing forward to exactly where the corresponding mitigation is described. A protocol that just states “risks are minimal” without this kind of grounding is one of the most common reasons a narrative comes back for revision.

9. Potential benefits

Illustrative excerpt: “Participants may or may not experience improved sleep quality; this cannot be assured, as the study is not designed or powered to demonstrate a treatment effect. The primary anticipated benefit is to future patients, through information gained about the feasibility of this intervention model.”

Why this works: This deliberately avoids overstating benefit to the individual participant — a frequent problem in earlier drafts is language that reads like a promise of therapeutic benefit from what is actually an unproven, unpowered pilot. Separating “benefit to this participant” (uncertain) from “benefit to future patients/knowledge” (the real justification) is what a risk-benefit reviewer is checking for here, and it also keeps the recruitment materials consistent — a flyer that promises improved sleep would contradict this section.

10. Privacy and confidentiality

Illustrative excerpt: “Survey responses will be collected via a university-licensed, encrypted survey platform and stored with a study ID rather than participant name. The link between study ID and identifying information will be kept in a separate, access-restricted file on institutional secure storage, accessible only to the study team. Audio is not recorded during telephone sessions. Data will be retained per institutional policy and destroyed at the end of the retention period.”

Why this works: This answers the practical questions a reviewer has about data security without requiring them to look elsewhere: what platform, how identifiers are separated from data, who has access, and what happens to the data afterward. Naming the mechanism (a separate, access-restricted linking file) rather than asserting the conclusion (“data will be kept confidential”) is the difference reviewers are looking for throughout this kind of section.

11. Data management and analysis

Illustrative excerpt: “Feasibility will be assessed descriptively: proportion of eligible contacts enrolled, proportion of enrolled participants completing all six sessions, and proportion completing the week-6 survey. Change in Pittsburgh Sleep Quality Index score will be summarized descriptively (mean change, range) and explicitly reported as preliminary and non-inferential, not as evidence of efficacy.”

Why this works: This ties directly back to the objectives in Section 3 — a reviewer checking internal consistency can confirm the analysis plan matches what was promised, and doesn’t smuggle in an inferential claim (a p-value framed as evidence of effectiveness) that the sample size in Section 1 couldn’t support.

12. Compensation

Illustrative excerpt: “Participants will receive a $20 gift card after completing the baseline survey and a $20 gift card after completing the week-6 survey ($40 total if both are completed), prorated for partial completion of the second survey only. Compensation is not contingent on completing the intervention sessions themselves.”

Why this works: Stating the amount, the schedule, and explicitly that payment isn’t tied to completing the intervention (only the assessment surveys) heads off an undue-influence question: participants aren’t penalized for withdrawing from the intervention itself, only for not completing the separate, lower-burden survey step tied to each payment.

13. Vulnerable populations

Illustrative excerpt: “This study does not target and will not knowingly enroll individuals in the additional-protection categories under 45 CFR 46 Subparts B, C, and D (pregnant women as a study focus, prisoners, or children). Should a prospective participant disclose current incarceration during eligibility screening, they will be excluded and referred back to their usual care.”

Why this works: Even when a study doesn’t involve a protected population, saying so explicitly — and describing what happens if one is encountered unexpectedly — is more convincing to a reviewer than silence on the topic, which reads as though the question was never considered rather than considered and found not applicable.

Common ways a full submission still gets sent back

Even a protocol built section-by-section like the example above can still come back for revision if the packet around it isn’t consistent. The most frequent patterns:

  • The consent form promises more than the protocol supports. A common inconsistency is a consent document written in more optimistic language about benefit than the protocol’s own risk-benefit section — reviewers cross-check these against each other.
  • Recruitment materials aren’t submitted, or don’t match the protocol. A flyer that describes the study differently than the protocol (different time commitment, different eligibility) is a frequent, easily avoidable return reason.
  • The risk section restates the conclusion instead of the reasoning. “This study is minimal risk” without the grounding shown in Section 8 above is treated as incomplete, not just brief.
  • A waiver is requested without addressing the specific regulatory criteria for that waiver — for example, requesting waiver of signed consent documentation without stating which of the applicable criteria the study meets.
  • Privacy language is generic rather than specific to the actual data flow — restating “confidentiality will be maintained” without describing storage, access, and identifier separation, as in Section 10 above.

CASRAI’s guide to writing a protocol narrative for IRB submission covers these failure patterns in more depth, and the IRB application guide covers the rest of the packet (consent forms, HIPAA authorization, recruitment materials) that has to stay consistent with the protocol narrative shown here.

Using this as a starting point

Don’t copy the section order or headings above directly into a submission — confirm your own IRB’s current template first; most electronic submission systems (Cayuse, IRBManager, Click) generate the protocol document from a structured web form rather than accepting a freeform narrative, and the form’s own section order and field labels take precedence over any general template. What should transfer regardless of the specific system is the underlying pattern in each annotation: state the specific mechanism or reasoning, not just the conclusion, and keep every document in the packet — protocol, consent form, recruitment materials — consistent with the others.

Frequently asked questions

Does every IRB protocol need all thirteen sections shown here?

No. Section names, order, and required depth vary by institution and by the electronic submission system in use. Exempt and expedited-category studies (see CASRAI’s expedited review entry) often use a shorter form with fewer sections than a study going to full board review. The thirteen sections above reflect what most full-board protocol templates ask for in some form, not a universal required structure.

How is a protocol written for IRB submission different from one written for a grant application?

A grant research plan is written to persuade a scientific review panel that the work is significant and well-designed; an IRB protocol narrative is written to let an ethics reviewer evaluate risk, consent, and subject protection specifically. The two overlap in describing study design and procedures but diverge sharply in what else they need to cover — see CASRAI’s guide on writing a protocol for IRB submission for the fuller comparison.

Can the risk-benefit section just say the study is “minimal risk” and cite the regulatory definition?

Citing the definition alone is rarely sufficient. Reviewers generally expect the narrative to apply that definition to the specific procedures in the study, as shown in Section 8 above, rather than assert the conclusion without the supporting reasoning.

Does a minimal-risk study still need a full protocol narrative like this one?

Often a shorter one. Many institutions use an abbreviated form for studies likely to qualify for exempt or expedited review, but the underlying content — population, procedures, risks, consent process — is still expected in some form, just at less length than a full-board submission would require.

Related CASRAI resources

Referenced across the research world

University of Cambridge logoColumbia University logoCrossref logoUniversity of Edinburgh logoHarvard University logoUniversity of Oxford logoPrinceton University logoStanford School of Medicine logoUniversity College London logoORCID logoUniversity of Cambridge logoColumbia University logoCrossref logoUniversity of Edinburgh logoHarvard University logoUniversity of Oxford logoPrinceton University logoStanford School of Medicine logoUniversity College London logoORCID logo
  • University of Cambridge logo
  • Columbia University logo
  • Crossref logo
  • University of Edinburgh logo
  • Harvard University logo
  • University of Oxford logo
  • Princeton University logo
  • Stanford School of Medicine logo
  • University College London logo
  • ORCID logo

View CASRAI adoption →