Skip to main content
v2026.11,610 entries · CC-BY 4.0
LAC HealthLaboratory & ResearchLab & research supplies.Reagents, consumables, PPE & instruments — documented, fast, chain-of-custody shipping.Shop lac.us lac.us

Canada’s NSGRP: Risk Assessment Form, Due Diligence, and the STRAC Sensitive-Technology List

How Canada’s National Security Guidelines for Research Partnerships (NSGRP) work: the Risk Assessment Form, the due-diligence process, the STRAC sensitive-technology list, and the rule against discrimination as a mitigation tactic.

Canada’s National Security Guidelines for Research Partnerships (NSGRP) integrate national-security risk assessment into how federal research-partnership funding gets evaluated and approved. Introduced in July 2021 by Innovation, Science and Economic Development Canada (ISED), Public Safety Canada, and Health Canada, the Guidelines apply national-security due diligence to research partnerships that involve a private-sector partner organization, on top of — not instead of — normal scientific merit review. For research administrators, the practical center of the NSGRP is a specific document: the Risk Assessment Form, completed alongside an application to a covered federal funding opportunity. This guide covers what triggers the NSGRP, how the Risk Assessment Form is structured, the due-diligence process behind it, how the related Policy on Sensitive Technology Research and Affiliations of Concern (STRAC) list works, and the Guidelines’ explicit prohibition on using discrimination or profiling as a risk-mitigation tactic.

What the NSGRP Is, and Why It Exists

The NSGRP was developed by the Government of Canada in consultation with the Government of Canada-Universities Working Group, a body representing federal departments alongside Canadian universities and their national associations. Its stated purpose is to help researchers, institutions, and funding agencies conduct “consistent, risk-targeted due diligence” on research partnerships, while preserving Canada’s open, internationally collaborative research environment. The Guidelines respond to a narrower concern than the phrase “national security” might suggest: not foreign collaboration generally, but the risk that some research partnerships — most often those involving organizations connected to a foreign government, military, or state-security apparatus — could be used for unauthorized transfer of sensitive knowledge, technology, or data, or for foreign interference and espionage more broadly.

The NSGRP does not ban partnerships with any particular country or type of organization outright. Instead, it requires that risk be identified and, where possible, mitigated through a documented process before public funds are committed.

When the NSGRP Applies: Private-Sector Partners and Alliance Grants

The NSGRP became a mandatory element of federal research-partnership funding starting with the Natural Sciences and Engineering Research Council of Canada’s (NSERC) Alliance Grants program, specifically for any application that involves a private-sector partner organization. That trigger — a private-sector partner — is the key operational fact for research administrators: applications without a private-sector co-funder generally do not require a Risk Assessment Form, while those with one do, once the opportunity has been designated as covered.

Since the initial 2021 rollout, coverage has expanded well beyond Alliance Grants. As of the tri-agency guidance jointly issued by NSERC, the Canadian Institutes of Health Research (CIHR), and the Social Sciences and Humanities Research Council (SSHRC), the Risk Assessment Form requirement has been phased in across a growing list of programs, including Alliance Grants, Idea to Innovation (Phase II), NSERC Project Grants (from Fall 2024), Partnership Grants and Partnership Development Grants, Partnership Engage Grants, and the Canada Biomedical Research Fund and Canada Impact+ programs, with effective dates staggered program by program. Because the list of covered programs continues to expand, research offices should check the specific funding opportunity’s program guide rather than assume a program is or isn’t covered based on an earlier funding cycle.

The Risk Assessment Form: What It Actually Asks

The Risk Assessment Form is the document through which an applicant institution documents its due diligence and proposed mitigation measures. Per the current version published by Science.gc.ca, the form is organized into five sections:

  • Section 1 – Know Your Research. Asks whether the proposed research itself could attract foreign interest — for example, involvement with critical minerals, critical infrastructure, personal data, large or sensitive datasets, export-controlled technology, or research areas the Government of Canada has flagged as sensitive or dual-use.
  • Section 2 – Know Your Partner Organization. Assesses risk arising from the partner itself: foreign government or military ownership or influence, lack of organizational transparency, personnel conflicts of interest, and what access the partnership would give the partner to institutional infrastructure or sensitive data.
  • Section 3 – Risk Identification. Requires applicants to document the actual findings of their due diligence — what resources were consulted and what was discovered — for any question in Sections 1 or 2 answered affirmatively.
  • Section 4 – Risk Mitigation Plan. Where risk has been identified, applicants must set out tailored mitigation measures, an implementation timeline, and how the measures will be monitored over the life of the partnership.
  • Section 5 – Additional Requirements. Declarations covering funding conditions and the transparency of funding sources behind the partnership.

The stated purpose of the information collected is to let the funding agency and, where needed, national-security departments assess whether the proposed partnership “could expose the research project to foreign interference, espionage or theft” — and, if so, whether that risk can be adequately mitigated.

The Due-Diligence Process, Step by Step

The Guidelines direct researchers to begin due diligence on a potential partner early — before an application is even drafted, and regardless of whether federal funding is the eventual funding source, since the same partnership risks exist independent of who pays for the work. In practice, the process runs roughly as follows:

  1. Early screening. The researcher and institutional research office assess the proposed partner and the research topic against the categories in Sections 1 and 2 of the Risk Assessment Form, ideally before substantive partnership discussions or an application are underway.
  2. Documented due diligence. Where a risk factor is identified, the applicant investigates it using available public and institutional resources (for example, corporate ownership records, sanctions and denied-party lists, prior research-security guidance) and records what was found.
  3. Form completion and mitigation planning. The applicant completes the Risk Assessment Form, including a mitigation plan for any identified risk, and submits it as part of the application package to the funding organization.
  4. Administrative review. The funding agency reviews the form administratively alongside the rest of the application.
  5. National-security consultation where warranted. For applications that raise material risk indicators, the agency consults with national-security departments before a funding decision is made.
  6. Outcome. Depending on the assessed and mitigated risk level, an application may proceed as submitted, proceed with conditions (for example, a strengthened mitigation plan or monitoring commitment), or be declined on national-security grounds.

Institutions should treat this as a partnership-development-stage process, not a form to fill in at the last minute before a deadline — meaningful due diligence on a partner organization, and design of a credible mitigation plan, both take real lead time.

STRAC: The Sensitive Technology Research Areas List

The Policy on Sensitive Technology Research and Affiliations of Concern (STRAC) is a distinct but complementary policy to the NSGRP. Where the NSGRP’s Risk Assessment Form is a general-purpose due-diligence tool applied case by case, STRAC works differently: it defines a specific list of Sensitive Technology Research Areas (STRA) and a list of Named Research Organizations (NROs) — foreign institutions the Government of Canada has identified as posing an elevated risk because of ties to military, national defence, or state-security entities — and requires that grant applicants in a listed STRA attest to having no current affiliation with, or funding from, a listed NRO.

Per Government of Canada guidance, the STRA list currently covers eleven technology areas:

  1. Advanced digital infrastructure technology
  2. Advanced energy technology
  3. Advanced materials and manufacturing
  4. Advanced sensing and surveillance
  5. Advanced weapons
  6. Aerospace, space, and satellite technology
  7. Artificial intelligence and big data technology
  8. Human-machine integration
  9. Life science technology
  10. Quantum science and technology
  11. Robotics and autonomous systems

STRAC operates through a mandatory STRAC Attestation: if an application’s research aims to advance a listed STRA, the applicant, co-applicants, and named collaborators must each complete an attestation confirming they hold no current affiliation with, or funding from, a Named Research Organization — a restriction that applies for the full duration of the grant, not just at the time of application. STRAC applies across NSERC, CIHR, and SSHRC funding opportunities and, per current guidance, the Canada Foundation for Innovation (CFI) as well. Because STRA and NRO lists are maintained and updated by the Government of Canada rather than fixed at policy launch, research offices should check the current lists on Science.gc.ca at application time rather than rely on a cached copy from a prior funding round.

The practical distinction for research administrators: the NSGRP Risk Assessment Form is about the proposed partner organization and partnership structure; STRAC is about whether the research topic itself falls in a sensitive-technology area and, if so, whether the people involved have a disqualifying affiliation. A single application can be subject to both — a private-sector partnership in a listed STRA area triggers both the Risk Assessment Form and the STRAC Attestation.

The Non-Discrimination Safeguard

Tri-agency guidance on the NSGRP states explicitly that risk mitigation measures “must never lead to discrimination against or profiling of any group or member of the research community.” This is a deliberate, stated design constraint, not an incidental footnote: it means a researcher’s or collaborator’s nationality, ethnicity, or citizenship cannot itself be treated as the risk factor, and cannot be used as a proxy for the actual risk indicators the Guidelines target — such as an organization’s ownership structure, transparency, or documented ties to a security-relevant entity. Mitigation plans are expected to address specific, documented risks tied to a partner organization or research context, not to exclude individuals or categorically restrict collaboration based on personal or national origin. Institutional research-security and equity offices are typically expected to review mitigation plans with this constraint in mind alongside the funding agency’s own review.

Which Funding Programs Currently Require the Risk Assessment Form

Coverage has expanded on a rolling basis since 2021. As of the current tri-agency guidance, the Risk Assessment Form applies to applications with a private-sector partner (or, for STRAC, a listed sensitive-technology focus) under programs including:

  • NSERC Alliance Grants (the original 2021 trigger program)
  • NSERC Idea to Innovation (Phase II)
  • NSERC Project Grants (from Fall 2024)
  • Partnership Grants and Partnership Development Grants (phased in 2025)
  • Partnership Engage Grants (from March 2026)
  • Canada Biomedical Research Fund (Stage 2) and Canada Impact+ programs

Given how frequently this list has grown since 2021, research offices should not assume a program is exempt because it wasn’t previously covered — confirm against the specific competition’s current program guide and the tri-agency guidance page before advising a principal investigator that a Risk Assessment Form isn’t required.

How NSGRP Compares to Other National Frameworks

The NSGRP sits alongside comparable research-security frameworks other governments have introduced over roughly the same period: the United Kingdom’s Trusted Research guidance (see CASRAI’s Trusted research framework (UK) entry) and the United States’ National Security Presidential Memorandum 33 (NSPM-33), which drives disclosure and institutional research-security-program requirements for US federal funding (see CASRAI’s coverage of NSPM-33 research security program deadlines and NSPM-33 disclosure requirements). All three frameworks share a common structure — partner and technology due diligence layered onto normal funding review, rather than blanket restrictions on international collaboration — but differ in mechanics: NSGRP’s Risk Assessment Form and STRAC Attestation are specific, standardized forms tied to particular funding competitions, where UK Trusted Research is guidance-based and institutionally implemented, and NSPM-33 works through mandatory disclosure requirements and institutional certification. Institutions active in both Canadian and allied funding systems increasingly need staff who can navigate more than one of these frameworks on the same file, since a single international partnership can trigger parallel obligations under each country’s system.

For related export-control obligations that can apply alongside the NSGRP on the same partnership — particularly where a sensitive technology area overlaps with controlled technical data — see CASRAI’s guide to export control (EAR/ITAR) and international research collaboration, and for the parallel institutional obligations around travel, see foreign travel security policy.

Frequently Asked Questions

Does the NSGRP apply to every federal research grant application?

No. The Risk Assessment Form requirement is tied to specific funding opportunities designated as covered — historically triggered by the presence of a private-sector partner organization, with coverage expanding program by program since 2021. Check the specific competition’s program guide rather than assuming coverage either way.

What happens if the Risk Assessment Form identifies significant risk?

The funding agency reviews the form administratively and, where risk indicators are material, consults national-security departments. Depending on the outcome and the strength of the proposed mitigation plan, an application may proceed as submitted, proceed with added conditions, or be declined.

Is the STRAC Sensitive Technology Research Areas list the same as the Risk Assessment Form?

No — they are complementary but distinct. The Risk Assessment Form assesses partnership and partner-organization risk generally. STRAC applies specifically when the research falls within one of the eleven listed Sensitive Technology Research Areas, and requires named individuals on the application to attest they have no current affiliation with a Named Research Organization.

Can an institution reject a collaborator based on their nationality to satisfy NSGRP mitigation requirements?

No. Tri-agency guidance explicitly states that mitigation measures must never lead to discrimination against or profiling of any group or member of the research community. Mitigation must target documented, specific risk factors tied to an organization or research context, not an individual’s nationality, ethnicity, or citizenship.

Who administers the NSGRP and STRAC?

Both were developed by the Government of Canada — led by Innovation, Science and Economic Development Canada, Public Safety Canada, and Health Canada — in consultation with universities and their national associations, and are jointly administered for grant purposes by the three federal granting agencies: NSERC, CIHR, and SSHRC.

Referenced across the research world

University of Cambridge logoColumbia University logoCrossref logoUniversity of Edinburgh logoHarvard University logoUniversity of Oxford logoPrinceton University logoStanford School of Medicine logoUniversity College London logoORCID logoUniversity of Cambridge logoColumbia University logoCrossref logoUniversity of Edinburgh logoHarvard University logoUniversity of Oxford logoPrinceton University logoStanford School of Medicine logoUniversity College London logoORCID logo
  • University of Cambridge logo
  • Columbia University logo
  • Crossref logo
  • University of Edinburgh logo
  • Harvard University logo
  • University of Oxford logo
  • Princeton University logo
  • Stanford School of Medicine logo
  • University College London logo
  • ORCID logo

View CASRAI adoption →