Ask. Never guess.Introducing Digital Twins →
GuidesResearch methods

How to create a research ethics review process when your team doesn't have a formal IRB


Most UX research, product research, and customer insights work happens outside academic institutions. There is no IRB down the hall, no ethics committee with a submission portal, and no one telling you what form to fill out before you start recruiting participants. Yet the ethical obligations are real.

If your team collects sensitive participant data—interview recordings, health-related responses, financial information, behavioral analytics, or anything tied to a real person's identity—you need a process for evaluating whether your research is ethical before it begins. Not because a regulation requires it (though some might), but because participants trust you with their information, and that trust has to be earned systematically rather than assumed.

This guide walks through how to build a practical, right-sized ethics review process for teams that lack a formal IRB but still want to do right by their participants.

Why an ethics review process matters outside academia

The IRB system was created to protect human subjects in federally funded research. Its origins trace back to well-documented abuses—the Tuskegee syphilis study, the Milgram obedience experiments—where participants were harmed or deceived without adequate safeguards. Academic and clinical researchers are bound by regulations that require ethics board approval before any data collection can begin.

Industry research teams usually fall outside these regulations. That regulatory gap sometimes leads to the assumption that ethics review is unnecessary for product and UX research. This assumption is wrong for several reasons.

Sensitive data is sensitive regardless of context. A participant disclosing their health condition in a usability test for a medical app faces the same privacy risks whether the research is funded by a university grant or a product team's quarterly budget.

Harm can be subtle. Research ethics is not only about preventing physical harm. It includes emotional distress, privacy violations, manipulation through dark patterns, power imbalances between researcher and participant, and the downstream consequences of how data is stored, shared, and used.

Regulatory exposure is growing. GDPR, state-level privacy laws in the United States, and sector-specific regulations increasingly apply to the kinds of data product teams collect during research. An ethics review process helps teams identify and mitigate compliance risks before they become legal problems.

Participant trust is a research asset. Teams that handle ethics well can recruit more effectively, build longer-term participant relationships, and produce higher-quality data. Teams that handle ethics poorly—even unintentionally—risk reputational damage and participant attrition.

Defining scope: what needs review and what doesn't

Not every research activity carries the same level of ethical risk. A five-minute unmoderated card sort using anonymized labels is different from a 90-minute interview about a participant's experience with debt. Treating them identically creates unnecessary friction, but ignoring the distinction creates real risk.

The first step in building your process is defining which activities require ethics review and at what level of scrutiny.

A simple risk-tiering framework

Most teams benefit from a three-tier system:

Tier 1 — Exempt or minimal review. Activities that involve no personally identifiable information, no sensitive topics, no vulnerable populations, and no deception. Examples include anonymized surveys about feature preferences, internal usability testing with employees who opt in voluntarily, and secondary analysis of already-anonymized data. These activities may require only a brief self-assessment checklist completed by the researcher.

Tier 2 — Expedited review. Activities that involve some identifiable data, moderately sensitive topics, or recording of participant sessions but are otherwise low-risk. Examples include moderated usability tests with screen recording, customer interviews about product satisfaction, and diary studies that capture daily behavior. These activities should be reviewed by a designated ethics reviewer—typically a senior researcher or research operations lead—within one to three business days.

Tier 3 — Full review. Activities that involve vulnerable populations, highly sensitive data (health, financial, legal), deceptive designs, potential for emotional distress, or research with minors. These should be reviewed by a small committee of two to four people, which may include a researcher, a legal or privacy representative, and an external advisor. Full reviews may take three to five business days.

The boundaries between tiers will vary by organization. A health tech company may route more studies into Tier 3 than a project management tool company. The important thing is that the boundaries exist, are documented, and are applied consistently.

Building the review committee

In a formal IRB, committee membership is governed by regulation. Your process can be simpler, but it still needs structure.

Who should be involved

A senior researcher who understands methodology, participant dynamics, and the practical constraints of product research. This person serves as the primary reviewer for Tier 2 studies and chairs the committee for Tier 3 reviews.

A privacy or legal representative who can evaluate data handling, consent language, and regulatory compliance. This person does not need to review every study—only those involving identifiable or sensitive data.

An outside perspective. Formal IRBs require at least one member who is not affiliated with the institution. For industry teams, this could be an advisor from another department (such as customer support or HR), a consultant with research ethics experience, or a peer from another company's research team. The purpose is to provide a viewpoint that is not shaped by the team's internal pressures and deadlines.

Avoiding bottlenecks

The most common failure mode for internal ethics processes is speed. If the review takes two weeks, researchers will stop submitting studies for review. Design the process with explicit turnaround commitments:

  • Tier 1 self-assessments: same day
  • Tier 2 reviews: one to three business days
  • Tier 3 reviews: three to five business days

If the committee cannot meet the turnaround commitment, the process needs to be simplified—not abandoned.

What the review should evaluate

A useful ethics review examines five areas:

Does the participant understand what they are agreeing to? Informed consent is not a form—it is a state of understanding. The review should assess whether participants are told:

  • What the research is about in plain language
  • What data will be collected and how it will be stored
  • Who will have access to the data
  • Whether sessions will be recorded and how recordings will be used
  • How long data will be retained
  • That participation is voluntary and can be withdrawn at any time without penalty
  • Whether and how participants will be compensated

Consent forms written in dense legal language do not produce informed consent. They produce signed documents. The review should evaluate whether the consent process is genuinely comprehensible to the participant population.

2. Data handling and privacy

How will participant data be collected, stored, shared, and eventually deleted? The review should assess:

  • Whether data is stored in systems with appropriate access controls
  • Whether personally identifiable information is separated from research data where possible
  • Who within the organization can access raw data versus anonymized findings
  • Whether data will be shared with third parties (including research tools and platforms)
  • What the data retention policy is and whether participants are informed of it

Tools like Dovetail that are designed for research data management can help teams centralize participant information, control access permissions, and maintain clear audit trails—making it easier to demonstrate that data handling practices align with what participants were told during consent.

3. Participant welfare

Could the research cause harm—emotional, psychological, financial, reputational, or social? The review should consider:

  • Whether the research topic could trigger distress (e.g., discussing experiences with illness, discrimination, or financial hardship)
  • Whether the researcher has a plan for responding if a participant becomes upset
  • Whether the power dynamic between researcher and participant is balanced (e.g., researching with your own customers who may fear losing access to a product)
  • Whether incentives are appropriate—enough to respect participants' time but not so high as to be coercive

4. Recruitment and inclusion

How are participants being recruited, and are the practices fair? The review should assess:

  • Whether recruitment materials accurately describe what participation involves
  • Whether the study excludes populations in ways that are unjustified
  • Whether participants from vulnerable groups receive additional protections
  • Whether the recruitment process respects participants' right to decline without pressure

5. Research design integrity

Is the methodology sound enough to justify the data collection? Poorly designed research wastes participants' time and exposes them to risk without producing useful knowledge. The review should consider whether the study is designed to answer its stated questions and whether the burden on participants is proportional to the expected value of the findings.

Creating the review artifacts

Your process needs a small number of clear, usable documents.

Ethics review submission form

A one- to two-page form that the researcher completes before beginning a study. It should capture:

  • Study title and brief description
  • Research questions
  • Participant population and recruitment method
  • Data collection methods (interviews, surveys, observation, recordings)
  • Data storage and access plan
  • Consent process and materials
  • Risk assessment (potential harms and mitigations)
  • Proposed tier level (Tier 1, 2, or 3)

Keep this form short. If it takes more than 20 minutes to complete, researchers will resent it and the process will erode.

A plain-language consent template that researchers can adapt for their specific studies. Include sections for study purpose, data practices, voluntary participation, and contact information. Make it easy for researchers to use without reinventing the document each time.

Review decision record

A brief record of the reviewer's or committee's assessment, including any required modifications and the final determination (approved, approved with conditions, or not approved). This creates an audit trail that protects both participants and the organization.

Embedding the process in team workflows

An ethics review process that exists in a shared drive but is not integrated into how research actually gets planned and executed will fail. The process needs to be embedded in the team's existing workflow.

Make it part of research planning. The ethics review should be a standard step in the research planning process, alongside defining research questions, choosing methods, and creating discussion guides. If your team uses a research repository or project management tool, add the ethics review as a required milestone.

Train the team. Every researcher—including contractors and new hires—should understand the ethics review process, why it exists, and how to complete a submission. Training does not need to be lengthy. A 60-minute workshop with real examples from your team's work is sufficient, followed by a brief refresher annually.

Review the process itself. At least once a year, revisit the ethics review process. Ask whether the tiering framework still matches the team's work, whether turnaround times are being met, and whether the process has caught genuine issues or is functioning as rubber-stamp bureaucracy. Adjust accordingly.

If your team uses Dovetail to manage research projects and participant data, the platform can serve as a natural home for ethics review records alongside the research itself—keeping consent documentation, study plans, and review decisions connected to the insights they produce.

Common mistakes to avoid

Over-engineering the process. A 15-page submission form and a six-person committee will kill adoption. Start with the minimum viable process and expand only when the team encounters situations the current process cannot handle.

Treating the review as a gate rather than a conversation. The goal is not to block research but to make it better. Reviewers should approach submissions as collaborators, not auditors. When a study raises concerns, the response should be "here is how to address this" rather than simply "no."

Ignoring low-risk studies entirely. Even Tier 1 studies benefit from a brief self-assessment. It builds the habit of ethical reflection and catches edge cases that researchers might not recognize on their own.

Failing to close the loop on data retention. Many teams are thorough about consent and data collection but never revisit what happens to participant data after the study ends. Build data deletion timelines into your process and follow through on them.

Assuming consent is a one-time event. For longitudinal studies, diary studies, or ongoing participant panels, consent should be revisited periodically. Participants' circumstances and comfort levels change over time.

Starting small

If your team currently has no ethics review process, you do not need to build everything described here at once. Start with three things:

  1. A consent template that every researcher uses
  2. A risk-tiering checklist that every researcher completes before beginning a study
  3. A designated person who reviews any study that involves sensitive data or vulnerable participants

From there, expand based on what the team needs. Add committee review for high-risk studies when you encounter them. Create the submission form when the checklist proves insufficient. Build the annual review cycle once the process has been in place long enough to evaluate.

The goal is not to replicate an academic IRB. It is to build a process that is proportional to the risks your team encounters, fast enough to keep pace with your work, and rigorous enough that participants can trust you with their data. That trust is not a nice-to-have. It is the foundation of good research.

FAQs

Do UX research teams in industry need an institutional review board?

Institutional review boards (IRBs) are legally required for federally funded research in the United States and for clinical or academic research in many countries. Most UX and product research teams in private companies are not legally obligated to have an IRB. However, the absence of a legal requirement does not mean ethics oversight is unnecessary. Any team collecting sensitive participant data—health information, financial details, behavioral patterns, or data from vulnerable populations—should have a structured ethics review process, even if it is less formal than an academic IRB.

What types of research warrant an ethics review even in a corporate setting?

Any study involving personally identifiable information, sensitive topics like health or finances, vulnerable populations such as minors or people with disabilities, deceptive research designs, recording of participant behavior, or research where participants could experience emotional distress should go through an ethics review. Even seemingly low-risk usability testing can raise ethical questions when it involves real customer data, screen recordings, or topics that touch on personal circumstances.

How long does an internal ethics review typically take?

For most industry research teams, an internal ethics review can be completed in one to five business days depending on the complexity and risk level of the study. Teams that implement a tiered review system—where low-risk studies receive expedited review and only high-risk studies require full committee evaluation—can avoid bottlenecks while maintaining meaningful oversight. The key is designing the process so that it is fast enough to keep pace with product development cycles but thorough enough to catch genuine ethical concerns.

Editor's picks↘

Latest articles↘

Turn customer feedback into product innovation