Route psychology and social-science student research through a tiered system, not a single committee queue: a self-certified minimal-risk tier for anonymous, non-sensitive studies with adult participants; a light-touch tier reviewed by a departmental ethics officer for moderate-risk designs; and full committee review reserved for research involving vulnerable participants, deception, or GDPR special-category data such as mental health or sexual orientation. Matching the review burden to the actual risk is what keeps a full committee’s capacity for the submissions that genuinely need it.
Why does a single ethics queue create a bottleneck in psychology?
Psychology and social-science departments generate an unusually high volume of small, individually low-risk student research — the standard undergraduate and taught-masters dissertation model in these fields is a primary study with human participants, not a literature-based project, so nearly every student in the cohort needs some form of ethics sign-off before data collection can start. Where every submission, regardless of risk, is routed to the same full committee, the committee’s capacity becomes the limiting factor on the department’s entire dissertation timeline, and a routine anonymous-survey study waits in the same queue as a study involving clinical patients or minors. The fix is not more committee capacity; it is not sending the low-risk majority to the committee at all.
What does a tiered risk route actually look like?
Three tiers cover the great majority of psychology and social-science student designs, each with a different reviewer and a different turnaround expectation.
- Tier 1, self-certified minimal risk. Anonymous or fully de-identified data collection, adult participants with full capacity to consent, no special-category data, no deception, no incentive that could constitute undue influence. The student completes a checklist against these criteria and a nominated reviewer — often the module leader rather than an ethics specialist — countersigns within days, not weeks.
- Tier 2, departmental light-touch review. Designs with identifiable participant data, mild deception disclosed at debrief, online or community samples that are harder to verify, or minor scope changes to an already-approved protocol. A departmental ethics officer — a single named academic, not the full committee — reviews and signs off, typically inside one to two weeks.
- Tier 3, full committee review. Any design touching vulnerable participants (children, patients, prisoners, people lacking full capacity to consent), sustained or significant deception, GDPR special-category data, or any element the departmental officer judges to exceed their own sign-off authority. Full committee review carries the longest turnaround and should be flagged to students as early as possible in project selection, since it is the tier most likely to affect a dissertation timeline.

Which studies must go to full committee, without exception?
Four categories should be hard-coded into the tiering checklist as automatic Tier 3, regardless of how minor the rest of the design appears: research involving children or young people under the age of legal consent for research participation in the relevant jurisdiction; research involving patients, service users or others recruited through a clinical or care setting; research using deception where participants cannot be fully debriefed immediately, or where the deception concerns a sensitive personal matter; and any collection of GDPR special-category data — health information, sexual orientation, religious or philosophical belief, political opinion, or data revealing racial or ethnic origin — which is common in psychology research on well-being, identity or clinical constructs even when the study otherwise looks low-risk. A checklist that lets a departmental officer wave through a study because “it’s just a questionnaire” without checking whether the questionnaire asks about mental health history is the single most common failure mode in a tiered system.
What do the BPS and APA codes actually require?
The British Psychological Society’s Code of Human Research Ethics and the American Psychological Association’s Ethical Principles of Psychologists and Code of Conduct both set out the substantive obligations — informed consent, the right to withdraw, debriefing, protection from harm, confidentiality — that any tier of institutional review is checking for. Neither code prescribes a specific committee structure or a specific number of review tiers; that operational design is left to the institution. What both make clear is that the level of scrutiny should scale with risk to participants, which is the professional-body backing for a tiered route rather than a justification for routing every submission through the same process regardless of risk.

How does data protection interact with the ethics route?
GDPR special-category data is the single most common trigger that moves a psychology study from a lower tier into full committee review, and it is also the category students most reliably miss on a self-certification checklist, because a question about mood, stress or general wellbeing does not read as “health data” to someone outside data protection. The ethics checklist and the data protection assessment should ask the same question in the same place rather than as two separate forms completed at different points in the project, since a design that changes to add one sensitive question after data-protection sign-off but before ethics sign-off — or the reverse — is a real and common failure point. Where a supervisor is also involved in reviewing or processing student data for marking or feedback purposes, the same disclosure boundaries apply as in the rules on staff putting student work into an AI tool: participant data collected under an ethics approval has its own consent basis, which is a separate question from the consent basis a platform vendor operates under, covered more generally in whether a university can rely on student consent to deploy an AI tool.
How long should each tier actually take?
Tier 1 self-certification should be same-week, since its entire purpose is to remove low-risk studies from any queue at all; a design that takes longer than a few days to self-certify is usually evidence that it does not actually belong in Tier 1. Tier 2 departmental review is realistically one to two weeks, driven by a single reviewer’s availability rather than a scheduled meeting cycle, which is the main reason to keep it as a named individual rather than a sub-committee. Tier 3 full committee review is the slowest by design, typically tied to a scheduled meeting cycle rather than continuous review, and departments should publish the committee’s meeting dates alongside the dissertation timeline so that a student whose project is likely to need full review can be steered toward that assessment early, rather than discovering the mismatch after the project is already chosen. Most of the delay complaints a graduate school actually receives trace back to a Tier 3 submission that should have been flagged as such during project approval, not during ethics review itself.
How should a department audit its own pipeline?
Two numbers, tracked per term, reveal whether a tiering system is actually working rather than just existing on paper: the proportion of submissions in each tier, and the proportion of Tier 1 or Tier 2 submissions later escalated to a higher tier after initial review. A healthy pipeline should see the large majority of undergraduate and taught-masters submissions clear at Tier 1 or Tier 2; a pipeline where most submissions land in Tier 3 either has a genuinely high-risk research portfolio, which is plausible in a clinical or forensic psychology programme, or has a Tier 1/2 checklist that is too conservative and is routing routine studies to full committee unnecessarily. A high escalation rate from Tier 1 or 2 to Tier 3 after initial review is the clearer warning sign: it usually means the self-certification checklist is missing a trigger question, most often the GDPR special-category question described above, and needs revision before the next intake rather than at the next scheduled policy review.
The audit itself should sit alongside, not inside, the department’s existing data protection review process. Where a psychology study collects participant data through a platform the institution has procured — a survey tool, an online experiment builder — the same data protection impact assessment discipline set out in how to run a data protection review before deploying an AI writing tool applies to the research platform itself, not only to the study design: a vendor processing special-category psychological data needs its own documented lawful basis and data processing agreement, independent of whether the study protocol has cleared ethics review. Treating the two as one combined sign-off, rather than two separate approvals that can drift out of alignment, is the same principle behind auditing evidence quality more generally, covered in what evidence stands up when a student appeals an AI misconduct finding — a decision recorded without a clear, checkable rationale is a decision that will not survive scrutiny later, whether that scrutiny comes from an appeals panel or a data protection audit.
The same discipline-specific-overlay logic set out for a law faculty’s AI policy in what a law faculty should add to the university’s AI policy applies here in reverse: a psychology department’s ethics route is not a generic university process with a psychology label attached, it is a discipline-specific governance layer built around the particular risk profile of research with human participants, and it should be documented and reviewed as its own artefact rather than as a subsection of a broader research-governance policy.
If you would like help auditing your own department’s ethics routing against this tiering model, request an institutional evaluation and we will work from your current forms and committee data.
Frequently asked questions
What counts as minimal risk for Tier 1 self-certification?
Anonymous or fully de-identified data collection from adult participants with full capacity to consent, with no special-category data, no deception and no undue-influence incentive. Any design outside those criteria should not self-certify.
Who should review Tier 2 submissions if not the full committee?
A single named departmental ethics officer, typically a senior academic with ethics training, reviewing individually rather than through a scheduled sub-committee meeting, which is what keeps the turnaround to one to two weeks.
Does a simple online survey ever need full committee review?
Yes, if it collects GDPR special-category data such as mental health, sexual orientation or religious belief information, even anonymously. Anonymity reduces some risks but does not remove a study from the special-category trigger.
What do the BPS and APA codes require regarding review structure?
Neither prescribes a specific number of review tiers or a specific committee structure; both require that scrutiny scale with risk to participants, which supports a tiered approach without mandating any particular design.
Why do mental health and wellbeing questions get missed on self-certification checklists?
Because they do not intuitively read as “health data” to a student outside data protection, even though mood, stress and wellbeing measures are commonly GDPR special-category data. This is the most common gap in a self-certification checklist.
How should a department handle a project that changes design after initial ethics approval?
Any change that could move the study into a higher risk category — adding a sensitive question, recruiting a different population — should trigger a fresh tiering check rather than being treated as a minor amendment to the original approval.
What is the biggest indicator that a tiering system needs revision?
A high rate of Tier 1 or Tier 2 submissions later escalated to Tier 3 after initial review, which usually means the self-certification checklist is missing a trigger question rather than that the research portfolio has genuinely shifted toward higher risk.
Should ethics approval and data protection review happen on the same form?
Ideally the same question set is asked in one place rather than two separate forms completed at different project stages, since a design change between the two sign-offs is a common and hard-to-catch failure point.
