Nine findings the Aspen IRB writes most, and the question underneath each one
A returned file feels like a verdict on your project. It almost never is. What comes back is a list of places where the documents did not answer a question the board is obliged to answer for itself — and every one of those questions can be put to your own file this afternoon. That is the entire argument for reading a package before the board does: the findings exist either way, and the only variable is whose record they end up in.
Miriam Kessler, DNP, APRN · 2026-08-23
In short. Nine findings account for most Aspen returns: an incomplete package, careless drafting, an unreadable consent, a weak site letter, missing assent, unlicensed instruments, a thin data answer, a missing records authorisation, and consent given in a language nobody verified. All nine are visible before filing.
Why does a board write findings at all?
Because approval is not an opinion it forms — it is a set of conclusions it has to be able to write down. Aspen publishes them: risks minimised, risks reasonable against the benefit, participants chosen equitably, consent sought and documented where it applies, privacy and confidentiality provided for, safeguards where someone might be leaned on, and site permission secured. If a document does not supply the evidence for one of those conclusions, the board cannot simply assume it. It writes back.
Aspen is unusually direct about what that costs. Applications that arrive incomplete, that contain errors, or that carry inconsistent information will be delayed — and the disposition reserved for an incomplete file, deferral, is not a comment on your design at all. It is the board saying it could not begin.
The nine, with the question each one is really asking
Severity below is marked the way a reviewer weighs it: an observation is noted and cured cheaply, a minor finding costs a query and a corrected page, a major finding sends the file back.
major finding
Finding 1 — The package cannot be read as one file
The question underneath. Do I have everything I need to start? Aspen requires three items with every application without exception — the chair-approved application form carrying a signature and date, the university-approved proposal covering its first three chapters as a Word file, and the training certificates — then a conditional list on top of that.
Corrective action. Assemble the package as one labelled object and check it against Aspen’s own required list before anything is sent. A missing attachment does not earn a partial reading; it stops the reading.
observation — cheapest to cure
Finding 2 — Typos, and numbers that disagree with each other
The question underneath. If this much care went into the paperwork, how much went into the people? Aspen says outright that a well-written, accurate submission gives the board confidence, and that anything a participant will lay eyes on may be sent back for accuracy and clarity — because errors in a flyer or a consent make a stranger doubt the whole undertaking.
Corrective action. Read the package for agreement, not for style: every figure, instrument name, site count and date must be identical in every document that mentions it. Then read the participant-facing pages aloud.
minor finding
Finding 3 — The consent is written above the person signing it
The question underneath. Could this person actually understand what they agreed to? Aspen sets a measurable bar rather than a vague one: consent should sit below a ninth-grade reading level, and it names the Flesch grade-level formula as the way to check. It also asks that key information come first, so the decision can be made without decoding the rest.
Corrective action. Run the readability measure and record the score. Strip jargon, shorten sentences, and put voluntariness, the right to stop, and what happens to the data where they will be read first.
major — slowest to cure
Finding 4 — The site letter does not do what a site letter does
The question underneath. Does somebody with the power to say yes know precisely what will happen on their premises? Aspen lists what the letter must carry: printed on letterhead, with email explicitly not sufficient; your name and the project title; a purpose in one to three sentences; a statement that the protocol has been reviewed; an account of exactly what is permitted; any restrictions; and a signature from someone attesting they hold the authority to grant it, with their title, address and telephone number. For DNP work Aspen expects that signatory to be a chief medical officer or director.
Corrective action. Request it first, not last — it is the only finding written on somebody else’s clock. Ask the site whether it has its own template before offering one, and remember Aspen treats this as a separate instrument from any immersion agreement already signed.
major finding
Finding 5 — Assent or guardian permission is missing
The question underneath. Who else has to agree before one signature is enough? Aspen is specific: written assent for young people aged thirteen to seventeen, an oral assent with a submitted script for those between seven and twelve, guardian permission obtained before the young person is approached, and assent for adults whose capacity is impaired. Aspen warns that where the committee judges an assent form appropriate and it is absent, the protocol cannot be approved and is postponed.
Corrective action. Establish who your participants actually are before drafting, then take the assent and permission forms from Aspen’s own materials rather than adapting an adult consent.
minor finding
Finding 6 — The instrument arrives without permission behind it
The question underneath. Are you entitled to use this tool the way you intend to? Some authors ask nothing; others require registration or a licence even when no money changes hands. Aspen asks for proof of purchase where a tool was bought, and for the author’s written permission wherever you modify an instrument or a protocol — changing wording, dropping items, altering a scale.
Corrective action. Settle permissions while the plan is still being fixed. Attach the tool exactly as it will be administered, with any licence or permission alongside it.
minor finding
Finding 7 — The data answer is one sentence where six are wanted
The question underneath. Who can put a name back on this person, and when does that stop being possible? Aspen asks the application to state what will be collected, how, where it will be held, who may reach it, how it is protected, and how and when it will be destroyed. It also asks for coding, with the list linking codes to names kept somewhere separate — a different server entirely, where the data are electronic. Sensitive material invites more still: authentication, a firewall, anti-virus provision, encrypted files, and physical security for the machines.
Corrective action. Write six named answers rather than one reassuring adjective, and say plainly where the linking list lives and when de-identification happens.
major finding
Finding 8 — Records are opened with no authorisation attached
The question underneath. Are you touching a medical record at any point? Aspen ties this to a factual trigger rather than a judgement call: where medical records are used at any stage — electronic, paper or archived — the privacy rule is engaged and an authorisation form belongs with the protocol. Chart review counts. A quality-improvement framing does not switch it off.
Corrective action. Trace every path your data travels and mark each point a record is opened. If any exists, the form goes in the package.
major finding
Finding 9 — Consent is taken in a language nobody verified
The question underneath. How will you know the agreement was understood? Aspen requires two separate things where participants do not speak English. First, a translated consent and translated materials, approved by the board before use, produced either by a certified service carrying its stamp or by translation and independent back-translation with a note confirming the process. Second, a fluent witness present at the conversation — and Aspen states that the person taking consent cannot also be that witness.
Corrective action. Decide early whether your setting will produce participants in this position. If it might, build the translation and name the independent witness before the submission rather than after.
What do all nine have in common?
Not one concerns the merit of your project. Each is a property of a document, or of the agreement between two documents — and properties like those are testable by anyone prepared to read a package as a reviewer does. That is a strange kind of good news: the costliest part of this process is also the most preventable.
It is also why order matters. Requesting the site letter first, settling the category before the forms, fixing the plan before anything quotes it — not niceties, but the sequence that keeps the nine from appearing. That order is drawn in the process, in order; what each document must carry sits in the checklist; and how it works shows where we take the file over.
What to do next
Put the nine questions to your own package. Where you cannot answer one from a document rather than from memory, you have found a finding. If you would rather someone else ran that pass, ask for the free application review from our contact desk: three consultants read your file as Aspen’s board would, and a written report comes back with each finding, the evidence a reviewer would see, its severity, and the correction. There is no cost and nothing is owed afterwards — a clean package is told it is clean. Where findings do exist, the cure can be ours as well: the classification settled from the design, each document rebuilt and cross-read, the submission prepared and filed with you, and every reply drafted until the board has finished writing. Your project, its data and its conclusions stay with you. The determination belongs to the board. Our FAQ handles the questions that come up alongside these.