IRB-Compliant Research Transcription: What U.S. Universities Should Ask a Transcription Vendor
Aug 8, 2026

IRB-Compliant Research Transcription: What U.S. Universities Should Ask a Transcription Vendor

by Verbalscripts2 minute read

Quick answer: A transcription company is not made “IRB compliant” by a badge or generic certificate. The practical question is whether the vendor can perform the transcription work exactly within your approved protocol, consent language, institutional security requirements, and any applicable privacy rules. Before sending recordings, confirm who will access them, where data will be transferred and stored, whether subcontractors are used, how long files are retained, how deletion is documented, and what happens if protected health information (PHI) or other sensitive data is present.

For researchers working with interviews, focus groups, oral histories, or clinical conversations, the transcript can become one of the most sensitive datasets in the project. A recording may contain names, workplaces, diagnoses, immigration histories, family details, allegations, or indirect identifiers that were never meant to circulate outside the research team. Choosing a transcription vendor therefore belongs in the study’s data-management plan - not at the end of fieldwork when a deadline is approaching.

If your team needs human-reviewed research transcripts, VerbalScripts academic and conference transcription and qualitative interview transcription can be evaluated against the checklist below. For institution-specific requirements, request a written quote and workflow before uploading restricted data.

What “IRB-compliant transcription” should mean in practice

In the United States, Institutional Review Boards review research under the rules and policies that apply to the institution and study. HHS regulations at 45 CFR part 46 set federal requirements for many human-subjects studies, while universities may impose additional contractual, security, or privacy controls. The IRB approves the research protocol; it does not normally confer a universal compliance certification on an outside transcription company.

That distinction matters. A vendor can have strong security practices and still be unsuitable if the approved protocol says recordings will be accessible only to named study personnel, retained for a particular period, processed in a particular environment, or stripped of identifiers before an outside party receives them.

The safest procurement language is therefore concrete: “Can this vendor meet the requirements of our approved protocol and institutional data-security terms?”

12 questions to ask before sending research audio

1. Can the vendor work within the approved protocol and consent form?

Send the vendor only the provisions that are necessary to define the workflow, and identify any promises made to participants about recording, transcription, third-party access, de-identification, retention, or destruction. If outsourcing transcription was not anticipated in the protocol, ask the PI or IRB office whether a modification is needed before transferring recordings.

2. Who can access the audio and transcript?

Ask for a role-based description, not a vague promise of confidentiality. Clarify whether access may include a project manager, transcriptionist, reviewer, proofreader, technical administrator, or subcontractor. Then compare that access model with your protocol.

3. Are subcontractors or independent transcriptionists used?

The research team should know whether the company performs all work itself or routes files to additional parties. If subcontractors can receive identifiable data, ask how they are bound to the same confidentiality and security obligations and whether your institution requires prior approval.

4. What security protects data in transit and at rest?

Your university may have a security questionnaire specifying encryption, authentication, access controls, logging, password standards, vulnerability management, or incident-response obligations. Do not substitute marketing language for the institution’s actual checklist. Ask the vendor to answer the controls that matter to your data classification.

5. Where will the data be stored or processed?

Some protocols, grants, contracts, tribal agreements, export-control rules, or institutional policies can restrict where data is handled. Ask about storage location and any cross-border processing rather than assuming that “online transcription” means domestic processing.

6. What is the retention and deletion policy?

Define the lifecycle for audio, working copies, drafts, final transcripts, backups, and support attachments. Decide whether deletion happens immediately after acceptance, after a fixed quality-assurance window, or on written request. If your institution requires evidence of deletion, state that requirement in the order.

7. How are identifiers handled?

A research transcript can remain identifiable even after names are removed. Locations, job titles, rare conditions, relationship details, and distinctive events may be indirect identifiers. Specify whether the vendor should:

transcribe identifiers exactly;

replace them with neutral placeholders such as [PARTICIPANT NAME];

produce both an original and a de-identified copy; or

leave de-identification to the research team.

The vendor should never invent a de-identification scheme that conflicts with the codebook or analysis plan.

8. Is a Business Associate Agreement required?

IRB requirements and HIPAA requirements are different. When a HIPAA covered entity or business associate hires a vendor to create, receive, maintain, or transmit PHI on its behalf, a Business Associate Agreement (BAA) may be required. HHS specifically describes business-associate obligations and downstream subcontractor requirements. For health-related studies, your privacy office should determine whether the recording contains PHI and whether the transcription relationship requires a BAA.

9. What transcription convention will be used?

Security is only one part of research quality. Tell the vendor whether the study needs clean verbatim, full verbatim, pauses, fillers, false starts, overlapping speech, nonverbal events, timestamps, or special notation. A transcript that is “cleaner” but analytically incompatible with the methodology can be a poor research deliverable.

For phenomenological work, see Phenomenological Research Transcription. For coding workflows, see Thematic Analysis Transcription.

10. How does quality assurance work?

Ask whether a second person reviews the transcript, how uncertain speech is marked, how names and technical terms are verified, and whether the vendor accepts a study glossary. A responsible workflow marks genuinely inaudible material instead of guessing.

VerbalScripts describes a human-driven workflow across transcription, review, proofreading, and formatting. For research teams, the practical benefit of multiple review stages is consistency across participant files - particularly when a dissertation or funded project contains dozens of interviews.

11. What happens after a security incident?

Your contract or data-use agreement may require notification within a defined time. Ask who receives incident reports, what information is supplied, and how the vendor coordinates containment and investigation. This should be established before an incident, not negotiated afterward.

12. Can the vendor document the workflow for procurement or the IRB file?

Research offices often need more than a price. Ask whether the vendor can provide a written scope covering confidentiality, access, file transfer, retention, deletion, turnaround, transcription convention, and any required agreement. This makes the arrangement easier to defend during internal review and easier to reproduce later.

A procurement checklist you can paste into an RFP

Study fit: Confirmation that the vendor can follow the approved protocol and consent restrictions

Confidentiality: NDA/confidentiality terms and description of authorized personnel

Subcontracting: Disclosure of any downstream processors or transcriptionists

Security: Transfer, storage, authentication, access-control and incident-response information

HIPAA: BAA capability when the relationship and data require one

Data location: Processing/storage locations relevant to institutional restrictions

Retention: Defined retention window for audio, drafts, finals and backups

Deletion: Deletion procedure and documentation if required

Transcript standard: Verbatim level, timestamps, speaker labels, redaction/de-identification rules

QA: Review/proofreading process and treatment of inaudible speech

Deliverables: Word/PDF/text format, naming convention, QDAS-ready structure if required

Project management: Turnaround, revision window, point of contact and escalation process

What should researchers send with the recordings?

Provide a concise project brief. Include participant codes rather than real names when feasible, the moderator/interviewer name, expected speaker count, a terminology list, transcription convention, timestamp rule, redaction instructions, file-naming scheme, and the deadline. If a consent form or protocol imposes restrictions, communicate the operational requirement without unnecessarily circulating the entire research file.

For dissertation projects, VerbalScripts also maintains a dedicated dissertation interview transcription service. Researchers can upload files through the order portal only after confirming that the chosen workflow is permitted by their protocol and institution.

Frequently asked questions

Does an IRB “certify” transcription vendors?

Generally, no. An IRB reviews the research and the protections described in the protocol. A university may separately approve or contract with vendors. Treat “IRB compliant” as shorthand for a vendor workflow that follows the approved study requirements, not as a universal certification.

Do I need IRB approval to use a transcription service?

It depends on the study and what the approved protocol already permits. If the protocol or consent materials did not anticipate third-party transcription, identifiable data, or a new data-handling arrangement, contact the PI or IRB office before outsourcing.

Should interviews be de-identified before transcription?

When feasible, minimizing identifiers before transfer can reduce risk, but it is not always practical because identifiers may be spoken throughout the recording. The approved protocol and analysis needs should control whether the vendor transcribes, masks, or leaves identifiers for the research team to remove.

Is HIPAA the same as IRB compliance?

No. HIPAA regulates certain health information handled by covered entities and business associates; IRB and Common Rule requirements concern human-subjects research. A clinical study can implicate both, one, or neither depending on the facts.

Can a transcript be imported into NVivo, ATLAS.ti, MAXQDA, or Dedoose?

Usually yes when the output uses consistent speaker labels, clean paragraph structure, predictable filenames, and stable participant IDs. Tell the vendor which analysis environment you use before transcription begins.

Bottom line

The best research transcription vendor is not simply the one that says “secure.” It is the one that can explain who touches the data, how it moves, how it is protected, how long it exists, how it is deleted, and how the transcript will preserve the analytic features your methodology requires.

If you are preparing a U.S. university study, dissertation, or funded qualitative project, request a VerbalScripts quote with your protocol constraints, file count, approximate audio minutes, and desired transcript convention. The team can then scope the transcription workflow before restricted research data is transferred.

Research compliance note: This article is operational guidance, not legal advice or a substitute for your IRB, privacy office, information-security team, or institutional counsel.

Authoritative references

U.S. HHS Office for Human Research Protections, 45 CFR part 46 and human-subjects guidance

HHS, Business Associates under HIPAA

HHS, HIPAA Security Rule

NIH, Data Management and Sharing Policy

NIH, Principles and Best Practices for Protecting Participant Privacy

Subscribe to our newsletter.

Get latest updates for our Articles & Blogs. We post fresh content every week.

Weekly articles
Stay updated with our weekly articles covering various topics.
No spam
We respect your inbox. No spam, just valuable content.