Today

NHMRC has published several updates to support clear and consistent governance across funded research.

The 2026 NHMRC Funding Agreement is now available and is effective from 1 September 2026. It replaces the 2023 NHMRC Funding Agreement and includes updates relating to definitions, fraud provisions, child safety compliance, foreign interference and redress, information management and reporting, and moral rights obligations.

Child safety requirements (clause 18) – This clause largely confirms and strengthens obligations that Administering Institutions already have to support child safety, including complying with the National Principles for Child Safe Organisations and complying with relevant state/territory legislation relating to working with children checks. NHMRC does not expect the additional compliance activities in clause 18 to be applied retrospectively; the clause applies to grants awarded from 1 September 2026 onwards. Where risk assessments that include child safety are conducted and risk management strategies put in place under existing institutional processes, including ethics approvals, these would generally satisfy the obligations at 18.2. Please note that the National Office for Child Safety provides resources for child safe organisations and the Australian Human Rights Commission provides free online child safe organisations training.

Fraud requirements (clause 17) – NHMRC’s updated Fraud and Corruption Control Framework (2026-2028) provides further information about responding to fraud related to NHMRC research funding, including reporting and investigation (see Appendix B of the Framework, in particular). If an Administering Institution becomes aware of fraud (including an allegation of fraud) and has any concerns about notifying NHMRC within the five working-day notification period, it can contact NHMRC at governance@nhmrc.gov.au to discuss this.

Nothing in the Funding Agreement limits or derogates from the Administering Institution's obligations under any Commonwealth, state or territory law.

A new cyber security incident reporting page for Administering Institutions is also available. It sets out the reporting pathway for cyber security incidents involving NHMRC-funded research activities and notes that incidents should be reported as soon as practicable.

NHMRC will provide further advice about updates to the Research Integrity and Misconduct Policy when available.

Share