gcuirb Free application review

The exhibit file: every document that rides with a GCU IRB application

Nobody at Grand Canyon University reads your IRB application on its own. It arrives with attachments, and the board treats the bundle as one document that either agrees with itself or does not. GCU publishes both halves of the test — what a convened board receives, and what a reviewer checks on a doctoral submission — so the exhibit file is one of the few parts of this process you can prepare against a written standard.

Tessa Galbraith, MSN, RN · 2026-08-23

The short answer

One application, many attachments — GCU reads them as a single file. Expect the application itself, CITI completion reports, consent and assent, recruitment materials with readability reports, instruments and permissions, a site authorization letter for every location, and HIPAA paperwork where health information is involved.

Why does the board read the attachments as one document?

Because the attachments are where the promises live. The application says what will happen; the consent form is what a participant is told; the recruitment letter is the first thing they see; the site letter is what an organisation has agreed to permit. A board deciding whether people are protected must know those four accounts describe one study — and GCU makes that explicit rather than aspirational. Its document checklist for doctoral learners requires inclusion, exclusion and activities to match exactly across application, consent and recruitment. It is a comparison test, run on your file whether or not you ran it.

The form also builds its own attachment list as you work: iRIS prompts for further supporting documents based on what you have entered, so the exhibit file is partly a consequence of your own answers. Anticipating which answers summon which attachments is most of the preparation.

What does GCU send to a convened board?

GCU's procedure for full committee review lists what members receive, and it is the cleanest published picture of a complete file: the initial review application including the detailed protocol and a copy of the full research proposal; CITI training completion reports; the recruitment plan with any HIPAA authorisation or waiver request; recruitment materials — letters, advertisements, postings, email announcements; consent forms or a request for waiver of consent; an assent form where applicable; HIPAA authorisations or waiver applications; the site authorization letter; and, where they apply, a sponsor's protocol, device manual or funding application.

The second item is the one candidates underestimate. A copy of the full research proposal travels with the application to the people reading it. The board is never unaware of what the university approved — which is why the approved proposal sets the standard for the bundle.

What is in the file, and how does each piece fail?

The exhibit file at GCU: what each document is for, and the failure that recurs.
ExhibitWhat GCU expects of itHow it commonly fails
The applicationEvery section completed, no unanswered questions, branching answers consistentSections left open because a later answer changed what the form asked
CITI completion reportsHuman Subjects Research–Basic and Responsible Conduct of Research, registered under the GCU email so records load automaticallyRegistered with a personal address, so nothing appears in the submission packet
Informed consentCurrent GCU template; signature line intact for a confidential study, agree and disagree buttons intact for an anonymous oneA template edited into something the checklist no longer recognises
Readability reportsOne for consent and one for recruitment, at Flesch–Kincaid grade 9.0 or lowerMissing entirely, or run on a version that was later revised
Recruitment materialsCurrent GCU recruitment template, with screening criteria embedded in the inclusion criteriaPromising something the consent does not, or reaching people the eligibility criteria never named
Online survey linkThe live link in the recruitment letter and in the application; the approved consent as the first and separate page behind itConsent buried after demographics, or a link that resolves to the instrument directly
Assent formRequired where children participate; GCU publishes a written child assent template for greater-than-minimal-risk workAdult consent language reused for a population that cannot read it
Instruments and permissionsThe instruments as approved, with permission or licence attached and currency visibleAn instrument revised after approval, or permission that has gone out of date
Site authorizationA letter from every site, on letterhead, signed by someone with authority, current within a year of approvalA site named in the application with no letter behind it
HIPAA paperworkAuthorisation form, or GCU's waiver of authorisation, where protected health information is involvedAssumed unnecessary because the setting feels routine

Template names and portal fields change; GCU's current doctoral handbook or IRB portal governs which apply. The failures above are how a reviewer reads them, not a substitute for the source.

What does GCU's doctoral checklist actually test?

It is short, and every item is binary. A reviewer works it as yes-or-no, which is why a thoughtful but unaligned file still fails. The eleven checks cover completeness; correct current templates; the signature line or the agree and disagree buttons, according to whether the study is confidential or anonymous; screening criteria embedded in the inclusion criteria; the exact match across application, consent and recruitment; readability reports for both documents; live link and consent placement for online surveys; and the currency of authorizations and permissions.

Two deserve emphasis. Readability is a hard threshold, not a preference — a consent form pitched at postgraduate level fails however accurate it is. And GCU treats a site authorization as good for one year from its date of approval, with a clear date stamp visible, which turns a letter obtained early into something to re-check before filing.

What has to appear in a site authorization letter?

GCU publishes the requirements in unusual detail, separating the request you send from the letter you get back. The request must specify authorisation to contact potential participants, to recruit them, and to collect data. The returning letter should carry the following.

  1. Department letterhead, with the title and signature of the faculty member or department head giving the authorisation.
  2. Your name and title, the protocol title, and the GCU affiliation.
  3. A brief summary of the study — purpose, research questions, significance — confirming the site understands what it is permitting.
  4. The three authorisations, named separately: to contact, to recruit, to collect data.
  5. What the site has agreed to allow, any restrictions or limitations, and what responsibilities it assumes.
  6. A statement that the site will receive the IRB-approved, stamped consent document.
  7. A signature line with printed name, title and date.

GCU also asks that the request be professionally written and free of typographical errors, and suggests supplying a sample letter so every permission comes back complete. Two further points: where a site runs its own board, that board's approval is needed too, and prisons, veterans' hospitals, military bases and international sites carry extra review. One caution on GCU's older appendices — the site authorization procedure still names IRBNet, the system used before submission moved into iRIS. The letter requirements carry forward; the destination does not.

What else sits on GCU's forms shelf?

More than most candidates realise, and knowing the shelf is how you stop discovering a required form mid-application. Alongside its two consent templates, GCU publishes a recruitment script, a general site authorization letter, a written child assent form for greater-than-minimal-risk work, a HIPAA authorisation and a waiver, a data use agreement, a debriefing form, a non-disclosure agreement, an institutional affiliation agreement, an international research form, a translation certification, a form for when the submitter is not the principal investigator, guidance on confidentiality versus anonymity, social media and survey platform guidance, a glossary, the review level decision matrix, the handbook, and document checklists for doctoral candidates and for faculty, staff and external researchers.

Current versions live in the DC Network's forms and templates folder, and GCU's checklist sends reviewers there precisely to confirm they have the latest. A superseded template is a defect in an otherwise sound file — and GCU's standing responsibilities for a principal investigator include routinely reviewing the IRB research centre for revised forms, policies and procedures.

How do you assemble a file that agrees with itself?

Build outward from the approved proposal rather than inward from the templates. Take the load-bearing facts — population, setting, eligibility, activities, instruments, identifiability, data handling — and write each exhibit from that single source. Then read in pairs: consent against recruitment, recruitment against site letters, application against consent, all of it against the proposal. Any two documents should describe one participant doing the same things under the same protections.

Then check the mechanical layer, which fails independently of the prose: templates current, readability reports run on final versions, permissions and site letters in date, CITI records showing under your GCU email, every branch of the form answered. The level your file is heading for changes what a reader expects — mapped in the four ways a GCU study can be read — and the sequence around it in how a GCU IRB file moves.

What to do next

Send the bundle as it stands — draft application, consent, recruitment, instruments, site letters. We read it against your approved proposal and against GCU's published standards, then return a written finding: what aligns, what has drifted, what is missing. The review costs nothing, and where the honest answer is that the bundle needs nothing from us, it says so.

Where you would rather the whole thing left your desk, it can: the determination and document plan, each exhibit drafted against the approved proposal, the filing in GCU's portal, and each answer the board asks for until its letter arrives. Study, data and conclusions stay with you. The decision stays with the board.

Sources

  1. GCU — IRB Document Checklist for Doctoral Learners — completeness; correct templates; signature line and agree/disagree buttons; the exact match rule; readability at Flesch–Kincaid 9.0 or less; live survey link and consent placement; currency of authorizations; DC Network templates
  2. GCU IRB Resource Center — Procedure for Full Committee Review — members' materials, the full research proposal included
  3. GCU IRB Resource Center — Procedure and Guidelines for Site Authorization — what the request and the returned letter must contain; site boards; special sites
  4. GCU IRB Resource Center — Responsibilities of the Principal Investigator — adequacy of submissions; watching for revised forms; amendments before changes take effect
  5. GCU Office of Research — Institutional Review Board — the published forms and templates list; CITI reports in iMedRIS
  6. GCU — Steps to Prepare IRB Application — consent templates; chair review; iRIS prompting for attachments; on- and off-campus site requests

gcuirb.com is an independent consulting practice. There is no affiliation with Grand Canyon University and no endorsement by it. Where this page diverges from GCU's current doctoral handbook or IRB portal, GCU's text governs.