Regulations

Malign Foreign Talent Recruitment Programs (MFTRP) — certification & prohibitions

In force · Agency implementations 2024–2025 Last reviewed: 2026-07-18

Under CHIPS Act §10632, federal research awards may not be made to any covered individual who is a party to a Malign Foreign Talent Recruitment Program (MFTRP) as defined in §10638, and institutions must certify per award that no covered individuals are participating in such a program. Federal science-funding agencies (NIH, NSF, DOE, DoD) have rolled out the certification requirement across 2024–2025.

The statutory definition

Under §10638, an MFTRP is a program, position, or activity that both:

  1. Involves the individual receiving compensation, in cash or in kind, from a foreign country of concern or an entity based in or acting on behalf of such a country; and
  2. Includes one or more of the following enumerated features:
    • The individual is required to recruit trainees, students, or researchers to the foreign entity.
    • The individual is required to establish a laboratory, entity, or company in the foreign country.
    • The individual is required to transfer intellectual property owned by the U.S. entity to the foreign entity.
    • The individual is required to omit acknowledgment of the U.S. institution or the federal award.
    • The individual is required to not disclose the participation to the U.S. institution or funder.
    • Certain other statutorily enumerated features (see §10638 for full text).

The definition is deliberately specific. Participation in a foreign talent program, in itself, is not automatically an MFTRP — the enumerated features are what convert an ordinary international engagement into a prohibited one.

Who has to certify — and to what

The certification is per award. The institution certifies that, to the best of its knowledge, no covered individual on the award is a party to an MFTRP. "Covered individuals" tracks the sponsor's senior/key-personnel designation plus any additional persons the institution's process brings into scope.

How institutions verify

In practice, institutions collect an attestation from each covered individual and layer that attestation against sources that can corroborate or contradict it — publications acknowledging foreign support, disclosed foreign appointments, external directories of talent-program rosters where available. The AOR's certification is only as strong as this verification layer. This is where enforcement cases have most often been made: not on the researcher's attestation, but on what could have been seen and was not.

Interaction with the disclosure standard

MFTRP certification and the Common Forms disclosure standard are complementary. The disclosure standard requires the researcher to declare all outside support and appointments. MFTRP requires the institution to certify — as a separate act — that none of what was disclosed (or should have been) meets the statutory definition of a malign program.

What institutions should do now

  1. Define "covered individuals" for each award class. Not every agency's certification uses the same scope; document your institution's operational definition.
  2. Build a per-award certification workflow, not an annual one. The certification is a submission-time gate.
  3. Verify against sources the researcher cannot control. Publications, sponsor-acknowledged affiliations, and Section 117 foreign contract filings.
  4. Document the review, not just the outcome. When a certification is later questioned, the institution needs to show what it looked at, not only what it concluded.
  5. Escalate ambiguous cases. Not every foreign engagement is an MFTRP; the ones that are not should be documented as reviewed and cleared.

Frequently asked questions

What is a "malign foreign talent recruitment program" under CHIPS §10632?

The CHIPS Act defines an MFTRP as a program, position, or activity that includes compensation from a foreign country or entity of concern AND has certain enumerated features — for example: requiring the recipient to recruit trainees to the foreign entity, to establish a laboratory or company in the foreign country, to transfer intellectual property to it, or to omit the participation from institutional disclosures. The definition is specific and set out in §10638.

Who has to certify?

For any federal research award, the institution must certify that no covered individual on the award is a party to an MFTRP. "Covered individuals" is a specific defined term that includes senior/key personnel and any other individual the institution designates. Certification is at the award level, per submission.

How does an institution actually verify that a researcher is not participating?

The statute puts the certification on the institution; the underlying knowledge comes from the individual researcher's disclosure and from institutional review. In practice, institutions ask covered individuals to attest, and layer that against publicly available signals — publications, affiliations, foreign talent-program participation records where those exist. Verification is what makes the certification defensible.

Are there specific programs on a public list?

Federal agencies (notably NIH and NSF) publish guidance and non-exhaustive examples of programs that meet or approach the MFTRP definition; the FBI and OSTP have also issued advisories. No single government "MFTRP list" is authoritative — the statutory definition, applied to the facts of a specific program, is what governs.

What is the exposure for a false MFTRP certification?

False Claims Act liability. Federal research award certifications are statements to the government; a knowingly false MFTRP certification is FCA territory. Undisclosed talent-program participation has been a recurring theme in the university FCA settlements to date (see the FCA enforcement tracker).

ResearchSecurity.ai runs continuous checks against U.S. government restricted-party and exclusion lists, integrated into the same evidence trail your AOR signs against.

How screening supports MFTRP certification →
Founding Partner Program

Verification for the institution certifying these disclosures.

Founding partners run ResearchSecurity.ai against their own compliance reality — with preferred terms and direct access to the team building it.