Performing trustworthiness: governance theatre versus governance maturity
Elizabeth Green, Felix RitchieAbstract
Universities, governments, and health research infrastructures increasingly invoke the language of “trusted,” “secure,” and “safe” research environments to legitimise access to sensitive data. While technical infrastructures such as Trusted Research Environments, Secure Data Environments, and cloud-based analytical platforms have expanded rapidly, equivalent growth in operational governance capability has not always followed. This article argues that contemporary research governance risks drifting towards “governance theatre”: the performance of trustworthiness through visible technical controls, secure branding, and procedural symbolism while comparatively less attention is devoted to disclosure expertise, behavioural governance, independent oversight, and operational maturity. Using recent controversies surrounding the UK Biobank as an illustrative governance stress test rather than an isolated institutional failure, this article examines tensions emerging across contemporary research practices—including platformisation, global collaboration, artificial intelligence, code sharing, and increasingly complex data systems. Drawing on the five safes framework, this article argues that trustworthy governance cannot be reduced to technical infrastructure or formal compliance alone. Governance maturity depends upon layered socio-technical systems capable of managing disclosure risk, researcher behaviour, and organisational accountability across the full research life cycle. Moving beyond governance theatre will require greater investment in governance literacy, disclosure expertise, independent output review, and reflexive oversight capable of adapting to rapidly evolving systems.