Examples
Worked examples
- Is an instance
A health-data trusted research environment applying accreditation (Safe People), ethics approval (Safe Projects), a locked-down virtual desktop (Safe Settings), a pseudonymised extract (Safe Data), and manual output disclosure review (Safe Outputs) together.
Counter-examples
Looks similar, but isn't
- Not an instance
A carefully-vetted-user analytics platform that still permits unrestricted download of query results — missing the Safe Outputs control despite strong Safe People controls.
Editorial commentary
Each 'safe' addresses a distinct control: Safe People (are the researchers vetted and trained?), Safe Projects (is the proposed use lawful, ethical, and in the public interest?), Safe Settings (is the analysis taking place in a secure environment?), Safe Data (has the data been appropriately minimised and de-identified?), Safe Outputs (have results been disclosure-controlled before release?). The framework underpins the operation of UK government statistical microdata access (ONS SRS), TREs across the NHS England SDE network, and many international equivalents.
Why all five, together
The framework’s design point is that no single control is sufficient on its own — a system with excellent output disclosure control but no vetting of who can log in is not safe, and a system that vets researchers thoroughly but leaves the analysis environment unrestricted (permitting local downloads) is not safe either. A trusted research environment (TRE) is assessed against the whole set, and a gap in any one dimension is treated as a real gap, not offset by strength elsewhere.
Worked example (illustrative)
Illustrative composite: a health-data TRE requiring researcher accreditation and training (Safe People), IRB/ethics approval documenting public benefit before project onboarding (Safe Projects), analysis restricted to a virtual desktop with no local file export (Safe Settings), a pseudonymised extract with direct identifiers removed before it enters the environment (Safe Data), and manual statistical disclosure control review of any output — tables, figures, model coefficients — before it leaves the environment (Safe Outputs), is the standard shape a Five Safes-compliant setup takes in practice.
Counter-example
A cloud analytics environment that vets and trains its users carefully (Safe People) but allows unrestricted download of any query result is not Five Safes-compliant — the missing Safe Outputs control means disclosure risk sits entirely on researcher judgement rather than on a documented review step.
Related pages
See also data safe haven (a specific implementation model built on the Five Safes), sensitive data repository, trusted digital repository, and the HIPAA Privacy Rule as a US regulatory analogue for de-identification (Safe Data).
References
- Desai T., Ritchie F., Welpton R., ‘Five Safes: designing data access for research’ (Bristol Centre for Economics and Finance working paper, 2016).
- UK Office for National Statistics, Approved Researcher Scheme / Secure Research Service (ons.gov.uk).
Also known as
Five Safes · 5 Safes
Machine-readable encodings
Use in your systems
<role vocab="credit"
vocab-identifier="https://casrai.org/dictionary/"
vocab-term="Five Safes framework"
vocab-term-identifier="https://casrai.org/dictionary/term/five-safes-framework" />{
"@context": "https://schema.org",
"@type": "DefinedTerm",
"@id": "https://casrai.org/dictionary/term/five-safes-framework",
"name": "Five Safes framework",
"identifier": "https://casrai.org/dictionary/term/five-safes-framework",
"description": "A framework for the safe use of sensitive data in research, articulated by the UK Office for National Statistics, that organises controls under five dimensions: Safe People, Safe Projects, Safe Settings, Safe Data, and Safe Outputs.",
"inDefinedTermSet": "https://casrai.org/dictionary/domain/data-infrastructure#set",
"url": "https://casrai.org/dictionary/term/five-safes-framework",
"sameAs": [
"Five Safes",
"5 Safes"
],
"license": "https://creativecommons.org/licenses/by/4.0/",
"publisher": {
"@id": "https://casrai.org/#organization"
},
"author": {
"@id": "https://casrai.org/#editorial-team"
},
"datePublished": "2026-05-21T02:22:48",
"dateModified": "2026-08-23T05:20:09",
"inLanguage": "en-GB",
"isAccessibleForFree": true
}







