Last updated: 2026-09-23
Two Kinds of Ethics: What a Committee Checks, and What's Still Left to You
Every other page in this section describes a procedure — a research ethics committee's approval, a professional body's code of conduct, a citation rule. Read enough of that and it's easy to slide into thinking ethics is the procedure: that ticking every box is what it means to have behaved ethically, and that failing to tick one is the only way to behave unethically. Both halves of that are wrong, and the site is more useful once the two things it's actually conflating are pulled apart.
Procedures Answer a Narrower Question Than "Is This Ethical?"
A research ethics committee, a data protection impact assessment, a medical-device classification, a professional body's disciplinary process — each of these checks whether a specific, pre-defined set of conditions holds. AI on Health and Genomic Data covers a concrete case: whether a study can legally access identifiable NHS records without individual consent isn't a matter anyone reasons their way to from first principles on the day — it turns on whether UK GDPR's research condition is met, whether Section 251 support has been granted, whether the underlying biological sample was consented to under the Human Tissue Act. These are, very often, direct legal requirements, not judgement calls at all. A committee's job is to check whether they're satisfied, and that job is exactly as narrow as it sounds.
What a committee structurally cannot do — and doesn't try to — is ask which ethical framework you used to decide the study was worth doing, or to reach any of the design choices inside it. That's not a gap in how committees are run; it's what makes procedural ethics workable at all. A process that had to adjudicate between rival philosophical positions before granting approval would never approve anything, and an REC that could only function if every applicant reasoned the same way philosophically would be enforcing a specific ethical theory by the back door, which is not what it is for. So it doesn't ask. It checks the conditions instead.
It Doesn't Matter to the Committee Which Framework You Used
Studying Ethically introduces three classic ways of reasoning about a decision: virtue ethics asks who you're becoming by acting a certain way; utilitarianism asks what the net effect of an action is on everyone it touches; deontology asks what happens if the underlying rule were applied universally, regardless of how the specific outcome turns out. These aren't the only frameworks philosophy offers, but they're the three that show up most often in professional and research contexts, and they can genuinely disagree with each other about the same case.
None of that disagreement is visible to a committee. Two researchers can reach the identical, fully-compliant study design — the same consent process, the same data safeguards, the same risk mitigations — by two completely different routes: one because the expected benefit to future patients clearly outweighs the privacy cost to today's, the other because they'd hold themselves to the same data-minimisation standard regardless of how favourable the cost-benefit arithmetic happened to look. The committee approves the same protocol either way. It has no mechanism for asking, and no reason to.
But the Individual Still Has to Choose, Inside the Boundary
This is the half of the picture procedural pages tend to leave out: satisfying every applicable requirement still leaves real decisions to make. Approval and the law together define a boundary — what's permitted — and a great deal of genuine judgement lives in the space inside it.
Take the genomic research case again. Suppose approval permits access to a defined set of identifiable records for a specific analysis. Nothing in that approval says how much of the accessible data to actually touch — a researcher reasoning from something like a duty to minimise intrusion regardless of convenience will access less than the approval technically allows; one reasoning from expected net benefit might access more, if the marginal privacy cost seems small against the marginal research value. Or suppose the analysis surfaces an unexpected, clinically significant finding the original protocol never anticipated — approval doesn't tell you whether to act on it. A framework focused on outcomes points toward disclosure if the benefit is large enough; a framework focused on respecting the boundaries of the original consent points toward referring the question upward rather than acting unilaterally outside the study's own approved scope. Both researchers can be fully within what the committee approved and the law permits, and still make genuinely different, defensible choices — because the committee's permission was never trying to answer that question in the first place.
Professional Ethics's whistleblowing scenario and Studying Ethically's "it's completely legal, do you build it?" dark-pattern case are the same structure from a different angle: the law and the employer's instructions define what's permitted, and a real ethical decision still has to be made inside that space, using some framework or other whether or not anyone names it.
Two Ways This Gets Blurred
- Treating permission as the whole answer. "It's approved, so it's fine" and "it's legal, so it's fine" both quietly promote a procedural finding into a moral one. Professional Ethics's own point about the gap between a compliance mindset ("what can I get away with?") and a professional-standards mindset ("what should I do?") is a version of exactly this error — a code of conduct is still a procedure, and clearing it is still a narrower achievement than having made the right call.
- Treating personal conviction as a substitute for permission. The opposite mistake is just as real: being confident you've reasoned your way to the right answer does not grant the legal or institutional authority a REC, a CAG approval, or a data protection condition actually requires. A well-reasoned utilitarian case for accessing a dataset without the approval that's actually needed is still accessing it unlawfully.
A Practical Way to Hold Both at Once
The two layers aren't in tension if they're kept in the right order. First, identify and satisfy everything that's actually required — the committee approval, the legal basis, the professional code — as a non-negotiable floor, not a formality to get past quickly so the "real" work can start. Second, inside whatever latitude remains once that floor is satisfied, be explicit — to yourself, and ideally in whatever record of the work already exists, such as the discovery log this site's project-guidance material recommends keeping — about which consideration is actually doing the work in a specific judgement call: an expected outcome, a rule you'd hold to regardless of outcome, or a question about what the choice says about the kind of practitioner you're being. Naming it makes the decision reviewable — by a supervisor, a colleague, or your own later self — in a way that "I followed the process" never quite is on its own, because the process was never trying to answer that specific question.
Related Topics
- Research Ethics — the committee-and-consent procedure this page argues is necessary but not sufficient.
- Professional Ethics — the compliance-versus-standards distinction, a related but different split within the procedural side.
- Studying Ethically: Beyond the Rulebook — the three frameworks this page treats as tools for the space inside a boundary, not an alternative to having one.
- AI on Health and Genomic Data — the worked legal-procedure example this page draws on throughout.
- AI Governance — the same committee-versus-judgement structure at the scale of an entire regulatory system rather than one decision.
Resources
- Mill, J. S. (1863). Utilitarianism.
- Kant, I. (1785). Groundwork of the Metaphysics of Morals.
- Aristotle. Nicomachean Ethics.
- The Belmont Report (1979) — see Research Ethics for its principles applied to the committee process directly.