Edition #024

|

10 Sep 2026

Introduction

In my last newsletter, I asked a simple question: do journals actually know who their authors are?

My conclusion was that, in most cases, they do not.

A person can create an account on a manuscript submission system, enter a name, provide an email address, claim an institutional affiliation and submit a paper. The journal might subsequently carry out checks for plagiarism, images, references, statistical anomalies and possible paper-mill activity. Yet one of the most basic questions may remain unanswered.

Is the person who submitted the paper actually who they say they are?

If we accept that this represents a weakness in scholarly publishing, the obvious follow-up question is what we should do about it.

Should authors have to prove who they are?

The obvious answer might be “yes”

At first sight, the answer seems straightforward.

We verify identity in many situations that carry significantly less professional consequence than publishing a scientific paper. Universities verify the identities of students sitting examinations. Banks carry out “know your customer” checks. Airlines want to know who is travelling. Employers check identities before appointing people.

Yet scholarly journals can permanently place a piece of research in the scientific record without being certain that the people named as authors are real, that they are the people submitting the manuscript, or even that they know their names appear on it.

The scholarly publishing industry has recognised that this is becoming increasingly difficult to ignore. STM has established a Researcher Identity Task & Finish Group[1] specifically to examine how publishers might verify authors, reviewers and editors. Its Researcher Identity Verification Framework proposes what it describes as proportionate and inclusive verification, using existing infrastructure wherever possible rather than imposing one universal identity check on everybody.

That word proportionate is important.

Requiring every researcher in the world to upload a passport before submitting a manuscript would set a high barrier. It would also likely create an entirely new collection of problems.

Perhaps we should start with the corresponding author

One possibility would be to verify only the corresponding author.

There is some logic to this. The corresponding author is normally the journal’s main point of contact and is usually expected to take responsibility for communication with the other authors. Requiring that person to establish their identity would therefore introduce at least one verified individual for every submission, and its subsequent publication.

It would also be considerably easier to implement than verifying every author.

But it would not solve the problem completely. If a paper has eight authors, verifying one of them tells us very little about the other seven. Their names could have been added without permission. Some could be fictitious. Others could have purchased their authorship position.

If the purpose is simply to establish accountability for the submission, verifying the corresponding author might be sufficient. If the aim is to establish that everybody listed on a paper is genuinely an author, it does not go far enough.

There is also an argument that verification should not necessarily happen at the same level for every paper. A manuscript containing unusual authorship patterns, suspicious affiliations or other integrity signals might justify additional checks. A submission from established researchers whose identities and publication histories are already strongly connected through trusted systems might require much less intervention.

That would move us towards risk-based verification rather than a single rule for everybody.

What about institutional email addresses?

Perhaps the simplest solution is already available. Require authors to submit using their university email address. That would help, but it is nowhere near sufficient.

Not every legitimate researcher has an institutional email account. Independent researchers, retired academics, consultants and researchers between appointments may have no current university affiliation. Some institutions do not provide permanent email accounts, while others close them very quickly after somebody leaves.

An institutional email address also verifies access to an email account. It does not necessarily verify everything claimed about the person using it.

It is another useful signal, but it is not proof of identity.

Surely ORCID solves this?

ORCID looks like an obvious solution because it already provides persistent identifiers for researchers and is deeply embedded in scholarly publishing.

But an important distinction needs to be made.

ORCID itself states explicitly that an ORCID ID does not assure somebody’s identity[2]. ORCID does not collect the private information normally required to perform formal identity verification. Anyone can create an ORCID record.

That does not make ORCID unhelpful. Far from it.

The important development is the idea of an authenticated ORCID iD, combined with trusted information attached to the record. Publishers can require authors to sign into ORCID rather than simply typing an ORCID number into a form. ORCID records can then contain connections added or validated by publishers, universities and funders.

Imagine an ORCID record showing a long history of publications deposited by publishers, an institutional affiliation asserted by the institution, funded projects added by recognised funders and other established scholarly activity.

That is different to an ORCID record created yesterday containing only information entered by the account holder.

The challenge therefore becomes less about possessing an ORCID identifier and more about the strength of the trusted connections behind it.

Universities could play a much bigger role

Another possibility is institutional authentication.

Most universities already know who their staff and students are. They have conducted employment checks, issued credentials and provided access to institutional systems. If a researcher could authenticate themselves to a journal through their university’s identity system, the publisher would not need to repeat all those checks.

In principle, this is attractive. Rather than every publisher creating its own identity-verification infrastructure, journals could rely on institutions that have already done much of the work.

The difficulty, however, is global coverage.

Large, well-resourced universities may have sophisticated digital identity infrastructure. Smaller institutions may not. Researchers outside universities would again need another route. Any system that effectively says “you can publish easily if you work for a major university, but everybody else faces additional hurdles” would be deeply problematic.

This is why any workable system would need several ways to establish confidence rather than one mandatory route.

What about passports?

At the stronger end of the spectrum is conventional identity verification: passports, national identity cards, driving licences or third-party verification services similar to those used by banks and financial technology companies.

That would undoubtedly make impersonation more difficult.

It would also create serious questions. Do we really want publishers holding copies of researchers’ passports?

Even if verification were outsourced so that the publisher never saw the underlying document, somebody would still be processing highly sensitive personal information. Publishers would need to consider cybersecurity, privacy laws, data retention, breaches and differing national requirements.

There are also practical questions about access. Not everybody has a passport. National identification systems vary considerably. Names may appear differently across documents. Transliteration creates additional complications. Researchers in some countries may have greater difficulty accessing recognised identification than researchers elsewhere.

A system designed to protect research integrity should not inadvertently make scholarly publishing even more difficult or unequal than it already is.

And what about people who cannot safely identify themselves publicly?

There is another complication.

We tend to assume that scholars should publish using their real names. Usually they do. But there may be legitimate circumstances in which somebody needs to protect their identity, particularly when researching politically sensitive subjects, authoritarian regimes, conflict, corruption or other areas in which publication might place them at personal risk.

Identity verification does not necessarily mean that identity has to be publicly disclosed. A journal could theoretically know who an author is while allowing publication under a pseudonym in exceptional circumstances.

But that illustrates why this issue is more complicated than simply adding a “verify identity” button to a submission system.

We would need rules for exceptions, confidentiality and appeals. We would need to decide who within the publishing organisation could access verified identity information and under what circumstances it could be disclosed.

Those are governance questions as much as technological ones.

We should not build another barrier to publication

There is a danger here that concerns me. Research integrity initiatives are generally created for good reasons. But every additional requirement also imposes a cost on legitimate researchers.

For somebody employed by a major research university, using an institutional login, with a well-established ORCID record and dozens of previous publications, identity verification may be almost invisible.

For an early-career researcher at a small institution in a lower-income country, it could become another obstacle between completing research and getting it published.

STM’s own work appears conscious of precisely this problem. Its proposed framework emphasises both proportionality and alternative verification routes so that improving security does not unnecessarily exclude genuine researchers.

That seems the right principle.

The objective should not be to create the strongest identity-verification system technically possible. It should be to create the least burdensome system that provides sufficient confidence.

What would identity verification actually stop?

This is perhaps the most important question. Identity verification could make some forms of abuse more difficult.

It could reduce simple impersonation. It could make it harder to invent entirely fictitious researchers. It could make fraudulent reviewer accounts more difficult to create. It could establish clearer links between submissions and identifiable individuals. It might also increase the consequences for people participating in paper-mill activity because anonymity becomes harder to maintain.

These are not trivial benefits.

The publishing industry is already investing substantially in systems designed to detect paper mills and other forms of manipulation. The STM Integrity Hub, for example, brings together publishers and screening technologies to identify suspicious patterns across submissions. More than 35 publishers were reported as using the Hub by late 2025, screening more than 125,000 manuscripts each month and intercepting around 1,000 suspected paper-mill submissions monthly.

Identity could become another signal within that wider integrity infrastructure.

But we should be equally clear about what identity verification would not achieve.

A verified author can still cheat

Suppose I prove beyond any reasonable doubt that I am Graham Kendall.

What does that tell a journal about the paper I have submitted?

  • It does not prove that I collected the data.
  • It does not prove that the data are genuine.
  • It does not prove that the other authors made the claimed contributions.
  • It does not prove that I did not buy the manuscript from a paper mill.
  • It does not prove that somebody did not pay me to add their name.
  • It does not prove that the images have not been manipulated.
  • … and it certainly does not prove that the research is correct.

A completely genuine, thoroughly verified researcher can still commit research misconduct.

Identity verification therefore cannot be a substitute for peer review, editorial scrutiny, image checking, plagiarism detection, authorship declarations or wider research-integrity processes.

But it does address a much narrower problem. It helps establish that the person standing behind the submission is who they claim to be. That may sound modest, but it matters.

Perhaps verification should become part of the infrastructure

I am not convinced that authors should be required to upload passports to journals. I am also not convinced that every author needs to undergo the same level of verification for every submission.

But I am increasingly persuaded that scholarly publishing needs to move beyond a system in which an email address and a typed name are treated as sufficient evidence of identity.

A sensible model might combine several signals: authenticated ORCID records, trusted institutional affiliations, institutional sign-on, established publication histories and, where necessary, stronger third-party verification. Researchers unable to use one route would need alternatives.

Crucially, the system should verify identity once and allow that trust to travel with the researcher rather than forcing somebody to prove who they are separately to Elsevier, Springer Nature, Wiley, Taylor & Francis and every other publisher they encounter.

The technology to do much of this already exists. The more difficult questions concern proportionality, inclusion, privacy and governance.

Last week I asked whether journals actually know who their authors are. The answer, in many cases, is no.

The question now is whether we are happy with that, and whether we should do something about it.


I publish two free newsletters each week

Governance & Research in HE
A weekly brief for higher education leaders and researchers examining governance, leadership and research in practice.
https://buff.ly/GhsZqVl

Publishing with Integrity
Examining scholarly publishing through an ethical lens, challenging assumptions and supporting academic career development.
https://buff.ly/WiG1yFb

If you subscribe, you will be alerted whenever I publish a new edition.


About the Author

Graham Kendall is Vice-Chancellor of GlobalNxt University in Malaysia and an Emeritus Professor at the University of Nottingham. He has published more than 300 peer-reviewed papers and has held senior university leadership positions in Malaysia and the United Kingdom. He writes regularly about research integrity, academic publishing, artificial intelligence and higher education.


[1] https://stm-assoc.org/what-we-do/strategic-areas/standards-technology/researcher-id-tfg/, accessed 31 August 2026

[2] https://support.orcid.org/hc/en-us/articles/360006972413-Does-an-ORCID-iD-assure-my-identity, accessed 31 August 2026

Originally published on LinkedIn

This edition was first published as part of my LinkedIn newsletter. If you use LinkedIn, I recommend reading it there, where you can also join the discussion. This version is provided particularly for readers who do not have a LinkedIn account.

Would you like to know when the next edition is published?

Receive an email whenever I publish a new edition of my newsletter.