Blog

What Are the Steps of a Systematic Review?

steps of systematic review

A systematic review follows eight stages: define the question, write and register a protocol, build and run the search, screen titles and abstracts, screen full texts, extract data, assess risk of bias, then synthesise and report.

Published guides put the count anywhere between 5 and 24, which is why the question "how many steps" returns contradictory answers. The disagreement is about where to draw the lines, not about what the work is. This guide uses eight stages as a practical framework, reconciles the common variants, and covers the parts most guides leave out: how long each step actually takes, how many people you need, what to do if you have no team, and where automation is safe.

Key Takeaways

steps of systematic review
  • Eight stages, running from question definition to synthesis, with protocol registration sitting at step 2 rather than as an afterthought
  • Review duration varies by scope, databases, retrieval and synthesis. Most full reviews fall in the 12 to 18 month range, but shorter or longer timelines are common depending on the question
  • Cochrane will not publish single author reviews, and team size depends on the review's scope, though most guidance recommends at least two independent reviewers plus a third to resolve conflicts
  • PROSPERO registration belongs before screening starts, not after the search
  • PRISMA governs how you report the review, not how you conduct it. The Cochrane Handbook or JBI Manual governs the conduct

Why Guides Disagree on the Number of Steps

Before the steps themselves, the variant question, because it is the first thing that confuses people.

Count Where it comes from What it does differently
5 steps Khan et al., J R Soc Med 2003 Framing the question, identifying work, assessing quality, summarising evidence, interpreting findings. Merges screening and extraction
6 stages Some library guides Treats protocol and question as one stage
7 steps Several tool vendors and content sites Usually merges risk of bias into extraction
8 steps Duke, LSU, UNC, Pitt, Cochrane Handbook Separates protocol, screening stages, extraction and appraisal. Used here
9 steps Ohio State, Paperpile Splits write up from synthesis
10 steps Cureus, "Ten steps to conduct a systematic review" Adds a dedicated dissemination step
24 steps Muka et al. 2020, via UTHSC A granular checklist rather than a process model

The work is identical in every version. The only thing that changes is whether protocol writing, dual screening, appraisal and write up are counted as their own steps or folded into neighbours. Eight is used here because it separates the four stages where reviews most often go wrong, and because it matches the highest authority cluster of sources.

Steps of a Systematic Review

steps of systematic review

Step 1: Define an Answerable Question

A systematic review answers one specific question. If the question can be restated as "what is known about X", it is not yet a review question.

Use a structured framework to force specificity. PICO for intervention questions: Population, Intervention, Comparator, Outcome. PICOS adds Study design. PCC for scoping reviews: Population, Concept, Context. SPIDER for qualitative evidence.

The question determines everything downstream. Your eligibility criteria are the question restated as filters. Your search string is the question restated in database syntax. Your extraction fields are the question restated as columns. A vague question produces a search that returns tens of thousands of records and a screening process that never converges.

At this step, also confirm the review type is right. If your search cannot be predefined and reproduced, you are writing something else. Scoping reviews map a field rather than answering a narrow question, and narrative reviews build an argument from expert selection. Both are legitimate. Neither is a systematic review.

Typical duration: 2 to 4 weeks, including scoping searches to check that enough literature exists and that the review has not already been done.

Step 2: Write and Register a Protocol

The protocol states what you will do before you do it. Its purpose is to stop the criteria drifting to fit the results.

It contains the question, eligibility criteria, information sources, the draft search strategy, the screening process including how many reviewers and how conflicts are resolved, the extraction fields, the risk of bias tool, and the planned synthesis.

Register it before screening starts. This is the single most common timing error. Registering after you have seen the search results defeats the purpose, and PROSPERO will decline registrations for reviews where data extraction has already begun.

Registry For
PROSPERO Health and social care reviews with a health related outcome
OSF Registries Any discipline, including reviews PROSPERO declines
INPLASY Broad scope, faster turnaround
Campbell Collaboration Social and behavioural interventions
CEE Environmental evidence

If your review is not health related, PROSPERO will usually decline it, which surprises people at the worst moment. OSF is the general purpose alternative.

Report the protocol using PRISMA-P, the 17 item protocol extension.

Typical duration: 3 to 6 weeks, including registry turnaround.

The search is the part most often done badly and most often under reported.

Build the string from your question concepts, combining controlled vocabulary such as MeSH with free text synonyms, then translate it for each database's syntax. A MEDLINE strategy does not transfer to Embase unchanged.

Database selection should be justified according to the question and discipline rather than by a fixed number. Health reviews commonly use MEDLINE, Embase and CENTRAL as a starting set, with discipline specific sources added as the question requires: PsycINFO, CINAHL, ERIC, Scopus, Web of Science, IEEE Xplore. Trial registers such as ClinicalTrials.gov are expected for intervention reviews.

Involve a librarian if one is available. Reviews with librarian designed searches are measurably more reproducible, and most academic institutions provide this at no cost.

Record, as you go: the full strategy for each source, the date each was last searched, and the number of records from each. PRISMA item 7 asks for the full strategy for every source, not one representative database.

Health reviews commonly return 2,000 to 8,000 records before deduplication, but valid reviews can have fewer than 200 or many thousands depending on the question and the breadth of the search. The yield is a signal worth checking against the scope of your question, not a pass/fail threshold.

Typical duration: 3 to 5 weeks.

Step 4: Screen Titles and Abstracts

Screening is where the calendar goes. Two reviewers screen every record independently against the eligibility criteria, and a third resolves conflicts.

Run a pilot screen first: both reviewers screen the same 5 to 10 percent sample, then compare. Agreement below about 80 percent means the criteria are ambiguous, not that a reviewer is wrong. Fix the criteria before screening the rest, and record the amendment against your registration.

Screen liberally at this stage. The cost of wrongly including a record is one full text read. The cost of wrongly excluding one is a missing study nobody will ever find.

Rates vary by field and abstract length, but 30 to 60 records per hour per reviewer is a workable planning figure. At 4,000 records and two independent reviewers, that is roughly 130 to 270 person hours.

Record three separate numbers as you go: duplicates removed, records excluded by any automation tool, and records removed for other reasons. PRISMA 2020 wants these split, and reconstructing them later is usually impossible. The counts feed directly into the PRISMA flow diagram [1].

Typical duration: 6 to 12 weeks.

Step 5: Screen Full Texts

Obtain the full text of everything that survives title and abstract screening, then assess each against the criteria in full.

Two things must be recorded here that are easy to skip. Reports you could not obtain, which is a box in the flow diagram, and the reason each excluded report was excluded, using the categories from your protocol.

PRISMA 2020 requires reporting the reasons for excluding potentially relevant reports, and it also requires you to cite the studies that appeared eligible but were excluded. That means keeping the near miss list as a citation list, not just a count. Reconstructing it means re reading the excluded set [1].

Full text screening is slower than it looks. 2 to 6 reports per hour per reviewer is realistic once you are reading methods sections rather than abstracts.

Typical duration: 4 to 8 weeks.

Step 6: Extract Data

Extraction pulls the same fields from every included study into one structured table.

Standard fields: study identifiers, design, setting and country, participant characteristics, sample sizes, intervention and comparator detail, outcomes with definitions and time points, effect estimates with measures of precision, and funding and conflicts.

Pilot the form on 3 to 5 studies before extracting the rest. Fields that seemed obvious turn out to be ambiguous the moment two people fill them differently.

Extract in duplicate where feasible. Where the team is too small, one extractor with a second person verifying is the common compromise, and it must be declared in the methods.

Typical duration: 4 to 8 weeks.

Step 7: Assess Risk of Bias

Risk of bias asks whether each study's design, conduct or analysis could have distorted its result. It is separate from extraction because it is a judgement rather than a transcription.

Study type Tool
Randomised trials RoB 2
Non randomised intervention studies ROBINS-I
Diagnostic accuracy studies QUADAS-2
Observational studies Newcastle Ottawa Scale

Two assessors, independently, with disagreements resolved by discussion or a third party. The output is a per domain judgement per study, usually presented as a traffic light figure [4].

Assess bias from missing results separately. That is a review level judgement about what never got published, and it connects to publication bias rather than to any individual study.

Typical duration: 3 to 5 weeks.

Step 8: Synthesise and Report

Synthesis is either statistical or structured narrative, and the choice is driven by whether the studies are similar enough to pool.

If they are, a meta analysis produces a summary effect size with a confidence interval and a heterogeneity estimate. If they are not, a structured narrative synthesis groups studies by an explicit logic and explains the pattern without inventing a pooled number.

Then rate certainty in the body of evidence, commonly with GRADE, and write up.

Reporting is where PRISMA applies. The PRISMA 2020 checklist is a 27 item main checklist that governs what the manuscript must state, with expanded explanation and elaboration materials supporting each item. The flow diagram reports the selection counts. Neither told you how to do any of the seven steps above [1].

Writing alone can take roughly 120 hours by one published estimate, though this is a rough figure that varies widely with the review's scope and complexity. It is most of a month of full time work and is routinely underestimated in project plans.

Typical duration: 8 to 14 weeks.

paperguide systematic review

How Long Does a Systematic Review Take?

Review duration varies by scope, the number of databases searched, retrieval time and the complexity of synthesis. Most guides say "6 to 24 months" and stop. Here is the breakdown.

Step Typical duration Notes
1. Define the question 2 to 4 weeks Includes scoping searches
2. Protocol and registration 3 to 6 weeks Registry turnaround varies
3. Search 3 to 5 weeks Faster with librarian support
4. Title and abstract screening 6 to 12 weeks The largest single variable
5. Full text screening 4 to 8 weeks Slowed by retrieval delays
6. Data extraction 4 to 8 weeks Scales with study count and field count
7. Risk of bias 3 to 5 weeks Often runs alongside extraction
8. Synthesis and write up 8 to 14 weeks Writing alone is a substantial share
Total Commonly 12 to 18 months Duration varies by scope, databases, retrieval and synthesis

Two things stretch this. Retrieval delays at step 5, where interlibrary loans take weeks. And team availability, because most reviews are done alongside other work rather than full time.

How Many People Do You Need?

Role Involved at steps Essential?
Lead reviewer All Yes
Second reviewer 4, 5, 6, 7 Yes. Independent screening and extraction both require two
Third reviewer / arbiter 4, 5, 6, 7 Yes, for conflict resolution
Information specialist or librarian 3 Strongly recommended
Statistician 8 Where meta analysis is planned
Content expert 1, 8 For question framing and interpretation

Cochrane will not publish single author reviews. There is no universal rule that every systematic review must have exactly three people, but most guidance recommends at least two independent reviewers plus a third to resolve conflicts, with additional expertise for the search and statistics as the review requires [2].

If you have no team

This is the most common real situation for a PhD student and the one almost no guide addresses.

The honest options, in order of preference. Recruit a second screener from your department, offering co authorship, even for screening only. Use your supervisor as the arbiter, which most supervisors will agree to because it is bounded work. Dual screen a sample: screen everything yourself, have a second person independently screen 10 to 20 percent, report the agreement rate, and single screen the rest.

Whichever you choose, declare it as a limitation. A single screened review clearly labelled is publishable in many journals. A single screened review described as dual screened is a misrepresentation.

Where PRISMA Fits, and Where It Does Not

This is the most confused distinction in the topic and it is worth stating plainly.

Governs Applies at Answers
Cochrane Handbook / JBI Manual How to conduct the review Steps 1 to 8 How do I actually do this?
PRISMA 2020 How to report the review Throughout, governs the write up at step 8 What must I disclose?
AMSTAR 2 How to appraise a finished review Afterwards, by others Was this review well conducted?

PRISMA never tells you how many reviewers should screen, how to build a search string, or which risk of bias tool to use. It tells you that you must state what you did. You conduct a review according to a methodology and report it according to PRISMA, and the verb carries the whole distinction. PRISMA is primarily a reporting framework, but it should be considered throughout the review, because the information required for reporting needs to be captured as each step happens rather than assembled at the end. The full explanation is in what PRISMA is in research [5].

The practical consequence: keep the reporting requirements visible from step 2 rather than discovering them at step 8. Almost every item PRISMA asks for is easier to record when it happens. The PRISMA reporting steps cover each checklist item in detail.

What Can Safely Be Automated, and What Cannot

Software helps at some steps and cannot help at others. The distinction matters more than the tool choice.

Task Step Safe to assist?
Deduplication 4 Yes. Mechanical matching, verifiable
Search translation between databases 3 Partly. Always human checked
Title and abstract triage 4 Yes, as a first pass with human confirmation of every decision
Full text screening against criteria 5 Yes, with per criterion evidence a human verifies
Extraction pre fill 6 Yes, with source citations a human checks
Final inclusion decisions 4, 5 No. Human judgement, always
Risk of bias judgements 7 No. Requires methodological reasoning
Interpretation and certainty rating 8 No. The core intellectual contribution
Flow diagram generation 8 Yes, if generated from the actual screening record

The rule is that assistance is appropriate where the work is retrieval, matching or transcription, and inappropriate where it is judgement. Anything that produces a decision a reviewer will be held accountable for needs a human who actually made it.

Paperguide's Systematic Review is built around that division: the protocol defines the criteria, screening produces per criterion evidence and exclusion reasons that a human confirms before the stage advances, and the PRISMA flow diagram is generated from those confirmed decisions rather than assembled afterwards.

Common Mistakes

systematic review common mistakes

Mistake 1: Registering the Protocol After the Search

Registration exists to fix your criteria before you see the results. Registering afterwards is a formality with no methodological value, and PROSPERO may decline it.

Fix: register at step 2, before screening begins. Amend and record the amendment if the criteria change.

Mistake 2: Screening Alone Without Declaring It

Single screening is a real limitation with a real effect on sensitivity.

Fix: dual screen where possible, and where impossible, dual screen a sample, report the agreement rate, and declare it.

Mistake 3: A Question Too Broad to Converge

A search returning 30,000 records usually means the question was never narrowed.

Fix: run a scoping search at step 1. If the yield is unmanageable, narrow the population, the intervention or the outcome before writing the protocol.

Mistake 4: Reconstructing Counts at Write Up

The numbers in the flow diagram, the Results text and the checklist all describe the same process and must agree.

Fix: record counts as each stage completes, not at the end.

Mistake 5: Treating PRISMA as the Method

PRISMA governs reporting. It will not tell you how to screen or appraise.

Fix: choose the Cochrane Handbook or the JBI Manual as your methodology at step 1, and use PRISMA for the write up.

Mistake 6: Skipping the Pilot Screen

Criteria that read clearly to their author are routinely ambiguous to a second reader.

Fix: pilot on 5 to 10 percent, compare, and revise the criteria before screening the rest.

Mistake 7: Underestimating Write Up

Writing can take roughly 120 hours by one published estimate, though this varies widely. That is close to a month of full time work that most project plans do not contain.

Fix: budget the last quarter of the timeline for synthesis and writing.

Systematic Review Quality Checklist

  • [ ] The question is answerable and framed with a structure such as PICO, PICOS or PCC
  • [ ] A protocol was written and registered before screening began, with the registry named
  • [ ] Amendments to the protocol are recorded with reasons
  • [ ] Database selection is justified by the question and discipline, with the full strategy and last searched date recorded for each source
  • [ ] Two reviewers screened independently at both stages, with a stated conflict resolution rule
  • [ ] A pilot screen was run and criteria revised before full screening
  • [ ] Pre screening removals are split three ways: duplicates, automation exclusions, other
  • [ ] Full text exclusions carry reasons, and near miss exclusions are retained as citations
  • [ ] Risk of bias was assessed with a design appropriate tool by two independent assessors
  • [ ] Certainty of evidence was rated, commonly with GRADE
  • [ ] Counts agree across the flow diagram, the Results text and the checklist
  • [ ] Single screening or single extraction, if used, is declared as a limitation

Try It Yourself (2 Minutes)

  1. Open a recent systematic review and check three things: whether a protocol registration number appears, whether two reviewers screened independently, and whether the search dates are given per database. Reviews missing all three are common and it tells you where the corners were cut.
  2. Pick one of those reviews and check whether the exclusion reasons in the flow diagram sum to the total excluded. Then compare the flow diagram counts against the Results text. Where they disagree, you have found the reconciliation error that proper record keeping prevents.
  3. If you are planning your own review, set up the protocol and screening criteria in Paperguide's Systematic Review software so your counts are recorded from the first decision rather than reconstructed at the end. When you reach the reporting stage, build the flow diagram directly in Paperguide's free PRISMA flow diagram generator.

This takes about two minutes and it converts an abstract process into a check you can run on any review you read.

Conclusion

Eight steps, commonly twelve to eighteen months, and at least two independent reviewers. The count varies between guides because the boundaries are arbitrary, but the work does not: define, register, search, screen twice, extract, appraise, synthesise.

The steps that decide whether a review succeeds are the early ones nobody enjoys. A question narrow enough to converge, a protocol registered before you see the results, and a search designed with someone who builds searches for a living. Reviews that fail rarely fail at synthesis. They fail because the question was too broad in month one, and every subsequent step inherited the problem. Running the review inside a workspace that records each decision as it happens, such as Paperguide's Systematic Review, means the counts and reasons required for reporting exist by the time you reach step 8.

Frequently Asked Questions

What are the 7 steps of a systematic review?

Seven step versions usually merge risk of bias assessment into data extraction, or merge protocol writing into question definition. The underlying work is identical to the eight step version used here. The most common seven step framing is: define the question, search, screen, extract, appraise, synthesise, report. Counts across published guides range from 5 to 24, and no numbering is official. The widely cited five step framing covers the same ground at coarser resolution [3].

How long does a systematic review take?

Duration varies by scope, the number of databases searched, retrieval time and the complexity of synthesis. Most full reviews fall in the 12 to 18 month range, and Cochrane's own estimate is around one year. Title and abstract screening is the largest single variable at 6 to 12 weeks, and the writing phase is routinely underestimated in project plans.

Can one person do a systematic review?

Not to full methodological standard. Independent dual screening and dual extraction both require a second person, and Cochrane will not publish single author reviews. There is no universal rule requiring exactly three people, but the workable compromises for a smaller team are recruiting a second screener for co authorship, using a supervisor as the arbiter, or dual screening a 10 to 20 percent sample and reporting the agreement rate. Whichever you use must be declared as a limitation.

What is the first step in a systematic review?

Defining an answerable question, using a structured framework such as PICO. Everything downstream derives from it: the eligibility criteria are the question restated as filters, the search string is the question in database syntax, and the extraction fields are the question as columns. A question that cannot be narrowed produces a review that never converges.

Do I have to register my systematic review on PROSPERO?

Not universally, but registration before screening starts is expected practice and many journals ask for the number. PROSPERO covers health and social care reviews with a health related outcome and will usually decline reviews outside that scope. OSF Registries, INPLASY, Campbell and CEE cover other disciplines.

Do two reviewers have to screen every abstract?

Independent dual screening is the methodological standard and what Cochrane and most journals expect. Where a second screener is unavailable, the accepted compromise is to dual screen a 10 to 20 percent sample, report the inter rater agreement, single screen the remainder, and declare the limitation explicitly.

What is the difference between PRISMA and the Cochrane Handbook?

The Cochrane Handbook governs how you conduct a review, covering methodology across every step. PRISMA governs how you report it, specifying what the finished manuscript must disclose. They are complements rather than alternatives: you conduct a review according to a methodology and report it according to PRISMA. PRISMA is primarily a reporting framework, but it should be considered throughout the review because the information required for reporting needs to be captured as each step happens [5].

How many studies do you need for a systematic review?

There is no minimum. A systematic review with two included studies is valid if the search was comprehensive and the question was answerable, and reporting that the evidence base is thin is itself a useful finding. Meta analysis is a different question: pooling two studies is possible but rarely informative, and the decision depends on heterogeneity rather than count.

References

  1. Page MJ, McKenzie JE, Bossuyt PM, et al. "The PRISMA 2020 statement: an updated guideline for reporting systematic reviews." BMJ, 372:n71, 2021.
  2. Higgins JPT, Thomas J, Chandler J, et al., editors. Cochrane Handbook for Systematic Reviews of Interventions, version 6.5. Cochrane, 2024.
  3. Khan KS, Kunz R, Kleijnen J, Antes G. "Five steps to conducting a systematic review." Journal of the Royal Society of Medicine, 96(3):118-121, 2003.
  4. Sterne JAC, Savović J, Page MJ, et al. "RoB 2: a revised tool for assessing risk of bias in randomised trials." BMJ, 366:l4898, 2019.
  5. Sarkis-Onofre R, Catalá-López F, Aromataris E, Lockwood C. "How to properly use the PRISMA Statement." Systematic Reviews, 10:117, 2021.

Read more