What Counts as a Protocol Deviation, and How to Report It

Almost every review departs from its protocol somewhere. Reviewers do not object to deviation; they object to deviation that arrives undeclared.

5 min

Almost every completed review departs from its registered protocol somewhere. Searches return a literature that looks different from the one you imagined, an outcome turns out to be reported in three incompatible ways, and a planned subgroup analysis has four studies in it instead of fifteen.

None of that is misconduct. What draws a reviewer's objection is a departure that arrives undeclared, because an undeclared change is indistinguishable from a change made after seeing the results.

The distinction that matters

Not every difference between protocol and paper is a deviation worth reporting. The useful test is whether the change could plausibly have been influenced by knowledge of the findings.

Changes that could be influenced by results need declaring. Adding, dropping or redefining an outcome. Changing the primary outcome. Altering eligibility criteria. Switching effect measure. Changing the meta-analysis model. Adding a subgroup or sensitivity analysis that was not prespecified. Dropping one that was.

Changes that could not be influenced by results generally need only a brief mention. Correcting a database name, updating a search to a later date, fixing an error in a search string, adding a language the team gained capacity to screen.

The second group is housekeeping. The first group is where credibility is won or lost, and the empirical case for taking it seriously is not new: Kirkham and colleagues (2010) documented outcome reporting bias operating inside the systematic review process itself, not just in the trials being reviewed.

Where to put it

Three places, and each has a different job.

The registry record. Both PROSPERO and INPLASY allow the record to be updated/amended. Update it when the change is made, not at write-up. A registry that shows an amendment dated before the analysis was run is evidence. One updated the week of submission is not.

The methods section. A short paragraph headed "Differences between the protocol and the review" or similar. Cochrane requires this section by convention and non-Cochrane journals increasingly expect it.

The PRISMA 2020 flow and checklist. Item 24c asks directly about amendments to registered information.

What a defensible entry looks like

The pattern that works has three parts: what changed, why, and when relative to seeing the data.

Weak: "The primary outcome was changed to pain intensity at 12 weeks."

Defensible: "The protocol specified pain intensity at 6 months as the primary outcome. At full-text screening we found that only 4 of 19 eligible trials reported outcomes beyond 12 weeks, while 17 reported 12-week data. The primary outcome was therefore changed to pain intensity at 12 weeks. The decision was made after eligibility assessment but before any effect estimates were extracted, and the registry record was amended on 14 March 2026. Six-month data are reported as a secondary outcome."

The second version is longer by four sentences and it closes the question completely. The reader can see the change was forced by the literature rather than chosen from among results, and the amendment date is checkable.

The deviation people forget to declare

Post hoc subgroup and sensitivity analyses are the most common undeclared change, and often the most consequential, because they are the analyses most likely to have been prompted by an unexpected pooled result.

There is nothing wrong with running one. There is something wrong with presenting it in the same table, with the same visual weight, as the analyses you committed to in advance. Label post hoc analyses as post hoc, keep them out of the abstract, and treat their findings as hypothesis-generating in the discussion.

What to write when a reviewer objects

The objection usually reads: "The registered protocol specifies X but the manuscript reports Y. Please explain."

A response that works states the change plainly, gives the reason in terms of the literature rather than the results, gives the date, points to the amended registry record, and where possible reports the original plan as a sensitivity analysis. That last step is the strongest available answer, because it lets the reviewer see for themselves that the conclusion does not depend on the change.

If the original analysis is not possible, say why. "The protocol-specified analysis could not be performed because only two studies reported the outcome" is a complete answer.

References

Kirkham, J. J., Altman, D. G., & Williamson, P. R. (2010). Bias due to changes in specified outcomes during the systematic review process. PLoS ONE, 5(3), e9810. https://doi.org/10.1371/journal.pone.0009810

Page, M. J., McKenzie, J. E., Bossuyt, P. M., Boutron, I., Hoffmann, T. C., Mulrow, C. D., Shamseer, L., Tetzlaff, J. M., Akl, E. A., Brennan, S. E., Chou, R., Glanville, J., Grimshaw, J. M., Hróbjartsson, A., Lalu, M. M., Li, T., Loder, E. W., Mayo-Wilson, E., McDonald, S., … Moher, D. (2021). The PRISMA 2020 statement: An updated guideline for reporting systematic reviews. BMJ, 372, n71. https://doi.org/10.1136/bmj.n71

Shamseer, L., Moher, D., Clarke, M., Ghersi, D., Liberati, A., Petticrew, M., Shekelle, P., & Stewart, L. A. (2015). Preferred reporting items for systematic review and meta-analysis protocols (PRISMA-P) 2015: Elaboration and explanation. BMJ, 350, g7647. https://doi.org/10.1136/bmj.g7647

Silagy, C. A., Middleton, P., & Hopewell, S. (2002). Publishing protocols of systematic reviews: Comparing what was done to what was planned. JAMA, 287(21), 2831–2834. https://doi.org/10.1001/jama.287.21.2831

Common questions

Does deviating from the protocol weaken the review?
Not by itself. Reviews of complex literatures almost always require some adaptation, and reviewers know this. What weakens a review is a departure the reader discovers by comparing the registry record to the paper, rather than one the authors declared. Declared deviations with dated reasons are a sign of a well-run process.
Should I update the registry record or explain in the paper?
Both. The registry amendment establishes when the decision was made; the methods paragraph explains it to the reader, who will not go looking at the registry. Doing only one leaves an obvious gap.
We changed eligibility criteria after piloting the screening form. Is that a deviation?
Yes, and it is a routine and defensible one. Pilot screening exists to surface ambiguity in the criteria, so refinements at that stage are expected. Report it as a deviation, note that it happened during piloting on a sample of records, and state that no effect estimates had been extracted.