Back to Intel

A Spreadsheet Is A Control Until Someone Asks

The conversation that follows a control finding is almost always the same. Someone from finance explains, correctly, that the reconciliation is performed every month and reviewed by a second person who genuinely reads it. The auditor agrees that this is probably true and says it cannot be tested. Both people leave the meeting believing the other one has missed the point.

Neither has. They are discussing two different things that share one name. One of them is the performance of a control. The other is the evidence that the performance happened, in the right order, by the right person, before the period closed. A control can be excellent at the first and produce nothing at all of the second, and only the second is what gets sampled.

This is why remediation programs stall. Companies respond to an evidence problem with a process improvement, which makes the work better and the file no thicker.

An auditor asking a finance manager for evidence
Illustration: an auditor asking a finance manager for evidence.

Performance And Evidence Are Different Things

The distinction is written into the standards. The standard on audit evidence (PCAOB, AS 1105) treats inspection of records and documents as a primary procedure, and treats inquiry — asking the person whether they did it — as insufficient on its own. The standard on audit documentation (PCAOB, AS 1215) applies the same logic to the auditor's own work: the file must let an experienced person with no prior connection to the engagement understand what was done, by whom, and when.

The practical consequence is blunt. A control that leaves no durable trace is not treated as a weak control. It is treated as an absent one, because there is no procedure available that would distinguish the two.

A spreadsheet sits exactly on that line. It is superb at the calculation and silent about everything else. It holds the numbers and none of the facts that make the numbers testable.

What a tester asksWhat the file answers
Who performed this?The last person to save it
When, relative to the close?The last modification time, which may be later
Which version of the input was used?Whatever is pasted in the tab
Was the reviewer a different person?Nothing
What was rejected, and why?Nothing — rejections are corrected in place
Did the steps run in the required order?Nothing

The last two rows are where most findings actually originate. An exception that was investigated and resolved correctly leaves the same file as an exception nobody noticed, because the resolution was applied by overwriting a cell.

The file records the answer. The audit is about everything that happened before the answer.

The Error Rate Is Not The Real Problem

Spreadsheets do also contain mistakes, and the measured rates are not small. The research summarizing what is known about spreadsheet errors (Panko, Journal of Organizational and End User Computing, 1998) collected field audits and experiments showing that a large share of operational spreadsheets contain at least one error, with cell error rates that stay stubbornly non-zero across careful developers. The catalog of publicly reported spreadsheet failures maintained by the European Spreadsheet Risks Interest Group is the applied version of the same finding.

But error rate is the less interesting half. A control environment can tolerate an error that gets caught. What it cannot tolerate is being unable to demonstrate that catching happens, and that is a property of the medium rather than of the person using it. A careful analyst and a careless one produce files that look identical to a sample.

Attention Is Not A Control

The most common remediation sentence in circulation commits to more review by more senior people. It is an appealing answer because it costs nothing to write, and it fails for a reason that has been measured for almost eighty years.

The original study of vigilance decrement (Mackworth, Quarterly Journal of Experimental Psychology, 1948) showed detection performance falling measurably within the first half hour of a monitoring task and continuing to fall. Later work extended the pattern well beyond the laboratory. A study of extraneous factors in sequential expert decisions (Danziger, Levav & Avnaim-Pesso, PNAS, 2011) found favorable rulings varying sharply with position in the day's sequence and recovering after breaks; the size of that effect has been argued about since, and it should be read as directional rather than precise. The direction is not controversial: sustained attention on repetitive checking degrades, and it degrades fastest under time pressure and volume.

Period end is precisely the window where volume and time pressure peak. The remediation plan is therefore asking for the most attention at the exact moment the least is available.

There is a further trap in the other direction. The classic account of the ironies of automation (Bainbridge, Automatica, 1983) observes that automating the easy parts of a task leaves the human with only the hard residue, and less practice at it. The design conclusion is not to remove the person. It is to let the system carry sequence, identity, completeness and retention — the parts that are mechanical and unforgiving — and leave judgement to the person, who is good at it.

Make The Step Produce Its Own Record

The change that closes an evidence finding is usually far smaller than the remediation plan implies. In most cases the spreadsheet should stay. It is a good calculation tool and the team is fluent in it. What moves is the act of performing and reviewing.

Four properties do essentially all the work:

  • Identity. The person who performed the step is recorded because they were signed in, not because they typed their name. The reviewer is a different identity, enforced rather than requested.
  • Order and time. The step cannot be marked complete before its inputs are, and the completion time is recorded when it happens, not when someone remembers.
  • Version. The exact input used is captured and kept, so a later question about which extract fed the calculation has an answer.
  • Exceptions as items. Anything that does not match becomes a thing with a state and an owner, rather than a corrected cell and a message in a chat window.

Structure of this kind outperforms diligence in settings far more demanding than a monthly close. The trial of a surgical safety checklist across eight hospitals (Haynes et al., New England Journal of Medicine, 2009) reported substantial reductions in complications and death from a short structured procedure applied by teams that were already expert and already trying. The mechanism transfers even where the setting does not: making the required steps explicit, ordered and recorded changes outcomes among people who were not being careless.

When software is involved in these workflows, the same principle sets where it belongs. Language models are useful for reading a document, drafting an explanation or proposing a match — and they are the wrong thing to put in the path that decides whether a step completed. Keeping AI on the surfaces and the execution deterministic is the shape that survives an audit: the record of what happened is produced by code with no discretion, and anything probabilistic is a suggestion a named person accepts or rejects, with the acceptance itself recorded.

First Steps

  1. Pick the control the auditor asked about most recently. Ask the person who performs it to produce the last three instances, without preparing anything. Time how long it takes and note what is missing.
  2. Write down the six questions a tester asks — who, when, which version, which reviewer, what was rejected, in what order — and mark which ones your current artifact answers. The unanswered ones are the specification.
  3. Do not change the calculation. Change where the performance is recorded. Keeping the spreadsheet and moving the sign-off is a two-week change; replacing the spreadsheet is a project.

The Smallest Change That Closes The Finding

Most evidence findings do not require a new system of record, a consolidation project or a new hire. They require one workflow where the step cannot complete without leaving behind the six facts a sample will ask for, and where exceptions live as items with owners instead of as corrected cells.

A fifteen-minute call — nothing paid, nothing signed — takes one such control apart: what the record must contain, where each field comes from, and what it takes to build. Where the answer is build, that work runs as a monthly engineering partnership, with acceptance targets written down before each release starts and what happens when something goes wrong agreed in advance rather than left to the imagination. The work runs in a repository we own, and paid-for deliverables transfer to you monthly — full history and documentation.

The version of this that fails is the one where the control gets more attention. Attention is a real resource, it is the scarcest thing your team has in the last week of the quarter, and it leaves nothing behind for anyone to inspect.

References

  1. Public Company Accounting Oversight Board. AS 1105: Audit Evidence. PCAOB Auditing Standards.
  2. Public Company Accounting Oversight Board. AS 1215: Audit Documentation. PCAOB Auditing Standards.
  3. Panko, R. R. What We Know About Spreadsheet Errors. Journal of Organizational and End User Computing, 1998.
  4. European Spreadsheet Risks Interest Group. Spreadsheet Mistakes News Stories. EuSpRIG.
  5. Mackworth, N. H. The Breakdown of Vigilance During Prolonged Visual Search. Quarterly Journal of Experimental Psychology, 1948.
  6. Danziger, S., Levav, J., & Avnaim-Pesso, L. Extraneous Factors in Judicial Decisions. PNAS, 2011.
  7. Bainbridge, L. Ironies of Automation. Automatica, 1983.
  8. Haynes, A. B., et al. A Surgical Safety Checklist to Reduce Morbidity and Mortality in a Global Population. New England Journal of Medicine, 2009.
NEXTTO PRODUCTION

Check your position.

Two minutes. Your main blocker and first move.

15 minutes · no charge · with Omar