Skip to content

JOURNAL

Published on

WHEN A SPREADSHEETBECOMES A RISK

The spreadsheet is never the problem. The day it became the record is.

THE ANSWER

A spreadsheet becomes a business risk when it stops being a calculation. It becomes the record: the only place a figure exists. The list of people who can open it is no longer checked. The formulas decisions rest on haven’t been reread in months. The limit isn’t technical: nobody answers for the file.

Five overlapping circles in semi-opaque planes, intersecting at the centre.

AI-generated image

IN SHORT

  • Write at the top who answers for the file.

  • Wrong formulas don’t stop: they answer anyway.

  • Need per-row permissions and the sheet is done.

THE POINT

THE SPREADSHEET ISN’T THE PROBLEM

I use spreadsheets every day. I have no intention of talking you out of them. The risk doesn’t start there. It starts the day the file stops being a working copy and becomes the original. The only place recording who has paid, who is late, how much was ordered. (From then on it is a system handled like a document.)

WHERE IT BREAKS

THE LIMITS OF SPREADSHEETS AT WORK

None of these risks announces itself with an error on screen. That is why they stand for years.

An exploded axonometric view: one solid separated into five parallel layers.

AI-generated image

WHAT TO DO

LOWER THE RISK, KEEP THE FILE

None of these steps needs a project, a budget or me. They are an afternoon, and they change the file’s risk category.

  1. Name the owner

    One person answers for that file: who has access, what the columns mean, when it gets archived. A file with no owner is a file nobody answers for.

  2. Reread the list of who can open it

    Remove the open links, remove people no longer on that process, leave edit rights with those who use it. Everyone else reads.

  3. Separate the data from the calculation

    Raw data in one sheet, formulas and summaries in another that reads it. A badly pasted row then spoils one thing only.

  4. Lock what must not be touched

    Protect the calculated columns and the headers. Validation on the fields that must have a shape — dates, statuses, amounts — removes half the mistakes.

  5. Freeze a copy at regular intervals

    A read-only copy, with the date in its name, kept somewhere else. It answers what last month looked like without consulting anyone’s memory.

  6. Write at the top what it means

    Two lines: what the file holds, who updates it, what must not be done to it.

THE SIGNALS

WHEN THE SPREADSHEET IS DONE

A spreadsheet doesn’t break: it answers anyway, with the wrong number.

QUESTIONS

So should I stop using spreadsheets?
No, and anyone who says otherwise is selling something. A spreadsheet is right for a calculation, for a short-lived list, for trying an idea. The line is the moment it becomes the only place a value exists.
Does an online sheet differ from one on a laptop?
On these risks, barely. Sharing and history are more comfortable online, and one fewer copy on a laptop is one fewer exposure. But the missing owner and the unread formulas are identical.
Isn’t version history enough?
It shows what changed; it doesn’t stop the change. And it gets consulted after somebody has spotted a problem. If the error returns a plausible number, nobody goes looking.
Where do I start, if time is short?
The access list, and the owner’s name written at the top of the file. Both take a quarter of an hour. They remove the part of the risk that has nothing to do with the sheet.

Once a spreadsheet has stopped being a spreadsheet, replacing it isn’t a large program. It is the smallest piece that holds the data and the permissions. The sheet keeps doing the sums on top.

The internal apps I build