The Problem
You cannot migrate what you cannot document. And you cannot sign off what you cannot explain to Risk, Audit, or a regulator.
Spreadsheets that nobody fully understands. SAS programmes built by analysts who left years ago. Access databases with no documentation. Legacy reports that feed regulatory returns — and no record of how they work.
Discovery work that should happen before migration happens during it — at full programme cost.
Legacy assets feeding regulatory returns carry undocumented assumptions. 'The spreadsheet calculates it' is not an answer to a regulator.
SS1/23, BCBS 239, and FCA Consumer Duty create obligations that undocumented assets routinely fail to meet.
Migrating an undocumented asset means migrating its errors. They are harder to find and harder to fix on the other side.
Our Solution
We systematically analyse your legacy data assets and produce structured, audit-ready documentation. Every engagement follows a three-stage methodology.
Stage 1
What does this asset do? Who uses it? What does it produce and who receives the output? Written for a Board member, a project sponsor, and a migration lead simultaneously.
Stage 2
What connects to what? Where are the formula chains, the data flows, the fragile linkages? What breaks if something changes — and will you know about it?
Stage 3
What are the risks? What assumptions drive the outputs? What governance gaps exist? Structured for Risk, Audit, and Compliance with full regulatory citations.
Working days to first deliverable pack
Structured methodology compresses discovery without cutting corners.
What You Receive
Every deliverable is structured for a specific audience — so the right people get the right information at every stage of your programme.
What the asset does, what it produces, who receives the output, and what the key concerns are for migration.
Every significant data flow, formula chain, and cross-system dependency — with fragility ratings and change impact assessments.
The written analysis behind the dependency map — covering the single point of failure, silent failure modes, and pre-migration actions.
A formal risk assessment with regulatory citations — every identified risk, governance gap, and undocumented assumption, rated and actionable.
A complete, filterable risk register with risks, assumptions, governance gaps, and a prioritised remediation plan — structured for immediate use.
Why Greywood Analytics
We are not a generalist consulting firm. We do one thing, for organisations where getting it wrong has real consequences.
10+ years working inside Financial Services and Utilities. We understand IFRS 9, regulatory reporting, model governance, and SS1/23 — not as frameworks to reference, but as environments we have worked in.
What a traditional internal team would take 6–9 days to produce, Greywood Analytics delivers in 2–3 working days. Our structured methodology compresses discovery and documentation without cutting corners.
Every finding is cited to a specific cell, formula, comment, or programme section. Our outputs do not need to be converted into audit evidence. They are audit evidence.
Governance gaps are cited against the specific regulation they breach — SS1/23, IFRS 9, BCBS 239, FCA Consumer Duty — making outputs immediately actionable for compliance teams.
Every engagement is scoped before work begins. You know exactly what you are receiving, for which assets, by when. No scope creep. No open-ended retainers.
Excel workbooks, SAS programmes, Access databases, flat files, legacy reports. Whatever form your undocumented assets take, our methodology applies.
Get in Touch
Every engagement begins with a no-commitment scoping conversation. Tell us about your migration programme and the assets in scope — we will respond within one working day.
Start a Conversation yemi.michael@greywoodanalytics.comgreywoodanalytics.com