Across Financial Services, a category of risk sits largely unquantified and largely unaddressed: the legacy spreadsheet. Built quickly, maintained informally, and inherited repeatedly as people move on, these assets have become load-bearing elements of critical processes — from regulatory reporting to risk calculation to Board dashboards.
The cost is not hypothetical. Industry research estimates that the top 50 financial institutions carry over $12 billion in EUC Value at Risk. Since May 2024, the PRA's SS1/23 has made governance of these assets a legal obligation — not a best practice. And yet most migration programmes still encounter them undocumented, unvalidated, and unready.
The ember has been smouldering for years. The question is whether your organisation addresses it before the heat becomes visible to someone else.
The asset nobody owns
Every organisation in Financial Services has them. A spreadsheet built by an analyst who left three years ago. A SAS programme that runs every month on a scheduled job — reliable, unquestioned, and entirely undocumented. A reporting model that feeds the Board Risk Committee, whose logic exists nowhere except inside the file itself.
These are End User Computing assets — EUCs. And the defining characteristic of a mature EUC estate is not its complexity. It is its invisibility.
"The problem lies not with the high-profile, high-risk models in well-governed treasury operations. It lies with the ones nobody has thought to look at."
EUCs were not built to be permanent. They were built to solve an immediate problem. They became permanent because they worked — and because the institutional knowledge required to replace them walked out of the door with the person who built them.
Three risks that compound in silence
The danger of an undocumented EUC is not that it will fail noisily. It is that it will fail quietly — producing outputs that appear correct, passing through review processes that cannot detect what they cannot see, and being carried forward into migration programmes as an unexamined assumption.
Operational risk is the most visible. A copy-and-paste error in a value-at-risk spreadsheet contributed to a $6 billion trading loss in 2012. A formatting error in a contract spreadsheet forced a UK bank to buy $1.35 billion of worthless US contracts in 2008. These are not edge cases — they are the documented surface of a much larger and mostly undocumented problem.
Migration risk is where the cost accumulates most quietly. When a transformation programme reaches a legacy EUC, the team faces a choice: migrate it without understanding it, or stop and document it first. The first option transfers the risk. The second option delays the programme — at full programme cost. Neither is acceptable. Both are avoidable.
Regulatory risk is where the stakes have changed most significantly in the last twelve months.
In May 2023, the Prudential Regulation Authority published Supervisory Statement SS1/23 — the most comprehensive model risk management framework issued by a major regulator to date. It came into legal force on 17 May 2024.
SS1/23 is unambiguous on the question of spreadsheets: EUC tools and offline spreadsheet calculations are explicitly within scope. The PRA has confirmed that these principles apply to all models wherever they are used in the bank — not just those used for regulatory capital calculations.
Firms that have not yet conducted a formal self-assessment of their EUC estate against SS1/23 are, as of May 2024, already behind the curve. The PRA has commenced supervisory engagement with the first cohort of firms.
The implication is direct. An undocumented spreadsheet feeding a regulatory return is not merely a governance weakness. It is a potential breach of a binding supervisory requirement. And when a regulator asks for the documented basis of a figure, "the spreadsheet calculates it" is not an answer that satisfies Principle 2 of SS1/23.
Making the invisible legible — before it becomes a liability.
Greywood Analytics specialises in the systematic deconstruction of legacy EUC assets — Excel workbooks, SAS programmes, Access databases, flat files, and legacy reports — producing structured, audit-ready documentation that makes them legible, assessable, and safe to migrate.
For every asset in scope, we produce five deliverables across three stages:
- Plain English Summary — what the asset does, who uses it, what it produces, and what the migration concerns are. Written for a project sponsor and a Risk Director simultaneously.
- Dependency Map — every data flow, formula chain, and cross-system dependency, with fragility ratings and change impact assessments.
- Dependency Mapping Narrative — the single points of failure, the silent failure modes, and the actions required before the asset is touched.
- Risk & Assumption Narrative — every identified risk and governance gap, cited against SS1/23, IFRS 9, BCBS 239, and FCA Consumer Duty where applicable.
- Risk Register — a complete, filterable register with a prioritised remediation plan, structured for immediate use by Risk, Audit, and programme teams.
Every finding is grounded in specific evidence from the file. Not pattern-matching. Not generic observations. Evidence — cited to a specific cell, formula, comment, or programme section.
First deliverable pack typically received within 2–3 working days of engagement start.
The cost of waiting
The organisations that manage EUC risk well are not the ones that had fewer legacy assets. They are the ones that decided to understand what they had before a migration forced the question, before an audit surfaced the gap, or before a regulator asked for documentation that did not exist.
The ember has been in most organisations for years. It does not announce itself. It simply waits for the conditions that turn it into something more significant — a migration deadline, a regulatory review, a key person departure, or a model output that nobody can explain.
The cost of addressing it now is a structured engagement and a clear deliverable pack. The cost of addressing it later is everything that happens between the ember and the inferno.
"The most dangerous asset in a migration programme is not the one that is broken. It is the one that appears to work — and that nobody fully understands."Greywood Analytics
If this resonates with what you are seeing in your migration programme or regulatory reporting environment, we should talk. Every engagement begins with a no-commitment scoping conversation.
Start a Conversation