← Back to Insights
Executive Summary

Internal audit functions in Financial Services have sharpened their focus on End User Computing assets considerably since the PRA's SS1/23 came into legal force in May 2024. Spreadsheets, SAS programmes, and Access databases that feed material business processes are no longer invisible to audit — they are actively sought out.

The findings, when they come, are consistent: undocumented assets, absent ownership trails, unvalidated assumptions, and governance gaps that no single person in the organisation can fully explain. These are not new problems. They are long-standing problems that regulatory pressure has made newly urgent.

The question is not whether your auditors will find them. It is whether you find them first.

The audit lens has shifted

For much of the last decade, internal audit coverage of EUC assets in Financial Services was inconsistent. Some firms had EUC registers. Most had gaps in those registers. And the practical reality — that critical processes were running on spreadsheets built by people who had long since left — was privately acknowledged and collectively ignored.

That has changed. The combination of SS1/23, increasing FCA scrutiny of operational risk, and the volume of active data migration programmes has put EUC governance firmly on the internal audit agenda. Audit teams are not stumbling across spreadsheet risk as a side finding — they are looking for it deliberately, with specific frameworks and escalation paths in place.

"The spreadsheet that nobody owns is exactly the kind of asset that generates a high-priority audit finding — not because it is broken, but because nobody can prove it is working correctly."

Regulators have been explicit about what good looks like. SS1/23 Principle 2 requires that models — including EUC tools — have documented ownership, clear methodology, and evidence of independent review. Most EUC estates in active Financial Services organisations meet none of these requirements for a significant proportion of their assets.

57%
of capital markets firms have suffered compliance breaches linked to EUC misuse
Source: Genesis Global / Risk.net
66%
of financial institutions acknowledge EUCs represent a major operational risk
Source: Risk.net
May 2024
SS1/23 came into legal force — EUC governance is now a binding PRA obligation
Source: PRA

The eight questions your auditors will ask

When an internal audit team reviews a legacy EUC asset, they work through a consistent set of questions. These questions are not difficult to anticipate — they are the same questions that any competent governance framework would ask. What is difficult, for most organisations, is answering them.

The Eight Questions
01
Who owns this asset? Not who uses it — who is accountable for its accuracy, its governance, and its outputs. In most organisations, the honest answer is that ownership transferred informally when the original author left, and has never been formally assigned since.
02
Where are the controls? What prevents an error in this asset from propagating into a regulatory return, a Board report, or a risk dashboard without being detected? For most EUCs, the answer is: manual review, if anyone remembers to do it.
03
What assumptions drive the output? Every model contains assumptions. Are they documented? Are they validated? Are they still appropriate given changes in the business environment since the asset was built?
04
Is there documentation? Not comments inside the file — a standalone methodology document that an independent reviewer could use to understand and replicate the logic without asking anyone.
05
Has it changed? When? Who approved it? A change log is the minimum. An approved change log — with methodology impact assessments and sign-off from a qualified reviewer — is what SS1/23 expects.
06
What does it connect to? What feeds into this asset, and what does this asset feed into? If the asset fails or produces an incorrect output, what downstream processes are affected — and would anyone know?
07
What breaks if it fails? Single points of failure are an operational resilience concern as much as a governance one. An asset with one owner, no backup, and no documented logic is a single point of failure by definition.
08
Has it ever been independently reviewed? Independent validation — not a second pair of eyes from the same team, but genuine independent assessment of the methodology and outputs — is an SS1/23 requirement for material models. For most EUCs, the answer is never.

The value of knowing these questions in advance is not to prepare a defensive answer for each one. It is to understand where the genuine gaps are — and address them before they become audit findings that require escalation to the Board Risk Committee or, in the worst case, to the regulator.

Regulatory Context — Global Internal Audit Standards 2025

Updated Global Internal Audit Standards came into effect in January 2025, explicitly redefining the purpose of internal auditing to include providing "foresight" — not just assurance on what has already happened. This means audit functions are increasingly expected to identify emerging risks, not just document existing ones.

For EUC governance, this shift is material. An audit team operating under the 2025 standards is not just asking whether your spreadsheets are currently causing problems — it is asking whether they represent a foreseeable risk to the organisation's ability to meet its regulatory obligations. An undocumented EUC feeding a PRA return is precisely that kind of foreseeable risk.

How Greywood Analytics Helps

Answering the eight questions — before your auditors ask them.

A Greywood Analytics deconstruction engagement produces documentation that directly addresses every one of the eight questions above. For each asset in scope, we deliver:

Every finding is cited to a specific cell, formula, comment, or programme section — not a generic observation but evidence that stands up to audit scrutiny.

First deliverable pack typically received within 2–3 working days of engagement start.

The cost of waiting for the finding

An internal audit finding on EUC governance is not simply an observation for the action log. At many Financial Services firms it triggers mandatory escalation — to the Chief Risk Officer, to the Audit Committee, and in some cases to the regulator directly under SS1/23's requirement to notify the PRA of material model risk management failures.

The remediation that follows an audit finding is also significantly more expensive than proactive documentation. It is conducted under time pressure, with audit scrutiny at every stage, and with the reputational cost of having been found rather than having acted.

The eight questions above are not a mystery. Every internal audit team in Financial Services is asking them. The only variable is whether your organisation answers them on its own terms — or on the auditor's.

"The best time to prepare for an audit finding is before the auditors arrive. The second best time is today."
Greywood Analytics

If any of the eight questions above cannot be answered for your most critical legacy assets, we should have a conversation. Every engagement begins with a no-commitment scoping discussion.

Start a Conversation