← Back to Insights
Executive Summary

Most conversations about EUC risk lead with a regulation — SS1/23, BCBS 239, an audit standard. This one does not need one. The plainest version of the problem needs no regulatory hook at all: an undocumented spreadsheet, built and maintained by one person, quietly informs a decision worth far more than anyone checked.

This has already happened, publicly, at organisations with more oversight than most. A trading model that understated risk. An academic paper that shaped fiscal policy in multiple countries. A bidding error that cost a mid-sized company millions. In each case the failure was not exotic — it was a formula, an assumption, or a copy-paste, sitting unvalidated in a spreadsheet that someone trusted.

The lesson is not "hire better analysts." It is that unvalidated tools eventually get relied upon for decisions they were never built to carry.

Three decisions, three unvalidated spreadsheets

These are not hypothetical scenarios constructed to make a point. Each is a matter of public record, and each involved competent, experienced people working inside organisations that had far more general oversight than the average business — which is exactly what makes them worth knowing.

Three Documented Cases
01
JPMorgan's "London Whale" — c. $6 billion trading loss (2012) A risk model used to assess the bank's Synthetic Credit Portfolio relied on a spreadsheet where a calculation divided by a sum instead of an average, understating the portfolio's risk. The error was one contributing factor in a trading loss that ultimately grew to roughly $6 billion and drew regulatory scrutiny on both sides of the Atlantic.
02
Reinhart–Rogoff — an influential paper on debt and growth (2010) A widely cited academic paper linking high government debt to lower economic growth, used to help justify austerity policy discussions in several countries, was later found to contain a spreadsheet formula that accidentally excluded several countries' data from the calculation — materially affecting the paper's headline result once corrected.
03
TransAlta — approximately $24 million loss (2003) A Canadian power company's contract bidding spreadsheet contained a copy-paste error that misaligned a set of hedging contracts, contributing to a loss of roughly $24 million on the mispriced positions.

"None of these organisations lacked talent. What they lacked, in each case, was a second set of eyes on a tool nobody had classified as important enough to check."

Why nobody checks — and why that's normal, not negligent

It's tempting to read these cases as failures of competence. They are better understood as a structural, entirely predictable pattern. A spreadsheet usually starts small, built quickly to solve an immediate problem by someone who understands it completely. Over time, its role quietly grows — more people rely on its output, more decisions sit downstream of it — but nobody formally re-assesses it as it grows, because no single moment ever marks the crossing from "minor tool" to "material input."

Independent validation is a routine, expected practice for models that carry a formal label — credit models, pricing models, regulatory capital models. It is almost never applied to the spreadsheet sitting just outside that formal boundary, even when its output feeds directly into a decision of comparable weight.

94%
of operational spreadsheets examined across field audit studies contained at least one error
Source: Panko, weighted average across 88 field-audited spreadsheets
$6bn
approximate scale of JPMorgan's "London Whale" trading loss, with a spreadsheet error among the contributing factors
Source: public regulatory and press reporting, 2012–2013
0
the number of these three cases that required a banking regulator to be true — the risk exists with or without a regulatory trigger
Greywood Analytics analysis
Why this brief carries no regulatory citation

Every other Executive Brief in this series ties EUC risk to a specific regulatory obligation — SS1/23, BCBS 239, internal audit standards. This one deliberately does not, because the underlying risk does not require one. A business does not need to be a regulated bank, or subject to any particular supervisory statement, for an unverified spreadsheet to quietly drive a bad decision.

For organisations outside the most heavily regulated frameworks, this is often the most relevant door into the same conversation: not "are you compliant," but "do you actually know if the numbers behind your biggest decisions are right."

How Greywood Analytics Helps

Independent validation for the tools nobody else is checking.

A Greywood Analytics deconstruction engagement applies the same rigour to a business-critical spreadsheet that a regulated model would receive as standard — regardless of whether a regulation requires it. For each asset in scope, we deliver:

The goal is simple: by the time a tool is influencing a major decision, someone other than its builder should have checked it.

First deliverable pack typically received within 2–3 working days of engagement start.

The question worth asking this week

Somewhere in most organisations sits a spreadsheet that has quietly become more important than anyone officially decided it should be — informing pricing, forecasting, resourcing, or a decision that will land on a Board table. It was never validated, because nobody ever formally noticed it needed to be.

The three cases above were not obscure or poorly run organisations. They are a reminder that scale and competence are not substitutes for independent verification — and that the gap is closeable, once someone actually looks for it.

"The question is rarely 'is our spreadsheet wrong.' It's 'when did we last check' — and for most business-critical tools, the honest answer is never."
Greywood Analytics

If there's a spreadsheet quietly driving decisions in your organisation that nobody outside its original builder has ever checked, we should have a conversation. Every engagement begins with a no-commitment scoping discussion.

Start a Conversation