Most conversations about EUC risk lead with a regulation — SS1/23, BCBS 239, an audit standard. This one does not need one. The plainest version of the problem needs no regulatory hook at all: an undocumented spreadsheet, built and maintained by one person, quietly informs a decision worth far more than anyone checked.
This has already happened, publicly, at organisations with more oversight than most. A trading model that understated risk. An academic paper that shaped fiscal policy in multiple countries. A bidding error that cost a mid-sized company millions. In each case the failure was not exotic — it was a formula, an assumption, or a copy-paste, sitting unvalidated in a spreadsheet that someone trusted.
The lesson is not "hire better analysts." It is that unvalidated tools eventually get relied upon for decisions they were never built to carry.
Three decisions, three unvalidated spreadsheets
These are not hypothetical scenarios constructed to make a point. Each is a matter of public record, and each involved competent, experienced people working inside organisations that had far more general oversight than the average business — which is exactly what makes them worth knowing.
"None of these organisations lacked talent. What they lacked, in each case, was a second set of eyes on a tool nobody had classified as important enough to check."
Why nobody checks — and why that's normal, not negligent
It's tempting to read these cases as failures of competence. They are better understood as a structural, entirely predictable pattern. A spreadsheet usually starts small, built quickly to solve an immediate problem by someone who understands it completely. Over time, its role quietly grows — more people rely on its output, more decisions sit downstream of it — but nobody formally re-assesses it as it grows, because no single moment ever marks the crossing from "minor tool" to "material input."
Independent validation is a routine, expected practice for models that carry a formal label — credit models, pricing models, regulatory capital models. It is almost never applied to the spreadsheet sitting just outside that formal boundary, even when its output feeds directly into a decision of comparable weight.
Every other Executive Brief in this series ties EUC risk to a specific regulatory obligation — SS1/23, BCBS 239, internal audit standards. This one deliberately does not, because the underlying risk does not require one. A business does not need to be a regulated bank, or subject to any particular supervisory statement, for an unverified spreadsheet to quietly drive a bad decision.
For organisations outside the most heavily regulated frameworks, this is often the most relevant door into the same conversation: not "are you compliant," but "do you actually know if the numbers behind your biggest decisions are right."
Independent validation for the tools nobody else is checking.
A Greywood Analytics deconstruction engagement applies the same rigour to a business-critical spreadsheet that a regulated model would receive as standard — regardless of whether a regulation requires it. For each asset in scope, we deliver:
- Plain English Summary — what the tool actually does, in language a decision-maker who didn't build it can verify against their own understanding.
- Dependency Map — every input, formula chain, and downstream use, surfacing exactly how far the tool's influence actually reaches.
- Dependency Mapping Narrative — the single points of failure and silent failure modes an independent reviewer, not the original builder, can identify.
- Risk & Assumption Narrative — every embedded assumption tested against whether it still holds true today.
- Risk Register — a clear, prioritised view of what to fix first, and why.
The goal is simple: by the time a tool is influencing a major decision, someone other than its builder should have checked it.
First deliverable pack typically received within 2–3 working days of engagement start.
The question worth asking this week
Somewhere in most organisations sits a spreadsheet that has quietly become more important than anyone officially decided it should be — informing pricing, forecasting, resourcing, or a decision that will land on a Board table. It was never validated, because nobody ever formally noticed it needed to be.
The three cases above were not obscure or poorly run organisations. They are a reminder that scale and competence are not substitutes for independent verification — and that the gap is closeable, once someone actually looks for it.
"The question is rarely 'is our spreadsheet wrong.' It's 'when did we last check' — and for most business-critical tools, the honest answer is never."Greywood Analytics
If there's a spreadsheet quietly driving decisions in your organisation that nobody outside its original builder has ever checked, we should have a conversation. Every engagement begins with a no-commitment scoping discussion.
Start a Conversation