---
title: "The Unaudited Workbook: When Critical Plans Hang on a Single File"
description: "Spreadsheet risk is the dependence of critical planning and reporting outputs on workbooks that lack version control, separation of inputs from logic, and independent recalculation. In single-user, one-off models this dependence is a rational shortcut; once the file hardens into institutional infrastructure, errors propagate silently and the cost is paid through inventory, service levels, covenant reporting, and the valuation multiple."
url: https://www.beirek.com/en/blog/spreadsheet-risk-in-planning-models
canonical: https://www.beirek.com/en/blog/spreadsheet-risk-in-planning-models
published: 2026-01-15
modified: 2026-01-15
category: "Operations & Supply Chain"
category_url: https://www.beirek.com/en/blog/category/operations-supply-chain
language: en-US
reading_time_minutes: 7
publisher: BEIREK LLC
publisher_url: https://www.beirek.com
license: "© BEIREK LLC — citation with attribution and link permitted"
keywords: ["spreadsheet risk","planning model governance","supply chain parameter calibration","covenant reporting integrity","key person dependency in diligence"]
topics: ["Model risk and control design in supply and capacity planning","Reproducibility of financial and operational figures during due diligence","Institutional mechanisms for version control, ownership, and recalculation discipline"]
alternate_language_url: https://www.beirek.com/tr/blog/spreadsheet-risk-in-planning-models
---

# The Unaudited Workbook: When Critical Plans Hang on a Single File

> **In short:** Spreadsheet risk is the dependence of critical planning and reporting outputs on workbooks that lack version control, separation of inputs from logic, and independent recalculation. In single-user, one-off models this dependence is a rational shortcut; once the file hardens into institutional infrastructure, errors propagate silently and the cost is paid through inventory, service levels, covenant reporting, and the valuation multiple.

*A company's procurement, capacity, and cash plans frequently live not in the ERP but in a single workbook maintained by a single person. Born as a temporary calculation aid, the file becomes permanent infrastructure without ever crossing an approval threshold, and the cost surfaces not in operations but at the diligence table.*

---

When someone in a supply planning meeting asks where a figure came from, the answer is rarely the name of a system; it is the name of a file, typically carrying a date suffix, sometimes a set of initials, occasionally the word "final." The person who produced the number is in the room and can defend it line by line, yet no one has ever tested whether a colleague, working from the same source data while that person is on leave, would arrive at the same result through the same steps. The meeting moves past the question, since the figure came from the same place last quarter and last quarter produced no incident. This is the most durable form of confidence inside an institution: not having been verified, but not yet having been falsified.

The second surface of the same pattern appears at the moment the number leaves the building. A capacity plan presented to the board, a compliance certificate sent to a lender, or a unit price submitted into a tender is seldom a standard system output; more often it is raw extract that has been corrected, completed, and interpreted inside a workbook. Some portion of those corrections is legitimate and necessary, because no enterprise system is configured to carry every exception a real operation generates. Where the same metric requested from three functions returns three different values, however, the issue is not arithmetic but the absence of a reconciliation architecture — a designated layer at which competing versions are forced to agree before any of them is allowed to travel outward.

The name for this pattern is spreadsheet risk: the dependence of critical plans, and of figures declared to external counterparties, on workbooks that carry no version control, no separation of access rights, and no independent verification layer. Reading the underlying tendency as negligence would be misleading, since the spreadsheet is the lowest-friction modeling instrument available inside almost any organization, requiring neither an IT ticket, nor a capital approval, nor a vendor contract. The analyst constructs the logic at their own pace and answers the question by morning. Where a decision will be taken once and the model used once, that choice is entirely rational; the difficulty begins when the condition changes — when the file is bound to a weekly rhythm — and the choice remains fixed.

The transition happens quietly because no threshold exists to mark it. Bringing software into institutional use requires approval, testing, and formal acceptance, whereas a workbook becomes permanent infrastructure simply by being opened a few more times. During that drift, adjustments believed to be one-off migrate into the file: a coefficient typed by hand into the middle of a formula, a summation range that stops covering the final row once a line is inserted, a link pointing at a closed file that no longer refreshes, a unit conversion lost somewhere between tonnes and kilograms. What these errors share is that they make no noise; the model does not crash, raises no exception, and continues generating the wrong figure with exactly the confidence it applied to the right one.

Ownership drifts with the same silence. The person who built the file is promoted or leaves; the successor, unable to reconstruct the logic in full, avoids touching the calculation layer and updates only the inputs. What accumulates is a computational stratum that nobody fully understands yet everyone relies upon, invisible on the formal organization chart, with neither a process owner nor a control point attached to it. This is institutional memory in its most fragile configuration: undocumented logic producing documented output.

The operational cost accumulates first inside parameters. Safety-stock coefficients, economic order quantities, supplier lead-time assumptions, and capacity ceilings are rarely recalibrated once written into the workbook, so the file continues to run on the same values even after supplier performance shifts, freight regimes move, or demand variance widens. The balance-sheet expression of this rigidity usually appears not in the inventory line itself but in inventory turnover holding the same band across two consecutive years. Once expedited shipments and premium freight are added alongside, the annual cost carried by one stale assumption sitting in a single cell can exceed, by an order of magnitude, the cost of the system investment that would have corrected the parameter.

The second cost line is contractual. The DSCR calculation submitted to a lender, the progress-payment file presented for employer certification, the liquidated-damages accrual under an EPC contract, and the unit-price schedule entering a tender typically emerge from that same unaudited layer. Here the consequence of an error is no longer internal efficiency but the legal position established with a counterparty: a miscalculated coverage ratio opens a technical default discussion, while a price-adjustment mechanism imperfectly reflected in a bid converts into margin erosion carried for the full contract term. What these items share is that by the time the error becomes visible it has ceased to be correctable, because a signature has already been applied.

The third cost, and usually the most expensive, is paid at the review table. In a sale, partnership, or financing process, the counterparty's analyst tests not whether the number is correct but whether it can be reproduced; where the evidentiary chain running from source document to cell cannot be assembled, even an accurate figure is classified as an unverified one. The practical consequences show up as an expanding set of normalization adjustments in the quality-of-earnings analysis, a working capital target pulled toward the conservative end, and representation and warranty coverage that explicitly carves out the affected line items. Price often does not move directly; it is rewritten as a condition precedent, a higher escrow percentage, or an earn-out trigger. What determines valuation is not performance itself but the demonstrability of performance independent of the individual who produced it.

The mechanism that neutralizes this tendency is not an appeal to individual care but a four-component design. The first is a criticality inventory: rather than cataloguing every workbook in the organization, the exercise classifies only those files whose output is declared externally or triggers a spending authority, and confines the control perimeter to that set. The second is the separation of input, logic, and output; assumptions are consolidated onto a single parameter sheet, the calculation layer is locked, and hard-coding a constant inside a formula is made structurally impossible rather than merely discouraged. The third is named ownership with a designated deputy, meaning every critical file has an owner and a second person capable of defending its logic, with handover executed through a record rather than an email attachment. The fourth is triggered recalculation: rather than following the calendar, the model is rebuilt from source by an independent party upon defined events — a parameter change, a contract signature, a new supplier, a new jurisdiction — and the two results are compared.

In the projects it manages, BEIREK operates this layer as a distinct control line. Critical calculations are entered into a model register, and each entry records which decision the file feeds, which assumption it draws from which source document, and at which gate it will be revalidated. The validation gates are structural rather than calendar-driven: investment decision, financial close, first drawdown, and commissioning. At each gate the parameter set is reconciled back to the underlying contract and the system of record, critical outputs are independently recomputed by a team member who did not build the model, and variances are logged with their rationale rather than quietly corrected and closed. The value of that log lies less in the errors it surfaces than in what it makes possible at the diligence table: an account of how the number was produced.

The maturity of an institution's planning discipline is measured not by which software it licenses but by how long it takes to reproduce a critical figure without the person who produced it. Where that interval is measured in days, what the organization holds is not a plan but an estimate attached to an individual, and that distinction is eventually priced at a negotiating table.

## Key Points

- The spreadsheet is rational precisely because it permits modeling at near-zero marginal cost; the difficulty arises when a temporary instrument becomes permanent decision infrastructure without passing any approval gate.
- Workbook errors are silent rather than noisy: a broken summation range, a constant hard-coded inside a formula, or a mismatched unit does not halt the system but continues producing an incorrect figure with undiminished confidence.
- Operational cost accumulates in safety-stock coefficients, lead-time assumptions, and capacity ceilings, while contractual cost surfaces in covenant reporting, progress-payment certification, and bid pricing.
- What governs the diligence outcome is not whether the number is correct but whether it can be reproduced independently of the person who prepared the file.
- The tendency is neutralized not by individual vigilance but by a criticality inventory, a separation of input, logic, and output layers, named ownership with a designated deputy, and event-triggered independent recalculation.

## Questions

### What exactly is spreadsheet risk, and why is it not simply an error problem?

Spreadsheet risk is the dependence of critical plans and externally declared figures on workbooks lacking version control, access separation, and an independent verification layer. Its distinguishing property is not the frequency of errors but their silence: a broken summation range or a constant embedded inside a formula does not halt the model, it continues producing the wrong result with identical confidence and enters the decision chain unnoticed.

### Does migrating critical spreadsheets into the ERP solve the problem?

Migration alone is rarely sufficient, because workbooks typically originate to handle exceptions the system does not carry, and new ones appear if that gap persists after implementation. What proves decisive is the control design around the instrument rather than the instrument itself: assumptions consolidated in one parameter layer, calculation logic locked, ownership named with a deputy, and independent recalculation triggered by defined events.

### How does an investor or acquirer detect this weakness in planning models?

At the review table, reproducibility is tested rather than accuracy. The analyst typically selects one output and asks that it be traced back to the underlying contract or system of record; where the chain cannot be assembled, or can be explained only by one individual, the finding is reported as key person dependency. The consequence usually appears not in price but in conditions precedent, escrow percentage, and warranty coverage.

### Which workbooks should fall inside the control perimeter — should all of them be audited?

Auditing the entire population is impractical and generates friction without corresponding benefit. The defensible criterion is impact: a file enters scope where its output is declared outside the institution, triggers a spending or procurement authority, computes a contractual obligation, or sets an inventory, capacity, or pricing parameter. In practice this definition selects a small fraction of the workbook inventory and keeps the cost of control manageable.

---

Source: https://www.beirek.com/en/blog/spreadsheet-risk-in-planning-models
Publisher: BEIREK LLC — https://www.beirek.com
