When someone in a supply planning meeting asks where a figure came from, the answer is rarely the name of a system; it is the name of a file, typically carrying a date suffix, sometimes a set of initials, occasionally the word "final." The person who produced the number is in the room and can defend it line by line, yet no one has ever tested whether a colleague, working from the same source data while that person is on leave, would arrive at the same result through the same steps. The meeting moves past the question, since the figure came from the same place last quarter and last quarter produced no incident. This is the most durable form of confidence inside an institution: not having been verified, but not yet having been falsified.

The second surface of the same pattern appears at the moment the number leaves the building. A capacity plan presented to the board, a compliance certificate sent to a lender, or a unit price submitted into a tender is seldom a standard system output; more often it is raw extract that has been corrected, completed, and interpreted inside a workbook. Some portion of those corrections is legitimate and necessary, because no enterprise system is configured to carry every exception a real operation generates. Where the same metric requested from three functions returns three different values, however, the issue is not arithmetic but the absence of a reconciliation architecture — a designated layer at which competing versions are forced to agree before any of them is allowed to travel outward.

The name for this pattern is spreadsheet risk: the dependence of critical plans, and of figures declared to external counterparties, on workbooks that carry no version control, no separation of access rights, and no independent verification layer. Reading the underlying tendency as negligence would be misleading, since the spreadsheet is the lowest-friction modeling instrument available inside almost any organization, requiring neither an IT ticket, nor a capital approval, nor a vendor contract. The analyst constructs the logic at their own pace and answers the question by morning. Where a decision will be taken once and the model used once, that choice is entirely rational; the difficulty begins when the condition changes — when the file is bound to a weekly rhythm — and the choice remains fixed.

The transition happens quietly because no threshold exists to mark it. Bringing software into institutional use requires approval, testing, and formal acceptance, whereas a workbook becomes permanent infrastructure simply by being opened a few more times. During that drift, adjustments believed to be one-off migrate into the file: a coefficient typed by hand into the middle of a formula, a summation range that stops covering the final row once a line is inserted, a link pointing at a closed file that no longer refreshes, a unit conversion lost somewhere between tonnes and kilograms. What these errors share is that they make no noise; the model does not crash, raises no exception, and continues generating the wrong figure with exactly the confidence it applied to the right one.

Ownership drifts with the same silence. The person who built the file is promoted or leaves; the successor, unable to reconstruct the logic in full, avoids touching the calculation layer and updates only the inputs. What accumulates is a computational stratum that nobody fully understands yet everyone relies upon, invisible on the formal organization chart, with neither a process owner nor a control point attached to it. This is institutional memory in its most fragile configuration: undocumented logic producing documented output.

The operational cost accumulates first inside parameters. Safety-stock coefficients, economic order quantities, supplier lead-time assumptions, and capacity ceilings are rarely recalibrated once written into the workbook, so the file continues to run on the same values even after supplier performance shifts, freight regimes move, or demand variance widens. The balance-sheet expression of this rigidity usually appears not in the inventory line itself but in inventory turnover holding the same band across two consecutive years. Once expedited shipments and premium freight are added alongside, the annual cost carried by one stale assumption sitting in a single cell can exceed, by an order of magnitude, the cost of the system investment that would have corrected the parameter.

The second cost line is contractual. The DSCR calculation submitted to a lender, the progress-payment file presented for employer certification, the liquidated-damages accrual under an EPC contract, and the unit-price schedule entering a tender typically emerge from that same unaudited layer. Here the consequence of an error is no longer internal efficiency but the legal position established with a counterparty: a miscalculated coverage ratio opens a technical default discussion, while a price-adjustment mechanism imperfectly reflected in a bid converts into margin erosion carried for the full contract term. What these items share is that by the time the error becomes visible it has ceased to be correctable, because a signature has already been applied.

The third cost, and usually the most expensive, is paid at the review table. In a sale, partnership, or financing process, the counterparty's analyst tests not whether the number is correct but whether it can be reproduced; where the evidentiary chain running from source document to cell cannot be assembled, even an accurate figure is classified as an unverified one. The practical consequences show up as an expanding set of normalization adjustments in the quality-of-earnings analysis, a working capital target pulled toward the conservative end, and representation and warranty coverage that explicitly carves out the affected line items. Price often does not move directly; it is rewritten as a condition precedent, a higher escrow percentage, or an earn-out trigger. What determines valuation is not performance itself but the demonstrability of performance independent of the individual who produced it.

The mechanism that neutralizes this tendency is not an appeal to individual care but a four-component design. The first is a criticality inventory: rather than cataloguing every workbook in the organization, the exercise classifies only those files whose output is declared externally or triggers a spending authority, and confines the control perimeter to that set. The second is the separation of input, logic, and output; assumptions are consolidated onto a single parameter sheet, the calculation layer is locked, and hard-coding a constant inside a formula is made structurally impossible rather than merely discouraged. The third is named ownership with a designated deputy, meaning every critical file has an owner and a second person capable of defending its logic, with handover executed through a record rather than an email attachment. The fourth is triggered recalculation: rather than following the calendar, the model is rebuilt from source by an independent party upon defined events — a parameter change, a contract signature, a new supplier, a new jurisdiction — and the two results are compared.

In the projects it manages, BEIREK operates this layer as a distinct control line. Critical calculations are entered into a model register, and each entry records which decision the file feeds, which assumption it draws from which source document, and at which gate it will be revalidated. The validation gates are structural rather than calendar-driven: investment decision, financial close, first drawdown, and commissioning. At each gate the parameter set is reconciled back to the underlying contract and the system of record, critical outputs are independently recomputed by a team member who did not build the model, and variances are logged with their rationale rather than quietly corrected and closed. The value of that log lies less in the errors it surfaces than in what it makes possible at the diligence table: an account of how the number was produced.

The maturity of an institution's planning discipline is measured not by which software it licenses but by how long it takes to reproduce a critical figure without the person who produced it. Where that interval is measured in days, what the organization holds is not a plan but an estimate attached to an individual, and that distinction is eventually priced at a negotiating table.