IT & Cyber Audit
End-User Computing Controls
Governance of spreadsheets and Access databases used in financial reporting outside core systems.
Spreadsheets in the reporting chain are an uncontrolled financial system
Spreadsheets and desktop databases used to prepare or adjust financial figures sit outside the change control, access management and audit logging of core systems, yet they routinely feed the annual financial statements. Uncontrolled end-user computing is a well-documented source of material misstatement and a recurring AGSA and COSO control concern. AuditPro Core brings these tools into scope by tracking the spreadsheets and databases relied on for reporting so that high-risk, uncontrolled artefacts are governed rather than invisible.
The Numbers
AuditPro Core renders this view from your tenant's live, tamper-evident records. The figures below are illustrative sample data.
EUC assets registered
342
High materiality
61
feed AFS directly
No version control
188
Unreviewed > 1 yr
97
EUC assets by control maturity
Highest-risk EUC assets
| Asset | Use | Materiality | Controls |
|---|---|---|---|
| GRAP asset register.xlsx | PPE valuation | High | None |
| Conditional grant tracker | Grant reporting | High | Partial |
| Leave provision model | AFS disclosure | Medium | Partial |
Figures shown are illustrative sample data for demonstration. AuditPro Core renders these views from your own tenant's live, tamper-evident records.
Why spreadsheets are high risk
Formula errors, broken links and unprotected cells are easy to introduce and hard to detect, and a single mistake can flow undetected into a disclosed figure because there is no system validation.
Version and change control
Without enforced versioning, multiple copies circulate and it becomes impossible to know which spreadsheet produced the reported number. A defensible audit trail requires a controlled, identifiable master version.
Access and integrity controls
Critical spreadsheets need the same access restriction, input validation and cell protection that core systems enforce. Their absence means anyone can alter a calculation that drives the statements.
Inventory before assurance
An entity cannot control what it has not identified. Establishing a complete inventory of reporting-critical end-user computing is the precondition for any meaningful assurance over it.
How AuditPro Core Bridges the Gap
- Inventory: spreadsheets and desktop databases used in financial reporting are catalogued with their owner and purpose.
- Risk rating: each artefact is rated by its complexity and influence on disclosed figures.
- Exception workflow: high-risk, uncontrolled tools are flagged for version control, protection and review.
- Traceability to source: reported figures can be linked back to the controlled spreadsheet that produced them.
Key Takeaways
- Reporting spreadsheets are an uncontrolled financial system and a misstatement risk.
- Enforce versioning so the figure-producing master file is always identifiable.
- Apply access restriction, input validation and cell protection to critical artefacts.
- Inventory end-user computing first; you cannot assure what you have not identified.
See This on Your Own Data
AuditPro Core renders this dashboard from your tenant's live, tamper-evident records — every figure traceable to source.
