Back to Explore
๐Ÿ›ก๏ธ

IT & Cyber Audit

End-User Computing Controls

Spreadsheets that feed the financial statements often have none of the controls applied to the core system that they bypass.

๐Ÿ“– 6 min read๐ŸŽฏ Intermediateโœ๏ธ Updated 2026

Why critical spreadsheets are an under-governed reporting risk

A large share of public-sector financial reporting still passes through spreadsheets and end-user databases that sit entirely outside the controlled core system, where a single broken formula or unprotected cell can misstate a figure that reaches the annual financial statements. These end-user computing tools rarely carry version control, access restriction or independent review, yet they feed numbers the AGSA tests under GRAP. AuditPro Core profiles the entity's critical spreadsheets by risk so that the few that genuinely drive financial reporting receive the controls โ€” protection, review and version history โ€” that their materiality demands.

The Numbers

AuditPro Core renders this view from your tenant's live, tamper-evident records. The figures below are illustrative sample data.

EUC tools registered

287

High-risk

34

feed AFS directly

Version-controlled

41%

Untested formulas

58

EUC tools by risk rating

Highest-risk spreadsheets

ToolFeedsBalance
Provisions modelAFS Note 14R 240 m
Revenue accrualStatement of FPR 188 m
Asset depreciationPPE registerR 96 m

Figures shown are illustrative sample data for demonstration. AuditPro Core renders these views from your own tenant's live, tamper-evident records.

Why EUC tools are high risk

Spreadsheets combine logic, data and presentation in one editable file with no enforced separation of duties. A formula change or an overwritten cell can silently change a reported number.

Identifying the critical few

Most spreadsheets do not matter; a small number feed material disclosures or calculations. Risk profiling concentrates control effort on those that can actually misstate the financials.

Baseline controls for critical EUC

Critical workbooks need input validation, cell and formula protection, restricted access, an owner, version history and independent review of changes โ€” the same control intent as a system, scaled to a file.

The handoff to core systems

The riskiest moment is where the spreadsheet output is keyed or imported into the ledger. That interface should be reconciled so a spreadsheet error cannot pass silently into the records.

How AuditPro Core Bridges the Gap

  • Risk profiling: the inventory scores each EUC tool by the materiality and complexity of what it feeds, isolating the critical few.
  • Control-status tracking: protection, access restriction, ownership and review status are tracked per critical workbook.
  • Exception workflow: critical spreadsheets missing baseline controls are raised for remediation.
  • Reconciliation to the ledger: spreadsheet outputs feeding the core system are reconciled at the handoff so errors cannot pass silently.

Key Takeaways

  • A handful of spreadsheets carry most of the EUC reporting risk โ€” find and govern those.
  • Critical workbooks need protection, access control, ownership and change review.
  • The spreadsheet-to-ledger handoff is the highest-risk interface and must be reconciled.
  • EUC risk is a recognised IT general-control weakness the AGSA tests under GRAP reporting.

See This on Your Own Data

AuditPro Core renders this dashboard from your tenant's live, tamper-evident records โ€” every figure traceable to source.