IT & Cyber Audit
End-User Computing Controls
Spreadsheets that feed the financial statements often have none of the controls applied to the core system that they bypass.
Why critical spreadsheets are an under-governed reporting risk
A large share of public-sector financial reporting still passes through spreadsheets and end-user databases that sit entirely outside the controlled core system, where a single broken formula or unprotected cell can misstate a figure that reaches the annual financial statements. These end-user computing tools rarely carry version control, access restriction or independent review, yet they feed numbers the AGSA tests under GRAP. AuditPro Core profiles the entity's critical spreadsheets by risk so that the few that genuinely drive financial reporting receive the controls โ protection, review and version history โ that their materiality demands.
The Numbers
AuditPro Core renders this view from your tenant's live, tamper-evident records. The figures below are illustrative sample data.
EUC tools registered
287
High-risk
34
feed AFS directly
Version-controlled
41%
Untested formulas
58
EUC tools by risk rating
Highest-risk spreadsheets
| Tool | Feeds | Balance |
|---|---|---|
| Provisions model | AFS Note 14 | R 240 m |
| Revenue accrual | Statement of FP | R 188 m |
| Asset depreciation | PPE register | R 96 m |
Figures shown are illustrative sample data for demonstration. AuditPro Core renders these views from your own tenant's live, tamper-evident records.
Why EUC tools are high risk
Spreadsheets combine logic, data and presentation in one editable file with no enforced separation of duties. A formula change or an overwritten cell can silently change a reported number.
Identifying the critical few
Most spreadsheets do not matter; a small number feed material disclosures or calculations. Risk profiling concentrates control effort on those that can actually misstate the financials.
Baseline controls for critical EUC
Critical workbooks need input validation, cell and formula protection, restricted access, an owner, version history and independent review of changes โ the same control intent as a system, scaled to a file.
The handoff to core systems
The riskiest moment is where the spreadsheet output is keyed or imported into the ledger. That interface should be reconciled so a spreadsheet error cannot pass silently into the records.
How AuditPro Core Bridges the Gap
- Risk profiling: the inventory scores each EUC tool by the materiality and complexity of what it feeds, isolating the critical few.
- Control-status tracking: protection, access restriction, ownership and review status are tracked per critical workbook.
- Exception workflow: critical spreadsheets missing baseline controls are raised for remediation.
- Reconciliation to the ledger: spreadsheet outputs feeding the core system are reconciled at the handoff so errors cannot pass silently.
Key Takeaways
- A handful of spreadsheets carry most of the EUC reporting risk โ find and govern those.
- Critical workbooks need protection, access control, ownership and change review.
- The spreadsheet-to-ledger handoff is the highest-risk interface and must be reconciled.
- EUC risk is a recognised IT general-control weakness the AGSA tests under GRAP reporting.
See This on Your Own Data
AuditPro Core renders this dashboard from your tenant's live, tamper-evident records โ every figure traceable to source.
