By 2007, most substantial companies had finished installing an ERP system. The promise had been a single source of truth. The reality, in almost every finance function, was that the month-end numbers were assembled in Excel, from extracts, on one analyst's laptop. This was not a transitional state. Twenty years later it is still the most common reporting architecture in the mid-market, and it is the one control weakness that auditors, regulators and finance directors have collectively agreed to keep not looking at too closely.
What a Shadow System Actually Is
A shadow system is not a spreadsheet. It is a spreadsheet doing a system's job. The test is simple. Does it run on a recurring cycle? Does the business depend on its output? Does it apply logic that exists nowhere else? Does one person understand it? If the answers are yes, you are running an unmanaged application with no change control, no access control, no testing and no documentation — and it is producing numbers that go to your board, your bank or your tax authority. The typical portfolio in a mid-sized company includes the management accounts pack, the revenue recognition workings, the commission calculation, the inventory reconciliation, the cash-flow forecast, the consolidation for entities the ERP never absorbed, and the pricing model sales actually uses instead of the one in the system.
Why They Formed Around Every ERP
The shadow systems were not a sign of indiscipline. They were a rational response to four specific ERP reporting gaps. The report writer was unusable. Producing a new report required a specialist, a ticket and a queue. Producing it in Excel required an export and an afternoon. The implementation descoped reporting. Reporting was consistently the phase compressed to protect the go-live date. Organizations went live with transaction processing that worked and reporting that did not, then closed the gap manually and never reopened it. The model did not match the business. Management wanted profitability by customer segment, channel or route; the chart of accounts was designed for statutory reporting. Bridging the two in the system meant a change project. Bridging it in a spreadsheet meant a lookup table. Month-end has a deadline. When the close is due in four days, nobody escalates a reporting gap. They solve it, in Excel, and the solution becomes permanent because it works.
What the Research Said, and Nobody Acted On
The academic evidence was already unambiguous. Work collected through the European Spreadsheet Risks Interest Group — including Panko and Ordway's analysis of spreadsheets under Sarbanes-Oxley — found that field audits of operational spreadsheets detect errors in the large majority of those examined, and that cell error rates in spreadsheet development are comparable to error rates in other human activities without formal review. The implication is uncomfortable but not really arguable: a complex spreadsheet that has never been independently reviewed almost certainly contains an error. Whether that error is material is a matter of luck, not control. Sarbanes-Oxley should have forced the issue. Section 404 required management to assess internal control over financial reporting, and the guidance of the period said little about end-user computing. Most organizations documented their ERP controls in detail and treated the spreadsheets sitting between the ERP and the financial statements as though they were not part of the reporting process. The subsequent record speaks for itself. A Canadian power company lost a reported $24 million to a cut-and-paste error in a bidding spreadsheet. A major bank's internal review of its 2012 trading losses described a risk model spreadsheet requiring manual copying between files, containing an operation that divided by a sum where it should have used an average. An influential economics paper was found to have excluded rows from a formula range. A public health agency lost roughly sixteen thousand case records because it used a file format with a row limit. None of these were exotic failures. They were the ordinary failure modes of unmanaged spreadsheets, occurring in organizations with substantial control functions.
Why It Is Getting Worse, Not Better
Three developments have increased the risk since 2007. Cloud ERP reduced customisation, which increased extraction. Modern platforms discourage modification, so the gap between what the system reports and what management wants is now bridged outside the system more often, not less. Self-service BI added a layer without removing one. Dashboards were built on top of the same spreadsheet logic, giving unreviewed calculations a professional presentation layer and wider distribution. AI assistants write formulas now. A generated formula that looks right and is never reviewed is exactly the failure mode the research describes, produced faster and with more confidence. The same applies to assistants that export data into new unmanaged files on request.
Closing the Gap Without Banning Excel
Prohibition does not work, because the spreadsheets exist to solve a real problem. Treat them as an inventory to be managed and a symptom to be diagnosed.
- Inventory the recurring ones. Anything that runs monthly and feeds a decision, a statement or a payment. Most finance teams find between fifteen and forty.
- Classify by consequence. What is the worst outcome if this is wrong — a misstated account, an incorrect payment, a regulatory filing? Rank by that, not by complexity.
- Fix the top five in the system. Each high-risk spreadsheet is a specific, documented reporting requirement. That is a better specification than any requirements workshop will produce.
- Control the ones that remain. Named owner, locked formula cells, input validation, version history in a managed location, a documented reconciliation back to the source system, and at least one person other than the author who can run it.
- Require independent review for changes to any spreadsheet in the high-consequence tier. This single control catches most material errors.
- Eliminate manual re-keying between files. Copy-paste between workbooks is the most reliable error source in the entire category.
- Set an expiry. Every high-risk spreadsheet gets a date by which it is retired into a managed report, or a written decision to keep it with controls. The strategic point is easy to miss: your shadow systems are the most accurate specification of your real reporting requirements that exists anywhere in the business. They document precisely what management needs and the system does not provide. Most organizations treat them as an embarrassment. They are better used as a roadmap.
Inventory
Find recurring spreadsheets that feed decisions, statements or payments.
Rank consequences
Prioritise the impact of an incorrect output rather than workbook complexity.
Replace or control
Move high-risk requirements into the system; assign ownership and reconciliation to retained files.
Review changes
Have someone independent review high-consequence changes and remove manual re-keying.
Set an expiry
Retire the file or record the decision to retain it with controls.
Qualitative summary of this article's source text, not a measured outcome or performance estimate.
Common Questions
What is a spreadsheet shadow system?
A spreadsheet that performs a function a business system should perform — recurring, business-critical, containing unique logic, and operating without change control, access control or documentation.
How risky are spreadsheets in financial reporting?
Research consistently finds errors in the majority of operational spreadsheets audited. The risk is not the tool; it is the absence of testing, review and version control that any equivalent application would require.
Should we ban spreadsheets in finance?
No. Ban unmanaged high-consequence spreadsheets. Excel remains the right tool for analysis, modelling and one-off work; it is the wrong tool for recurring processes that produce numbers other people rely on.
How do we know which spreadsheets to replace first?
Rank by consequence of error rather than by size or sophistication. A simple file that determines payments or feeds the statutory accounts outranks a complex model used for internal discussion.
Reporting Gap Assessment — Outpace inventories the spreadsheets your finance close actually depends on, ranks them by consequence of error, and converts the highest-risk ones into controlled reporting inside your systems.
