On this week's Compliance Unfiltered, Todd Coshow and Adam Goslin unpack why spreadsheets are one of the biggest risks to a compliance program. They share real-world stories of version chaos, scattered evidence, and audit-day scrambling, then explain how a centralized system gives teams real-time visibility, better control, and confidence in their compliance status.

Episode Tracking:

Today, we’re going to chat about the biggest risk, in my opinion, possibly in some other people’s opinion, to your compliance program, and that is, dun, dun, dun, the spreadsheet.

That’s right. The spreadsheet is the biggest risk to your compliance program. It’s almost as difficult as it is for me to say.

Now, Adam, if you were in the middle of your onsite and your assessor asked for specific evidence, how long would it take organizations to actually find it?

Adam Goslin:
If we’re talking about my engagement, how long would it take? Seconds.

But for a lot of people that are rocking off spreadsheets, longer than anybody wants to admit.

This goes back quite a ways, way back in the day when I was doing consulting before the existence of TCT and being forced to use that horrifying effing spreadsheet.

I was in some onsite sessions with clients where the assessor was like, “Go ahead and show me this.”

All of a sudden, it’s crickets. People are scrambling. They’re looking at their watch.

“Hold on a second. I think it’s over here.”

They go and look over there.

“Okay, I’ll find it. If it’s not there, it’s got to be over here. Give me a couple more minutes.”

No, it’s not there either.

“You know what? Evan knows exactly where it’s at. Give me one second.”

Ring, ring, ring, ring.

His phone went to voicemail.

“Anyway, look at the time. It’s 10:45 in the morning. Isn’t it about time we went and grabbed lunch?”

It was an effing nightmare.

A lot of people think that they know where things are until they’re under the gun and have to prove it.

If I’ve got to scan across email threads, shared drives, different versions of documents that exist in 18 different spots, Slack messages, text messages, voicemails, network shares, and whatnot, you’re not just stepping up to the plate and proving a control out. You’re trying to reconstruct history at that point in the game.

It’s astoundingly uncomfortable when the assessor is asking for stuff and you can’t just put your finger on it.

It really degrades their sense that the people they’re talking to actually have their act together.

Todd Coshow:
I can definitely appreciate that.

Spreadsheets are still everywhere in compliance, but why are they such a problem?

Adam Goslin:
Spreadsheets weren’t designed to manage living, breathing systems.

We’ve talked before about the levels of complexity that exist within these things.

A spreadsheet is static, and compliance isn’t.

There could be one or more compliance standards I’m going up against. The organization could have one or more locations they’re going up against. The organization could have one or more applications they’re going up against.

You could have workflows that flow from control owners to internal QA, over to a consultant, up to an assessor, to assessor QA, to complete. It could be in any of those states.

If I start multiplying all the cross-sections, with a spreadsheet, literally one poor soul has to manage the sheet if you want to try to keep anything sane.

The spreadsheet isn’t showing you what’s happening right now in your compliance program. It’s showing whatever the last person did that went and typed it in.

Podden och tillhörande omslagsbild på den här sidan tillhör Total Compliance Tracking. Innehållet i podden är skapat av Total Compliance Tracking och inte av, eller tillsammans med, Poddtoppen.