Compliance Unfiltered is TCT’s tell-it-like-it is podcast, dedicated to making compliance suck less. It’s a fresh, raw, uncut alternative for anyone who needs honest, reliable, compliance expertise with a sprinkling of personality.
Show Notes: Why Spreadsheets are the Biggest Risk to Your Compliance Program
Quick Take
On this week’s Compliance Unfiltered, Todd Coshow and Adam Goslin unpack why spreadsheets are one of the biggest risks to a compliance program.
They share real-world stories of version chaos, scattered evidence, and audit-day scrambling, then explain how a centralized system gives teams real-time visibility, better control, and confidence in their compliance status.
Read The Transcript
So let’s face it, managing compliance sucks. It’s complicated, it’s hard to keep organized, and it requires a ton of expertise in order to survive the entire process.
Welcome to Compliance Unfiltered, a podcast dedicated to making compliance suck less. Now, here’s your host, Todd Coshow, with Adam Goslin.
Todd Coshow:
Welcome in to another edition of Compliance Unfiltered. I’m Todd Coshow, alongside the new shiny chrome trailer hitch to your compliance pickup, Mr. Adam Goslin. How the heck are you, sir?
Adam Goslin:
I’m doing good. For some reason, I had truck nuts going through my brain at the moment. I’m thinking about, “I’m down south. I’m Baja-ing.”
Todd Coshow:
That’s fantastic. I don’t even know where to go from there, so I’m going to go ahead and say thank you to every single person who happens to be listening to this right now.
We appreciate your input, as well as your effort in listening to us and sharing some of your space in the compliance world.
If you have the desire to reach out to us and tell us how much you love truck nuts or other things, please feel free to do so at [email protected].
Adam Goslin:
Wait a second. I think I need to win an award for it. I’m not sure that on this pod I’ve managed to stymie you yet, but I’m glad that today was the day.
Todd Coshow:
That was great. Truck nuts indeed.
Today, we’re going to chat about the biggest risk, in my opinion, possibly in some other people’s opinion, to your compliance program, and that is, dun, dun, dun, the spreadsheet.
That’s right. The spreadsheet is the biggest risk to your compliance program. It’s almost as difficult as it is for me to say.
Now, Adam, if you were in the middle of your onsite and your assessor asked for specific evidence, how long would it take organizations to actually find it?
Adam Goslin:
If we’re talking about my engagement, how long would it take? Seconds.
But for a lot of people that are rocking off spreadsheets, longer than anybody wants to admit.
This goes back quite a ways, way back in the day when I was doing consulting before the existence of TCT and being forced to use that horrifying effing spreadsheet.
I was in some onsite sessions with clients where the assessor was like, “Go ahead and show me this.”
All of a sudden, it’s crickets. People are scrambling. They’re looking at their watch.
“Hold on a second. I think it’s over here.”
They go and look over there.
“Okay, I’ll find it. If it’s not there, it’s got to be over here. Give me a couple more minutes.”
No, it’s not there either.
“You know what? Evan knows exactly where it’s at. Give me one second.”
Ring, ring, ring, ring.
His phone went to voicemail.
“Anyway, look at the time. It’s 10:45 in the morning. Isn’t it about time we went and grabbed lunch?”
It was an effing nightmare.
A lot of people think that they know where things are until they’re under the gun and have to prove it.
If I’ve got to scan across email threads, shared drives, different versions of documents that exist in 18 different spots, Slack messages, text messages, voicemails, network shares, and whatnot, you’re not just stepping up to the plate and proving a control out. You’re trying to reconstruct history at that point in the game.
It’s astoundingly uncomfortable when the assessor is asking for stuff and you can’t just put your finger on it.
It really degrades their sense that the people they’re talking to actually have their act together.
Todd Coshow:
I can definitely appreciate that.
Spreadsheets are still everywhere in compliance, but why are they such a problem?
Adam Goslin:
Spreadsheets weren’t designed to manage living, breathing systems.
We’ve talked before about the levels of complexity that exist within these things.
A spreadsheet is static, and compliance isn’t.
There could be one or more compliance standards I’m going up against. The organization could have one or more locations they’re going up against. The organization could have one or more applications they’re going up against.
You could have workflows that flow from control owners to internal QA, over to a consultant, up to an assessor, to assessor QA, to complete. It could be in any of those states.
If I start multiplying all the cross-sections, with a spreadsheet, literally one poor soul has to manage the sheet if you want to try to keep anything sane.
The spreadsheet isn’t showing you what’s happening right now in your compliance program. It’s showing whatever the last person did that went and typed it in.
If I’m not the one actually updating it, then I can’t go look in the mirror and go, “Hey, buddy, you’ve got to get this thing updated.”
Now I’m begging Mary, let’s say, who’s in charge of updating the sheet, to make the updates.
Maybe the boss swings by at 6:00 p.m. asking, “Where are we at?”
Meanwhile, Mary’s gone for the day. Maybe the last time she updated it was two days before.
There’s no guarantee that it’s up to date or updated properly.
The spreadsheet gives you the feeling that you have control and that we’re covered, but there’s no guarantee.
That’s just the start of the problems with spreadsheets.
Todd Coshow:
It certainly is.
Let’s talk about version control, because that’s where things really start to break down.
Adam Goslin:
Version control is where compliance goes to die.
You have one called “final_V3,” and then you have “final_V7_updated,” and then you’ve got “final_V7_update_real,” and nobody knows which one’s right.
Different teams happen to be working off different versions. Nobody wants to stomp on each other’s updates.
Even if you’re using a shared sheet, like a 365 sheet where everybody can go in and update it, it doesn’t stop multiple people from blasting over each other’s updates.
The control owner sends the thing up, so they go in and update the status to, “This went to internal QA.”
Internal QA moved it up to their consultant. That went up to the assessor. The assessor rejected it.
Now the assessor wants some additional evidence, so I switch the status to, “This is in the control owner’s hands.”
Meanwhile, the internal QA department sees that the item has been switched back into the control owner’s hands, but they know they sent it up to the consultant, so they go in and update the status to “consultant review.”
It’s a nightmare, and we’re talking about one line item.
Nobody knows. That’s just on a shared effing sheet, let alone if people start peeling off versions of the sheet for their own purposes.
Then people start updating the wrong ones, and now you’ve got this divergence of stuff.
That’s a big part of the reason why most organizations end up running into all these effing problems and deal with all of the shortcomings of having one ring to rule them all.
It gets too chaotic.
If you’ve got multiple people going in and making these updates, even then, at best, the company has relegated one person to update the status sheet.
Well, guess what? The assessor has a completely different status update sheet, which doesn’t synergize with yours.
Now we’ve got at least two different organizational spreadsheets for the same engagement about who’s doing what and where it’s at.
You don’t have a single source of truth. You have a multitude of competing versions of the truth.
Now you’re back to herding the compliance cats and trying to mitigate confusion on the engagement.
It’s an absolute nightmare whenever you’ve got to go through and do that.
Todd Coshow:
It sounds that way.
How does that impact evidence collection and audit readiness?
Adam Goslin:
Basically, it’s almost like a forced fire drill every single time.
The evidence is scattered and sprinkled all over the place: email, SharePoint, somebody’s desktop, a ticketing system.
The auditor pops up and says, “Show me proof of this,” and all of a sudden it’s a mad scramble.
Did the team, in advance of the onsite, preserve the evidence? Did they put a comment into the spreadsheet that’s pointing to this particular piece of evidence sitting over here? When was the last time they took it? Who grabbed it?
It all becomes a challenge as you’re going through that process.
It’s point-in-time evidence, but it doesn’t show you any type of proof of a continuous control, unless you start getting into the game of versioning documents with dates in them as you were gathering them across the course of the engagement.
You’re just showing that, at a certain point in time, something existed, but you’re not showing that the thing is continuously operating.
All the way around, it’s a problem.
Todd Coshow:
Sounds that way.
What’s the real risk here? A lot of teams would say, “Yeah, it’s messy, but we’ll still pass.”
Adam Goslin:
The risk is false confidence.
I would say there are several risks, not the least of which is the poor person you nominated to manage this freaking hellhole of a spreadsheet.
They’re actively going out of their damn mind for about three months, trying to keep up desperately with the workload they have to go through.
The uppity-ups, as I like to call them, are all, “We passed the audit, so let’s just go into the guiding assumption that everything worked.”
The reality is that they have false confidence in this obnoxiously horrifying process that they’re invoking by making people choke on a spreadsheet.
You’ve got controls that are either broken, outdated, or inconsistently applied, and you wouldn’t know.
Your spreadsheets aren’t going to jump up and alert you that there’s an issue.
They aren’t doing any form of interim validation. They’re not telling you when something is drifting off course.
You’re operating in a vacuum.
You’ve got this document from last November that says you passed the audit.
When you’re doing it with a spreadsheet and trying to manage a single individual engagement for their annual hoop diving, that’s its own process.
Trying to do that in some form of operational mode with a spreadsheet adds about 40 times more complexity to the spreadsheet, which already isn’t working.
It is a challenge that many compliance teams, unfortunately, have had to face, stare down, and gulp once they get into the process.
Todd Coshow:
I guess the critical question is: what does it actually look like to fix this? What replaces the first spreadsheet?
Adam Goslin:
Coming from somebody who used to do this, which is why I realized just how effing painful it is, you need a system to replace it.
You don’t need snapshots of reality. I just want to be able to go in and see what’s going on with my engagement.
What do you need? You need centralized visibility.
You need real-time or near-real-time shots of evidence.
You need your system set up in an operational compliance mode, where you are literally up to speed on not only preparation for the annual recertification activities, but also making absolutely certain that you’re staying on track with all of your operational compliance requirements.
You’ve got to make sure that you’ve got monitoring of your various controls, not just documentation that says you’re doing it.
Most importantly, it means that you can answer the question at any point in the game: are we compliant right now?
You can answer that question when you’re leveraging a system.
In the past, using spreadsheets and annual processes, your only choice was to hunt people down, chase them down, and collect evidence to answer the question.
Just getting that answer is going to require a week of digging.
If that’s the case, you’re not in control of your program. You’re playing catch-up.
You’ve got to get to the point where you have systematic capabilities to leverage.
It’s a game changer for organizations once they ditch the spreadsheet and use some technology.
Todd Coshow:
Parting shots and thoughts for the folks this week, Adam.
Adam Goslin:
Keep in mind that all of this is coming from real-world, firsthand experience of having to go through and do this.
I mentioned the uppity-ups earlier.
For those people, we’ve done so many things on the cost of spreadsheets. I just want to grab the uppity-up and shake them.
You are causing an astounding amount of pain for your team if you’re forcing them to continue using spreadsheets.
You are giving up the opportunity to save so many brain cells and so much time, and greatly mitigate the chances that your central figure who manages your compliance annually is either going to have an embolism or throw in the towel as they’re going through the process.
Quite frankly, it is a game changer.
When we created the TCT Portal, it’s a single pane of glass.
It allows literally anybody on the team to go in and see the reality of the current state instantly.
I know exactly where everything is.
Is this item still in Frank’s hands? They asked him to get it done last week. I can just go look it up.
Have we been keeping up with our operational compliance stuff? I can go look it up.
The uppity-up who comes swinging by the desk at 4:35 in the afternoon on a Friday and says, “Are we compliant right now?”
You can pull up the interface and go, “Yeah,” “No,” or whatever.
You’ve got it all there at your fingertips.
All of that complexity and spread of information is boiled down to a single location, a single system.
It helps your newbies get up to speed.
If you have any personnel turnover, it’s easy to tell what the predecessor had done, reference it, review it, and know precisely what evidence they passed in the last time.
Trying to do those types of functions with the old-school way of doing it, a SharePoint or a file server with a spreadsheet, is 18 dimensions of hell.
The more that I can implore folks to move away from the dark side, the better.
Todd Coshow:
And that right there, that’s the good stuff.
That’s all the time we have for this episode of Compliance Unfiltered. I’m Todd Coshow.
Adam Goslin:
And I’m Adam Goslin.
Todd Coshow:
Hope we helped to get you fired up to make your compliance suck less.