Excel can run an important business process for years without appearing on a risk register. The licence is already paid for, the team knows the workbook and no large project has been approved. That can make the process look inexpensive.
Its real cost may be spread across time spent checking versions, correcting entries, preparing reports and covering for the one person who understands the formulas. Its risk may sit in events that have not happened yet: the wrong price sent to a customer, a missed renewal or confidential data shared too widely.
None of this means Excel is inherently unsafe. A well-owned workbook used by a small, skilled team can be entirely appropriate. The question is whether the controls around a particular business process still match its importance.
Measure the work around the workbook
Begin with observation rather than a replacement proposal. For four normal working weeks, keep a simple log of the effort and incidents connected with the process.
Record time spent finding the current file, combining copies, repairing formulas, rekeying information, answering status questions and producing routine reports. Include interruptions to the workbook owner as well as scheduled work. If six people each spend 20 minutes a week checking and reconciling figures, that is two hours of hidden effort before any mistake occurs.
Then record incidents and near misses. A near miss might be an old price list caught just before issue, a row restored after accidental deletion or an approval completed without all the required information. Note the practical consequence, who had to resolve it and how long resolution took. Avoid inventing a financial value where none can be supported; elapsed time and delayed decisions are still meaningful evidence.
This measured approach separates an occasional nuisance from a repeated operating cost.
Version uncertainty creates decision risk
The obvious sign is a collection of files with names such as Master FINAL 4.xlsx. The less visible risk is that people stop trusting the information. Managers ask for a manual confirmation, staff keep private backup copies and reporting acquires an extra checking day.
One official workbook in SharePoint or OneDrive, with clear ownership and co-authoring enabled, may remove this risk. If editable attachments continue because users cannot reach or comfortably use the shared file, the process still lacks central data in practice. A focused change to how spreadsheet copies are shared is a sensible first intervention.
Measure the number of editable copies created, the time spent reconciling them and the age of the data used for key decisions.
Person dependency threatens continuity
Many operational workbooks contain knowledge that is not visible in the cells. One colleague knows which tab to refresh first, why March is handled differently and what a red cell really means. Their expertise keeps the process working, but annual leave, illness or departure can expose the weakness very quickly.
Test continuity in a controlled way. Give the written instructions and a safe copy to a suitably experienced colleague who does not normally run the process. Note where they need help and whether they can produce the expected result. The purpose is not to catch anyone out. It is to find undocumented rules while the expert is available to explain them.
Better guidance, clearer labels and fewer hidden steps may be enough. If the task cannot be completed without interpreting one person's judgement at numerous points, those decisions need to be made explicit before any software change.
Broad file access can expose the wrong information
A person who needs to update one column may receive the whole workbook. Hidden sheets and locked cells help prevent accidental edits, but they do not provide the same control as giving each role access only to the records and actions it needs.
List the people who can currently open the file and mark which information each role genuinely needs. Pay particular attention to personal details, commercial rates, payroll-related information and approval rights. Also note how quickly access is removed when somebody changes role or a contractor finishes.
This exercise often reveals two separate risks: too many people can see sensitive information, while too few can complete the work without asking the owner. A web app can address both by supporting multiple users against central data with role-based permissions. It only helps if those permissions are designed and reviewed properly.
Manual handovers hide delay and missed work
Spreadsheets can record a status, but they do not necessarily make the next action visible. A row marked “Ready for approval” may wait until somebody emails the manager. Remote staff may update a local copy and send it when they return to the office. Customers and colleagues then chase for an answer because nobody can see where the work has stopped.
Choose a sample of records and measure the time between stages: received, checked, approved, completed and reported. Compare active working time with waiting time. If most of the delay sits between people, faster formulas will not solve it.
A shared web app can show a queue of outstanding tasks, support access from a phone or remote location, and notify the right person when action is due. It can also prevent incomplete records moving forward. These are practical workflow controls, not a promise that every delay will disappear.
Weak history makes errors expensive to investigate
When a figure is challenged, the business may need to know who entered it, whether it was later changed and who approved the outcome. Emails, file properties and remembered conversations can sometimes reconstruct the answer, but the investigation consumes time and may still leave uncertainty.
Track how long it takes to answer one real change-history question. If the process carries financial, contractual or regulatory significance, agree what evidence should be retained. Excel's version history and an approval register may meet a modest requirement. For a busier process, an application can keep a dated history of important actions alongside each record.
An audit trail is not a substitute for governance. Somebody must still decide what should be recorded, how long it should be kept and who may view it.
Reporting effort can conceal poor data quality
A monthly report that takes a day to prepare is not necessarily sophisticated. The time may be going into standardising dates, removing duplicate rows and filling gaps before the numbers can be trusted.
Measure preparation separately from analysis. Preparation is the work needed to make the data usable; analysis is the work that produces insight. A rising preparation figure suggests the input process lacks sufficient checks or consistency.
Excel validation, protected formulas and a cleaner input sheet may improve matters. A web app can go further by requiring key information, using agreed choices and keeping all users on the same current records. Either way, the objective is to catch problems when data is entered rather than just before the board pack is due.
Slowness and fragility have an operational cost
Long opening times, calculation pauses and broken links waste time, but they also change behaviour. Users avoid saving, keep local copies or postpone updates until the workbook is quiet. That increases the version and reporting risks described above.
Log waiting time and failures before assuming the workbook must be replaced. Formula and file improvements may produce a large benefit; the guide to a slow Excel workbook covers the common causes. Replacement becomes more relevant when performance problems are tied to many simultaneous users, growing records and a process that needs to be available throughout the day.
Turn the evidence into a proportionate decision
Summarise the month on one page: hours of avoidable administration, incidents and near misses, average waiting time between stages, access concerns, report preparation time and reliance on key individuals. Add the expected effect of growth, such as another branch or twice as many weekly submissions.
Three outcomes are reasonable. Keep Excel where the risk is low and the workbook is doing analysis or light tracking well. Improve it where ownership, sharing, validation or documentation would address the measured problem. Consider moving the operational process to a supported web app where central multi-user access, precise permissions, workflow steps, mobile use and reliable history are now business requirements. Excel can remain available for modelling and exports.
If your evidence points in different directions, an assessment can review the workbook and surrounding process before you commit to a build. The important result is a proportionate decision based on observed cost and risk, not a judgement about whether Excel is old-fashioned.
