Scorecard

Spreadsheet risk self-assessment

Seven scored rows, one column per workbook, a total that fills itself, and the decision the score forces — working file or system of record — with an inventory tab to carry the action, owner and date.

A spreadsheet used informally is not non-compliant. Once it is the operational system of record it has to carry weight it was never built to carry, and the regulations that apply — Part 11, §211.68, §211.194, Annex 11, the MHRA data-integrity guide — never mention Excel; they describe a computerised system that creates or holds GxP records. This workbook scores each file you still rely on against the seven mechanisms in why spreadsheets fail in regulated quality systems: the unofficial copy that is the real original, the formula nobody validated, the logic anyone can change, the version history that is a filename, the approval that lives in an inbox, the training and change records that don't share a story, and the trail that isn't there. Then it asks the only question that matters — is this a working file or a system of record? — and tells you whether the file is acceptable as it stands.

Free · Excel workbook · unlocks in seconds
Complere vs spreadsheets
Spreadsheet risk self-assessment — the Excel workbook you download, showing the seven breaks and one scored column per workbook

What the assessment covers

The workbook has three tabs. An Instructions tab explains the scoring, the four-line test for working file versus system of record, and the clauses each break maps to. The Scoring tab is the matrix: seven rows, one per break, each with what to look for and where it sits in the regulations, and four columns for the workbooks under assessment — score each break 0 (the control exists and is evidenced), 1 (informal or partly in place) or 2 (absent). The total fills itself; the row beneath it asks what the file is for; the verdict row reads both and tells you whether the file is acceptable as it stands. The Inventory tab is the register: one row per workbook that holds GxP data, with what it holds, the decision made from it, its role, its total, the action, an owner and a date.

  • The unofficial copy is where the truth was — is this file the first capture, with an "official" form transcribed from it?
  • The formula is the method — specified, tested across its range, protected, and the check recorded?
  • Anyone who can open it can change the logic — who can edit, and can a paste-over silently replace a formula?
  • Version history is a filename; approval lives in the inbox; training, change and the tracker don't share a story
  • There is no trail to review — file-level "last modified" and Track Changes are not a computer-generated, cell-level audit trail

How to use it

List the workbooks first. The Inventory tab wants a row for every file that still holds GxP data — the stability tracker, the training matrix, the deviation log, the assay calculation — with its owner, what it holds and what decision is made from it. Then take them four at a time onto the Scoring tab and score each break from the dropdown. Scores are evidence-based: 0 only where the control can be shown, not where someone believes it exists.

The decision row is the post's own distinction. A working file is a calculation you can reconstruct from the raw data, a personal analysis discarded after the decision, a one-off extract from a governed system — one author, short life, nobody else depends on it. A system of record is where current status lives, what people approve against, what an inspector is handed — shared and enduring. Excel is excellent at the first column. A system of record scoring above zero is not acceptable as it stands: migrate it to a governed system, or apply compensating controls with QA approval and a date to revisit. Carry the total, the role and the action back to the Inventory tab. Pair it with the data integrity (ALCOA+) checklist for the system you migrate to, and the audit trail review checklist once there is a trail to review.

How an inspector reads this

An inspector does not ask whether you use Excel. They pick a result that supported a quality decision and ask where the number came from, who could have changed the formula, which version was in force on the date, who approved it, and where the trail is. §211.68(b) already describes the unlocked formula cell — changes only by authorised personnel, input and output checked for accuracy — without waiting for Part 11; §211.194(a)(5) wants a record of the calculations and (a)(8) a second person's review; §11.10(e) wants a secure, computer-generated, time-stamped audit trail when the workbook is the electronic record; Annex 11 clause 9 wants GMP-relevant changes and deletions recorded with reasons and reviewed; the MHRA guide says electronic worksheets are version controlled and data transferred into them is not altered and carries a trail of the transfer. FDA warning letters have cited unvalidated spreadsheets used to calculate assay results and cell formulas that produced impossible values.

A file that opens and calculates can fail every row of this sheet. The cost of "free" arrives as QA labour — reconstructing which version was in force, chasing the approval email, joining three lists by hand — and it arrives during the inspection. The scoring is there to find it before then.

Frequently asked questions

Do spreadsheets need to be validated under Part 11?

Part 11 is an electronic-record regulation, not a spreadsheet regulation. If a predicate rule requires the record and you keep it in a workbook, §11.10 applies — validation, accurate and complete copies, retention, limited access and a computer-generated audit trail, which native Excel does not produce at cell level. §211.68 applies before Part 11 does: authorised changes and checked input and output already describe the unlocked formula cell, and §211.68(a) treats a calculating workbook as equipment to be checked.

What is the difference between a working file and a system of record?

What the file is for. A working file is a calculation you can reconstruct from the raw data, a personal analysis discarded after the decision, a one-off extract from a governed system — one author, short life. A system of record is where current status lives, what people approve against and what an inspector is handed. The assessment scores every workbook the same way but only a system of record scoring above zero fails the verdict.

What can compensating controls do, and where do they stop?

Locked cells, a controlled template, a review signature on a printout and a documented transfer check each close part of a break, and the verdict row accepts a system of record only when they bring the score to zero with evidence. They stop where the mechanism does: no procedure gives a native workbook a computer-generated, cell-level trail of who changed what and why, and a filename cannot become a revision history. Those two rows are where migration is the control.

Bring the highest-scoring workbook to a demo

Book a demo and walk the file that scored worst through Complere — who changed which value and when, the approval on the record against the version in force, the calculation and its review in one place — so the verdict on the sheet becomes a plan with a date.