Control deficiencies from bypassing designated workforce record platforms
- The most recurrent deficiency when designated workforce record platforms are bypassed is authoritative-source and lineage failure, because exports, copied workbooks, and copied presentation content detach the working artifact from the source record that should remain authoritativeSettlements (2013)Microsoft (n.d.)Mitchell (2026)
- Incomplete auditability and non-repudiation are the next most common deficiencies, because materially relevant edits in Excel and PowerPoint can occur outside a complete retained trail of actor, prior value, revision type, and review outcomeTechnology (2020)Microsoft (n.d.)Microsoft (n.d.)
- Weak change control is a common downstream deficiency, because shadow artifacts allow undocumented assumptions, manual workarounds, and local edits to bypass approved change decisions, validation expectations, and retained change recordsTechnology (2020)Settlements (2013)Deloitte (n.d.)
- Inventory, ownership, and access governance deficiencies recur because business-user tools outside the central technology framework are harder to discover, classify, assign, permission, and monitor as controlled process componentsDeloitte (n.d.)Intrenion (2019)Technology (2020)
- Data-quality degradation is a common deficiency, because manual reconciliation, manual adjustments, one-way refresh paths, and inconsistent underlying data can directly distort reports and decisions and can also slow themBank (2024)Settlements (2013)Microsoft (n.d.)
- Operational-resilience weakness is also common, because spreadsheet and presentation bypasses concentrate process knowledge, prolong manual compilation, and make control execution more fragile during staff turnover, stress events, or urgent management requestsSettlements (2021)Settlements (2013)Deloitte (n.d.)
- The same six deficiency classes align strongly across Basel Committee on Banking Supervision, National Institute of Standards and Technology, and European Central Bank control surfaces, and accessible Control Objectives for Information and Related Technologies materials place them in compatible data, change, business-control, and compliance categoriesSettlements (2013)Technology (2020)Bank (2024)Intrenion (2019)
- Severity rises when the bypassed artifact informs access, staffing, attestations, or risk reporting, because the same local workaround then affects privacy, accountability, governance, and operational-resilience outcomes beyond the immediate teamSettlements (2021)Bank (2024)National (n.d.)
Research Question
What control deficiencies are most common when designated workforce record platforms are bypassed by spreadsheet, presentation, and list-based shadow workflows?
Findings
Executive Summary
Bypassing designated workforce record platforms most commonly produces six recurring control deficiencies: broken authoritative-source and lineage control, incomplete audit evidence and non-repudiation, weak change control, incomplete inventory and ownership governance, data-quality drift from manual reconciliation, and resilience weakness from manual and key-person dependence.
These deficiencies are common in this item's sense because they recur across the three shadow artifact types and across both framework and practitioner sources. This item does not claim that one public survey provides a single universal ranking for workforce shadow workflows.
The highest-impact deficiency is the loss of a single authoritative record, because once copied artifacts become working records, integrity, completeness, reconciliation, and reviewability degrade together.
Severity rises further when the shadow workflow informs access, staffing, attestations, or risk reporting, because the same local bypass then affects enterprise governance and operational resilience.
Key Findings
- The most recurrent deficiency when designated workforce record platforms are bypassed is authoritative-source and lineage failure, because exports, copied workbooks, and copied presentation content detach the working artifact from the source record that should remain authoritative.
- Incomplete auditability and non-repudiation are the next most common deficiencies, because materially relevant edits in Excel and PowerPoint can occur outside a complete retained trail of actor, prior value, revision type, and review outcome.
- Weak change control is a common downstream deficiency, because shadow artifacts allow undocumented assumptions, manual workarounds, and local edits to bypass approved change decisions, validation expectations, and retained change records.
- Inventory, ownership, and access governance deficiencies recur because business-user tools outside the central technology framework are harder to discover, classify, assign, permission, and monitor as controlled process components.
- Data-quality degradation is a common deficiency, because manual reconciliation, manual adjustments, one-way refresh paths, and inconsistent underlying data can directly distort reports and decisions and can also slow them.
- Operational-resilience weakness is also common, because spreadsheet and presentation bypasses concentrate process knowledge, prolong manual compilation, and make control execution more fragile during staff turnover, stress events, or urgent management requests.
- The same six deficiency classes align strongly across Basel Committee on Banking Supervision, National Institute of Standards and Technology, and European Central Bank control surfaces, and accessible Control Objectives for Information and Related Technologies materials place them in compatible data, change, business-control, and compliance categories.
- Severity rises when the bypassed artifact informs access, staffing, attestations, or risk reporting, because the same local workaround then affects privacy, accountability, governance, and operational-resilience outcomes beyond the immediate team.
Assumptions
- Public sources are sufficient to rank recurring deficiency classes even though they do not provide a single workforce-specific census with one universal numeric ranking.
- The workforce artifacts in view influence consequential decisions such as access, staffing, attestation, or reporting; otherwise the same deficiencies would still exist but some severity judgments would weaken.
Analysis
The evidence was weighted toward primary framework language for control classification and toward Microsoft product documentation for mechanism detail.
The ranking gives first place to authoritative-source and lineage failure because it simultaneously destabilizes source authority, reconciliation, completeness, and downstream reviewability, which then drives the other deficiencies.
Incomplete auditability and data-quality degradation were ranked next because National Institute of Standards and Technology controls and European Central Bank supervisory findings both show that weak evidence and weak data quality directly impair consequential decisions.
Weak change control, incomplete inventory and ownership governance, and resilience weakness were treated as tightly coupled but slightly downstream classes, because they are frequently the conditions that allow the authoritative-source, audit, and data-quality failures to persist unchallenged.
A spreadsheet-error-only reading is incomplete, because the cross-framework evidence shows that bypassed artifacts also weaken source authority, evidence retention, governed change, and recoverability at process level.
Risks, Gaps, and Uncertainties
- Public sources do not provide a single workforce-specific prevalence dataset that numerically ranks these six classes across all enterprises, so the ranking in this item is a synthesis built from multiple framework, product, and practitioner sources.
- Control Objectives for Information and Related Technologies public access is summary-level, so the COBIT contribution here stays at objective-level categorization and does not reach clause-level process-practice quotation.
- Microsoft documentation explains product behaviour but does not itself quantify how often firms misuse the features in workforce governance settings, so recurrence judgments rely partly on practitioner and supervisory synthesis.
Open Questions
- Which public control frameworks best define quantitative escalation thresholds for when a workforce shadow artifact must be re-platformed back into the designated source system?
- Which detective controls most reliably identify when a copied spreadsheet or presentation has become the real working record?
- How should the ranking change when the bypassed workforce artifact is read-only reference material instead of a write-capable decision artifact?
sources
- [x] Bank for International Settlements (2013) Principles for effective risk data aggregation and risk reporting - primary Basel Committee on Banking Supervision (BCBS) framework for governance, accuracy, completeness, timeliness, and adaptability
- [x] Bank for International Settlements (2021) Principles for the sound management of operational risk - primary operational-risk framing for failed processes, people, and systems
- [x] European Central Bank (2024) Guide on effective risk data aggregation and risk reporting - supervisory evidence on persistent manual-adjustment, reconciliation, and data-quality weaknesses
- [x] National Institute of Standards and Technology (2020) Security and Privacy Controls for Information Systems and Organizations - primary control catalog for Audit and Accountability, Configuration Management, System and Information Integrity, and Continuous Assessment mappings
- [x] National Institute of Standards and Technology (2018) Risk Management Framework for Information Systems and Organizations - governance and accountability linkage between system controls and mission or business use
- [x] National Institute of Standards and Technology Glossary provenance - authoritative provenance definition
- [x] National Institute of Standards and Technology Glossary system of records - governance definition for identifier-linked record collections
- [x] Control Objectives for Information and Related Technologies resources - official Control Objectives for Information and Related Technologies (COBIT) framework landing page
- [x] Intrenion Control Objectives for Information and Related Technologies 2019 processes - accessible process list for Managed Data, Managed Information Technology Changes, Managed Business Process Controls, and Managed Compliance With External Requirements
- [x] Microsoft Support Export to Excel from SharePoint or Lists - one-way export behaviour and downstream disconnect from the source list
- [x] Microsoft Support View previous versions of Office files - version-history scope for Excel and PowerPoint
- [x] Microsoft Support Get help with Show Changes in Excel - unsupported edits, clearing conditions, and previous-value limits in Excel change history
- [x] Microsoft Support Work together on PowerPoint presentations - collaboration, revision-highlighting limits, and storage conditions for PowerPoint revision data
- [x] Deloitte Australia Analytics, automation and spreadsheets: Who's in control? - control and governance signals for business-user tools outside the central technology framework
- [x] Deloitte United Kingdom Spreadsheet controls: are your spreadsheets exposing your organisation to unmitigated risks? - recurring spreadsheet-control deficiency patterns, including accountability, testing, lifecycle, and knowledge concentration
- [x] European Spreadsheet Risks Interest Group (EuSpRIG) Research and Best Practice - research summary on spreadsheet error prevalence and common spreadsheet-risk categories
- [x] Mitchell (2026) Basel Committee on Banking Supervision, International Organization for Standardization, and National Institute of Standards and Technology: classifying shadow workforce-system risk - adjacent completed item that classifies shadow workforce systems as a cross-framework control surface
- [x] Mitchell (2026) National Institute of Standards and Technology Special Publication 800-53: provenance gaps in workforce shadow artifacts - adjacent completed item on provenance and change-history gaps in Microsoft Lists, Excel, and PowerPoint