Skip to content

Enterprise EUC Risk: The Excel Problem Nobody Fixes

Excel estate triage Coherent

In brief:

  • End-user computing (EUC), also called user-developed applications (UDA), covers the tools business users build outside formal IT governance: spreadsheets, Access databases, scripts, low-code apps, and increasingly AI-generated logic.

  • The exposure is documented. The most widely cited industry estimate remains Chartis Research's 2016 calculation of USD 12.1 billion in one-year EUC value at risk across the 50 largest financial institutions, and audit research consistently finds errors in roughly nine of ten operational spreadsheets.

  • AI adoption is growing the EUC population faster than manual governance can register it. Every AI productivity win widens the governance gap.

  • Banning spreadsheets doesn't work. The practical path is governing the logic in place: know what exists, control how it changes, and generate the evidence at the moment the control operates.

EUC, or end-user computing, has been around for decades. But lately it's become one of those topics that keeps showing up in boardrooms and audit committees, particularly in financial services and insurance.

The reason is simple: employees have been building their own tools for years, and most organizations can't prove how much risk is sitting inside those files.

Here's what EUC actually is, why it's a headache, and what can be done about it.

What is EUC?

EUC refers to applications and tools that employees create or maintain outside formal development processes. Risk and regulatory frameworks sometimes use the equivalent term user-developed applications (UDA), particularly in banking.

The most common EUC culprit is Microsoft Excel. Employees across every function use it for modeling, calculations, scenario testing, reporting. If there's a business process that needs to happen and IT has a six-month backlog, someone is going to build it in a spreadsheet. That's not a guess. That's just how organizations work.

The category is broader than spreadsheets, though, and it's widening. A modern EUC estate includes VBA and macros, Access databases and user-written SQL queries, automation scripts, low-code apps and flows built in tools like Power Apps and Power Automate, and now logic generated or modified with AI assistance. What defines an EUC is the lifecycle, business-built, business-maintained, outside IT's change controls, and the governance obligation attaches to the logic, whatever the file type.

And honestly, these tools exist for good reason. They help people move faster without waiting on overstretched IT teams or grinding through procurement. For power users in financial institutions, that could mean running complex pricing analyses, building underwriting models, or stress-testing data scenarios on their own timeline.

But those same tools almost never have version control, formal testing, audit trails, or security oversight.

Why is EUC such a challenge?

The low-code and no-code movement poured fuel on this fire, and AI-assisted development has poured on more. Tools that used to require a developer now come with drag-and-drop interfaces or a prompt box anyone can use. That's great for productivity. It's less great for governance.

Here's where the risk builds up:

  • No governance over the logic. Logic built in spreadsheets and local apps often isn't documented, reviewed, or stored centrally. When the person who built it leaves, the knowledge walks out the door with them.

  • No audit trail. Decisions driven by spreadsheet outputs may not be traceable. For regulated firms this is a compliance exposure with real teeth. When an examiner asks how a number was produced, the answer starts with "we believe" instead of "we can show you."

  • No formal testing. These tools rarely go through any kind of QA. Errors can sit undetected for months. Sometimes years.

  • Human error under pressure. Tight deadlines and reporting demands are exactly the conditions where mistakes in manually maintained files are most likely, and most costly.

  • Security gaps. Files are often unencrypted, shared over email or chat, and stored wherever is most convenient rather than most secure.

None of this makes EUC tools inherently bad. They fill a real gap. But without controls around them, they quietly become one of the largest sources of operational risk in an organization.

How big is the exposure?

Bigger than most inventories suggest, and externally documented.

The most widely cited industry estimate remains Chartis Research's 2016 calculation: USD 12.1 billion in aggregate one-year EUC value at risk across the world's 50 largest financial institutions. It is a standing estimate rather than a measure of current exposure, and no comparable independent update exists. What has changed since it was calculated is the scope underneath it: the tool population it measured has only broadened as low-code applications, automation scripts, and AI-assisted development have joined the spreadsheet.

The error research is just as consistent. Decades of spreadsheet audit studies (Panko) repeatedly find that roughly nine in ten operational spreadsheets contain at least one error. Recent history supplies the headline cases: a multi-billion-dollar trading loss traced in part to a copy-and-paste error in a risk model, and a formatting error that left a bank holding contracts it never intended to buy.

The exposure is documented. What most organizations lack is a scalable way to govern it.

Why is Excel always at the center of this?

Because Excel might be the most versatile data tool ever created. It's been a fixture in nearly every company on the planet since 1985, and it's earned that position.

Its superpower is accessibility. Someone can go from tracking monthly expenses to building a sophisticated underwriting model, a regulatory reporting tool, or a back-testing framework, all within the same application. No deployment process. No code review. No permission needed.

Which is also exactly the problem.

Excel was never designed to be an enterprise application platform. It has no built-in version control, no audit logging worth mentioning, and no native testing framework. Files, often unencrypted, get copied, emailed, saved to shared drives, and edited by multiple people with no clear record of what changed, when, or by whom.

For any company, that's a concern.

For financial institutions, where spreadsheet outputs can feed directly into regulatory filings, pricing decisions, and risk assessments, it's a material one.

People love to complain about Excel, but the reality is more nuanced: it's both indispensable and dangerous. You can't get rid of it. You have to govern it.

AI is growing the estate faster than governance can register it

There's a newer accelerant. Enterprise rollouts of AI assistants are increasing the speed and volume at which business users create or modify logic: local files, prompts, and agent-built automations, most of which never touch a register.

The external numbers are stark. Gartner reported in late 2025 that 69% of organizations suspect or have evidence that employees are using prohibited generative AI tools, and Netskope's 2026 research found that 47% of workplace generative AI users still work through personal, unmanaged accounts. Gartner separately predicts that more than 40% of enterprises will experience shadow-AI-linked security or compliance incidents by 2030.

The irony is that many of these same organizations are standing up control planes for their newest automation class—AI agents—while the oldest and largest class of user-developed logic—the spreadsheet estate—still runs ungoverned.

AI governance and EUC governance are connected disciplines: wherever AI-generated logic enters business-controlled tools, it needs the same ownership, change, review, and evidence controls as the rest of the estate.

AI assists the file. Governance still has to control the estate.

How can organizations address EUC risk?

Not by banning spreadsheets. That's been tried. It doesn't work.

The practical path is systematic governance layered on top of the tools people already use.

That means:

  • Clear policies for how employees adopt and use EUC tools: what's allowed, what needs review, and where the boundaries are. Most regulated institutions already have the policy; the gap is operating it at the scale of the estate.

  • A register that can be defended. Most firms maintain an EUC or UDA inventory, but a register captures what the institution remembers to list. The difference between a list and a control record is whether each entry is classified, risk-tiered, ownership-assigned, and assessed against the policy, with a controlled process for adding what's newly identified.

  • Documentation standards for logic that drives business decisions. If a spreadsheet feeds into pricing or regulatory reporting, the logic inside it needs to be reviewable by someone other than the person who built it.

  • A transparent path to formal development for when a spreadsheet outgrows its original purpose. Every organization has that one file that started as a quick calculation and is now load-bearing infrastructure. There needs to be a clear process for graduating those tools into something properly governed.

For organizations thinking about citizen development more broadly, Noel Carroll's whitepaper on Shell's approach to "DIY Development" is a solid read. It covers how Shell brought citizen development inside their enterprise governance framework rather than trying to stamp it out.

But the harder, more specific question remains: what do you do about the EUCs that already exist, the ones running critical processes today, right now, without proper controls?

How Coherent approaches EUC governance

Coherent governs business-critical logic in place. Business owners keep working in Excel, and the workflow changes by a submit button rather than a platform migration, while the estate gains the controls and evidence that enterprise systems take for granted.

The approach runs on a consistent mechanism. The platform builds a structural understanding of each workbook first, parsing formulas, dependencies, and embedded code into an explicit model of how the file computes, so any AI reasoning that follows works from the model behind the cells rather than the cells alone. Assessments run against the institution's own EUC policy, with per-answer reasoning available to the reviewer and a human sign-off gate on every outcome. And the control is recorded at the moment it operates: version, decision, owner, rationale, and evidence captured at action rather than reconstructed for the auditor.

Across the estate, that plays out in three moves:

  1. Find what matters. Coherent Insights reveals the shape of the estate, which files share logic, which are core models and which are drifted variants, where complexity, VBA, and sensitive data concentrate, so governance is scoped against the models that matter rather than every file equally.

  2. Govern what stays in Excel. Coherent Control adds review and approval workflows, cryptographic version fingerprinting, role-based permissions, and an immutable audit trail around the workbooks that belong in Excel. When the examiner asks, the answer is a record.

  3. Industrialize the logic that should scale. For the minority of models that genuinely need to run at production volume, Coherent Spark turns the governed workbook into a deterministic, regression-tested calculation service deployable by API to any connected system, with the governed workbook remaining the source of truth.

Where this leaves you

EUC risk isn't new. But it's one of those problems that's easy to deprioritize until it isn't: until a regulator asks a question you can't answer, or a key spreadsheet breaks and nobody knows how it worked in the first place.

Spreadsheets are deeply embedded in critical business processes, and that's not going to change. Every organization runs on this logic. The question is whether the governance, auditability, and testing infrastructure around it can prove the logic is controlled, and produce the evidence when someone asks.