Compliance
The Hidden Validation Cost of Excel Registers in GMP Environments
Excel looks like the cheapest option for GMP registers until you count the effort needed to demonstrate control, accuracy, and data integrity. A risk-based way to decide what a spreadsheet actually needs.
Most GMP organisations still run on spreadsheets. Calibration registers, equipment logs, training matrices, risk registers, and more than a few "temporary" trackers that quietly became permanent. Excel earns that trust because it is familiar, flexible, and appears to cost nothing to set up.
The cost only becomes visible later, and it rarely shows up in the IT budget. It shows up in the hours spent preparing for an inspection, defending a formula nobody remembers building, or proving that a register nobody formally validated is still fit for purpose.
The useful question has quietly changed.
It used to be: "Can Excel do it?"
It is now: "Can we demonstrate control, accuracy, data integrity, and compliance?"
This article sets out a practical, risk-based way to answer that question, and where a governed SharePoint pathway may reduce the ongoing burden. It is a practical interpretation, not a validation protocol or a determination that any specific spreadsheet is or is not compliant. The applicable regulatory expectations (including Annex 11 themes referenced by EU and TGA GMP inspectors, and the equivalent expectations FDA inspectors apply), the organisation's own risk assessment, and its quality system remain the controlling references.
Not every spreadsheet needs the same validation effort
A common mistake is treating every spreadsheet the same way: either "it's just Excel, it's fine" or "every spreadsheet must go through full software validation." Neither position holds up well in practice.
Validation effort should scale with what the spreadsheet actually does and what happens if it is wrong. A simple calibration log that only records dates and certificate references carries a very different risk profile to a spreadsheet that calculates pass/fail status against a specification limit.
A useful way to see this is a three-level maturity model.
Level 1: Register spreadsheet
Records information. IDs, dates, references, locations, comments. No calculations, no decision-making logic. The spreadsheet is a structured list, not a system.
Level 2: Decision-support spreadsheet
Contains formulas that interpret data: pass/fail calculations, tolerance checks, status flags, trend indicators. The spreadsheet now influences a GMP decision, even if a person still signs off on the outcome.
Level 3: Quality-critical spreadsheet
Drives GMP decisions directly, feeds other systems or reports, or replaces a controlled record. Complex formula chains, macros, or multiple dependent tabs are common at this level.
Validation effort increases sharply at each level, and it rarely increases in a straight line. A register that takes a few hours to assess can sit next to a decision-support spreadsheet that needs formal requirements, risk assessment, and formula verification.
What tends to drive the effort up
Regardless of which level a spreadsheet sits at, the same practical risks show up repeatedly:
- Manual transcription errors between certificates, instruments, and the register.
- Formula corruption where a cell is overwritten, a range shifts, or a copy-paste breaks a calculation without anyone noticing.
- Poor version control, with multiple copies in email, shared drives, and local desktops.
- Limited audit trails, so it is difficult to show who changed what, and when.
- No record of intended use, risk assessment, or verification, so there is little to point to when someone asks how the organisation knows the spreadsheet works.
None of these risks mean Excel is inherently non-compliant. They mean that as reliance on the spreadsheet grows, the organisation needs a clearer answer to the control questions an inspector is likely to ask.
Where SharePoint changes the equation
Many organisations already hold a Microsoft 365 licence that includes SharePoint. That means a number of controls that have to be built manually around a spreadsheet already exist natively in a SharePoint list:
| Capability | Excel | SharePoint list |
|---|---|---|
| Version control | Manual, multiple copies | Native version history |
| Audit trail | Limited or absent | Native change history |
| Access control | Weak, often shared files | Native permissions |
| Certificate attachment | Separate file location | Native, linked to the record |
| Reminders | Manual | Automatable (for example, Power Automate) |
| Review evidence | Manual compilation | Native views and reports |
| Validation effort | Concentrated on formula logic and process control | Concentrated on configuration and process verification |
This is not a claim that SharePoint requires zero validation, or that migrating is free. It is an observation that the effort shifts: away from re-proving spreadsheet logic and manual process control, and towards verifying that the list is configured, permissioned, and used as intended. Our worked SharePoint quality-register validation example sets out what that evidence can look like for a comparable register.
A structured way to decide
Rather than defaulting to "replace everything" or "leave everything alone," a structured spreadsheet assessment can identify, register by register, whether it should be:
- Retained, with lightweight, proportionate controls;
- Remediated, with formal requirements, risk assessment, and validation evidence; or
- Migrated, to a governed SharePoint list where the ongoing burden is likely to be lower.
The right answer depends on what the spreadsheet does today, and what it is likely to be asked to do next year.
Where this pillar leads
This article introduces the maturity model. Three companion articles work through it in more detail:
- My Calibration Register Is Just a Spreadsheet. Does It Really Need Validation? looks at a Level 1 register spreadsheet.
- When Your Spreadsheet Starts Making GMP Decisions looks at what changes once formulas start deciding pass/fail status.
- The Spreadsheet Trap: Why SharePoint Can Be Easier to Validate Than Excel compares the ongoing validation burden of each platform using the same calibration example.
For broader context on quality registers generally (not only calibration), see The Hidden Compliance Risk in Your Excel Registers, Beyond Excel: A Practical GxP Approach to Quality Registers Using SharePoint Lists, and Annex 11 in Plain English for the underlying computerised-systems themes.
Where to start
Excel is not the problem. Lack of control is the problem. The goal is not to eliminate spreadsheets; it is to apply the right level of control based on risk, and to be able to demonstrate it.
If you are not sure which level your spreadsheets sit at, start with a GMP spreadsheet assessment to get a risk classification and a recommended next step for each register. Where migration is the right answer, our Excel-to-SharePoint assessment and implementation support can help plan the register, certificate, and workflow migration alongside the evidence you need to support it. For the wider platform context, see SharePoint governance and configuration and practical GxP quality systems.
Book a discovery call to talk through your spreadsheet register and the most proportionate next step.