Before approving a spreadsheet replacement, ask whether another authorised person could run and validate the work without its maintainer. Unanswered questions about inputs, exceptions or approvals belong on the immediate continuity agenda, even if a replacement is already planned.
For a business-critical spreadsheet, make the workflow transferable before deciding its technical future. Use the following review to identify priority dependencies, assign accountability and choose proportionate controls or migration. It is a proposed operating framework, not an empirically validated assessment method.
Review the workflow, not just the file
Start with operational reliance. Prioritise spreadsheets that carry decisions, reconciliations, approvals, records or coordination between systems. Ask what depends on their output and what would happen if it were late, unavailable or wrong. Distinguish those dependencies from local analysis that another person could readily reproduce.
Dartmouth’s spreadsheet research collection reports error analysis of 50 spreadsheets used by companies. The collection description provides no company identities, geography, sampling method, timeframe or findings. That establishes a limited point: company-used spreadsheets have been studied for errors. It does not establish an error rate or tell you which files deserve attention in your business.
For this continuity review, look beyond formula correctness. Identify who supplies the data, interprets the result, authorises exceptions and relies on the output. Ask the maintainer to explain the whole operating chain, including judgments made outside the workbook. Use that dependency map to define the scope of the handover.
Find and rank the dependencies that matter
Bound the first review around a business process whose interruption would warrant management attention. Ask its accountable owner and the people performing the work to identify spreadsheet-dependent steps. Trace inputs and outputs across handoffs, then confirm the relevant files and access arrangements with their maintainers. Start with the work rather than an organisation-wide file count.
Record the workflow, file location, inputs, outputs and receiving teams.
Record deadlines, affected decisions and consequences of failure.
Name the accountable owner, maintainer and backup operator.
Check access, instructions, validation and acceptable recovery time.
Agree priority, action owner and review date.
A proposed review sequence, not a validated scoring model.
Build a dependency register that connects each file to its business consequences and recovery needs.Rank dependencies by failure consequences and the ability to continue without the maintainer. Give earlier attention to consequential work with untested cover or unresolved access. Record the reason for each priority; avoid a numerical score unless you can defend its assumptions.
Separate unknowns from confirmed weaknesses. Mark recoverability as untested where nobody has checked whether a colleague can run the process. Where access has been checked and is unavailable, record the specific gap. The management output should be a ranked dependency register with actions, not a blanket spreadsheet clean-up programme.
Test whether someone else can run the work
University of Iowa Human Resources describes its Knowledge Transfer Document as a resource for an outgoing employee and their supervisor to capture critical knowledge and transfer it to others in the unit. Its stated goals include continuity and onboarding. This is guidance for Iowa staff transitions, not spreadsheet-specific research or measured evidence that documentation ensures continuity.
For priority spreadsheet dependencies, take the review beyond document completion. Ask the maintainer to prepare operating instructions, then have a designated colleague follow them in a supervised, controlled setting. Keep consequential outputs subject to normal authorisation. The proposed handover record should cover:
- Purpose and timing: what the process produces, who receives it and when it is needed.
- Source data: where inputs come from, who supplies them and how completeness is checked.
- Rules and changes: calculations, manual adjustments, assumptions and authority to change them.
- Exceptions: how unusual cases are recognised, resolved and escalated.
- Access and recovery: approved permissions, authoritative file location, recovery steps and responsibility for restoring service. Keep passwords out of the record.
- Validation and approval: checks before release, who can judge the result and who may authorise its use.
Agree acceptance criteria before the exercise. Require the colleague to obtain the inputs, perform the work, explain the checks and recognise when to stop and seek approval. Log every undocumented explanation or intervention they need, then assign actions to close those gaps.
Record the conditions tested and those still unresolved. Do not treat a successful routine run as proof that every exception or recovery scenario is covered. Ask the accountable owner to decide whether the remaining gaps are acceptable, require further testing or need interim cover.
Choose a proportionate response
Choose the response against the gaps the review reveals. Consider retaining a spreadsheet where the workflow is bounded, understood and recoverable, with controls appropriate to its consequences. Evaluate redesign or migration where the current arrangement cannot adequately meet operating or control requirements.
Assign cover, capture rules and test independent operation.
Establish authorised access, change approval and recovery arrangements.
Resolve responsibilities and exception decisions before specifying software.
Compare options against scale, change frequency, integration and auditability needs.
Editorial decision criteria, not universal migration thresholds.
Match the response to the unresolved requirement. Combine options where necessary.Require a migration business case to name the unmet requirements and explain how the proposed system would satisfy them. Include transition effort, ongoing ownership, support, access, validation and recovery. Compare that commitment with the cost and limitations of retaining a controlled spreadsheet.
Keep immediate continuity work separate from the investment timetable. If a departure is approaching, assign cover and resolve essential handover gaps while evaluating the longer-term decision. Require the replacement proposal to account for existing business rules and exceptions rather than deferring their explanation to implementation.
Make continuity an operating responsibility
Assign an accountable business owner to each priority dependency. Distinguish that responsibility from file maintenance, even where one person holds both roles. Make the owner responsible for accepting residual risk, arranging cover and keeping the transfer record usable. Name the maintainer, backup operator and result approver explicitly.
Set a review cadence appropriate to the workflow’s consequences and rate of change. Trigger additional reviews when responsibilities, source systems, logic or access arrangements change, and when a departure is announced. Record when independent operation was last tested, what the test covered and which gaps remain open.
Ask each process owner to bring forward their highest-priority unresolved spreadsheet dependency, a named action owner and a decision date. Judge progress by whether another authorised person can perform and validate the work within agreed limits. Retire the spreadsheet only when the case for changing the workflow or its controls warrants it.



