Reconciliation

    How Safeheld Eliminates Spreadsheet Risk in Safeguarding Reconciliation

    Why spreadsheet-based reconciliation is the highest-risk component of most safeguarding programmes: and how automated reconciliation infrastructure replaces it.

    9 min read March 2026

    In short

    Spreadsheet reconciliation fails not because spreadsheets calculate incorrectly, but because they cannot evidence a process. They hold no version history of the logic applied, no immutable record of the source data as received, no segregation between preparer and reviewer, and no way to reproduce a historic position. Under a daily obligation with an annual audit against a specified standard, that gap is the control weakness.

    A workbook records a conclusion, not a process

    The output of a reconciliation workbook is a number and a status. What an auditor tests is everything that produced them: which files were used, when they arrived, what was excluded and why, which rules were applied, who reviewed the exceptions and what they concluded.

    A workbook holds the last state of the calculation. Earlier states are overwritten. When a formula is corrected mid-month, the corrected logic is applied retrospectively to the visible output, and the earlier basis disappears without trace.

    This is why reconstruction requests are so expensive in spreadsheet-based firms. The reconstruction itself is a new piece of work performed with today's knowledge, which is precisely what the evidence standard is designed to exclude.

    The problem is structural. No degree of discipline in workbook design removes the absence of an immutable process record.

    Broken lineage between source data and reported position

    Source data rarely arrives in a usable state. Statements are downloaded, opened, re-saved, filtered, sorted and pasted. Each of those actions is invisible in the final file, and each can silently alter the population.

    Common failure modes are well documented in operational risk literature: a filter left applied so that a range excludes rows, a paste that shifts a column, an autocorrected identifier, a date interpreted in the wrong locale, and a lookup that returns the nearest rather than exact match.

    None of these produce an error message. They produce a plausible number. A plausible number that reconciles is more dangerous than an obvious failure, because nothing prompts investigation.

    A controlled platform retains the source file exactly as received, applies a declared transformation, and preserves the link from every reported figure back to the original row. Lineage is the property that makes a figure testable rather than merely presentable.

    Single-operator dependency is a regulatory exposure, not an HR issue

    In most firms the safeguarding workbook has one genuine owner. That person understands the manual adjustments, the accounts deliberately excluded, the workaround for a counterparty that changed its file format, and the reason a particular tab exists.

    That knowledge is undocumented by definition, because if it were documented it would be a rule rather than a workaround. When the owner is unavailable, the reconciliation either stops or is performed without the adjustments that made it correct.

    Supervisors treat this as a governance failure. An obligation that operates daily cannot depend on the continuous availability of a single individual, and a firm that cannot demonstrate an operable alternative has not evidenced adequate systems and controls.

    Codifying the workarounds into declared, versioned rules is the only durable remedy. It also has the effect of exposing which workarounds were never justified.

    Preparer and reviewer cannot be segregated inside a file

    Review is a control only if the reviewer sees what the preparer did. In a shared workbook, the reviewer sees the current state and a signature cell. There is no record of the exceptions considered, the items overridden, or the judgements applied.

    A meaningful review trail records the exception, the evidence attached, the decision, the person who made it, the timestamp and whether that person had authority to make it at that value. Where a threshold is exceeded, a second approval must be enforced rather than requested.

    Access control is the parallel problem. Workbooks live on shared drives with permissions inherited from folders created for another purpose, so the population of people who can alter a safeguarding calculation is usually wider than the firm believes.

    These are the findings that appear in audit reports as control design deficiencies, and they are not addressable by adding a sign-off cell.

    Daily obligations break a monthly operating rhythm

    A spreadsheet process is sized for the frequency at which it was built. Firms that constructed monthly close workbooks and then applied them to a daily obligation find that the process consumes the working day, and that the reconciliation is completed late in the following period.

    Lateness is itself a breach. Under the FCA regime, the reconciliation must be performed as frequently as required and the position corrected without delay. A correct reconciliation performed three days late is still a failure of the control.

    Volume compounds the effect. As the firm adds a currency, an acquirer, a distributor or a jurisdiction, the workbook grows tabs rather than capacity, and the marginal cost of each new relationship is borne by the same operator.

    The commercial consequence is that safeguarding becomes a constraint on growth, which is the opposite of what an operating layer should do.

    What a controlled replacement has to provide

    Replacing a workbook is not a matter of moving the same logic into another interface. The replacement has to provide properties the workbook structurally cannot: immutable ingestion, versioned rules, enforced segregation, complete exception history, and reproducible historic runs.

    Safeheld ingests source files in the formats counterparties already send, retains them unaltered, maps them through declared schemas, and records every rule version in force at the time of each run.

    Exceptions carry their full life history: raised, investigated, evidenced, corrected, approved and closed, with the identity and authority of each actor. Completed runs are sealed with a cryptographic hash so that a later export is provably the same artefact that was reviewed.

    The test of the replacement is simple. Select a date at random, produce the position as it stood, and trace one item from the source file to the funded correction without asking anyone to remember anything. A workbook cannot pass that test. An operating layer must.

    Migrating without importing the existing weaknesses

    A migration that copies the workbook's logic into a platform reproduces the workbook's errors with better presentation. The migration is therefore also a methodology review, and should be treated as one.

    The first step is to enumerate every manual adjustment currently applied and require a written justification for each. Adjustments that cannot be justified are usually compensating for an upstream data problem that should be fixed at source.

    The second step is to run the platform in parallel with the workbook until they agree, and to investigate every difference in both directions. Differences where the platform is right are the value of the exercise; differences where the workbook is right reveal a configuration gap.

    The third step is to document the cutover, including the final parallel period, the sign-off and the date from which the platform is the record of control. An undocumented cutover leaves a period where neither system is authoritative.

    Where spreadsheets remain legitimate

    There is no requirement to eliminate spreadsheets from a finance function, and attempting to do so wastes effort on activities where the risk is immaterial.

    The distinction is between analysis and the record of control. Modelling a scenario, testing a hypothesis or preparing an ad hoc view for a committee are analytical activities and carry no evidential burden.

    The reconciliation itself, the exception register, the corrective funding record and the approval chain are the record of control. Those must live in a system that retains them immutably and can reproduce them later.

    A firm that applies this distinction consistently ends with a small number of controlled processes and an unrestricted analytical layer above them, which is both defensible and practical.

    Frequently asked questions

    Are spreadsheets prohibited for safeguarding reconciliation?

    No rule prohibits them. The obligations are outcome-based: reconciliations performed at the required frequency, discrepancies corrected without delay, and records sufficient to evidence both. Spreadsheets tend to fail the evidential element rather than the arithmetic one.

    What is the most common spreadsheet failure in practice?

    Silent population loss. A filter, a shifted paste, a locale-misread date or an inexact lookup changes the underlying set without producing any error, and the resulting figure still reconciles because both sides derive from the same altered data.

    How does automation change the audit engagement?

    It moves the engagement from evidence gathering to judgement. When the auditor can select a date, retrieve the sealed run and trace a sample end to end without manual requests, testing effort concentrates on methodology and exception handling rather than on reconstructing what happened.

    Can a firm keep spreadsheets for analysis?

    Yes. The distinction is between analysis and the record of control. Analysis performed outside the platform is unobjectionable provided the reconciliation itself, its exceptions, its corrections and its approvals live in a system that retains them immutably.

    Back to Resources

    The system of record for client funds and reserves