Skip to content

Spreadsheets versus a compliance management system: what changes, and what does not

Most compliance functions are not choosing between two systems. They are choosing between the estate they have and a system they have not run yet. Here is what actually changes when the estate goes, what stays your job, and the four tells that it is time.

By Vantage Point · Published 17 August 20267 min read

The estate everyone has

A regulated firm’s compliance function usually runs on an estate rather than a system: an obligations spreadsheet nobody has opened since the last visit, a risk register in another workbook, controls in a policy folder, the monitoring plan in a calendar and a shared drive of test evidence, and a set of registers (breaches, complaints, gifts, conflicts) each in its own file with its own conventions. It grew that way because each part was small and familiar when it started, and nothing forced the change.

The estate is not wrong. It is expensive in ways that do not show on a budget line: the hours before each committee meeting spent making the parts agree, the finding at the next visit that a change was assessed but not evidenced, the register that two people keep in different copies. The real competitor of a compliance management system is not another system. It is this inertia.

What actually changes

Four things change when the estate goes into one system, and it is worth being precise about them because they are the whole case.

A record of who changed what, and when. Every obligation, risk, control, test, action and register entry carries an audit trail: who changed which field, when, from what to what. A reviewer can reconstruct a decision from the record alone. A spreadsheet cannot give you this; a shared drive gives you a version history of files, which is not the same thing.

Alerts that fire without a person remembering. A test falls due, an action passes its deadline, a director accepts a third lunch from the same counterparty, a gift crosses the threshold: the system says so. In the estate, every one of those is a person remembering, and the finding is written the day they do not.

One fact, linked. The breach, the complaint it caused, the action it raised, the control it exposed and the risk that control treats are one linked set rather than five descriptions of the same event in five files. When a monitoring test fails, the control’s rating falls and the residual risk rises, the same day, without anyone updating a second workbook.

Reports that read from the records. The committee pack reads from the same data the work was logged in, so what the committee sees in March is what was recorded in March, and it reconciles with the register beside it. In the estate the pack is assembled by hand and disagrees with the register it was assembled from.

What does not change

A system does not decide your risk appetite. It does not write your controls or choose your sample. It does not reach the conclusion a test requires or decide whether a breach is reportable. It does not make the firm compliant with any regulation, and a vendor who implies otherwise should be shown the door. The methodology is yours; the judgement is yours; the relationship with the regulator is yours. What the system does is give those things a structure and a record, so the evidence of the work assembles itself instead of being reconstructed the week before the meeting.

That is also why “the methodology stays yours” is the test to apply to any system: if moving to it means adopting somebody else’s taxonomy, somebody else’s scoring, somebody else’s idea of what a test looks like, the estate is being replaced by a different estate.

The four tells

There is a point at which the estate stops being defensible, and it is usually reached before anyone decides to leave it. The tells are the same in every firm:

  1. You cannot show who changed a row.
  2. Two people are editing different copies of the same register.
  3. The alert is a human.
  4. The same event lives in three registers with three descriptions, and nothing links them.

Any one of those is a finding waiting to be written. Two or more, and the estate is costing more staff time than the system that would replace it. The registers are usually where the tells show first, which is why they are usually where firms start.

What a fair comparison looks like

What is compared The estate A compliance management system
Who changed what, when File version history at best Every record, every field, attributed
Alerts A person remembering Set on the register, the plan, the action
The breach, the complaint, the action Three files, three descriptions One linked set
The committee pack Assembled by hand, disagrees with the register Reads from the records, reconciles
Regulatory change Re-read the Code, email the team Diff of what moved, obligations affected, action raised
Your methodology Yours Still yours, or walk away
Making the firm compliant Not the spreadsheet’s job Not the system’s job either

Where Vantage Point sits in this

Vantage Point is a compliance management platform built for exactly this move: obligations, risks, controls, the monitoring programme, actions, registers and reports on one data model with one audit trail. Existing registers, risk assessments and monitoring histories come across during onboarding, imported and checked with you, so no history starts from zero, and firms are live in days, not months (see how onboarding works). The methodology stays yours: appetite bands are set per entity, test templates carry your own steps, sample and evidence, and register fields are configurable and versioned. It does not claim to make your firm compliant with anything, and it is software only: there is no consulting practice on the side.

Questions

Is a spreadsheet an acceptable compliance register?
Regulators rarely object to spreadsheets as such; they object to what spreadsheets cannot prove. A spreadsheet register cannot show who changed a row and when, cannot stop two people editing different copies, and cannot raise an alert without a person remembering. If a reviewer can reconstruct every decision from the sheet alone, it is doing its job; the moment they cannot, it is a liability rather than a record.
What does a compliance management system change that a spreadsheet cannot?
Four things: an audit trail on every record, alerts that fire without a person remembering, one copy of each fact linked to the others (the breach, the complaint it caused, the action it raised, the control it exposed), and reports that read from the same records the work was logged in. Everything else, the methodology, the judgement, the relationship with the regulator, stays with the compliance officer.
What does a compliance management system not do?
It does not decide your risk appetite, write your controls, choose your sample or make the judgement a test conclusion requires. It does not make a firm compliant with any regulation and no vendor should claim that it does. It gives the function a structure and a record; the function still has to run.
How do we know it is time to move off spreadsheets?
When you cannot show who changed a row; when two people are editing different copies; when the alert is a human; and when the same event lives in three registers with three descriptions and no link between them. Any one of those is a finding waiting to happen. Two or more and the estate is costing more staff time than a system would.
How long does moving take?
It depends on the estate, but the pattern that works is to bring the existing registers, risk assessments and monitoring histories across during onboarding, imported and checked with you rather than retyped, so no history starts from zero. Vantage Point onboards firms in days, not months, with a named onboarding lead; the methodology stays yours.
Next step30 min · Tailored · No deck

See it running on your firm's structure.

A 30-minute walkthrough using your entities, your licences and a real workflow you bring to the call. No slide deck.