Data and technology · Practitioner guidance

Spreadsheet Validation

Assess spreadsheets from intended use, calculations, data, failure impact, protection, independent verification, change control, and periodic review.

Author
Sandip Thorat
Published
12 September 2026
Last reviewed
12 September 2026
Version
1.0
Content type
Practitioner guidance
Primary references
2 linked sources in this guide

Assess the intended use

Identify the users, process, inputs, calculations, lookup data, manual steps, outputs, record or decision affected, frequency, approved platform and location, and prohibited uses. A spreadsheet without macros can drive a critical release decision; a workbook with macros can support a low-impact planning task. Macro use is not the deciding factor.

Functional risk and controls

Assess formula references, units, rounding, lookup tables, hidden rows or columns, ranges, external links, copy and paste, blank and invalid inputs, stale source data, output formatting, protection, permissions, version control, independent verification, backup, and change history.

Completed fictional product-acceptance calculation

A controlled workbook calculates a finished-product result from three approved inputs and compares it with a release limit. A new product range introduces a different unit and rounding rule. The evidence includes formula and reference review, independent calculations, exact known-answer values, values immediately below, at, and above the limit, invalid and blank inputs, unit challenges, protection checks, version identification, save-and-reopen behavior, and controlled-copy retrieval.

A boundary test shows that the workbook rounds an intermediate value instead of the final result and incorrectly passes one near-limit batch. The formula is corrected, independently verified, regression tested for both product ranges, and approved. The periodic review will confirm the approved version, use, platform, access, changes, incidents, and control effectiveness.

Regulatory and procedural context

Primary sources. FDA CSA guidance supports risk-based assurance for relevant production and quality-system software. 21 CFR Part 11 may apply when the workbook maintains or signs electronic records within its scope.

Company procedure. The organization’s approved validation, change-control, supplier-management, information-security, data-integrity, records-retention, and Quality approval procedures determine the required records, roles, and approval route.

CSVtoCSA practitioner interpretation. Validation depth should follow reliance, failure impact, complexity, and controls—not file extension, macro presence, or a blanket system category. This is a recommended validation approach, not a statement that every listed activity is a direct regulatory requirement.