PRACTITIONER METHOD

Practical software assurance playbook

Spreadsheet Assurance Playbook

A proportionate method for deciding when a spreadsheet matters and how to control formulas, data, use, change, and retirement.

Professional interpretationEducational practitioner method · Quality review required for case-specific use

Decision and evidence workflow

Work through the assurance boundary

  1. 01

    Intended Use

    Decision
    State the calculation, record, report, or decision the spreadsheet supports and who relies on the output.
    Evidence
    Approved intended use, owner, version, and use boundary.
  2. 02

    Complexity

    Decision
    Inventory formulas, lookup tables, macros, external links, hidden content, protection, and manual steps.
    Evidence
    Complexity inventory with critical cells and dependencies.
  3. 03

    Data Inputs

    Decision
    Identify source, units, ranges, completeness, transcription, import, and stale-data risks.
    Evidence
    Input specification and source-to-cell traceability.
  4. 04

    Calculation Risk

    Decision
    Trace formula, reference, rounding, unit, copy/paste, and sequence failures to the decision they can affect.
    Evidence
    Function-level risk assessment and critical acceptance criteria.
  5. 05

    Protection

    Decision
    Control approved templates, formulas, critical cells, access, storage, versioning, and unauthorized change.
    Evidence
    Protection configuration and controlled-copy procedure.
  6. 06

    Verification

    Decision
    Use independent calculations, boundary values, known-answer sets, negative tests, and realistic workflow checks.
    Evidence
    Executed evidence with inputs, expected results, actual results, and exceptions.
  7. 07

    Change Control

    Decision
    Assess formula, structure, reference-data, platform, protection, and intended-use changes before release.
    Evidence
    Version history, impact assessment, regression decision, and approval.
  8. 08

    Periodic Review / Retirement

    Decision
    Review access, use, incidents, copies, dependencies, platform compatibility, retention, and replacement.
    Evidence
    Periodic review or retirement record with migration and archival checks.

Release gate

Before the decision is defended

  • The approved file and authoritative location are unambiguous.
  • Critical formulas and data transformations are independently challenged.
  • Protection and change controls match the actual use environment.
  • Users can identify the current version and recover required records.

Scope and limitations

What this playbook does not establish

  • Cell protection is not evidence that calculations are correct.
  • A macro-free workbook can still be high risk when it drives a regulated decision.
  • Complex shared spreadsheets may be better replaced by a controlled application.

Use applicable regulations, final guidance, organizational procedures, and subject-matter review for the actual system and jurisdiction.