Why Your Audit Team Still Lives in Excel — And What It's Actually Costing You

June 26, 2026

If your auditors are maintaining spreadsheets alongside your AMS, your platform hasn't done its job. Here's the research — and the business case for doing something about it.

Ask any internal audit leader whether their team uses Excel alongside their Audit Management System, and the honest answer is almost always yes.

Not reluctantly. Not as a workaround for one edge case. But systematically — for risk assessments, finding trackers, status reports, audit plan management, and workpaper templates. The AMS is open in one window. The spreadsheet is open in the other. And this dual-system operation has become so normalised that most teams no longer recognise it as a problem.

It is a problem. And it's a significantly more expensive one than most audit leaders have quantified.

The Scale of the Workaround

Protiviti's 2024 Internal Audit Capabilities and Needs Survey found that 67% of internal audit teams use spreadsheets alongside their AMS for at least one critical workflow. That's not a fringe behaviour. That's the majority of the profession operating in a mode that their technology platform was explicitly designed to eliminate.

The ACCA's 2023 Technology in Finance and Audit Productivity Study put a time figure on it: 88 minutes per auditor per week lost to duplicate data entry between the AMS and parallel spreadsheet systems. Eighty-eight minutes. That's not a rounding error — that's the equivalent of over 76 hours per auditor annually. For a team of eight, it's 608 hours a year. At a loaded senior auditor rate of $85 per hour, that's over $51,000 in annual labour cost spent on data entry that should not exist.

And that's before accounting for the quality risk. EY's 2023 Global Internal Audit Survey found that 1 in 5 spreadsheet-based audit workpapers contain a material error requiring correction before sign-off. In a function whose output is a direct input to the board's risk oversight, that error rate is not acceptable — and it's a direct consequence of operating outside a controlled system of record.

Why Audit Teams End Up in This Position

The spreadsheet dependency in audit management doesn't happen because auditors prefer working in Excel. It happens because the AMS doesn't do enough.

Legacy platforms were built to manage workflow — routing approvals, storing documents, tracking findings from identification to closure. They were not built to support risk analysis, dynamic reporting, flexible workpaper templates, or the kind of real-time visibility that modern audit leadership teams need. When those capabilities aren't available in the platform, teams build them in Excel. And once a spreadsheet-based workaround is embedded in a team's operating rhythm, it persists — because rebuilding it within the AMS would require either significant configuration effort or a platform that actually supports the use case.

The practical consequence is that the AMS becomes a compliance artefact rather than an operational tool. Audit plans are maintained in spreadsheets. Risk ratings are calculated outside the system. Status reporting is done manually, by aggregating data from the AMS and a collection of shared spreadsheets, and presenting it in a PowerPoint that no one will ever find again.

This is not a technology failure. It is a product failure — and it's a failure that your vendor has no structural incentive to resolve, because your team's Excel workarounds aren't visible on the metrics they report to you at renewal time.

The Compliance Dimension

For audit teams operating under BNM, OJK, or BOT oversight, the spreadsheet problem carries an additional dimension that goes beyond productivity. Both regulators explicitly assess documentation completeness and audit trail integrity during inspections. Dual-system operations introduce version control risk — the right version of a workpaper may exist in the AMS, or it may exist in a shared drive, or it may exist in both, with different content. Data integrity gaps arise when findings are logged in Excel and transferred manually to the AMS, introducing transcription error and temporal inconsistency. Traceability failures occur when the rationale for a risk rating or a control assessment lives in a spreadsheet that isn't formally linked to the audit record.

These are not theoretical risks. The EY survey is explicit: parallel spreadsheet use represents a significant, systematically unpriced compliance risk. The word “unpriced” is important here. It doesn't appear on your invoice. But it has a cost — in remediation effort when an inspection surfaces a documentation gap, in the management time spent explaining a finding, and in the reputational exposure that comes with a regulatory observation about audit quality.

What to Do About It

The starting point is visibility. Most audit leaders know their teams use Excel alongside the AMS, but few have quantified the extent of it. A structured workaround audit — asking each team member to document every workflow they maintain outside the platform, with an estimate of the time involved — will typically produce a figure that is larger and more operational than expected.

The second step is accountability. Your AMS vendor should be able to tell you, precisely, which workflows in their platform currently require data to be maintained externally. And they should be able to commit, with specific delivery dates rather than roadmap aspirations, to a plan for eliminating those dependencies.

If they can't do either of those things, the spreadsheet problem is structural — and the cost of living with it is now clearly quantifiable.

The Full Picture

The Excel workaround cost is one of five hidden expenses that FlexCore has identified and quantified in the audit management software market. Together with AI capability gaps, annual price escalation, retraining overhead, and the absence of SEA regulatory templates for BNM, BOT, OJK, and MAS, they represent a systematic transfer of value from your audit budget to your vendor's margin — one that rarely appears on any invoice, and that your vendor has no incentive to surface.

Download the eBook here.

If your team is still living in Excel, your AMS hasn't done its job. It's time to quantify what that's costing you.

Contact Us
Get in touch with our team for demos, sales inquiries, or support.