In September 2020, England's contact-tracing system quietly stopped adding part of its positive Covid-19 results, and nobody noticed at first. According to a report by The Register, 15,841 cases fell out of the daily figures between September 25 and October 2 because the file used to consolidate lab results had been saved in an old spreadsheet format, capped at just over 65,000 rows. Once the limit was hit, the program simply stopped appending new rows — no warning, no error message, no sign that anything had gone off track.

The practical effect landed on real people: as many as 48,000 close contacts of infected people were never notified in time, because contact tracing depended directly on that file. There was no breach, no network failure, no bad policy call behind it. There was a spreadsheet a team had been using for months, for a job it had never been designed to handle at that volume.

Cases like this only make headlines when a government and a pandemic are involved. The mechanism behind it — an important process that ends up living inside a spreadsheet, maintained by whoever had the time and the goodwill to build it — repeats every day in companies of every size. That mechanism, not Excel itself, is what should worry the people making decisions.

Where the Process Actually Lives

HR has the spreadsheet for who can approve which type of reimbursement. Finance has the one with discount rules by customer and payment term. Sales has the one listing which contracts need legal sign-off before going out. Each was born the same way: someone had to solve a real problem, at a moment when nothing better was on hand, and a spreadsheet solved it on the spot.

The problem isn't that the spreadsheet got created. It's what happens next: the rule that was crystal clear in the head of whoever built it never quite makes it onto paper. When that person changes roles, takes extended leave, or leaves the company, the process doesn't just go with them — it disappears, because it never existed anywhere else.

Decades of academic research on real operational spreadsheets, compiled by researcher Raymond Panko from audits across companies, reach a similar conclusion from a different angle: errors are rare cell by cell, but in a large spreadsheet it's very likely that at least one error survives into the final result — because almost nobody reviews a spreadsheet the way they review a system, with testing, version control, and a second set of eyes.

Research by financial-modeling firm F1F9 paints a similar picture from the business side: 88% of all spreadsheets analyzed contained some error, and half of the spreadsheets used by large companies had a defect serious enough to sway a decision. The structural reason shows up in technical material on auditing what's called "end-user computing" — the tools a person builds on their own, outside anything IT tracks: this kind of file rarely has a declared owner, a current version, or a record of who changed what, and carries a critical error in as many as 94% of cases used for business decisions, according to the same material.

When this kind of spreadsheet underpins a major decision, the cost shows up fast. In 2012, the British government scrapped an entire multibillion-pound rail franchise competition after finding calculation errors in the model used to evaluate bidders' proposals — the government itself confirmed the cancellation in an official statement, and the episode ended up costing taxpayers more than $76 million, according to an estimate cited by an industry consulting firm.

Documenting Isn't the Same as Governing

Documenting Isn't the Same as Governing

The most common reaction, once someone grasps the size of the problem, is to ask the person to "document" the process — a summary in a text file, a page on an internal wiki, a training recorded once. It helps a little and fixes little: the spreadsheet stays the place where the work actually happens, and the standalone document stops matching reality the first time the rule changes.

Another common reaction is to ban it: lock the file, restrict who can edit it, promise to migrate everything to a bigger system "as soon as it's ready." In practice, the bigger system's deadline never arrives, the day-to-day pressure never lets up, and the spreadsheet disappears from the view of whoever issued the ban — without disappearing from the work of whoever has to deliver today.

This is exactly where AI walks in and exposes the whole problem. Someone asks an AI assistant to help with that reimbursement or discount approval routine, and the assistant has no way of knowing the rule that only exists in the head of whoever maintains the spreadsheet — so it gets it wrong, or gives back an answer too generic to be useful, and the team goes back to doing things the old way. Or, worse, someone pastes the entire file's content into a personal AI tool for help, and the process that was already informal gets a second copy, even further outside anyone's control than the first.

Errors are rare cell by cell. But in a large spreadsheet, it's very likely that at least one error survives into the final result.

Raymond Panko, spreadsheet-error researcher

What Has to Be in Place

A workplace where AI can genuinely help with these processes rests on concrete mechanisms, not on good intentions.

A single identity, the same one the company uses. People access the process and the AI with the same corporate network login — not a personal account nobody else can see.

A declared owner for every process. Every important business rule has a person or team responsible for keeping it current, and that's on record, not implied.

A current version, not the last spreadsheet someone saved. There's one official, recognizable version of that process, distinct from any personal copy sitting on someone's own machine.

Review before a change becomes an official rule. Meaningful changes pass through a second person before they apply to everyone — without that step, any last-minute tweak becomes policy without anyone actually deciding it should.

Reuse with permission by person, group, and role. Anyone who needs that process can use it within what their role allows — without having to ask the one colleague who "knows how it works" for the file.

A trail of who changed what. Changing a business rule gets logged, with a date and an owner, the same way any other meaningful company decision would be.

This is how Skyller was designed: knowledge with an owner and a current version, access based on each person's role, and reuse across teams, instead of depending on whoever happens to keep the file.

When What Works Multiplies

When What Works Multiplies

The easiest gain to justify is about risk: less dependence on a single person, less chance of a silent error becoming an official decision. But what usually seals the argument is something else.

When a process lives only in a personal spreadsheet, whatever works well stays locked to whoever figured it out. The person in finance who spent months tuning the perfect discount logic by payment term is the only one in the company who knows how to run it — and if they leave, the knowledge goes with them, even if the file stays behind.

In an environment where that knowledge has an owner, a version, and defined permissions, the path runs the other way: someone on the team solves the process once, and other people and teams can reuse the same path, within what their role allows. Skyller, for instance, already ships with more than 170 ready-made policy and process templates, so a company doesn't have to start that organizing work from zero.

There's also an effect on whoever joins the company later. A new hire doesn't learn the process by asking whoever "knows it by heart" — they find the current version, already on record, and start using it on day one.

A Quick Test for That Spreadsheet

Before opening that spreadsheet behind an important process one more time, it's worth answering these questions with the team itself:

  1. If the person who maintains this file left tomorrow, does anyone else know how to run the rule inside it? If the answer is "only she does," the process doesn't have an owner — it has a hostage.
  2. Is there a version of this spreadsheet everyone recognizes as the official one? If every team keeps its own copy, different versions are probably already deciding different things at the same time.
  3. Did anyone review the last change to this rule before it took effect for everyone? Without a second set of eyes, a last-minute tweak becomes policy without anyone actually deciding it should.
  4. If an AI assistant had to follow this rule today, where would it find the text of it? If the answer is "in someone's head," the AI will get it wrong or be ignored — not because the tool is bad, but because the rule never existed in writing.

Discover Skyller