Almost every team tracks compliance the same way at the start: a spreadsheet. A tab for obligations, a tab for who's done their training, a status column shaded green. It's free, everyone can use it, and on day one it's genuinely enough. The trouble is that a spreadsheet doesn't fail loudly — it fails quietly, one stale cell at a time, and you tend to find out at the worst possible moment: during a review, an audit, or an incident.
Spreadsheets fail at compliance for structural reasons, not because people are careless. There's no single source of truth once the file is copied or emailed; no ownership, because a cell never chases anyone; no reminders, so deadlines depend on someone remembering to look; no audit trail, so you can't prove what was true and when; and the obligation, the action and the evidence live in separate places. A purpose-built system closes each gap — obligations, activities, actions and training in one place, with a record that stands up to scrutiny.
It works — until it quietly doesn't
The spreadsheet earns its place because, early on, the load is small: a dozen obligations, a couple of people, deadlines you can hold in your head. The discipline it depends on — someone remembering to open it, update it, and act on what it says — is easy to sustain when the team is small.
As the team, the obligations and the deadlines multiply, that same discipline is exactly what gives way. Nothing dramatic happens on any single day; the sheet just drifts a little further from reality each week. Here are the five ways it happens.
1. There is no single source of truth
The moment a spreadsheet is emailed, downloaded, or copied “just to be safe”, there are two versions — then five. Someone updates the wrong one. A decision is recorded in a copy nobody else can see. A column is renamed in one file and not the others.
Before long you can't answer a simple question with confidence: which version is current, and is it right? A compliance record that you can't trust to be current isn't much of a record — it's a document that happens to contain some true things.
2. A cell doesn't own anything
A spreadsheet can record that something is due. It can't chase the person responsible, escalate when the date passes, or notice that the owner left three months ago. Accountability lives in people's memories and goodwill, not in the tool.
The predictable result is the diffusion-of-responsibility problem: when everyone is responsible for checking the sheet, no one is. Items don't get missed because someone decided to ignore them — they get missed because the sheet assumed a human would notice, and that week, nobody did.
3. Nothing reminds you
A due date in a spreadsheet is inert. It doesn't send a reminder, flag itself when it's overdue, or surface the three things that need attention this week. It waits to be looked at.
So deadlines are met when someone remembers to look, and missed when — one busy week — nobody does. The tool that's supposed to reduce the risk of forgetting is, in fact, entirely dependent on people not forgetting.
4. There is no audit trail
This is the failure that hurts most in a review. A spreadsheet shows the current state — the cell says “complete”. It doesn't reliably show how you got there: when the obligation was identified, who actioned it, what changed, and when.
Compliance is judged after the fact, and “trust me, it was done” is not evidence. When an auditor, regulator or client asks for the history, the spreadsheet sends you back to your inbox to reconstruct it from emails and file versions — the audit scramble. A record you have to rebuild under pressure is the opposite of being audit-ready.
5. The obligation, the action and the evidence live apart
The obligation is in the spreadsheet. The action taken is in an email thread. The evidence is a PDF in a shared drive — or an attachment someone can nearly find. Three things that belong together, kept in three different places.
A reviewer wants them joined up: this obligation, this action, this proof. Because spreadsheets keep them apart, every review becomes an exercise in re-assembling a story that was never recorded as one story in the first place.
| A spreadsheet | A purpose-built system | |
|---|---|---|
| Source of truth | Multiplies once copied or emailed | One record everyone works from |
| Ownership | A cell chases no one | Every item has an owner and due date |
| Reminders | Inert — relies on memory | Reminds and escalates automatically |
| Audit trail | Shows the state, not the history | Timestamped, tamper-evident record |
| Obligation → action → evidence | Scattered across tools | Linked in one place |
What “good” looks like
None of these failures are about carelessness — they're structural, which is why more discipline doesn't fix them. A system built for the job closes each gap by design:
- One source of truth everyone works from, so “which version” stops being a question.
- An owner and a due date on every item, so accountability sits in the tool, not in someone's memory.
- Reminders and escalation, so nothing depends on a person remembering to look.
- A timestamped, tamper-evident record that ties each obligation to the action taken and the evidence behind it.
The test is simple: can you show, on demand, that the right thing was identified, done, and can be proven? A spreadsheet struggles with the “on demand” and the “proven”. A system is built for both.
Where Provenance fits
This is the problem Provenance is being built to solve. Provenance is an AI-native compliance and operations system — in development — for small and medium teams. It aims to bring obligations, activities, actions and training into one place, give each a clear owner, and keep a verifiable record that's ready when someone asks. → The Provenance software
The capabilities described there are planned features and subject to change — if the spreadsheet problem sounds familiar, you can register your interest and we'll keep you posted as it takes shape.
Frequently asked questions
Can you track compliance on a spreadsheet?
Yes, and most teams start there. A spreadsheet is free, familiar and genuinely enough when there are only a handful of obligations and one person keeping an eye on them. The difficulty is that spreadsheets don't scale with a team: as the number of obligations, people and deadlines grows, the manual discipline a spreadsheet depends on quietly breaks down — usually without anyone noticing until a review or an incident.
Why do spreadsheets fail for compliance tracking?
For structural reasons rather than carelessness. A spreadsheet has no single source of truth once it's copied or emailed, no ownership so a cell never chases anyone, no reminders so deadlines depend on someone remembering to look, and no audit trail so you can't prove what was true and when. It also keeps the obligation, the action taken and the supporting evidence in separate places — exactly what a reviewer wants to see joined up.
What should compliance tracking software do?
At a minimum it should hold your obligations, activities, actions and training in one place, give every item a clear owner and due date, remind people before things fall due, and keep a timestamped, tamper-evident record of what was done. The goal is to be able to show, on demand, that an obligation was identified, an action was taken, and there's evidence to support it.
When should a team move off spreadsheets for compliance?
A practical signal is when more than one person needs to update the same record, when you can't quickly answer “what's overdue right now”, or when preparing for a review or audit means reconstructing history from emails and file versions. At that point the spreadsheet has become a source of risk rather than a source of truth.
What is an audit trail and why does it matter?
An audit trail is a record of what happened and when — which obligation was reviewed, what action was taken, who did it, and what evidence supports it. It matters because compliance is judged after the fact: a regulator, auditor or client wants to see that the right things were done at the right time. A spreadsheet can show the current state, but not reliably how you got there.
Is the Provenance software available yet?
Provenance is in development. It's being built as an AI-native compliance and operations system for small and medium teams, designed to bring obligations, activities, actions and training into one place with a verifiable record. You can read what it aims to do on the software page and register your interest.
Related reading: Compliance & Regulatory Reporting — the framework, monitoring and reporting side. Operational Governance — governance, risk and operating standards. The Provenance software — the system being built to bring it together.