The largest independent GRC practitioner survey to date — 795 respondents, no vendor funding — found that spreadsheets are still the number one compliance tool in active use, ahead of ServiceNow and every commercial GRC platform combined. 59% of GRC practitioners use no commercial GRC tool at all, and 70% still rely on spreadsheets or repurposed tools like Jira, Notion or SharePoint. (Source: State of GRC 2026 Report, grcengineer.com.)
If that's you, this isn't a "you're doing it wrong" post. A spreadsheet is a genuinely reasonable place to start a compliance program — it's flexible, everyone already knows how to use it, and it costs nothing extra. The real question isn't whether spreadsheets are bad. It's knowing which specific things break first as the program grows, so you can see the failure coming instead of discovering it during an audit.
What actually breaks, in the order it usually breaks
1. Nobody can say who changed what, or when
A shared spreadsheet has no real audit trail. Version history in Google Sheets or Excel Online technically exists, but it wasn't designed to answer "who changed this risk score from Medium to Low, and why" in a way an auditor will accept. Once more than two or three people are editing the same file, this becomes the first thing that quietly stops being trustworthy — usually well before anyone notices.
2. Ownership drifts
Controls, risks and findings all need an owner. In a spreadsheet, "owner" is a text field, not an enforced relationship — so when someone leaves the company or changes roles, their name just sits there, orphaned, until someone manually notices and fixes it. At small scale this is a minor annoyance. Past a few dozen controls, it's a structural gap an auditor will find faster than you will.
3. Evidence goes stale silently
A screenshot or exported log attached to a control is only valid for as long as it's actually representative of current reality. Spreadsheets have no concept of an evidence expiration date — nothing tells you a piece of evidence from eight months ago no longer reflects your current AWS configuration. You find out when an auditor asks for something current and you have to go re-collect everything, under time pressure.
4. The same control gets tracked five different ways
If you're working toward more than one framework — ISO 27001 and SOC 2, say, or adding GDPR and KVKK on top — a spreadsheet-based program usually ends up with one tab per framework, each with its own copy of overlapping controls. Access control policy gets entered, tracked and updated separately in four places, and the four copies drift apart the first time one of them changes and the others don't.
5. Reporting becomes a manual project
"Can you send the board a current risk summary by Friday" turns into hours of manually reconciling tabs, checking what's actually up to date, and reformatting into something presentable. This is usually the moment a spreadsheet-based program starts looking for a dedicated tool — not because the spreadsheet itself broke, but because producing a trustworthy report from it stopped being fast.
A genuinely underserved starting point
Here's the part of the research that surprised us most: the 59% of practitioners using no commercial tool at all isn't a niche group choosing spreadsheets over Vanta or Drata on price. It's the majority of the market, and most GRC platforms aren't really built for them — they're built for teams that already have a dedicated compliance function. The same research found average self-reported technical skill among GRC practitioners is 5.3 out of 10, while most platforms still assume a semi-technical "GRC engineer" persona comfortable with APIs and scripted integrations.
That's a real gap, not a marketing angle: most of the addressable market for GRC software isn't choosing a competitor over anyone. It's choosing nothing, because nothing on offer assumes their actual starting point.
What to look for when you do move
- A real import path, not a blank slate. Re-entering everything from scratch is the single biggest reason spreadsheet-to-tool migrations stall. Look for a tool that can read your existing spreadsheet exports and propose structured entries — with a human reviewing and approving each one — rather than asking you to start over.
- An append-only audit trail by default, not a feature you have to turn on or configure correctly.
- One control library across frameworks, so you stop maintaining four copies of the same access control policy.
- Evidence with an actual expiration concept, so staleness surfaces on its own instead of at the worst possible moment.
- Plain-language everywhere, not tooling that assumes you already speak fluent GRC.
This is exactly the gap our Asset Agent is built around: it reads your existing spreadsheets and exports and proposes structured, attribute-complete inventory entries, flagging anything it isn't confident about instead of guessing — so moving off a spreadsheet doesn't mean re-typing a year of accumulated data by hand. Nothing writes to your live inventory until a person reviews it.
If your program is still spreadsheet-based, the honest test isn't whether it's "good enough" today. It's whether you can already name which of the five failure points above is closest to happening to you — because by the time it does, it's usually an audit finding, not a planning conversation.
