Home / Resources / Spreadsheets and IFRS S2
Controls

Spreadsheets and IFRS S2: where the calculation ends and the control begins

Almost every criticism of spreadsheets in sustainability reporting is aimed at the wrong target. The complaint is usually that the maths is unreliable. In my experience the maths is generally fine.

The problem sits one layer up, in everything that happens around the calculation.

Key points

  • For the calculation, a spreadsheet is fine. Teams have run emissions workings in Excel for years and the arithmetic holds up.
  • Three things a workbook cannot produce: who approved a figure, what it was before someone changed it, and a durable link to the source document.
  • A cell overwrite destroys the previous value. Not archived, not hidden — gone.
  • You probably do not need to replace the spreadsheet. You need the approval and change history to live somewhere that records itself.

The concession: the arithmetic is not the problem

Consumption times emission factor, aggregated across sites, converted to a common unit. That is a spreadsheet's home ground.

Your team already knows the tool. The model is transparent in a way that a black-box calculation is not. You can audit the formula by reading it.

Anyone who tells you the calculation itself is the risk is selling something. The reason first cycles struggle is not that companies cannot multiply.

Two columns comparing what a spreadsheet does well — calculation, modelling and speed — against what it cannot do: record who approved a figure, retain what a value was before it was overwritten, and hold a durable link from a number to its source document.
A boundary, not a verdict. Most reporting teams need both sides; the mistake is assuming one covers the other.

The three things a workbook cannot tell your assurer

Who approved this figure. A workbook records values, not authority. You can type a name into a cell, and the next person can type a different one. Nothing distinguishes the approval from the assertion.

What the value was before. This is the structural one. Overwrite a cell and the prior value ceases to exist. There is no archive, no shadow copy, no history. If your Scope 2 figure moved between the September pack and the March filing, the workbook cannot tell you it moved, let alone why.

Which document supports this number. Files sit in a folder. Numbers sit in a sheet. The connection between a specific invoice and a specific cell lives in someone's memory, which is a poor storage medium with high staff turnover.

What "version 7 final FINAL" actually costs you

Filename versioning is a reasonable habit and a bad control.

It tells you the order in which files were saved. It does not tell you what changed between two of them, who changed it, or on what basis. Reconstructing that means opening both files and diffing them by eye, assuming both still exist.

The cost lands at the worst moment. Your assurer asks why the figure differs from the draft they received in September. The honest answer is usually "a correction came in" — and the evidence for that answer is a file that was overwritten.

Keeping the spreadsheet and adding the control layer

The useful reframing: stop asking whether to replace Excel, and start asking where the boundary sits.

Calculation stays where it is. Approval, change history and the link from figure to document move somewhere that records events as they happen rather than storing a final state.

That division is workable, and it is much less disruptive than migrating a model that already works.

Four stage round trip: export cycle figures to xlsx with each row carrying an id, edit in Excel, re-import matched to existing rows rather than duplicated, and the change recorded with the old value kept. Below, a ledger row showing Scope 2 market-based moving from 1,284 to 1,301 recorded as a change.
Keeping the spreadsheet and adding the control layer. The figures shown are illustrative.

What a controlled import looks like

Concretely: the workbook is uploaded and kept as supporting documentation, hashed so it can be shown to be unaltered. Each figure it produces carries a reference back to the file, sheet and row it came from. The import itself is recorded.

Then the round trip. Export the figures, work on them in Excel, bring the file back. Because each row carries an identifier, changed values are matched to the existing figure and recorded as changes with the previous value retained — rather than arriving as new duplicates or overwriting silently.

That last property is the one worth paying attention to. It is the difference between a change history and a sequence of files. You can test what a record that cannot be altered behaves like directly, and the product page sets out the rest.

When a spreadsheet genuinely is enough

Worth saying plainly, because the answer is not never.

If you are a single-entity company with one site, two data sources and one person doing the reporting, a spreadsheet plus a disciplined change log in a separate document will get you through a first cycle under limited assurance. It is fragile and it works.

It stops working when any of three things happen: more than a handful of contributors, a move toward reasonable assurance where controls get tested rather than described, or staff turnover in the team that built the model.

The opinion: the spreadsheet is not the problem, and replacing it is not the fix. The fix is deciding that approval and change history are not things you keep in a file. Teams that grasp that keep their model, keep their speed, and stop failing the two tests that actually get them written up — which are set out in The audit trail behind your climate numbers.

Common questions

Can you do IFRS S2 reporting in a spreadsheet?

You can do the calculation in a spreadsheet, and for most companies the arithmetic is not the weak point. What a spreadsheet cannot produce is evidence of who approved a figure, what a value was before someone changed it, and a durable link between a number and the document supporting it. Those are the things an assurance provider tests.

What is wrong with version control by filename?

Nothing, until someone needs to know which version a figure was approved in. A file called v7 final updated tells you the order files were saved in. It does not tell you what changed between v6 and v7, who made the change, or why. That is the information an assurer asks for, and filenames do not carry it.

Do I have to replace Excel to be assurance ready?

No. The realistic position for most teams is to keep the spreadsheet for calculation and put the approval, change history and evidence links somewhere that records itself. Replacing a working model mid-cycle carries more risk than the control gap you are trying to close.

What is a round-trip export?

An export where every row carries an identifier, so the file can be edited in Excel and re-imported without creating duplicates. Changed values are matched back to the existing figure and recorded as changes with the previous value retained, rather than overwriting silently.

Where do you stand against IFRS S2?

A free 6-minute diagnostic scores your readiness across all four pillars and sends a 12-page gap report naming what is missing.

Run the free diagnostic →

Md R Rafi

Founder of Auditably.co, which builds disclosure controls for IFRS S2 reporting — traceability, recorded review and sign-off, and an append-only activity log. He writes about first-cycle reporting from the preparer’s side rather than the assurance firm’s.

Connect on LinkedIn →