The Spreadsheet Running Your Company Is a Risk You Haven’t Priced

Nearly every founder-led company I work with has at least one spreadsheet doing a job nobody meant for it to do. Tracking cash. Calculating prices. Recognising revenue. Holding together the assumptions behind the whole business model.
Nobody sat down and designed it to become critical infrastructure — someone built it fast because the company needed an answer that week, and it held up well enough to get through the next few months. Then the company grew. More people started using it, more formulas got bolted on, and without anyone ever deciding it should, the spreadsheet quietly became part of how the business runs.
That’s the moment it stops being a productivity tool and starts being a business risk.
Growth outruns the systems underneath it
It happens slowly, and nobody chooses it on purpose. Revenue climbs, the team grows, customer numbers go up, and the processes underneath all of that stay roughly the same as they were when the company was a third the size.
Controls and reporting improvements just never make it to the top of a founder’s list, and I don’t blame them for that. Boards want to talk about growth, about customers, about the next round. Nobody’s asking to see how the monthly reconciliation gets done, or how changes to the model get recorded. So the growth gets the attention and the budget, and the systems underneath get patched together in whatever spare hour someone finds. For a while, that’s genuinely fine.
Here’s the trap: a fragile process looks exactly like a reliable one, right up until it isn’t. A formula error can sit there unnoticed for months. Two people can be working off different versions of the same file without realising it. Sometimes there’s exactly one person in the building who actually understands how the model works or where a particular number came from.
Then a board member asks a question nobody can answer cleanly. A figure in the data room doesn’t match the management accounts. The one person who could fix it is on holiday. What looked like a convenient spreadsheet turns into a bottleneck, fast.
What six years in trading taught me about controls
Before this, I spent six years running trading and operations for international teams. In that world, controls weren’t a compliance box to tick, they were just how the business worked, every day. When real money moves through a system, “it normally works fine” doesn’t cut it as an answer. Get it wrong and you can lose real money within hours.
A founder-led business doesn’t get that same fast feedback. A weak control on a trading desk shows up the same day. A weak control in a growing SaaS or healthcare company might not surface for a year. And when it does surface, it tends to pick the worst possible moment: a funding round, an audit, a big commercial decision.
An investor notices two reports don’t quite match on revenue. Someone explains it away, and the explanation raises another question. Then another. What started as one spreadsheet becomes a question about how much an investor can actually trust the company’s numbers.
What I took from those six years wasn’t that every business needs elaborate controls. It was simpler than that: know what could go wrong, make sure you’d actually notice if it did, and never let the only person who understands a critical number be one person, in one file, that nobody else has looked at.
When an internal inconvenience becomes a commercial problem
Investors don’t just look at the numbers. They want to know where the numbers came from. Is revenue coming out of a consistent process, or getting stitched together the night before the meeting? Can anyone other than the founder actually walk through how the forecast works, or is that knowledge sitting in one head?
A financial model only one person understands is a risk in itself. So is a pricing tool nobody reviews, a cash forecast pulled manually from half a dozen bank accounts, or a customer-profitability number built on assumptions nobody’s checked in a year.
It doesn’t mean the company is badly run so much as it means the business grew faster than the plumbing underneath it. But the moment investors, lenders or a buyer get involved, that stops being an internal quirk and starts touching confidence, valuation, and how fast a deal can actually close.
The fix usually isn’t a big systems project
Most founder-led companies don’t need to rip out every spreadsheet and buy an expensive platform, and honestly, doing that can create as many problems as it solves. What actually helps is simpler: work out which spreadsheets and manual processes have quietly become load-bearing, then put controls around just those, sized to the risk.
Give it an owner. Build in a review step. Limit who can touch it. Write the assumptions down somewhere other than a comment in cell A1. Keep a version history that actually means something. And build a process someone else can pick up when the usual owner is out sick or leaves.
None of that is complicated on its own. Put it together, though, and it’s the difference between a small mistake staying small and turning into something much worse.
To be clear, spreadsheets aren’t the villain here
For a lot of seed-stage and early-growth companies, they’re still the right tool, more flexible than anything else available, and bringing in formal systems too early just slows things down and adds cost the business doesn’t need yet.
I’m not arguing for getting rid of spreadsheets. I’m arguing for noticing the point where one of them quietly stopped being a convenient tool and became part of the company’s critical infrastructure. Once the business depends on it, the real question isn’t whether the spreadsheet works today, it’s what happens to the company on the day it doesn’t.