A guest post by Sam Lee, Head of Operational Risk, EMEA, SMBC, Torchlight Services
EUC risk is the potential for errors, unauthorized changes, or data loss in spreadsheets, macros, databases, and other end user built tools that operate outside formal IT development and testing controls. EUCs are commonly used to support financial reporting, regulatory filings, and executive decisions. As such, an uncontrolled error in a single EUC can produce inaccurate reporting, compliance violations, direct financial loss, or regulatory fines.
Left unmanaged, EUC risk sits inside the broader EUC and model risk management discipline, and it is the exact problem Mitratech ClusterSeven is built to solve.
What is End User Computing (EUC)?
End User Computing refers to applications that business users build and maintain themselves, rather than tools built through a formal IT development cycle of design, build, test, and release. Microsoft Excel is the most common example, but EUCs also include Access databases, Python, R, Matlab and other script-based applications, macros, and, more recently, AI agents.
Why does EUC risk matter?
EUC risk matters for two reasons:
- It is nearly universal. Any organization with key processes supported by spreadsheets or similar tools built and maintained outside the formal IT environment carries EUC risk. Very few businesses operate without them.
- It compounds other enterprise risks. EUC errors rarely stay contained. A flawed spreadsheet can trigger financial reporting risk, regulatory risk, operational risk, and reputational risk simultaneously, because the same file often feeds multiple downstream processes.
EUC risk also shows up directly in regulatory frameworks. For financial services firms, PRA SS1/23 compliance, BCBS 239, and the Federal Reserve, OCC, and FDIC’s SR 26-2 (which superseded SR 11-7 in April 2026) all set explicit expectations for how model and EUC risk gets governed.
What are examples of EUC risk?
- A pricing spreadsheet with a broken formula that understates cost and is used to set customer contracts
- A regulatory capital calculation maintained in Excel with no version control, where an untracked edit changes a reported figure
- A macro-driven model whose sole author leaves the company, leaving no one able to validate or maintain it
- A shared spreadsheet with no access controls, where any user can alter inputs without an audit trail
For a deeper walkthrough of the operational build, see 8 Key Steps for a Successful EUC Control Project, and for the audit angle, Lowering Spreadsheet Risk With an EUC Audit.
How do you manage EUC risk? A 5-step framework
- Inventory your EUC population. Identify every EUC in use, the type (spreadsheet, Access database, Python, R, Matlab or other script-based application, macro, or AI agent), and its complexity: for example, whether a spreadsheet uses macros, contains heavy coding, or connects to other files and systems.
- Assess criticality. Score each EUC on quantitative impact (potential dollar loss) and qualitative impact (regulatory exposure, client impact, reputational damage, loss of business function) if it were lost, corrupted, or altered without detection.
- Set a governing policy. Define risk tiers and the controls required at each tier, plus rules for documenting, testing, and maintaining the EUC inventory going forward.
- Build a risk heat map. Plot critical EUCs against key risk indicators (KRIs) to surface which files are non-compliant or overdue for review.
- Map EUCs to your risk library. Connect critical EUCs to the broader risks they touch, such as internal fraud, financial reporting, or data governance, so EUC risk is managed as part of enterprise risk rather than in isolation.
Doing this manually breaks down quickly at scale. Tracking every change to EUCs, such as formula, macro, and link changes in a spreadsheet, across hundreds or thousands of files by hand is not practical, and it becomes difficult to tell an intentional update from an unauthorized one. This is why most organizations adopt automated discovery, inventory, and monitoring for their EUC landscape.
To work through this step by step, download The Ultimate End User Computing Checklist.
Why critical EUCs need zero tolerance, not thresholds
For any EUC classified as critical, the honest target on ownership, version history, access control, and testing is 0% gaps, not a tolerance band. A critical spreadsheet with no documented owner or no version history is not a minor exception; it is an unmanaged risk sitting inside your reporting or compliance process. The real question is not “what threshold is acceptable” but “do we have transparency into which critical EUCs currently fail these checks at all,” since most organizations do not.
The ROI of EUC transparency
Achieving that transparency is not just a compliance exercise. It returns value across six areas:
- Retains the business agility EUCs provide. Managing EUC risk does not mean restricting the spreadsheets and tools people rely on daily; done well, it adds oversight without slowing anyone down.
- Reduces the risk of using EUC, including reputational damage. Visibility into critical files lowers the odds of the kind of reporting error that becomes a public incident.
- Meets regulatory compliance requirements. Frameworks like PRA SS1/23 expect firms to demonstrate they know where their critical EUCs are and how they are controlled.
- Improves data quality in the processes EUCs feed. Once you can see the EUCs behind a report, you can see where the data itself needs attention.
- Improves the efficiency of EUC usage. Time lost to corrupted files, outdated versions, or recreating lost work drops once EUCs are inventoried and tracked.
- Improves corporate knowledge of EUC assets. Firms stop discovering how many critical spreadsheets exist only after something goes wrong.
Each of these compounds: transparency into your EUC population is what makes the other five achievable.
Frequently Asked Questions
Frequently Asked Questions
What is the difference between EUC risk and IT risk?
Who is responsible for managing EUC risk?
Does EUC risk apply to small businesses?
Can EUC risk be eliminated?
What tools help manage EUC risk?
See Mitratech ClusterSeven in action
Request a Mitratech ClusterSeven demo to see how automated EUC discovery, inventory, and monitoring works in practice.
