A guest post by Sam Lee, Head of Operational Risk, EMEA, SMBC, Torchlight Services
End User Computing is a system in which users are able to create working applications besides the divided development process of design, build, test and release that is typically followed by software engineers. Microsoft Excel is perhaps one of the best known examples of an EUC platform.
With that in mind, EUC risk is therefore the potential for errors in key EUC business documents like spreadsheets. The flexibility of EUCs can lead to faults being made in these critical company documents. Given that the data produced by EUCs is generally accepted and relied on by management and other end users, this can quickly lead to incorrect data and, in turn, increases the risk of financial and reputational loss.
Why is EUC risk important?
While EUC risk is universal, it isn’t as well known or perhaps even recognized as some other enterprise risks, such as operational, financial and regulatory (or their sub categories). “Why do I need to care about EUC risk?” is often asked. There are two reasons.
Foremost, EUC risk is present in any organization that relies on spreadsheets, databases and other ‘man-made’ computing tools that sit outside of the IT application cycle. The level of the risk is informed by the risk management framework in the organization, but it is unlikely that a business does not use the above mentioned applications.
Secondly, EUC risk contributes to a whole host of other operational, regulatory and conduct risks. There’s a great deal of intercoonnectivity between EUC and other risks – all of which cumulatively contribute to enterprise risk. The diagram below shows this very clearly.
Therefore, one should challenge any organization that argues that EUC risk is not relevant to it in some shape or form. It’s imperative that organizations get to grips with the meaning of EUC risk.
The good news is that it is possible to manage and control End User Computing risk, even though it is fundamentally present across an organization. So, where’s the logical place to start?

End User Computing risk is an often underestimated threat, with data from EUCs providing the foundation for critical business decisions and reporting. Here are some top tips for managing your EUC risk:





Undertaking this kind of end-to-end and granular approach manually is almost impossible, due to the extent of spreadsheet and EUC usage in most organizations. Not only is it difficult to holistically identify and inventory the EUCs, it is also challenging to determine the inter-connections and corresponding impact of critical spreadsheets on other enterprise risks.
It is also almost impossible to effectively track changes to code, macros, and so on manually, whether the changes were deliberate and bona fide, or otherwise. Adopting technology that automates discovery, inventory, policy enforcement, control and overall management of the EUC landscape is the most cost-effective and fail-safe way forward.
Discover PolicyHub
It’s the Policy Management solution that’s easy to use, so you can build stronger compliance.

