Skip to main content
Skip to content

Replacing compliance spreadsheets

Moving from spreadsheets to a compliance management system

Most organisations do not decide to replace their compliance spreadsheet. They notice that it has quietly stopped being reliable, usually while trying to answer a question from a client, an insurer or a director, and find that answering it properly would take a fortnight.

The work already done still counts. Policies, training records, supplier information and evidence keep their value in a compliance management system. What changes is the structure around them, so that each item has an owner, an audience, a review date and a place in the record.

General information about Australian obligations, not legal advice.

What comes across with you
1
Policies you already have An existing policy set is loaded, given an owner, an audience and a review date, and issued for acknowledgement in its current form.
2
Training already completed Completed training is recorded so that the requirement dates from the last completion rather than from the day you started.
3
Supplier and system information What the register already holds becomes the starting content, with the missing fields visible instead of assumed.
4
Evidence worth keeping Reports, attestations and records that still mean something are attached to the control they support, with a date attached to each.
Recognising the point

Nine signs a compliance spreadsheet has stopped holding up

None of these is a crisis on its own. Together they describe an arrangement where the recorded position and the actual position have started to separate, and where nobody could say by how much.

  • Nobody is certain which register is current There is a version on the shared drive, a version somebody emailed, and a version with the recent updates. Reconciling them is a job in itself, so it does not happen.
  • Compliance depends on one employee One person understands the workbook, remembers what has been chased and knows which entries are placeholders. Their leave is a compliance risk that nobody has written down.
  • Policy acknowledgements are stored separately from the policies Signed forms in a folder, replies in an inbox, a tab of names in the register. Tying an acknowledgement to the version of the document it covered is manual, and usually has not been done.
  • Training records require manual checking Answering who is current means opening the provider's portal, exporting a list and comparing it against the register by hand. The answer is accurate on the day it is produced.
  • Former employees are still in the registers People who left months ago appear in training lists and against owned controls. The register understates completion and overstates ownership at the same time.
  • Evidence has no review date A folder of reports, screenshots and certificates with no view of which are still meaningful. A backup test from two years ago sits next to one from last month and looks identical.
  • Overdue items are found by looking for them Nothing surfaces on its own. Somebody opens the file, sorts by date and works out what has passed, which means overdue work is found when a person has time rather than when it falls due.
  • Management reporting means assembling data from several sources A board paper or client response requires pulling from the workbook, the policy folder, the training portal and the IT provider, then making the numbers agree. It takes days and is out of date shortly afterwards.
  • The position at an earlier date cannot be described Asked what was in place six months ago, the honest answer involves file history, memory and inference. This is the sign that matters most, because the period before an incident is the one that gets examined.

Three or four of these is normal

Very few organisations recognise none of them. The point at which it becomes worth acting is usually not the number of signs but the consequences: how often evidence is requested, how much would turn on the answer, and how confident anyone is that the register still matches reality. More detail on why this happens is on why spreadsheets fail as a compliance system.

Before the steps

You are not starting again

Existing policies, training records, evidence and control information keep their value. A compliance management system provides the structure around them so they can be assigned, reviewed, evidenced and maintained properly from here.

This is worth saying because the assumption that migration means discarding several years of work is the most common reason organisations delay. It does not. A privacy policy written two years ago and never reviewed is not worthless; it is a document that needs an owner, a review date and evidence that staff have seen it. A training spreadsheet is not worthless; it is a set of completions that should date the next requirement rather than being repeated from scratch. A supplier list is not worthless; it is the starting content for a register whose missing fields then become visible.

What migration actually replaces is the coordination layer: the manual reconciliation, the chasing, the version conventions and the memory. The material itself moves across.

Keeps its value

  • Policies and procedures, whatever state they are in.
  • Training completions, with the dates they were completed.
  • Supplier lists, contracts and questionnaire responses.
  • Asset and system inventories, including partial ones.
  • Reports, test results and attestations that are still current.
  • Known gaps and anything already recorded about them.

Does not come across

  • An audit trail the old arrangement never produced.
  • Acknowledgements that were never collected or recorded.
  • Reviews that were marked as done without a record of what was found.
  • Evidence that has passed the point of meaning anything.
  • The position as it stood at a date nobody documented.

The right column is not an argument against migrating. It is the reason to start sooner: the record begins when the system begins, and every month of delay is another month that will have to be described from memory.

The practical sequence

Eight steps to move a compliance record into a system

The order matters more than the pace. Each step makes the next one possible, and an organisation that works through them slowly ends up in a better position than one that loads everything at once and assigns none of it.

  1. Identify what compliance material already exists

    Find the registers, the policy folder, the training records, the supplier information, the questionnaire responses you have sent to clients, and the evidence that has accumulated in inboxes and drives. Include the material held by your IT provider, which is often where the technical evidence lives.

    The aim is an inventory, not an assessment. Resist the urge to fix anything at this stage. Knowing what exists and where it sits is the thing that makes every later step shorter.

  2. Establish the controls and obligations that apply

    Work out which safeguards and obligations are actually relevant to your organisation, based on what it does, what information it holds and who it answers to. A practice holding health information, an accounting firm handling tax file numbers and a services business with no personal information of consequence do not have the same list.

    Record the ones that do not apply, with the reason. An explicit exclusion with a rationale is a defensible position. An item that is simply absent from the register looks like an oversight, because usually it is one.

  3. Assign responsibility before loading content

    Give each control, policy and register a named owner. Where a review owner is different from the person who runs the control day to day, record both. This is the step most often deferred, and deferring it is what produces a well-populated system that nobody is accountable for.

    Ownership does not have to be perfect on the first pass. It has to exist, and it has to be visible enough that an incorrect assignment gets corrected rather than ignored.

  4. Load current policies and the evidence that still means something

    Bring across the policies as they stand, with the date each was approved. Where a policy is out of date, load it anyway and record the review as due. A current record of an out of date policy is more useful than an absence, and it puts the work on a list instead of in someone's memory.

    Apply the same test to evidence: attach what still supports a control, with its date, and leave behind what has passed the point of proving anything. Old material can stay in the archive it already lives in.

  5. Establish who your people are and what their roles require

    Load the current staff list, remove the people who have left, and set each person's role so that their training and policy requirements follow from it. Doing this ends the reconciliation problem, because the requirement is then derived from the role rather than maintained as a separate list.

    Record training already completed with its completion date, so that the next requirement falls due at the right time instead of everyone starting again on day one.

  6. Set the recurring review cycles

    Decide how often each policy, supplier, system, risk and control check should be revisited, and set the cycle. Annual is a reasonable default for policies and supplier reviews; operational checks are usually more frequent. The cycle matters less than the fact that a date exists and belongs to somebody.

    Set cycles you will actually keep. A quarterly review that is honoured is worth considerably more than a monthly one that is missed eight times a year, and the missed ones are visible in the record.

  7. Close the gaps you already know about

    The first honest pass through a compliance system usually produces a list of things the organisation knew were unresolved. Record each as a known gap with an owner and an intended resolution, then work through them in order of consequence.

    Recording a gap is not an admission that weakens your position. An identified, owned and actively remediated gap is a normal feature of a functioning compliance system. The weaker position is the one where nobody had noticed.

  8. Maintain the record from here

    The steps above establish a position. What makes it defensible is the next twelve months: acknowledgements collected when a policy is revised, reviews performed when they fall due, evidence refreshed as it expires, people added and removed as they join and leave, and gaps closed and recorded.

    This is the point of the exercise. A migration that is treated as a project ends with a well-organised snapshot. A migration that is treated as the start of an operating rhythm ends with a compliance position that can be shown at any point without preparation.

Sequencing

If you cannot do all of it at once

Very few organisations complete this in one uninterrupted effort, and it is not necessary. If the available time is limited, the order below produces the most improvement per hour spent, because each item removes a dependency on somebody remembering something.

  • People and roles first. Everything else attaches to them, and a current staff list corrects several registers at once.
  • Then policy issue and acknowledgement. It is the most frequently requested evidence and the most commonly missing.
  • Then ownership of controls. An owner turns a list into a set of assignments.
  • Then review cycles. This is what stops the position drifting again after the migration.
  • Then evidence. Attach what supports a control now, and let the rest arrive as reviews are performed.
  • Registers last. Suppliers, systems and risks benefit from the structure that the earlier steps create.

An incomplete system that is operating beats a complete one that is not

A compliance record covering the areas that matter most, kept current, with owners and dates and a trail of activity, demonstrates more than an exhaustive one populated in a single week and untouched afterwards. The first shows a system operating. The second shows a project that finished.

Worth avoiding

Six ways a migration goes wrong

One

Rebuilding the spreadsheet inside the system

Recreating the same flat lists, without owners, dates or relationships, reproduces the original problem in a new location. The structure is the reason for moving.

Two

Loading everything before assigning anything

A fully populated record with no named owners generates work that belongs to nobody. Ownership first, content second, is a slower start and a faster finish.

Three

Back-dating to make the history look better

Entering completions and reviews that did not happen on the dates recorded produces a record that will not survive examination. The trail starts when the system starts, and that is a perfectly normal thing for it to show.

Four

Treating it as an IT project

Most of this work is organisational. An IT provider holds the technical evidence and cannot decide who owns a policy, which suppliers matter or what training a role requires.

Five

Hiding the gaps found on the way in

The first pass surfaces things nobody wants written down. Recorded, owned and remediated is a stronger position than unrecorded, and the alternative is that the gap is found by somebody else.

Six

Stopping once it is populated

The value is in the maintenance. A record that was accurate at go-live and untouched for a year has the same weakness as the workbook it replaced.

Afterwards

What is different once the record is operating

The most noticeable change is not a report or a dashboard. It is that questions which used to require an investigation become questions with an answer. Who has not acknowledged the revised privacy policy. Which supplier reviews are overdue. What training the three people who started in July still owe. Which evidence expires before the end of the quarter. Whether the access review recorded in April was actually performed, and by whom.

The second change is that the account of what the organisation did accumulates without anyone maintaining it separately. Adoptions, acknowledgements, completions, reviews, gaps and resolutions each leave a dated entry as they happen. When a client questionnaire or an insurer's request arrives, the material is drawn from records that already exist rather than assembled under time pressure.

None of that guarantees an outcome. What it changes is the position an organisation is in when the question is asked. What proving compliance involves, and how the evidence system works.

Talk through what moving across would involve

A short walkthrough covers what your existing material would become, what would need an owner, and where the gaps are likely to be. If you would rather start with a benchmark, the Readiness Check reports where your organisation currently stands.

FAQ

Questions about replacing a compliance spreadsheet

How do we move compliance data out of spreadsheets without losing the history?

Load what is current and keep the workbook as an archive. Policies come across with their approval dates, training completions with the dates they were completed, and evidence with the date it was produced. The history that existed in the spreadsheet remains available in the spreadsheet. What the new record adds is a trail from the point it starts, which is why starting sooner produces a longer trail when it is eventually needed.

How long does it take to replace a compliance spreadsheet?

It depends far more on decisions than on data entry. Loading policies and people is quick. Working out which safeguards apply, who owns each of them and what review cycle is realistic is the part that takes time, because it requires the people who run the business. Organisations that treat it as a series of short sessions over several weeks generally get further than those that block out a single day.

Should we fix our policies before moving them across?

No. Load them as they are and record the review as due. Improving a policy before it enters the system delays the point at which it has an owner, an audience and a review date, and those are the things that were missing. A policy that is current in the record and marked for review is in a better state than a better-drafted one that is still in a folder.

Can we keep using spreadsheets for anything?

Yes, and most organisations do. Analysis, drafting, modelling and anything that has no permanent home are all reasonable uses. The distinction worth holding is between working material and the organisation's record of what it did. The second one needs to survive edits, staff changes, time and scrutiny, which is the part a workbook does not do well.

What if our compliance position is worse than we would like?

That is the ordinary starting point, and it is not a reason to delay. A first pass through a structured system reliably surfaces work nobody had got to. Recording those items as known gaps, with owners and intended resolutions, puts the organisation in a stronger position than leaving them undocumented, because an identified and actively managed gap is a normal feature of a functioning compliance system.

© 2026 Cleverer. Human-layer cyber compliance for Australian businesses.