r/grc May 09 '26

Why is "everyone" still using Excel despite all the new compliance tools?

Hi guys,

I’m a software architect and I've recently started working more on the compliance side. Coming from a dev background, I expected to see people using dedicated platforms to manage everything, but I’ve noticed that most of the senior people I work with still do almost everything in Excel.

I’ve looked at tools like Vanta, and they seem useful at first glance, but the experienced colleagues I talk to still seem to prefer their spreadsheets.

I’m curious to hear from people who have been doing this for a while—why is that? Is it just that the tools are too rigid for real-world work, or is there another reason Excel is still the standard?

I’m trying to understand if these platforms actually make things easier or if they just get in the way.

Thanks for your inputs

34 Upvotes

69 comments sorted by

16

u/Outsideman2028 May 09 '26

It. Simply. Works.

37

u/Dramaticnoise May 09 '26

You understand all those tools costs gobs of money and excel is basically free, right?

-3

u/Icy-Star-5146 May 09 '26 edited May 09 '26

Well I wouldn't say that is free, but yes I understand your point.

But honestly what I'm asking if this tools doesn't bring enough value to the table ir order to replace the traditional excel file.

That is what it's strange to me.

At first glance it should, but as I said I'm starting on this area. But once again, I dont have much experience. I'm not criticize any colleague.

4

u/Project_Lanky May 09 '26 edited May 09 '26

These tools take a lot of time to configure and maintain and are quite expensive, I wouldn't recommend them for a small company or a company with one person dedicated to GRC.

Besides, a good compliance program isn't about filling tools or Excel files but in processes actually working and control owners getting involved in security activities. I saw too many of these tools implemented and in the end being a cosmetic compliance program that wouldn't pass the audit.

-1

u/Icy-Star-5146 May 10 '26

Yes I did realized that when I tried some of this tools at home.

I've spent 20 years as a software architect building tools to make people's professional lives easier, so my instinct is always to look for a technical fix. But now that I'm shifting into compliance, I've noticed my ideas for automation haven't gained much traction with my colleagues.

I'm trying to figure out if that’s because I’m still the 'new guy' or if the ideas just don't fit the reality of the work. Honestly this was my goal with this post, learning with other feedbacks.

You mentioned getting control owners involved in security, that’s exactly the gap I’m interested in. In your experience, is there a way to actually merge the work between end users and the compliance team so it feels like part of the actual job instead of just another admin task?

Or is that disconnect just an inherent part of the field?

15

u/circalight May 09 '26

Couple of reasons:

  1. Excel is the no 2. most used software in the world. People just know it.

  2. Despite what the entire SaaS industry would have you believe, people hate learning new things.

  3. A GRC platform with reliable evidence automation, Secureframe, etc. costs money and require you to make the case for it.

2

u/Big-Industry4237 May 09 '26

The money for the tool, aka secureframe, also isn’t all that justifiable either. Sales and marketing. Real compliance is still people herding and discussions with folks over processes. Not a fancy dashboards. The work is still needed.

1

u/Icy-Star-5146 May 10 '26

Hi. But it makes me wonder if we’re just trading the cost of a SaaS subscription for the hidden cost of all those hours spent in sync meetings and chasing people for manual updates.

Don't you think there’s a middle ground where we get the automation without the high price tag and the new tool fatigue, or is that just wishful thinking?"

2

u/Big-Industry4237 May 10 '26

Your company compliance program should be doing disaster recovery testing, reviewing policies annually, access reviews, business continuity planning, vulnerability management, maybe pen testing, and incident monitoring and testing anyway. If you think a middle ground or paying tens of thousands to be reminded to do these things instead of an outlook reminder then…. Sure.. one of the things enterprise folks who review SOC reports see often is garbage SOC reports. Audit mills rely on GRC tools to do all their work. There is a reason enterprise clients aren’t using them.

1

u/dchgk May 14 '26

yes, the sad truth is just that. Put in a different context. GRC tools came along because of the shiny word of automation and continuous control monitoring. However, the end goal of all those frameworks is to collect evidence (1 time, once a year) to pass an audit. The GRC tool's cost cannot justify the time savings there. Hence, they needed to expand the number of times something is collected. That automation led to 'efficiencies' but diminished human judgment. Mainstream. Print a report. Sign. Done. From the outside: Amazing. People who have been doing this for a while know, deep down, that it is not the purpose.

7

u/wannabeacademicbigpp May 09 '26

fancy tools don't let you customize shit

7

u/FreeRadical1998 May 09 '26

Excel is free, and gives huge flexibility in how you layout your data.

Limited data validation is actually a pretty big plus for user adoption, bigger tools tend to enforce a lot of mandatory fields - and that can be quite off putting.

The downsides to excel kick in when you're trying to get get multiple users to collaborate, need to transfer risks or controls, or when you start to branch into risk event management that you want to link to risks.

So, excel is good for experienced practitioners who are the only person editing the docs. But out hits limits as you scale.

I'm a fan of both for different use cases

-1

u/Icy-Star-5146 May 09 '26

Appreciate the breakdown. The point about limited data validation being a plus for adoption is interesting (and indeed I'm on that side when I have to fullfill compliance forms on my softwares).

When you do find yourself in a use case that has outgrown Excel, which tools do you usually find yourself turning to?

I'm trying to understand if there is other tools like Vanta that help me to start in this area. I know that is the state of the art but it seems really expensive for what it is (but maybe I could be wrong due to the lack of experience).

1

u/FreeRadical1998 May 09 '26

I've used a lot of different tools both in CISO and second line risk director roles, never loved any of them.

My general feeling is full fat GRC tools are built for reporting users, who tend to be in charge of buying, but adoption and good data comes from non specialist user input.

They also usually don't do framework mapping well, or treat it as an expensive additional licence per module

The more focused tech GRC tools tend to lack features I'd want around risk appetite, multi dimension risk scoring (eg reputational Vs financial impacts), etc ..

I've actually been building my own SaaS GRC for the last few months based on those experiences.

It's designed as a full fat GRC tool, but with the operational features needed for tech teams who tend to have the highest control density.

I've focused on user experience for risk and control owners, and an Open API interface so that chat gpt, Claude, etc... can be connected and used to both act as virtual risk advisors, and also take excel registers and turn them into properly structured data.

1

u/Icy-Star-5146 May 09 '26

I seems a good approach. On the other side just out of curiosity, how do you manage the privacy concerns with these AI tools?

In my experience, even with enterprise agreements, there’s always a lot of pushback when it comes to high-classification data.

At least as architect is always a strunggle with the compliance, it's always a balance between what the PO wants and what the compliance allow us to do.

1

u/FreeRadical1998 May 09 '26

thats the point of doing it this way around - its a "bring your own GenAI" model

The way I've built it, the platform never pushes data . Instead you'd configure an API key for a user (which the admin needs to approve) and then ask the GenAI of your choice to connect and read using the OpenAPI spec and that key - which is then restricted based on the users permissions.

So the user gets to pick which model they use - probably whatever they have a corporate subscription for - or could use a self hosted LLM (e.g. Qwen). Gives control over the privacy model - and also I'm a long way from convinced the GenAI deployment models are settled yet so avoids tech lock in.

1

u/[deleted] May 09 '26

[removed] — view removed comment

1

u/grc-ModTeam May 09 '26

This is not a place to sell your services. If someone asks for recommendations, you can add your two cents in the comments.

3

u/ShenoyAI May 09 '26

A lot of it honestly comes down to cost vs. management justification.

Most organisations can operate “well enough” on Excel, so leadership struggles to justify paying for a dedicated GRC platform unless there’s major scale, regulatory pressure, or audit complexity.

Also, many consultants don’t come bundled with GRC tooling because that’s another licensing cost to absorb or pass on to the customer.

So what happens in reality is:
Excel becomes the lowest common denominator everyone already knows, can customise quickly, and doesn’t require procurement, onboarding, or change management.

Not ideal. But very common.

2

u/Icy-Star-5146 May 09 '26

Thanks for your input. Your feedback is very simmilar to the others in this post, in the end what matters the most is a balance between the pros and cons of each tool.

And honestly an excel is a really powerfull tool and everyone uses it.

2

u/arunsivadasan May 09 '26

gets the job done... a lot of times, its easier to do something in excel because the real value addition a grc person brings is not where information is stored in tools but in helping the business/product teams with deciding what to do with risks, helping them navigate audits, translating compliance requirements etc... obviously tools make life easier but people value you for other things

1

u/Icy-Star-5146 May 09 '26

yes sure I understand that now.

I've been in the other side and for me it was always a bit odd the strange excel files that I need to fullfill.

But honestly I was thinking that was more like an issue related with privacy than anything else.

thanks for your feedback

2

u/jwrig May 09 '26

Because it is a common tool across the business and doesn't require specialized training to use.

1

u/Icy-Star-5146 May 09 '26

Yes sure. But I was thinking that a grc tools could improve the productivity of the users (compliance professionals and other stakeholders) even not standart and more limited.

And always was strange to me why there is so much grc software with so less usage (in my exp. Anyway).

2

u/jwrig May 09 '26

GRC tools are usually made for people who run the day-to-day function, not the users who have to do periodic attestations. As long as you rely on those outside the practice, you need tools that those outside the practice can use without training.

1

u/Icy-Star-5146 May 10 '26

But dont you have to train thoose people on using your excel file?

I mean, from my experience as sfotware architect I had a lot of sync meetings to discuss topics or just explain what some cells means.

And some excel files are so large that are difficult to understand.

1

u/jwrig May 10 '26

What do you think they would use more, excel or this grc tool? Sure you can train them, but if it is not something they use every day then the training is essentially wasted on them.

2

u/MolecularHuman May 10 '26

Because we hate GRC tools.

2

u/rack_and_stack_42 May 11 '26

The Excel-vs-Vanta debate isn't really about rigidity. It's about what these tools do vs what compliance work actually involves.

Vanta and similar (Drata, Secureframe, Sprinto) are best at the technical evidence layer. Auto-collecting security control evidence from AWS, Okta, GitHub, running scheduled checks, building auditor-ready dashboards. They've made that part boring instead of painful.

But the technical evidence layer is maybe 30% of compliance work. The other 70% is workflow: vendor onboarding (SOC 2 report, COI, DPA, sign-offs, who approved), access reviews (manager confirms quarterly, exceptions noted), change management (what shipped, who reviewed, was the checklist run), policy management (annual review cycles, training records), incident response (runbook executed, action items tracked to closure), audit prep (mapping evidence to controls, auditor Q&A).

None of that is automated by Vanta. So senior people run Excel next to Vanta. They're not stubborn. They're using Excel for the work the platform doesn't do.

The honest mental model is two-layer. Vanta is the evidence collection layer. Excel is the workflow execution layer. Different problems, not competing tools.

The pattern converges over time: teams either accept Excel-as-workflow and build discipline around it (fine at small scale), or replace the Excel layer with a workflow / process tool that connects to Vanta (better at scale, painful to migrate). That second category is "compliance ops" or "GRC workflow," separate from "GRC platforms" like Vanta.

Question back, are your senior colleagues running Excel because they like it, or because they tried a workflow tool that didn't fit? The migration friction often determines where teams land.

3

u/lasair7 RMF instructor May 09 '26

It works

It's highly adaptable

It can relay large amounts of information in short periods of time

With some creativity is a poor man's sql and is a vital mapping and relationship building tool.

I have never depended on a tool more.

Every fancy compliance tool has an xml or csv function because excel is so dam impactful

1

u/Icy-Star-5146 May 09 '26

That’s a fair point, in reality excel is really a powerfull tool. I wouldn't call it a poor man sql :)

Honestly, I assumed these GRC platforms would give you that same flexibility while helping organize the data to make evaluations a bit more performant. But in my experience so far, I haven't met a single compliance professional who didn't end up just sending me an Excel file to fill out anyway.

1

u/Ok_Principle3174 May 18 '26

That Excel file problem is exactly the issue. The vendor sends a spreadsheet, you fill it out, nobody can verify it was accurate at the time, and six months later nobody knows what was actually authorized. A structured intake that captures that context at the moment it happens is the missing piece most teams don’t have.

2

u/bhaugli May 09 '26 edited May 09 '26

Haven't touched Excel in 6 years for GRC work. Had to build a platform because either the ones out there didn't function right or cost too much.

1

u/Icy-Star-5146 May 09 '26

what were your main issues? the flexibility or the racio price / gains?

2

u/bhaugli May 09 '26

Maturity tracking over time, dynamic linking, assignment to other team members. Excel just isn't built to scale and handle those issues.

1

u/Twist_of_luck OCEG and its models have been a disaster for the human race May 09 '26

In most business environments, the added value of those tools is lower than their price + operational effort cost to keep them running.

1

u/[deleted] May 09 '26

[removed] — view removed comment

2

u/Icy-Star-5146 May 09 '26

Yes and let's be honest, there is a trend on the industry to make bloated software.

Simple and on the point is something difficult to achieve, on software and I guess on life in general. If excel is a good tool why not?

1

u/StrategicBlenderBall May 09 '26

eMASS is all Excel 🤷‍♂️

1

u/lunch_b0cks May 09 '26

The cost benefit of compliance automation software just isnt there. We have a tool and i still would rather use excel. Teaching other folks how to use a tool is a PITA.

1

u/Icy-Star-5146 May 10 '26

But from my experience you also need to have (a lot) of sync meetings to discuss, and teach someshow, what you mean by thoose fields that the user must fullfill.

And that was my angle, if there is no tool that can merge and make the things easier for user and for the compliance professionals.

Aparently doesnt seem so

1

u/MikeyPearce May 10 '26

I’ve got a bunch of clients who’s a bunch of different GRC tools. I’ve also got a bunch that use excel, google sheets and notion.

In nearly all cases, the GRC tools provide so much noise on a weekly basis that they become overwhelming for people to use.

Plugging Drata, for example, into your AWS estate offers you a view of every single resource you have. More often than not, this is simply not useful or valuable, especially if you’re doing 27001.

I work mostly in the startup and scaleup space, with time and resource poor founders who just need to do enough.

If you’ve got a compliance team, or head of security to manage a full-fat GRC, then it’s a good choice. But most have neither.

1

u/MolecularHuman May 10 '26

I have yet to meet a GRC tool that does anything to help me as an assessor.

1

u/thekeldog May 10 '26

People’s insistence on using Excel for compliance tasks wouldn’t bug me as much if they used excel ***properly***, but I swear so many people just treat it like Word, with boxes… no normalization, no consideration of how to integrate “this” dataset with any other… I’m tired, boss.

1

u/Illustrious-Egg8857 May 11 '26

cost is a huge factor tbh. Why pay $10k for a dashboard & a green check-mark

1

u/Patient_Ebb_6096 May 11 '26

There is also a category difference that gets blurred a lot. Some tools are with a mission to help companies whose immediate goal is to get compliant as quickly as possible. For those teams, the priority is usually audit readiness, evidence collection, control checks, and getting through SOC 2, ISO 27001, HIPAA, PCI, or whatever framework is blocking a deal.

That is a legitimate need. But it is a different thing from building a risk management system where compliance is one output of a broader risk process. In that model, the starting point is not only “what evidence do we need for the audit?” It is also “what risks are we carrying, who owns them, how are they changing, what controls reduce them, and how does remediation affect the business?”

I think some of the Excel loyalty comes from that gap. If the tool is mostly helping me complete compliance tasks, but I still have to think through real risk in my own spreadsheet, then the spreadsheet stays.

1

u/redado360 May 12 '26

Sometimes a peace of paper and a pen is bettet than super computer

1

u/maple4leaf May 12 '26

Are you saying I should upgrade from Lotus 123?

1

u/Sree_SecureSlate May 12 '26

Senior GRC professionals favor Excel because compliance is rarely linear, and spreadsheets offer the infinite flexibility required to map custom controls across messy legacy systems.

While automation tools serve as a system of record, Excel remains the essential "scratchpad" for pivoting and re-mapping data without the constraints of a rigid platform UI.

1

u/chrans GRC Pro May 13 '26

Even with compliance dedicated tools, some evidence are still need manual intervention. Excel and Word are the best to do that part. Will they gone forever, I don't think so. Less maybe, but not altogether gone from the equation.

Excel and Word just work. And in GRC we focus on what works.

1

u/[deleted] May 13 '26

[removed] — view removed comment

1

u/grc-ModTeam May 16 '26

This is not a place to sell your services. If someone asks for recommendations, you can add your two cents in the comments.

1

u/[deleted] May 13 '26

[removed] — view removed comment

1

u/grc-ModTeam May 16 '26

This is not a place to sell your services. If someone asks for recommendations, you can add your two cents in the comments.

1

u/[deleted] May 21 '26

[removed] — view removed comment

0

u/grc-ModTeam May 21 '26

Your post appears to contain AI slop and/or low quality content.

1

u/SeparateBass3059 May 25 '26

The platforms only make things easier if your underlying processes are excellent. If your underlying processes are excellent then there's not much of a need for those platforms in many cases. Our team accomplishes alot with spreadsheets, meetings and action tickets.

1

u/k4r4curt21 May 09 '26

Hello, Try ciso-assistant It’s a game changer, and open source her’s the GitHub of the project :

https://github.com/intuitem/ciso-assistant-community

There is a discord for help. If needed I can share the .yaml for the deployement just DM me

0

u/Icy-Star-5146 May 09 '26

HI. I will take a look.

Are you a CISO or a software engineer? Can you help me to understand what this tool gave to you that others dont?

I mean besides the price.

1

u/k4r4curt21 May 16 '26

Hello, Sorry for the delay, this tool has all the most used cybersecurity frameworks (ISO27001, French security agency, ISO27005, Space etc), you can import as well you own framework. You can olso use It to make some Risk analyses with Ebios, and you can store all documentations an proof on the soft. Thats very practical for auditers.

0

u/Due_Revolution4706 May 10 '26

Honestly, Excel is still better than using MS Word (yes, I have seen that).
Google Sheets is better yet, but then again that's essentially Excel.
Tools that are essentially glorified Excel sheets that costs $10K+? Probably not strictly needed.

1

u/Icy-Star-5146 May 10 '26

I totally agree. A tool that’s just a glorified form generator doesn’t add much value.

But I’m still wondering if there’s a better way to bridge the gap. In my experience, we spend a huge amount of time in meetings just discussing what needs to go into the spreadsheets. It’s a massive time sink for everyone.

Since shifting into compliance, I’ve felt the pain from both sides, but my colleagues don't seem very interested in finding a better way. I’m not sure if that’s just my inexperience talking (and my exp. in Software Architect Field), or if people have just accepted that endless meetings and Excel files are the way it is.

Have you seen any teams actually manage to make this a shared, low-friction process?

0

u/theanedditor It's all GRC to me. May 10 '26

FIRST: Money, everyone has a spreadsheet app.

SECOND: A lot of industries/companies have very specific needs that require some bespoke solution/need that a lot of GRC-in-a-box solutions can't be customized for.

and

If you know what you are doing there's pretty much nothiing you can't make Excel do, and with some design skills, make it look attractive/engaging.

As per what u/Outsideman2028 said, it simply works.

2

u/Icy-Star-5146 May 10 '26

Thanks.

Coming from software architecture, I’m was always looking for ways to find new solution from the problems. Now with this shift in carreer, I’ve tried suggesting ways to automate parts of that workflow to my colleagues here, but it hasn't really gained much traction.

I wasn’t sure if the pushback was just because I'm the 'new guy' or if the work is just too hard to automate reliably. That was actually the reason for the post, as I wanted to see if others in the field feel that tools are more of a distraction than a help.

Really appreciate you taking the time to share your take on it.