Digitalization

Excel vs. Software for Quality Management: Which Evidence a Spreadsheet Can Produce

In nearly every quality management system I see during audits, part of the system runs on Excel: the annual audit plan, the findings log, action tracking, supplier evaluation. That is not an oversight. It is a rational decision — the file was already there, it cost nothing, and it has worked for ten years.

So the question here is not whether Excel is “good enough”. It is this: which evidence can a spreadsheet produce, and which can it not produce, structurally? That is not a matter of taste, and it is not a matter of team size. Three places in ISO 9001 answer it precisely [1].

Why Excel Works in QM — and Where Exactly It Stops

Excel is a calculation tool. It models a grid of cells in which values depend on other values, and at that it is exceptionally good. A gauge register with calibration intervals, a scoring matrix for supplier evaluation, a scrap-rate analysis per batch — nothing else in this price class comes close.

Clause 7.5 of ISO 9001 draws a distinction between two kinds of documented information, and that distinction is the key to the whole question. Information you maintain is the living, currently valid specification: the current inspection plan, the current procedure. Information you retain is the historical record: what was actually inspected, decided and released on 14 March. Annex A.6 sets the two terms side by side explicitly, and the cleanest illustration in the normative text is 4.4.2, where a) maintain and b) retain sit next to each other [1].

Excel is strong on the first and weak on the second. A spreadsheet always shows its current state — that is its purpose and its strength. A record has to show a past state and demonstrate that it has not been altered since. That seam is where things break, and it breaks the same way whether three people or thirty work in QM.

The usual objection, and why I am not making it. The spreadsheet-error literature gets wheeled out against Excel routinely, and it does exist: Panko collected thirteen field audits of operational spreadsheets and concluded that 94% of those audited contained errors, at an average cell error rate of 5.2% [2]. Powell, Baker and Lawson went back through those figures in a peer-reviewed review and registered serious reservations. The 94% rests on 88 spreadsheets from seven sources, three of them unpublished; most disclose neither a definition of “error” nor the method used to find one; and the study supplying 70% of the sample behind the cell error rate reported no error rate at all, but the share of cells auditors queried on first review [3].

So I am not resting the argument on those numbers. They would be the wrong argument anyway, because that research measures calculation errors, and the problem in QM is not a calculation error. A spreadsheet can be correct down to the last formula and still fail to produce the required evidence.

The Three Requirements That Decide It

Three clauses settle the question. All three are worded unremarkably, and all three are routinely underestimated in audit practice.

7.5.3.2 requires, among other things, control of changes — the standard names version control as the example — storage and preservation including legibility, and protection of retained evidence of conformity from unintended alteration [1]. That last phrase is the hard part.

9.2.2 f) requires you to retain documented information as evidence of two things: the implementation of the audit programme, and the audit results [1]. One subclause, two objects — and the first is the one almost everyone misses. Everyone has audit reports. Almost nobody has evidence that the programme was implemented as planned.

10.2.2 requires evidence of a) the nature of the nonconformity and any subsequent actions taken, and b) the results of any corrective action [1]. Point b) presupposes what 10.2.1 d) demands: a review of the effectiveness of the corrective action taken. Without that review there is no result to retain in the first place.

Clause Evidence required What a spreadsheet can show of it Where it breaks
7.5.3.2 Control of changes, e.g. version control the file’s current contents, plus a filename carrying a date who changed which cell when is recorded nowhere; “findings_final_v3_new.xlsx” is not version control
7.5.3.2 Storage and preservation, including legibility reasonable odds: the format is widespread and long-lived linked workbooks, macros and external references break when files move or versions change
7.5.3.2 Retained evidence protected from unintended alteration sheet and file protection, read permissions on the drive protection can be switched off and leaves no trace; a due date edited after the fact is undetectable
9.2.2 f) Implementation of the audit programme the annual plan as it looks today whether a date was moved, merged or dropped is invisible once the cell has been overwritten
9.2.2 f) Audit results the findings log and the filed reports the link between report, finding and audit criterion is free text, not a verified reference
10.2.2 a) Nature of the nonconformity and subsequent actions both, if the columns are filled in with discipline finding, cause and action usually live in separate files; the mapping is manual and unverified
10.2.2 b) Results of the corrective action a status field reading “closed”, with a date “closed” is not a result; the effectiveness review under 10.2.1 d) has neither a field nor an evidenced date

Look at the third column. In most rows a spreadsheet can in fact display the required content. The problem is not that the information is missing. The problem is that its history is.

What an Auditor Actually Asks Here

An auditor is not auditing your tool. They pull a sample and follow it. The question is almost never “do you use Excel?” It is “show me finding 2024-017.”

What follows is a backward trace. Which audit did it come from? Which criterion was being checked? Who was the auditor? What cause was determined, what action followed, who owned it, when was it due, when was it implemented — and who decided, on what basis, that it was effective?

Nine questions about one row. A well-kept spreadsheet answers seven of them. The two it snags on are the last one and an unspoken one: how do I know the due date in column H is still the date that was originally set?

There is no defensible answer to that in a spreadsheet file. The honest sentence is “that’s what we entered”, and an experienced auditor hears the difference between that sentence and a record immediately.

Assessment: In practice this gap is rarely written up as a major nonconformity. It shows up as an observation — right up until a sample turns up a genuine inconsistency, an implementation date that precedes the finding date, say. Then it stops being a question of form and becomes a doubt about the integrity of the records as a whole. Building question sets that hang off audit criteria, so the backward trace is possible at all, is the subject of the article on the audit question catalogue under ISO 19011.

The Tipping Point: Not Audit Volume, but Type of Evidence

The common rule of thumb says software starts to pay off above so many audits a year or so many employees. That rule is wrong because it measures the wrong thing. A company running four internal audits a year, but facing customer requirements on the traceability of batch releases, passed the tipping point long ago. A company running forty low-risk process audits with no external evidence pressure may not have reached it.

The signals that actually count:

  • A finding has to be traced across several files all the way to its effectiveness review.
  • Evidence has to hold up in front of third parties — a customer, a certification body, a regulator — not just internally.
  • The retention period outlives the file, the drive, or the person maintaining it.
  • Several sites or departments are to be assessed against the same audit criteria.
  • The annual audit plan shifts during the year, and those shifts are themselves part of the evidence under 9.2.2 f).
  • Management review regularly means copying data together by hand from several files.

Three of these at once are still not a compelling reason. One on its own can be — if it is the second or the third. The thresholds at which replacing Excel starts to make sense are set out individually there, and the reasoning behind a defensible programme is in the guide to audit programme planning.

There is also a date on the calendar. ISO 9001:2026 is due for publication in September 2026 as the sixth edition [4]. DIN Media rates the shift in emphasis toward documented information as evidence of implementation and effectiveness as the most far-reaching change in the revision [5]. That is precisely the point at which a spreadsheet is weakest to begin with; the detail is in the article on what changes with ISO 9001:2026.

What Excel Still Does Better

There are jobs in quality management where a spreadsheet is the better tool, and QM software does not improve them — it makes them slower.

Ad-hoc analysis. If you want to know whether a line’s scrap rate correlates with the shift, you need no configuration and no ticket. You need two columns and a pivot table, and you have the answer in ten minutes. Any system with a fixed data model is slower here, because the data model never anticipated this particular question.

One-off evaluations. A supplier scoring for a single tender, a feasibility calculation for extending a calibration interval, a side-by-side comparison of two quotes for an inspection service — these are calculations, not records. They are needed once and never again.

No rollout cost. No project, no training, no IT approval, no round with the data protection officer. The file exists thirty seconds from now.

No vendor dependency. An XLSX file sits on your drive and belongs to you. Twenty years from now half a dozen programs will still open it. Anyone who has had to extract data from a discontinued system knows exactly what that is worth.

Offline and without a login. In a supplier’s meeting room, on a shop floor with no Wi-Fi, on a train. A spreadsheet works where a web interface shows an error message.

Everyone already knows it. This is the most underrated advantage of all. Anyone in the company can open a spreadsheet, read it and understand it — with no training, no permissions concept, and nobody having to create them an account. That fluency took years to build, and it is a genuine operational asset.

Migration Without a Big Bang

The most expensive mistake in replacing a spreadsheet is trying to do everything at once, historical data included.

A better order follows evidence pressure. What moves first is whatever carries a retention obligation under 9.2.2 f) and 10.2.2: findings, actions, effectiveness reviews, the audit programme and the changes made to it during the year. That is the area where a spreadsheet structurally cannot deliver.

Master data comes next: organizational units, processes, audit criteria, question catalogues. It is usually well structured and transfers cleanly.

Historical findings stay where they are. A finding closed in 2022 gains nothing from migration; it meets its retention obligation just as well in the old file. Move the open items and a cut-off date, not the archive. Carrying findings through from capture to effectiveness review is covered in the article on findings and CAPA management, the distinction between correction and corrective action in the article on the CAPA process under ISO 9001.

The alternative is not necessarily a new application, either. If you already run SAP, check first what the QM module covers as standard — the limits of the SAP QM module in audit management and the comparison with SAP S/4HANA Audit Management scope that out.

In qportal, the part where spreadsheets fail is the core of the data model: findings hang off audit criteria, actions hang off findings, and open actions appear with owner and due date in the My Actions overview rather than in row 47 of a file nobody opens any more.

Conclusion

Excel is permissible under ISO 9001, and for part of the QM workload it remains the best tool available. Anyone telling you otherwise is selling you something.

The real point is narrower and harder: a spreadsheet is a calculation tool, not a record-keeping system. It shows a state, not the history of that state. As long as your obligations under 7.5.3.2, 9.2.2 f) and 10.2.2 amount to the information being present, it is enough. The moment someone has to demonstrate that the information has not changed since it was created, it is not — and no amount of file-naming discipline changes that.

That boundary does not fall at a headcount. It falls between maintain and retain.

Sources

Normative text

  1. DIN EN ISO 9001:2015-11, Qualitätsmanagementsysteme – Anforderungen (ISO 9001:2015); German and English version EN ISO 9001:2015. Beuth Verlag, Berlin. English text: ISO 9001:2015, Quality management systems — Requirements. Clause numbers are cited and requirements paraphrased; the normative wording is under copyright. Clauses used: 4.4.2, 7.5.3.2, 9.2.2 f), 10.2.1 d), 10.2.2, Annex A.6.

Peer-reviewed literature on spreadsheet errors

  1. Panko, R. R.: What We Know About Spreadsheet Errors. Journal of End User Computing 10 (1998), no. 2, pp. 15–21. DOI: https://doi.org/10.4018/joeuc.1998040102 (accessed 2026-08-27)
  2. Powell, S. G.; Baker, K. R.; Lawson, B.: A critical review of the literature on spreadsheet errors. Decision Support Systems 46 (2008), no. 1, pp. 128–138. DOI: https://doi.org/10.1016/j.dss.2008.06.001 (accessed 2026-08-27)

Standards bodies on the 2026 edition

  1. ISO: ISO 9001 — Quality management systems. Requirements. Stage 60.00, edition 6, publication date 2026-09, ISO/TC 176/SC 2. https://www.iso.org/standard/88464.html (accessed 2026-08-27)
  2. DIN Media (DIN Group): Revision der ISO 9001 — Veröffentlichung 2026. https://www.dinmedia.de/de/themenseiten/managementsysteme/qualitaetsmanagement/revision-der-iso9001 (accessed 2026-08-27)

Consultancy, certification-body and content-marketing pages are not cited. The figures in source [2] are reported explicitly subject to the reservations raised in source [3], and they do not carry this article’s argument. Where the text goes beyond the sources, it is marked as an assessment.

Frequently asked questions

Does ISO 9001 allow you to run a QMS on Excel?
Yes. ISO 9001 prescribes no tool. It requires documented information and sets requirements for controlling it, but it names no software, no file format and no medium. A spreadsheet is as permissible as a paper binder or a database. The only thing that decides the question is whether the required evidence can actually be produced.
Which requirement puts a spreadsheet under real pressure?
Clause 7.5.3.2. It calls for control of changes — version control is named as an example — and for retained evidence of conformity to be protected from unintended alteration. A shared XLSX on a network drive shows its current state, but not who changed which cell when. Sheet protection can be switched off and leaves no trace.
What evidence does ISO 9001 clause 9.2.2 f) actually require?
Two things inside one subclause: evidence of the implementation of the audit programme and evidence of the audit results. Most organizations hold only the second. Whether a planned audit date was moved, merged or dropped belongs to the first — and in a spreadsheet that information disappears the moment the cell is overwritten.
Is a spreadsheet enough for corrective actions under 10.2.2?
Only if it holds more than a tick box. Clause 10.2.2 requires evidence of a) the nature of the nonconformity and any subsequent actions taken, and b) the results of any corrective action. Point b) presupposes the effectiveness review required by 10.2.1 d). A status field reading "closed" with a date is not a result — it is an assertion.
At what team size does QM software start to pay off?
That is the wrong question. Four internal audits a year with batch releases you must be able to trace can already be past the tipping point; forty low-risk process audits with no external evidence pressure may not be. What decides it is the kind of evidence required — whether it is enough that the information exists, or whether you must show it has not changed.