Skip to main content
v2026.11,772 entries · CC-BY 4.0

GxP Spreadsheet Validation: Controls, Limits, and When to Replace It

Validating an Excel spreadsheet used for GxP calculations: cell protection, formula verification, version control, why Excel’s native audit trail falls short, and when the right answer is to replace the spreadsheet rather than keep validating it.

Ask CASRAI · included with Regulatory Radar

Ask about GxP Spreadsheet Validation: Controls, Limits, and When to Replace It

Ask CASRAI answers research-administration questions and cites the passages behind every claim — and says so when the corpus does not cover something, instead of guessing. It comes with a Regulatory Radar subscription at $29 a month, alongside the daily digest of regulatory changes and the dashboard of what changed.

150 questions a day, on this site, over the API, or inside your own tools through the CASRAI MCP server.

Everything CASRAI publishes — this page, the dictionary, the guides and the news — stays free to read, with no account and no card.

Written and maintained by CASRAI Editorial Board

Last updated

A “GxP spreadsheet” is any Excel (or Google Sheets) file that performs, or feeds, a calculation or a record that a GLP, GCP, or GMP process depends on: a stability-trending calculation, a dilution or potency calculation, a batch yield reconciliation, a sample-log or COA data table. If that spreadsheet’s output ends up in a regulated record, it is a computerized system in scope for the same expectations as any other GxP software — it just usually gets none of the controls a purchased, vendor-validated system gets automatically.

Why a spreadsheet is a harder validation problem than “real” software

Purchased GxP software (a LIMS, an eQMS, an ELN) arrives with vendor documentation, a defined configuration, and usually a native audit trail. A spreadsheet is the opposite: it is typically built by a scientist or QA analyst for one immediate need, has no vendor specification to validate against, gets copied and modified informally, and lives wherever the last person saved it — a shared drive, an email attachment, a laptop. Under a risk-based computer-system-validation framework like GAMP 5, this class of tool is generally treated as an End-User Computing (EUC) application rather than a configured or vendor-supplied product — which shifts the validation burden entirely onto the lab or QA unit that built it, because there is no vendor documentation to lean on. [REPORTED: GAMP 5 does not assign spreadsheets a single fixed category number; industry practice generally treats a spreadsheet with custom formulas or macros as bespoke/EUC and validates it accordingly, but this framing is drawn from established industry convention rather than a specific primary-source citation checked this session.]

The four controls an inspector actually checks

1. Cell and sheet protection

Every cell that contains a formula, a lookup, or a fixed reference value should be locked, with the workbook or worksheet password-protected against structural changes. Only the specific input cells a user is meant to type into should remain unlocked. Without this, a single accidental keystroke silently overwrites a formula with a hard-coded number — the calculation still “runs,” it just runs wrong, with nothing to flag it.

2. Formula verification

Every formula needs to be checked against a written calculation specification before the spreadsheet is released for use — not just spot-checked by eye, but independently re-derived by a second person and tested against boundary and edge-case inputs (zero, negative, blank, maximum expected value). This is the step most informally-built lab spreadsheets skip entirely, and it is the single most common source of undetected calculation error in GxP spreadsheet use.

3. Version control

There must be exactly one controlled master copy, with a defined owner, a change-history log, and a formal release process for any update — not a file that gets forwarded by email, copied to a desktop, edited locally, and forwarded back. If two analysts can each be working from a different, unknowingly-diverged copy of “the same” spreadsheet, the spreadsheet is not in a validated state regardless of how good the formulas are.

4. The audit-trail gap

This is the control most teams get wrong. Native Excel does not produce a 21 CFR Part 11-style audit trail: it cannot reliably show who changed which cell, when, and why, in a way that is both contemporaneous and tamper-evident. “Track Changes” and cell comments are not a substitute — both can be turned off, both can be deleted, and neither is enabled by default. A spreadsheet used for GxP data therefore needs a compensating SOP control: a defined, access-restricted location for the live file, a documented change-request/approval step for any formula edit, and periodic review of who has write access — because the software itself cannot generate the record electronically the way an audit-trail review procedure for a purpose-built GxP system would expect.

Periodic review, not one-and-done

A validated spreadsheet still needs a defined re-validation trigger: any formula change, any change to the Excel/Office version or platform it runs on, any expansion of its intended use beyond what it was originally validated for, and a periodic (typically annual) confirmation that it is still the version on file and still produces the expected output against a known test case. Treat this the same way a Validation Master Plan already treats periodic review for any other qualified system — a spreadsheet does not get a permanent pass just because it was validated once.

When the answer is “replace it,” not “validate it harder”

Spreadsheet validation has a ceiling. Past a certain point of complexity (nested formulas across many linked sheets), criticality (the output directly affects batch release, patient safety, or a submission), or volume (many concurrent users, high edit frequency), the compensating SOP controls needed to close the audit-trail gap become more expensive and less reliable than migrating the calculation into a purpose-built, natively-validated system. If a spreadsheet cannot show, electronically, who changed what and when, and the process it supports is genuinely high-risk, the honest fix is not another layer of SOP paperwork around Excel — it is a proper User Requirements Specification for a replacement system and a real IQ/OQ/PQ validation of it.

How this fits the wider GxP compliance picture

Spreadsheet validation sits inside the same 21 CFR Part 11 data-integrity expectations that apply to any electronic GxP record, and the same ALCOA+ principles (attributable, legible, contemporaneous, original, accurate, plus complete, consistent, enduring, and available) that a regulator will apply to a spreadsheet-generated record exactly as they would to a database-generated one. Any spreadsheet-driven change to a validated calculation should also flow through change control, and the underlying data-governance expectations are the same ones covered in data integrity in pharmaceutical manufacturing.

FAQ

Is Excel 21 CFR Part 11 compliant out of the box?

No. Excel has no native, always-on, tamper-evident audit trail tied to individual data changes, and no built-in electronic-signature workflow that meets Part 11’s requirements. Any Part 11 compliance for a spreadsheet comes from the controls wrapped around it (access restriction, change control, formula verification, periodic review), not from Excel itself.

Do “Track Changes” or cell comments count as an audit trail?

No. Both can be disabled, both can be deleted or edited after the fact, and neither is enabled by default — none of which meets the contemporaneous, tamper-evident bar a GxP audit trail requires.

Does a validated spreadsheet need IQ/OQ/PQ like a piece of equipment?

Not in the same formal installation/operational/performance-qualification structure typically used for instruments or configured software, but it needs the equivalent in substance: a written specification, documented formula verification against that specification, and evidence the released version produces the expected output — captured in a validation record proportionate to the spreadsheet’s actual risk.

How often should a validated spreadsheet be re-reviewed?

At minimum on any formula change, any platform/Office-version change, or any expansion of its use — plus a periodic (commonly annual) confirmation review even if nothing has changed, consistent with how a facility’s Validation Master Plan schedules periodic review for other qualified systems.

Follow CASRAI

Research-administration guidance, standards updates and independent tool reviews.

Referenced across the research world

University of Cambridge logoColumbia University logoCrossref logoUniversity of Edinburgh logoHarvard University logoUniversity of Oxford logoPrinceton University logoStanford School of Medicine logoUniversity College London logoORCID logoUniversity of Cambridge logoColumbia University logoCrossref logoUniversity of Edinburgh logoHarvard University logoUniversity of Oxford logoPrinceton University logoStanford School of Medicine logoUniversity College London logoORCID logo
  • University of Cambridge logo
  • Columbia University logo
  • Crossref logo
  • University of Edinburgh logo
  • Harvard University logo
  • University of Oxford logo
  • Princeton University logo
  • Stanford School of Medicine logo
  • University College London logo
  • ORCID logo

View CASRAI adoption →

Regulatory Radar

Stop finding out after the fact

$29/month, cancel anytime. Daily digest updates from our analysis, a dashboard holding the same items, and a cited assistant for everything they raise.

  • Federal Register, Federal Register+, Grants.gov, Regulations.gov, NSF News, UKRI, plus CASRAI’s own published content.
  • 72,264 indexed passages, and every answer cites the ones it drew on.