End User Computing risk is an often underestimated threat, with data from EUCs providing the foundation for critical business decisions and reporting. Here are some top tips for managing your EUC risk:

Understand the EUC population in your organization – the types of EUC applications used; how many there are of each type; and what is the level of complexity , or inherent riskiness of the different files – i.e. which ones are heavily coded, use macros, rely on connections to other spreadsheets, databases, etc.

Determine the ‘criticality’ of the EUCs to the business. Criticality must be assessed based on the quantitative (dollar loss) and qualitative (reputational risk, client exposure, regulatory sanction, loss of business functionality) impact on the business if these files were lost or otherwise unknowingly damaged or altered. For instance, assess what the cost to the business would be if the creator of a vital spreadsheet application left the organization? Would another member of the team have intimate knowledge of how the application works and needs to be maintained? Would they be able to test the integrity of the application in the event of inadvertent or malicious changes to any codes or macros in the application?

Design a policy for the creation of an EUC inventory, including definitions for the various levels of risk and the associated controls that must be put in place based on the criticality of the files. Additionally, the policy must also include rules for documenting, testing and maintaining the inventory of EUCs based on their criticality categorization. Obviously, the higher the criticality, the tighter the rules and more stringent the policies.

Create a heat map of critical EUCs and using Key Risk Indicators, show where the delinquent EUCs are. This representation will help the organization take corrective action.

Focus on the most critical EUCs, understand their use and map them to the potential wider risks as identified in the organization’s risk library. For instance, assess if any of the spreadsheet applications impact other risks such as internal fraud, financial reporting, data governance and so on.
Undertaking this kind of end-to-end and granular approach manually is almost impossible, due to the extent of spreadsheet and EUC usage in most organizations. Not only is it difficult to holistically identify and inventory the EUCs, it is also challenging to determine the inter-connections and corresponding impact of critical spreadsheets on other enterprise risks.
It is also almost impossible to effectively track changes to code, macros, and so on manually, whether the changes were deliberate and bona fide, or otherwise. Adopting technology that automates discovery, inventory, policy enforcement, control and overall management of the EUC landscape is the most cost-effective and fail-safe way forward.