Every organization has spreadsheets that run critical business processes. Most organizations also have policies governing those spreadsheets. The distance between those two facts is where Nora Ledgerwood has spent her career.
Ledgerwood has audited end-user computing controls across financial services for twenty-two years, through SOX implementation, Dodd-Frank, Basel II, and now the first wave of generative AI governance frameworks. She is a composite character, which she'd point out is exactly the kind of undocumented artifact she's spent her career trying to govern.
We talked to her about what two decades of spreadsheet governance actually taught her, and what she recognizes in the way organizations are approaching AI agents today. The recognition, she says, is uncomfortably precise.
You've described your career as "losing the same fight." That's a grim way to frame twenty-two years.
Nora: It's accurate. The fight was never fair. By the time anyone hired me to govern spreadsheets, the spreadsheets were already load-bearing. VisiCalc shipped in 1979.1 SOX arrived in 2002. That's twenty-three years of people building critical infrastructure in Excel before anyone with authority said, "Wait, should we know what these things do?"
I've never once walked into an organization and started from a clean slate. It's always triage.
What does triage look like in practice?
Nora: Step one is inventory. You need to know what exists. And here's the thing everyone learns and nobody wants to accept: the inventory is wrong the moment you finish it.
You spend three months surveying business units, scanning network drives, cataloging every spreadsheet that touches financial reporting. You produce this beautiful document. And while you were doing that, someone in treasury built four new ones.
The inventory is a photograph of a river.
So the full picture is permanently out of reach?
Nora: Permanently. And that's not a failure of effort. Spreadsheets get created at the speed of individual need. Governance operates at the speed of quarterly review cycles. Those two clocks will never be synchronized. Accepting that is step one. Most organizations never get past it.
The JP Morgan London Whale case comes up a lot in this context. What does that incident actually illustrate, from where you sit?
Nora: People love to tell it as a cautionary tale about Excel. The real lesson is about the gap between having a policy and having a control.
JPMorgan had an internal deadline of January 31, 2012, to automate their Value-at-Risk model and get it out of spreadsheets.2 They missed the deadline. The model kept running in Excel, with manual copy-paste serving as the data pipeline. The person building it had never built a VaR model before.3 Six billion dollars later, everyone learned what any auditor could have told them: a deadline on paper is not a control. A policy that says "automate this" does nothing if nobody enforces it.
Ralph Baxter from ClusterSeven said it perfectly in 2013: "Everyone seems to have spreadsheet policies but they don't implement them."2 That was thirteen years ago. I could say it today and it would still be news to somebody.
What separates real controls from theater?
Nora: Okay. This is the thing I feel most strongly about, so bear with me.
Theater is when you put the control at the wrong point in the process. The classic version: an executive signs an attestation saying the spreadsheet has been reviewed and tested. I've looked at thousands of these. I believe them, actually. They reviewed something. But what they reviewed is usually a description of the spreadsheet. A summary someone prepared. Not the actual formulas. Not the cell references. Not the circular logic buried in row 847 of a tab called "DO NOT DELETE."
Real controls are embedded at the point of execution. Locked cells. Input validation rules. Reconciliation totals that have to zero before the file can be used downstream. Friction at the moment it matters, not a form someone fills out three weeks later confirming they checked.
Risk tiering is the other thing that works. You cannot control every spreadsheet equally, and trying guarantees you'll control none of them. In one study, researchers looked at 25 operational spreadsheets across five organizations. They found 117 errors. Seventy had financial impact. The largest was $100 million.4 But nine of those spreadsheets had zero errors. The risk is concentrated, not distributed. Find the critical twenty percent and control those seriously. Let the rest have lighter oversight proportional to the damage they can do.
You mentioned ownership earlier. Why does that matter more than documentation?
Nora: Because documentation is a snapshot and ownership is a relationship.
The hardest thing to maintain isn't the spreadsheet. It's the human being who understands it. People get promoted. They leave. They move teams. The spreadsheet stays. The logic stays. The knowledge walks out the door.5
I've seen spreadsheets that were "owned" by someone who left three years ago. They show up in the inventory with a name next to them. The name means nothing. That spreadsheet is effectively ungoverned. And nobody knows it until something breaks. Which, in my experience, is usually a Tuesday in October during close.
You've said you recognize the AI agent pattern. What specifically looks familiar?
Nora: Almost everything. They're calling it "shadow AI" now.6 We called it shadow IT for twenty years, and before that we just called it "what people do when enterprise systems don't meet their needs." Census data from this year shows that nearly 7% of firms have workers using AI for tasks without any formal adoption at the firm level.7 Formal adoption and worker-led adoption proceeding on separate tracks. We lived that with spreadsheets. Same movie, different decade.
And then COSO published their generative AI guidance in February, built on the same Internal Control–Integrated Framework from 2013 that we applied to spreadsheet governance after SOX.8 Same framework. Same audit cycle. I'd bet real money the gap between the framework and operational reality will look familiar too.
Where does the parallel break down?
Nora: Right here. This is where I stop feeling like a veteran and start feeling like a student.
A spreadsheet gives you a number. A human still has to carry that number to the next step: enter it in a system, make a decision, send a report. That carrying step is where I can stand and ask, "Is this right?" I can put a review gate there. A reconciliation. A sign-off that means something because there's a natural seam in the process.
With an agent, the carrying is automated too. The agent doesn't produce a number and wait politely. It acts. It moves data between systems, triggers workflows, posts entries. The GSA inspector general found that their bots could perform thousands of read, write, and deletion actions at high speed, with errors propagating before anyone sees them.9
My entire career has been managing the distance between a stored computation and a human decision. Agents collapse that distance.
There's no natural seam where review happens unless you design one deliberately. And I've watched organizations try to design review seams for spreadsheets for twenty years. They mostly design attestation ceremonies instead.
So what would you actually recommend?
Nora: Same things that work for spreadsheets, but with the urgency turned up considerably. Automated discovery, because you cannot rely on people reporting what agents exist. Risk tiering, because not every agent use case needs the same oversight, but the critical ones need real controls, not paperwork. And controls at the point of execution, not the point of attestation.
But honestly? The thing I'd say loudest is: don't let the governance clock fall two decades behind the adoption clock again. That's what happened with spreadsheets. We're watching it start with agents right now. The river is already moving.
Last question. Are you optimistic?
Nora: I'm an auditor. I'm professionally required to be skeptical. [pauses] But I'll say this. The organizations that actually governed spreadsheets well did it by accepting they couldn't control everything and choosing to control the right things seriously. That's not optimism. That's just the only strategy that's ever worked.
I'd love to tell you I think everyone will learn from the spreadsheet era. But I've been in this job for twenty-two years, and the most consistent thing I've observed is that organizations prefer to rediscover lessons the expensive way.
Footnotes
-
Campbell-Kelly, M. (2007). "Number Crunching without Programming." IEEE Annals of the History of Computing. https://wrap.warwick.ac.uk/id/eprint/31463/ ↩
-
Forbes / Groenfeldt, T. (February 2013). "Solutions To Spreadsheet Risk Post JPM's London Whale." https://www.forbes.com/sites/tomgroenfeldt/2013/02/19/solutions-to-spreadsheet-risk-post-jpms-london-whale/ ↩ ↩2
-
Dolfing, H. "Case Study 18: How Excel Errors and Risk Oversights Cost JP Morgan $6 Billion." https://www.henricodolfing.ch/en/case-study-18-how-excel-errors-and-risk-oversights-cost-jp-morgan-6-billion/ ↩
-
Powell, S.G., Baker, K.R., and Lawson, B. (2009). "Impact of Errors in Operational Spreadsheets." Decision Support Systems. https://www.sciencedirect.com/science/article/pii/S0167923609000335 ↩
-
Coherent Global. "Enterprise EUC Risk: The Excel Problem Nobody Fixes." https://www.coherent.global/blog/end-user-computing-everywhere-all-at-once ↩
-
Finantrix. "Shadow IT & EUC Governance in Financial Services." https://www.finantrix.com/articles/shadow-it-and-end-user-computing-tools-governance ↩
-
Bonney, M. et al. (2026). "The Microstructure of AI Diffusion." Census Bureau Working Paper CES-WP-26-25. https://www2.census.gov/library/working-papers/2026/adrm/ces/CES-WP-26-25.pdf ↩
-
Deloitte/DART. "COSO Releases Publication on Internal Controls Related to Generative AI." https://dart.deloitte.com/USDART/home/publications/deloitte/heads-up/2026/coso-internal-controls-generative-ai ↩
-
GSA Office of Inspector General. "GSA Should Strengthen the Security of Its Robotic Process Automation Program." (2024). https://www.gsaig.gov/content/gsa-should-strengthen-security-its-robotic-process-automation-program ↩
