5 min read

Shadow IT and Supplier Data: The P&L Risk of Weak Audit Trails

European regulations demand immutable, machine-readable traceability. Discover how "Shadow IT" and fragmented data in your supply chain lead to failed European audits, contract terminations, and severe P&L impacts.
Shadow IT and Supplier Data: The P&L Risk of Weak Audit Trails
Shadow IT Supply Chain Fracture

The problem with shadow IT is not that a spreadsheet exists.

The problem is that the company may not know which spreadsheet is authoritative, who changed it, what source supports it, which product or transaction it affects, and whether its output agrees with the evidence presented to buyers, auditors or management.

European sustainability and product rules do not create a universal ban on spreadsheets or local applications. Nor do they require every supplier data point to be stored in a cryptographic system. What they increasingly require—directly or indirectly—is information that can be traced, explained and used for a defined legal, reporting, customs, product or contractual purpose.

Weak data control can become a financial issue because the business may need to reconstruct evidence under a deadline, delay a customer response, correct a disclosure, renegotiate a contract or investigate an inconsistency.

Where the evidence pressure comes from

CSRD and assurance

The amended CSRD framework applies to a narrower set of companies, but in-scope undertakings still need sustainability information capable of supporting limited assurance. Directive (EU) 2026/470 also introduced protections for value-chain undertakings below 1,000 employees, including limits on certain CSRD reporting requests.

This does not make every supplier spreadsheet an audit failure. It means reporting companies and assurance providers need to understand the source, method, control and limitations of material information.

CSDDD

CSDDD application begins on 26 July 2029 for companies within the revised scope. Due diligence requires a documented process, but the directive does not mandate one specific IT platform. Suppliers may still receive contractual evidence requests from customers preparing their own systems.

EUDR and CBAM

EUDR can require detailed origin, geolocation and legality information for covered commodities and products. CBAM can require covered importers to manage product classification, embedded-emissions data and certificate exposure. In both cases, the regulated EU actor may depend on upstream supplier information.

The data can originate in different systems. The control question is whether it can be connected to the relevant product, facility, shipment, calculation and responsible owner.

Digital Product Passport

The Ecodesign for Sustainable Products Regulation establishes a DPP framework whose product-level duties are defined through applicable delegated acts. The regulation includes requirements concerning open standards, interoperability, data access, security and the reliability of passport information.

It does not mean that every product already requires an identical digital twin or that any spreadsheet in the supply chain creates an automatic customs block.

What turns a local tool into a control risk

A spreadsheet, database or local application becomes material shadow IT when it performs a critical function without the company’s governance controls.

Common indicators include:

  • no documented owner or business purpose;
  • uncontrolled copies circulating by email;
  • formulas or mappings changed without review;
  • no connection to source records;
  • manual overrides without approval;
  • inconsistent product, supplier or facility identifiers;
  • access retained by former staff or third parties;
  • no retention or backup rule;
  • no reconciliation to invoices, customs records, production data or contracts;
  • data used externally without a documented review.

The risk is not defined by the tool. It is defined by the role the tool plays and the controls around it.

The financial exposure pathways

Weak audit trails can affect the P&L through several channels.

Reconstruction cost

Teams may spend significant time locating documents, confirming versions and rebuilding calculations when a buyer, auditor or manager asks for evidence.

Delayed commercial decisions

Incomplete files can delay onboarding, contract renewal, product approval, customer responses or internal sign-off. The outcome is fact-specific; delay does not automatically mean termination.

Correction and remediation

If external information is inconsistent with source evidence, the company may need to correct a report, resubmit documentation, retest controls or commission independent review.

Pricing and contract friction

Buyers may negotiate wider information rights, remediation duties, audit clauses or risk allocation when they cannot rely on the supplier file. These are contractual outcomes, not automatic regulatory penalties.

Management uncertainty

Board and finance teams may be unable to estimate exposure if data for products, suppliers, facilities and contracts cannot be reconciled.

A proportionate control framework

1. Register material tools

Create an inventory of local files and applications used for regulatory, buyer, reporting, product, customs or supplier-risk decisions. Record the owner, purpose, users, inputs, outputs and criticality.

2. Establish a source-of-record rule

For each material data field, identify the authoritative source. A dashboard or spreadsheet may transform information, but it should not obscure where the original fact came from.

3. Control versions and changes

Critical files need access controls, naming standards, version history, approval rules and protected formulas or mappings where appropriate. Changes to regulatory logic should be documented and tested.

4. Reconcile across the transaction

Supplier evidence should agree with the records that define the commercial event. Depending on the use case, this can include:

  • product and material records;
  • facility and production information;
  • purchase orders and invoices;
  • shipment and customs documentation;
  • contract representations;
  • calculation methodologies;
  • certificates and verification reports.

5. Preserve exceptions

Contradictory or missing information should not be silently overwritten. The company should record the exception, decision, approver, remediation and closure evidence.

6. Test the output

Controls should be tested against samples of source evidence and actual transactions. The purpose is to determine whether the system can reproduce a conclusion and explain its limitations.

Spreadsheets can be controlled

For many suppliers, a spreadsheet will remain part of the operating environment. A proportionate approach may include:

  • controlled storage and access;
  • locked calculation cells;
  • named data owners;
  • input validation;
  • change logs;
  • approval workflow;
  • links to source documents;
  • periodic reconciliation;
  • documented export and retention procedures.

The decision to migrate to a dedicated platform should be based on scale, complexity, risk, cost and the limitations of the existing control—not on the assumption that a regulator has prohibited spreadsheets.

The executive test

A company should be able to answer:

  • Which data files influence external claims or buyer decisions?
  • Who owns and approves them?
  • Can each material value be traced to a source?
  • Can the company reproduce the calculation?
  • Are estimates and assumptions clearly identified?
  • Can exceptions be found and explained?
  • Does the evidence agree with the commercial transaction?
  • What happens if the owner or supplier becomes unavailable?

Villanova ESG position

Villanova ESG reviews the evidence chain between Brazilian operations and European-facing decisions. The objective is to identify where uncontrolled tools, weak lineage or fragmented ownership make the supplier file difficult to use.

The work does not certify a system or guarantee buyer acceptance. It helps management define the controls, evidence and escalation required for a reviewable file.

Official source trail

Important qualification

This article is an executive data-control analysis. It does not provide legal advice, assurance, certification, customs clearance or a conclusion on any specific information system.

For a supplier-data and audit-trail review, contact Villanova ESG at contact@villanovaesg.com.

REQUEST EVIDENCE REVIEW