Can you manage ISO 9001 with Excel?
Yes — and here is exactly where it breaks, and how to run it well if you stay
The short answer: yes, legitimately. ISO 9001 does not require any particular software, and plenty of certified manufacturers run their quality system on spreadsheets. But Excel has specific, predictable failure points, and knowing where they are will tell you whether you are safe or exposed.
Why the answer is genuinely yes
Nothing in ISO 9001:2015 requires quality management software. Clause 7.5 requires documented information to be controlled — identified, reviewed, approved, available where it is needed, and protected. A spreadsheet can satisfy every one of those requirements if it is managed properly.
Auditors do not object to Excel. They object to uncontrolled documents, missing evidence and untraceable records, and those are possible in any system, including expensive ones.
So if someone tells you a spreadsheet cannot be compliant, they are selling something. What is true is that Excel puts more of the burden on discipline, and discipline is harder to sustain as more people get involved.
Where Excel actually breaks
The failure points are consistent, and worth knowing before an auditor finds them for you.
Revision control
This is the big one. The moment a spreadsheet is emailed, copied to a desktop or saved locally, you have parallel versions and no reliable way of knowing which is authoritative. Auditors find this constantly, and it is a legitimate finding — you cannot demonstrate control over documented information when three versions exist.
Shared drives and cloud storage help, but only if nobody downloads a local copy. In practice somebody always does, usually with good intentions and usually just before an audit.
No audit trail
Excel does not record who changed what and when. Edit a value and the previous one is simply gone. For a quality record that is a real weakness: an auditor asking whether a result was amended after the fact has no way to be satisfied — and neither do you.
Cross-referencing
Where spreadsheets cost the most time, and it is rarely obvious until you need it. Calibration records live in one workbook, inspection records in another. A gauge fails calibration, and answering “what did it measure since March” means manually cross-referencing two files that were never designed to talk to each other.
On a quiet week that is an afternoon. On a busy week with product at a customer, it is considerably worse.
Nothing reminds you
Calibration due dates, corrective action effectiveness checks, training expiry, the internal audit schedule, supplier re-evaluation — a spreadsheet holds all of these perfectly well and tells you about none of them. It depends entirely on someone opening the file and looking.
Concurrent use
Two people cannot reliably work in the same workbook. As soon as more than one person is creating quality records you get conflicts, lost edits, and — worse — people quietly making their own copies to avoid the conflicts.
Evidence assembly
When a registrar asks what evidence you hold against a clause, somebody has to go and assemble it. That is the hidden cost of a spreadsheet system. It never appears on a monthly bill; it appears as two weeks of somebody's time before every audit.
How to run Excel well, if you are staying
For a smaller shop a spreadsheet system may well be the right choice. These practices address most of the risk, and none of them cost anything.
- One authoritative location, no exceptions. A single controlled folder. No local copies, no emailing the workbook. Read-only access for anyone who does not need to edit.
- Version and date every file. In the filename and in a revision block inside the sheet. Superseded versions move to an archive folder rather than being deleted — you may need to show what was in effect on a given date.
- Lock down the structure. Protect formulas and headers. Someone will eventually sort one column without the others, and an unprotected sheet makes that unrecoverable.
- Turn on version history. SharePoint, OneDrive and Google Drive all keep it. This addresses the audit-trail weakness better than anything else available to you, and it is usually one setting.
- Build a review calendar separately. Since the spreadsheet will not remind you, put calibration dates, effectiveness checks, training expiry and audit dates into a shared calendar with named owners and reminders.
- Restrict who can edit. Fewer editors means fewer conflicts and fewer copies. If several people need to record data, give them a form that feeds the sheet rather than the sheet itself.
- Back it up somewhere that is not the same drive. A corrupted workbook is a lost quality system, and it happens more often than people expect.
- Write down how it works. If one person understands the workbook structure, you have a single point of failure that will retire, resign or take a holiday during your audit week.
A test worth running
If you want a clear-eyed answer about whether your spreadsheet system is still working, try this.
Pick a part number and a date six months ago. Then answer these four questions, and time yourself honestly:
- Which revision of the work instruction was in effect that day?
- Which gauge was used to inspect it, and was that gauge in calibration?
- Were there any nonconformances on that part in the last two years, and what caused them?
- If a corrective action was raised, was its effectiveness ever verified?
If you can answer all four in under fifteen minutes, your system is working. If it takes an hour, you are carrying a cost you have not counted. If you cannot answer them at all, that is the finding an auditor will write.
The honest comparison
Excel makes sense when: you are a smaller operation, one person maintains the records, the part count is manageable, audits are infrequent, and the discipline above is actually being followed. It is free, everyone already knows it, and there is no implementation.
Software makes sense when: multiple people create records, traceability spans several record types, you are facing customer audits, you hold or want AS9100, or audit preparation has become an event on the calendar rather than a routine task.
The economic question is straightforward. Add up the hours spent assembling evidence before each audit, chasing revisions, and cross-referencing records by hand. Multiply by a loaded hourly rate. If that exceeds the annual cost of a system built for the job, the spreadsheet is the more expensive option — you are simply paying for it in time rather than on an invoice.
If it does not exceed it, stay where you are. That is a legitimate answer and it is the right one for a great many shops.
In summary
- ISO 9001 does not require software. A well-run spreadsheet system is genuinely compliant.
- Excel's weaknesses are specific: revision control, audit trail, cross-referencing, reminders, concurrent use and evidence assembly.
- Most of the revision-control risk comes from local copies, not from Excel itself.
- Version history in SharePoint, OneDrive or Google Drive is the single highest-value fix, and it is free.
- Run the four-question test. If it takes an hour, you are paying for the system in time.
- Compare software cost against the hours your current system consumes, not against zero.
About this guide
This guide is published by Quality Systems On Demand, which makes QMS software for independent, small to mid-sized manufacturers — so we have an interest in this subject and you should read it with that in mind. We have tried to write the guide we would want to read if we were deciding, including the parts that say a spreadsheet may be all you need. If Excel is working for your shop, that is the answer. Our audit checklists, inspection forms and quality record templates are free to download with no signup at qualitysystemsondemand.com/resources — they work perfectly well alongside a spreadsheet, and you are welcome to them whether or not you ever become a customer.