FREE TOOLKIT: Sexual Harassment & Speak-Up Compliance Checklist
Get your copy.

The Spreadsheet Problem: Why 22% of Organisations Are Still Managing Misconduct Data Manually

8 min read
Published on
September 15, 2026
If a tribunal asked to see your organisation's full misconduct history tomorrow, could you produce it on demand? For nearly a quarter of UK organisations, the honest answer is no.

That question sits at the centre of a finding from the Culture Shifters Annual Report 26-27, which surveyed 300 UK HR professionals and over 1,000 UK employees. Almost a quarter (22%) of organisations are managing misconduct and speak-up data entirely through manual methods such as Word documents and spreadsheets.

At a moment when regulatory scrutiny of workplace misconduct is intensifying, that gap in data maturity is a structural risk sitting quietly inside organisations that, in many cases, believe they are already prepared.

What the misconduct data actually shows

The report's Part Six, on technology and case management, paints a picture of an HR function stretched thin and under-tooled. Respondents were asked how they collate and manage misconduct and speak-up data. The results, drawn from a multi-select question, show a landscape still dominated by manual processes even where systems exist:

  • 48% use an internal system
  • 46.7% use a reporting platform
  • 40% use Word documents
  • 27.3% use spreadsheets
  • 6% don't collate this data at all

Because the question allowed multiple answers, many organisations are running a hybrid model: a proper system on paper, propped up by manual documents in practice. That combination is arguably more revealing than the 22% figure on its own. It suggests that even organisations with some infrastructure in place are still leaning on ad hoc tools to fill the gaps, and this is where risk tends to sit.

Time pressure amplifies the problem. The same section of the report found that a third of HR respondents spend three to five hours a week on workplace conduct issues, reviewing reports, managing cases, working with managers and analysing data, while one in ten are spending more than a day a week on it. That is a significant chunk of a working week spent on a process that, for many, is running through spreadsheets never designed to hold sensitive case data.

Why fragmented documentation is a compliance risk

It is tempting to treat spreadsheets and shared drives as a temporary or low-cost solution. The report argues the opposite. When case data is spread across multiple platforms, spreadsheets, shared drives and email, organisations lose visibility of the full audit trail, along with the oversight and pattern recognition that purpose-built reporting systems like Report + Support™ are designed to provide.

That loss of visibility has direct consequences. Fragmented record-keeping creates real compliance and confidentiality risks. It also sends an unintended signal to employees that reports may not be handled with the consistency, care or rigour they expect, which matters enormously given how hard organisations already have to work to build trust in reporting channels in the first place.

There is also a pattern-recognition cost. The report's Part Four, on moving from reactive reporting to proactive prevention, makes the case that reports should be regularly monitored and analysed for patterns, behaviours and emerging trends rather than handled in isolation. That kind of analysis is difficult, if not practically impossible, when data lives across disconnected Word documents and spreadsheets maintained by different people at different times. Only 41% of organisations said they consistently aggregate and analyse misconduct or speak-up data to identify patterns, a figure that is hard to separate from the 22% still working entirely manually.

The regulatory backdrop makes this harder to ignore

From October 2026, the Employment Rights Act extends employer duties around sexual harassment prevention, requiring organisations to take "all reasonable steps" to protect their people. What counts as reasonable is fact-specific and depends on the size, resources and risk profile of the organisation involved, and organisations should seek their own legal advice on what it requires in their specific circumstances. But an audit-ready trail of documentation is a common thread running through most interpretations of the guidance, and it is exactly what fragmented, manual systems make difficult to produce at speed.

The report's Part Five found a striking gap between confidence and capability here. 91% of HR leaders said they were confident they could evidence all reasonable steps if challenged today. Yet when asked about the practical foundations required to actually evidence that, the picture was far less reassuring. Only half of organisations reported having clear reporting processes in place, just 39% said reporting data is regularly shared with the board, and only 38% had completed comprehensive risk assessments. As the report puts it, confidence and capability are not the same thing, and the gap between them is precisely where risk lives.

Moving from manual to managed misconduct reporting

None of this means spreadsheets are inherently the enemy. They are familiar, flexible and cheap. But misconduct data carries a different weight than a sales pipeline or a budget tracker. It involves sensitive personal information, needs to withstand external scrutiny, and benefits enormously from being analysed as a whole rather than case by case.

This is where dedicated reporting and case management platforms earn their place. A structured system like Report + Support™ centralises reports in one secure location, maintains a consistent audit trail by design, and makes it possible to spot patterns across teams, locations and time periods without manually cross-referencing spreadsheets. It also removes the version-control and access-control risks that come with case data living in shared drives or individual inboxes, which matters just as much for confidentiality as it does for compliance.

For HR teams already spending hours a week managing cases manually, you get a clearer view of what is actually happening across the organisation.

The full picture, including the report's findings on psychological safety, board visibility and third-party harassment readiness, is available in the Culture Shifters Annual Report 26-27.

Christine Bonney
Head of Culture Transformation
STORIES

What we're reading

Latest insights from the front lines of workplace culture.

Blog
8 min read

The Spreadsheet Problem: Why 22% of Organisations Are Still Managing Misconduct Data Manually

22% of organisations still track misconduct data via spreadsheets. Read why this data gap has become a genuine compliance risk in 2026.

Read more
Webinar
3 min read

Upcoming Webinar — Third-Party Harassment: Where the Risk Sits and What Organisations Need to Act On

Join this webinar to find out the third-party harassment obligations under the Employment Rights Act, where organisational risk sits, and what organisations need to act on to demonstrate compliance.

Read more
Blog
5 min read

What the FCA's Q2 2026 whistleblowing data tells regulated firms about culture risk

The FCA published its whistleblowing data for Q2 2026. Containing 886 allegations, 339 of which are related to misconduct and poor reporting systems.

Read more
CULTURE SHIFT

Feeling inspired?

Take the first step toward preventative misconduct management with a demo of our Report + Support™ platform. We can show you how to breakdown reporting barriers with anonymous 2-way messaging, and how to act before things escalate with name-matching and pattern-spotting across our analytics dashboard.

Dotted background image