An 18-month model tells management that cash will be stronger than expected. The hiring plan can start earlier and the next financing can wait. Nothing obvious is broken: revenue is driven by customer numbers and price, payroll comes from a headcount schedule, capital expenditure feeds depreciation, working capital connects receivables and payables to cash, and the debt schedule carries drawings, repayments and interest into the statements. The cash-flow statement rolls opening cash into closing cash and the balance sheet balances each month.
The change sits inside the receivables schedule. Days sales outstanding has moved from 60 days to 45. There are no new customer terms behind the improvement, no evidence that collections have changed and no approved base-case assumption. The number survived from a test run. It has no owner, date or change note.
That one edit lowers receivables and improves operating cash flow. It can also reduce the modelled need for debt. Every link may still calculate exactly as designed.
This is where “the model works” becomes an unsafe acceptance criterion. Arithmetic, accounting linkage and workbook integrity matter, but they do not establish that the business assumptions are defensible or that the model state is the one management thinks it is using.
A decision-grade model therefore needs to survive a different kind of review: can another qualified person trace the result, identify and challenge the material judgements, reproduce the state used for the decision, and understand where the model stops being reliable?
Treat the model as a decision system
A useful financial model has a visible route from judgement to consequence. One compact map is:
Assumptions → Drivers → Schedules → Three Statements → Controls → Validation → Version / Change Control
The ICAEW Financial Modelling Code recommends a clear flow from inputs to calculations and outputs. That separation gives a reviewer somewhere to look when a number changes. If assumptions are buried as constants in formulas and outputs can be overwritten directly, the workbook can still produce numbers while losing the lineage behind them. In the DSO example, a controlled assumption would identify the value, period and customer scope, supporting evidence or judgement, owner, date of change and affected outputs. A reviewer does not need to treat 45 days as inherently suspicious; they need to know why it became the base case.
Architecture also needs to match the use of the model. A low-impact, reversible estimate does not justify the same assurance effort as a model used for liquidity, financing or a board commitment. The UK Government’s AQuA Book applies the same broad principle to analytical assurance: the amount of assurance should reflect intended use, complexity and potential effect.
The practical architecture test is whether material judgements, calculations and decision outputs can be separated and traced without reverse-engineering the workbook from scratch.

Assumptions are first-class model data
Consider a revenue formula that is mechanically unremarkable: Revenue = Customers × Conversion × Average Price. The formula does not tell a reviewer whether the forecast is credible. Customers may be based on an installed base, a pipeline target or a market estimate. Conversion might be historical, aspirational or segment-specific. Average price might be list price, realised price or a blended figure. Each interpretation changes what the forecast means.
Material assumptions need context. A useful record includes the value, unit, period, scope, source and owner, plus the dependency or output that will move when the assumption changes. High-impact assumptions should also have a refresh trigger or some explicit challenge evidence.
Driver-based planning helps because it connects outputs to operational quantities and rates that can be inspected. A single “revenue grows 20%” input tells the reviewer very little. Volume and price can be examined separately. Payroll can be generated from opening headcount, hires, leavers, start dates, salaries and employment on-costs. Working capital can be connected to sales, purchasing and payment behaviour.
That does not make every field labelled “driver” causal. The relationship still has to match the business. This article uses driver-based planning only for that traceability function; the deeper forecasting methodology belongs elsewhere in the series.
For receivables, the chain should be visible enough to follow without guesswork: customer terms / mix assumption → DSO → A/R schedule → working-capital movement → operating cash flow → closing cash / debt requirement. If 45 days appears as an unexplained constant in the middle of that path, management may see a stronger cash forecast while the business judgement that created it has become harder to inspect.
The three statements should be generated from schedules
Three statements in one workbook are not automatically an integrated model. Integration comes from the schedules that generate them.
A headcount schedule can take opening staff, hires, leavers, start dates and compensation and produce payroll expense. That gives a hiring delay or an accelerated recruitment plan a consistent timing effect. Capital expenditure needs its own roll-forward because the cash outflow happens when the asset is acquired while depreciation reaches the income statement over later periods.
Receivables show the stock-flow logic directly:
Opening A/R + Credit Sales - Cash Collections = Closing A/R
That roll-forward links revenue recognition to the timing of cash collection. The 60-to-45-day change therefore moves through the working-capital schedule before it reaches operating cash flow.
Debt often introduces a second layer of dependency. Opening debt, drawings, repayments, interest, fees and closing debt need to reconcile. A cash sweep can create circularity because debt affects interest, interest affects profit and cash, and cash affects the debt required. Iterative calculation, average debt, opening-balance approximations and other approaches can all be defensible in the right context. The method needs to be explicit and accompanied by a cross-check. An unexplained plug can make the workbook look stable while obscuring how the financing result was produced.
Tax and foreign-exchange effects create similar integration risks. IAS 7 provides the accounting context for operating, investing and financing cash flows, while IAS 12 and IAS 21 provide relevant tax and foreign-exchange context. A financial model does not need to reproduce the standards, but it does need a consistent mapping between schedules and statements so that tax, FX, cash and debt effects are not duplicated or lost. By the time the statements are produced, net income should feed equity, balance-sheet movements should appear in cash flow, financing and investment activity should return to assets and liabilities, and closing cash should agree across the cash-flow statement and balance sheet. A balancing check is useful because it is now testing an integrated chain rather than repairing three independent forecasts after the fact.
Balancing is a gate, not proof of quality
The balance-sheet check catches real errors. A missing movement, an unclosed roll-forward or a broken cash link can all surface through Assets = Liabilities + Equity.
It does not challenge the commercial premise of 45-day DSO. If the schedule has been built consistently, lower receivables, stronger operating cash flow and higher closing cash can all reconcile perfectly.
Other failure modes sit outside the same check. A sign error may be offset elsewhere. A payment can be shifted by one month while the annual total remains plausible. Excel may also display a stale calculation state depending on calculation settings, links and workbook state. The controls have to reflect those different risks.
For a material model, the control set may include reconciliations, sign and range checks, reasonableness tests, control totals and model-state checks. The exact combination depends on what can go wrong.
A DSO of 45 days may pass a range test because it is a perfectly plausible number. An assumption-change report or prior-version variance review may be much more revealing, especially if material assumptions require a source, owner and reason for change before entering the base case.
This is why adding more green cells is not a substitute for control design. A control is useful when it is connected to a failure mode that matters to the decision.
Verification and validation solve different assurance problems
The AQuA Book distinguishes questions that are often collapsed into one review. Verification asks whether the model has been implemented correctly according to its design. Validation asks whether the design and method are fit for the intended use.
Take MAPE as a small forecasting example. A team can implement the formula correctly and reference the intended data. That can satisfy verification.
Percentage errors can still be misleading when actual values are zero or very small because the denominator can magnify the measure or make it undefined. Hyndman and other forecasting researchers have long discussed the limits of percentage-based accuracy measures and the need to choose metrics that fit the data. The reviewer therefore needs a second judgement: does MAPE answer the management question for this dataset?
Financial models create the same separation. A DSO schedule can be implemented perfectly while 45 days conflicts with customer contracts and collection behaviour. A debt schedule can calculate interest correctly while assuming financing terms or facility availability that do not exist.
A sensitivity table can work as designed and still vary variables that are immaterial to the actual decision. A very long forecast horizon can also make remote years look more precise than the information supports.
For higher-impact models, independent challenge becomes valuable because the author is naturally closest to the design assumptions. Independence can be proportionate rather than institutional. The reviewer needs enough distance to ask where a material assumption came from, whether the method fits the use, which uncertainty could reverse the decision and what limitation the model does not capture.
Versioning is part of analytical integrity
A folder containing Forecast_Final.xlsx, Forecast_Final_v2.xlsx and Forecast_Final_v2_reallyfinal.xlsx has a naming problem. The larger problem appears later, when nobody can identify which data, assumptions and calculation state produced the number shown to management.
A material release should make its state recoverable: data cut-off, assumption set, model version, author and reviewer, reasons for material changes, calculation or release state, and approved use.
These records do not all have to live on one tab. They do have to travel with the decision.
Actualisation is where teams often lose the historical state. Monthly actuals should update the analysis without erasing the original forecast vintage. If the old forecast is progressively replaced with actual results, a later accuracy review is comparing actuals with a forecast that has been rewritten by hindsight. Preserving the snapshot allows the team to ask what it knew at the time, what it assumed and which assumption later missed.
Calculation state deserves the same treatment. Microsoft documents stale-value and recalculation behaviour in Excel. If a model is material enough that a full recalculation is required before release, that should be an explicit release control with evidence, rather than an assumption that the workbook must already be current.
Version control is successful when an old decision can be reconstructed without relying on somebody’s memory of which attachment was “the real final”. Forecast calibration and performance review depend on that reproducibility.
Model-risk governance should scale with the decision
In April 2026, the US Federal Reserve, OCC and FDIC revised model-risk guidance within banking supervision. Federal Reserve SR 26-2 and OCC Bulletin 2026-13 describe a risk-based, tailored approach that responds to model use, materiality, complexity and risk profile.
Those documents apply to banking contexts. They do not turn ordinary corporate spreadsheets into regulated bank models. The useful principle for a company outside that scope is proportionality.
A weekly FP&A rough cut with transparent assumptions, low consequence and reversible actions may need only a competent peer review.
The same modelling mechanics deserve stronger assurance when the output is used to decide whether the company can fund the next 12 months, when to raise capital, how much to raise, whether to commit to a large hiring plan, whether to approve material CAPEX, or what goes into board and investor materials.
Stronger assurance can mean better documentation, an independent reviewer, explicit assumption challenge, controlled changes, re-performance, sensitivity work or periodic revalidation. It does not need to become a bank-style process by default.
The 18-month model from the opening makes the scaling problem concrete. When FP&A uses it as a rough internal view, a lighter review can be reasonable. Once management uses the same model to delay financing and accelerate hiring, the consequence of an unsupported 45-day DSO assumption is larger even if the workbook itself has not become more complicated.
Can another person challenge the model before the company acts?
A reviewer does not need to start by inspecting every cell. Pick a material output such as closing cash or debt requirement and work backwards through the model. Six questions are enough for an initial decision-worthiness test:
- Are the material assumptions visible? Can you find the value, period, scope, source, owner and latest material change?
- Can the output be traced backwards? Can closing cash or debt requirement be followed through the schedule to the underlying business driver?
- Do the controls cover different failure modes? Are balancing and reconciliation checks supplemented by sign, range, reasonableness, change and model-state checks where relevant?
- Have verification and validation both occurred? Has somebody checked the implementation and challenged whether the method fits the decision?
- Can the decision-time model state be reproduced? Are the data cut-off, forecast vintage, assumption set, version and review status preserved?
- Is the assurance proportionate to consequence? Is a low-impact estimate kept light while a liquidity, financing or major commitment model receives stronger challenge?
Apply that test to the 60-to-45-day DSO change. A reviewer should be able to find the assumption change, follow its effect through receivables and cash, and see which controls did or did not catch it.
They should also be able to challenge the evidence for 45 days and identify the exact model state management used.
A financial model can never be made incapable of error. The useful standard is that material assumptions, calculations, state and review evidence remain visible enough for somebody else to find the error before the company commits money, liquidity or capacity to the answer.
References
- ICAEW, Financial Modelling Code: official guidance
- ICAEW, 20 principles for good spreadsheet practice, 2024 edition
- UK Government Analysis Function, The AQuA Book: official guidance
- Federal Reserve, SR 26-2: Interagency Guidance on Model Risk Management: official guidance
- Office of the Comptroller of the Currency, Bulletin 2026-13: official bulletin
- IFRS Foundation / IASB, IAS 7 Statement of Cash Flows, IAS 12 Income Taxes, IAS 21 The Effects of Changes in Foreign Exchange Rates
- Hyndman, R. J. & Athanasopoulos, G., Forecasting: Principles and Practice
- Hyndman, R. J. & Koehler, A. B., Another Look at Measures of Forecast Accuracy
- Microsoft, Stale Value Formatting and guidance on circular references in Excel