Verify a signed workbook
Somebody has sent you a spreadsheet with a sign-off record in it, and the sheet says to check it here. This page explains how — and it is free, for anyone, with no account and no licence key.
What you are checking
The workbook carries a fingerprint of the calculation as it was when it was signed off: every formula, every constant outside the designated input cells, the defined names, and the sheet structure. Verifying recomputes that fingerprint from the file in front of you and compares the two.
- Green — the calculation is the one that was signed. Input values may have changed; that is what they are for, and it is reported separately.
- Red — the calculation has been edited since it was signed, and you are shown which cells and what they used to say.
- Amber — it could not be checked. Amber is never a pass. Most often it means the file carries no record at all, which is not the same as unchanged.
How to check it
- Install the Calculation Sign-Off and Lock add-in from Excel's Home tab → Add-ins.
- Open the workbook you were sent.
- Open the pane. It verifies as soon as it opens; the verdict is the box at the top.
If the Add-ins button is greyed out, you are standing on a protected sheet — Excel disables it there. Click the Sign-off tab at the bottom of the workbook, which is left unlocked for exactly this reason, and open the pane from that sheet.
You are not asked for a licence key, an email address or a card, and no request leaves your machine — the record is inside the file and the public key is inside the add-in.
If it comes up red
Red means the logic has changed since the record was made. It does not, on its own, mean anybody did anything wrong: a calculation is often legitimately revised and not re-signed. What it means is that the signature in the quality file does not describe the spreadsheet you are holding.
The pane lists the exact cells and, where the record carries the detail, what each one used to contain. Send that list to whoever signed it. That is a conversation, not an accusation.
If it comes up amber
The commonest cause is that the record has been stripped — often innocently, by a tool that re-saved the file and dropped its custom XML parts. Ask for the original.
"Signed under a different fingerprint version" means the add-in that signed it and the add-in you are using compute differently. Update, and it will check.
This is not Part 11 software, and does not pretend to be
Calculation Sign-Off and Lock is a sign-off record and tamper evidence. It is not a 21 CFR Part 11 or EU Annex 11 electronic signature: there is no per-user access control and no full audit trail, and the signer's name is typed rather than verified.
If you are in a regulated GxP environment, you want ExcelSafe or something like it, and it will cost you roughly four thousand dollars. This is for everyone below that line — ISO 9001 engineering calculation checking, finance model sign-off, non-GxP labs, consultancy deliverables — where the current control is a printout, a biro and hope.
Checking it yourself
The record format and the countersigning public key are published in full, so a record can be checked by anything, not only by this add-in.