Free Regulatory Change Tracker Spreadsheet, and When You'll Outgrow It

In short

A regulatory change tracker is a change log with one row per regulatory change, and the free Excel version here has 25 fields, worked rows for the EU AI Act, DORA and an FCA Grid item, and a ten-question scorecard for when to move to software. Panko's review of field audits found errors in 91% of the real-world spreadsheets examined, so the tracker is built around dated rows, written rationale and a named reviewer.

Download the Excel template

Free, no email needed. Sheets: README and changelog, Change Log, Horizon, Sources register, Scorecard. All templates

Below is a free regulatory change tracker spreadsheet: an ungated Excel workbook with five tabs, a 25-field change log, worked rows for the EU AI Act and DORA, a dedicated emerging-regulations tab, and no macros. Take it, no email required. But field audits since 1997 found errors in 91% of the 54 real-world spreadsheets examined (Panko's review of the evidence, presented at EuSpRIG in 2000), and 79% of compliance departments run on spreadsheets anyway (Regology, 2024).

A spreadsheet is the correct tool below roughly two jurisdictions, one regime and a weekly review cadence. Beyond that it fails for structural reasons: no audit trail, silent staleness, single-owner risk, no deduplication. The workbook is the best possible version of the spreadsheet, with a scored diagnostic for the day it stops being enough. You will find it in our trackers and templates hub next to our other templates.

Most compliance teams run on spreadsheets, and field audits find errors in most spreadsheets

Regology's 2024 State of Regulatory Compliance survey (a vendor survey of mid-to-senior professionals, 89% US-based) found that 82% of compliance departments rely on manual processes and 79% on spreadsheets. Wolters Kluwer's 2025 Regulatory and Risk Management Indicator (December 2025) found that 88% of US banking respondents use manual processes or spreadsheets "often" or "sometimes", and 63% plan investment in automating regulatory change management. The spreadsheet is the incumbent.

The problem is what audits find when they open the incumbent. Ray Panko's long-running research program on spreadsheet error, summarized in his paper for the European Spreadsheet Risks Interest Group, reports that field audits since 1997 found errors in 91% of the 54 real-world spreadsheets examined (the audits used different error criteria), with cell error rates between 0.4% and 2.5% in the audits that reported them, and at least 1% to 2% in experiments (arXiv:0802.3457). The finding I quote most, because nobody believes it applies to their tracker: in an experiment Panko describes, student developers estimated a median 10% chance that they had made an error, yet 86% had. At that base rate, your tracker is probably wrong somewhere, and you probably don't think it is.

When spreadsheets carry regulatory weight, the failures are documented. Public Health England left 15,841 positive COVID-19 cases out of its reported daily figures between 25 September and 2 October 2020, delaying contact tracing for them. Press reports traced it to legacy .XLS files capped at 65,536 rows, with multi-row case records meaning each sheet silently truncated at roughly 1,400 cases (The Register, 5 October 2020); officials at the time cited file size and a legacy system. JPMorgan's own task force found that the CIO's value-at-risk model ran through Excel spreadsheets "completed manually, by a process of copying and pasting" data between them, and that a formula divided by the sum instead of the average of two rates, muting volatility by a factor of two, ahead of losses that reached about $5.8 billion by 30 June 2012 (Task Force report, January 2013). Neither team was careless. The tool has no guardrails, so discipline is the only control, and discipline does not scale. So the template is the most disciplined spreadsheet you can run, built to tell you when discipline stops being enough.

The tracker has five tabs and 25 fields, with no macros and no email gate

The workbook is free and ungated. It works in Excel and Google Sheets; it uses dropdowns and conditional formatting only, and deliberately no macros, because compliance IT policies block them.

Tab What it does
1. README and changelog A ten-row how-to, the not-legal-advice note, and a visible changelog table (date, change, source) with "last reviewed" and "next review" cells, so the file audits itself.
2. Change Log The register: one row is one regulatory change, 25 fields, with worked rows dated as of 30 September 2026.
3. Horizon Emerging regulations: pre-adoption pipeline items with watch triggers for promotion into the Change Log.
4. Sources register The $0 detection layer: which regulator channels you watch, how, how often and who checked last.
5. Scorecard The ten-question "have you outgrown it" diagnostic, auto-summed and rendered in full below.

Each of the 25 columns exists because something specific goes wrong without it

A regulatory change log is a decision record, and every field earns its place by preventing a named failure.

# Column What you record Why it exists
1 Change ID Sequential ID, for example RC-2026-001 Minutes, emails and evidence can point at one unambiguous row
2 Date captured When you first logged it Measures detection lag; an examiner's first question is "when did you know?"
3 Source name and URL The regulator's page, not a blog about it A law-firm summary is commentary, not evidence
4 Source type Official regulator / Official journal / Supervisory statement / Industry body / News A simplified authority tier; news-tier rows need primary-source confirmation
5 Jurisdiction Country, bloc or state The first applicability filter, and how you split review work
6 Regulator or issuing body For example FCA, EBA, FinCEN Where the follow-up guidance will come from
7 Instrument reference For example "Reg (EU) 2024/1689, Art. 53" Checkable years later; "recent EU AI rules" is not auditable
8 Change type New rule / Amendment / Consultation / Guidance / Enforcement action / Speech or signal A consultation needs a response decision; an enforcement action needs a controls check
9 Stage Proposed, Consultation, Adopted, In force, Applicable (dropdown) In EU law "adopted" and "applicable" can be years apart; stage is your runway
10 Published date Date this version was published See the two-dates section below; this is where trackers rot
11 Effective or application date Date obligations bite The date your project plan hangs on
12 Plain-language summary 2 to 3 sentences So the next reader doesn't re-read the instrument
13 Applicability decision In scope / Out of scope / TBD (dropdown) Out-of-scope rows are half the audit value
14 Applicability rationale The written "why" A decision without reasoning is an opinion
15 Business impact High / Med / Low plus a note Prioritization; High items feed a regulatory change impact assessment
16 Impacted units, products and processes Named teams and systems Routes the work; "the business" owns nothing
17 Obligation(s) created Text, or a link into your obligations register The conversion from awareness to action, and the column most templates omit
18 Required actions Concrete steps What "compliant" means for this row
19 Owner One name A single accountable person, not a team alias
20 Reviewer A second name Group inspection catches about 80% of errors and individuals about half (Panko)
21 Action deadline Date; red when past due, amber under 30 days The sheet should shout before the regulator does
22 Status Not started / Assessing / In progress / Implemented / Evidence filed / N/A (dropdown) Pipeline reporting without a meeting
23 Evidence link Where the proof lives "Implemented" without evidence is a claim, not a fact
24 Last reviewed and next review Two dates The staleness alarm: an unopened tracker is misinformation with a logo
25 Notes Everything else Overflow, so the structured columns stay structured

Three of these deserve more than a table cell.

Published and effective dates are different facts, and conflating them is the most common tracking error

Regulators republish: corrections land, consolidated versions replace originals, page dates silently change. A consolidated text on EUR-Lex carries its own consolidation date, which is not the date the law was adopted or the date it applies. Article 64 of Regulation (EU) 2022/2554, for example, says DORA entered into force in January 2023 and applies from 17 January 2025 (EIOPA confirms); a tracker with one date column will hold whichever of those a person happened to copy. AI agents and experienced humans alike mis-date a change when the source shows the republication date. Two columns force the question "which date is this?" every time.

The applicability rationale is the column an auditor actually reads

"Out of scope" with no reasoning is indistinguishable, two years later, from "nobody looked." One sentence, such as "Out of scope: we are not a GPAI model provider; re-assess if we fine-tune and redistribute," turns a dismissal into evidence of a functioning process.

The obligation column is where a log becomes management

Tracking a change and acting on it are different disciplines, and that is the distinction between a change log and regulatory change management. Every in-scope row should produce an entry in an obligations register with an owner and a deadline, governed by your change management policy. A log where in-scope rows end at column 16 is a diary.

Three worked rows show what a finished entry looks like as of 30 September 2026

The workbook ships with filled-in rows so nobody has to guess what "good" looks like. They are condensed here (the file carries all 25 fields, plus a US Federal Register final-rule row):

Change ID Jurisdiction Instrument Stage Published Applies Applicability (condensed)
RC-2026-001 EU Reg (EU) 2024/1689 (AI Act), Ch. V, GPAI obligations Applicable OJ 12 Jul 2024; in force 1 Aug 2024 2 Aug 2025 (GPAI obligations); Commission enforcement powers from 2 Aug 2026 In scope: fine-tuned GPAI model deployed; Art. 53 duties if the modification makes us its provider, see our deployer checklist
RC-2026-002 EU Reg (EU) 2022/2554 (DORA), Art. 64 Applicable OJ 27 Dec 2022 17 Jan 2025 In scope: licensed payment institution; ICT risk framework and register of information
RC-2026-003 UK FCA Regulatory Initiatives Grid, 10th ed.: Cryptoasset Resolution Regime Proposed Grid published 19 May 2026 TBD: the Grid expects an FCA consultation paper in H2 2026 TBD: promote from the Horizon tab when the consultation paper lands

The AI Act's moving timeline shows why the README tab has a changelog. Regulation (EU) 2026/1744, in force since 27 July 2026, moved the high-risk obligations to 2 December 2027 (stand-alone Annex III systems) and 2 August 2028 (systems embedded in Annex I products), while the GPAI obligations kept their 2 August 2025 date. A row for this regime needs an "as amended" note and a near-term next-review date. A static PDF template cannot tell you that; a dated, changelogged register can.

The Horizon tab is your emerging-regulations tracker

Most of what will hurt you in 2027 is visible in 2026, in consultations, work programs and the regulators' own forward pipelines. The Horizon tab tracks items before adoption: Item, Jurisdiction, Stage, Expected next milestone and date, Pipeline source, Likely impact (H/M/L), Watch trigger ("promote to Change Log when...") and Watch owner.

The watch trigger keeps the tab from becoming a graveyard of interesting links: "promote when the final rule publishes in the Federal Register" is an instruction; a bookmark is not. Feed it from free regulator pipelines: the Unified Agenda (semiannual in principle; the edition after Spring 2025 was the 2026 Regulatory Plan and Unified Agenda, published in July 2026, and no edition was labeled Fall 2025) for planned US federal rules, and the FCA-hosted Regulatory Initiatives Grid, whose 10th edition (19 May 2026) tracks 135 live initiatives over a two-year pipeline. This tab is deliberately minimal regulatory horizon scanning; when the pipeline becomes its own workstream, graduate to the full horizon-scanning template.

The Sources tab is the free detection layer, because regulators already run the alerts

Regulators operate free alert infrastructure themselves, and that is what makes a $0 tracker workable. The Sources tab (Source, URL, Channel, Check frequency, Owner, Last checked) ships pre-filled with:

Add a free-tier page-change monitor for regulator pages with no feed (Visualping's free plan covers 5 pages and Changeflow's 3 sources, as of 30 September 2026), and detection is solved for $0. What is not solved for $0 is triage, deduplication and follow-through, which is exactly where the scorecard starts scoring against you. For the full range of methods, see how compliance teams track regulatory changes.

Five mistakes quietly corrupt a regulatory change log

  1. One date column. Covered above; the republication trap. Two columns, always.
  2. Logging the commentary instead of the instrument. If column 3 holds a law firm's client alert, your log inherits their scope decisions and errors. Link the regulator; cite the blog in Notes.
  3. Decisions without rationale. "Out of scope" with an empty column 14 fails the only audit question that matters: how do you know?
  4. No master copy. The moment "RC_tracker_v3_FINAL_amended.xlsx" is emailed, you have forked your compliance record. Keep one file in one location, with one changelog.
  5. Conditional formatting as a substitute for cadence. Red cells only work if someone opens the file. A tracker with no fixed weekly review and named backup goes stale silently, which is worse than none, because people trust it. This is the failure Panko's 86% figure predicts, because the file feels current.

Ten questions tell you whether you have outgrown the spreadsheet

Tab 5, rendered in full. Score each question 0 (no or never), 1 (sometimes) or 2 (yes or routinely); the workbook auto-sums.

# Question 0 1 2
1 Do you log more than 20 regulatory changes a month?
2 Do you track more than 3 jurisdictions?
3 Do you track more than 2 regulatory regimes?
4 Do more than 3 people regularly edit the file?
5 Has a regulator or auditor asked for your change-tracking evidence trail?
6 Have you missed an effective date in the last 12 months?
7 Have multiple conflicting copies of the file circulated?
8 Has the same change been logged twice from different sources?
9 Has the review cadence slipped by more than 2 weeks?
10 Does only one person really understand the file?

0 to 6: Keep the spreadsheet. It is the correct tool at your scale. Adopt the controls above (two date columns, rationale on every dismissal, a reviewer, a weekly cadence) and re-score quarterly.

7 to 12: Your tracker is now a risk register of its own. Either enforce discipline hard (a single master copy, a mandatory reviewer, a changelog entry on every edit) or go hybrid: automate detection so humans only do triage and follow-through.

13 or more: You have outgrown it. These thresholds are my rules of thumb, not a standard, but the logic is arithmetic. At more than 20 changes a month across more than 3 jurisdictions with more than 3 editors, the missing structural features (audit trail, deduplication, staleness alarms, access control) cannot be disciplined into existence.

The bands are positions; if you think your team beats the 86% base rate at 13 or more, I would like to see the file.

The spreadsheet is the manual version of what our agents populate

Full disclosure: RegWatch sells the software side of this conversion path. I am comfortable shipping a free spreadsheet because its columns map one to one onto the objects our platform maintains. Columns 3 and 4 are a Source, tracked with a health status. A hit from your weekly check is a Finding, with its URL, dates and a verbatim excerpt. Columns 12 to 15 are an Alert, except that our triage writes "Why this matters" in plain language for every item it accepts, and dismissing an alert requires a written reason, because a decision without inspectable reasoning fails the same audit test your column 14 exists for. Column 17 is an Obligation with an owner and an effective date; column 23 is Evidence; and the changelog tab is the audit log, which in the product is a tamper-evident, append-only record.

That is also where the crossover sits. A spreadsheet has no way to notice a new instrument across a dozen regulators, deduplicate it against the three law-firm alerts that mention it, and tell you why it does or does not apply to you. Someone has to do that reading, and the scorecard measures when that someone runs out of hours.

At 13 or more, buy against these criteria, in order: coverage of your source list, not the vendor's; recorded, inspectable reasoning for every accept and dismissal; deduplication across sources; a native change, obligation and evidence loop; and an audit trail you didn't build yourself. Our tools comparison applies those criteria across the market, ours included.

At 0 to 6: take the workbook, subscribe to the four free regulator channels this week, and run the weekly review. That is a real, defensible program at your scale, costing nothing but discipline.

This article is general information, not legal advice.

Download the Excel template

Free, no email needed. Sheets: README and changelog, Change Log, Horizon, Sources register, Scorecard. All templates

Questions

What should a regulatory change log include?

A complete regulatory change log has 25 fields. The minimum viable seven are the source URL (the regulator's page, not a blog), jurisdiction, instrument reference, published date, effective date, an applicability decision with written rationale, and an owner with a deadline. The most important structural choice is keeping published date and effective date as two separate columns, because regulators republish and conflating the two dates is the most common tracking error.

How do I track regulatory changes in Excel for free?

Subscribe to the regulators' own free channels (Federal Register email subscriptions, the reginfo.gov Unified Agenda, EUR-Lex, the FCA's Regulatory Initiatives Grid), log each relevant hit as one row in the change log, run a fixed weekly review with a named owner and backup, and score the outgrown-it diagnostic quarterly. The detection layer costs nothing; the effort is in the review discipline.

What free regulatory change tracking tools exist?

The regulator-native alert infrastructure (Federal Register subscriptions, Regulations.gov, the Unified Agenda, EUR-Lex saved searches, the FCA Grid dashboard, EBA and ESMA update pages), free tiers of page-change monitors such as Visualping (5 pages) and Changeflow (3 sources), and a free, no-signup change-tracker spreadsheet like the one on this page. Check current plan limits before relying on any free tier.

When should we move from a spreadsheet to software?

When the ten-question outgrown-it scorecard reaches 13 or more out of 20. As rules of thumb, the signals are more than 20 changes a month, more than 3 jurisdictions, more than 3 regular editors, or the first time an auditor asks for your change-tracking evidence trail. For scale, the Federal Register ran a record 106,109 pages in 2024, and CUBE found that 74% of firms take more than a year to implement new regulations.

Terms in this guide

Sources

  1. Panko, Spreadsheet Errors: What We Know. What We Think We Can Do (EuSpRIG 2000, posted to arXiv 2008, arXiv:0802.3457) accessed 30 Sep 2026
  2. Regology, 2024 State of Regulatory Compliance survey accessed 30 Sep 2026
  3. Wolters Kluwer, 2025 Regulatory and Risk Management Indicator (December 2025) accessed 30 Sep 2026
  4. The Register, Excel spreadsheet blunder blamed after England under-reports 16,000 COVID-19 cases (5 October 2020) accessed 30 Sep 2026
  5. JPMorgan Chase Management Task Force Regarding 2012 CIO Losses (16 January 2013) accessed 30 Sep 2026
  6. Regulation (EU) 2022/2554 (DORA), EUR-Lex accessed 30 Sep 2026
  7. EIOPA, Digital Operational Resilience Act (DORA) accessed 30 Sep 2026
  8. European Commission, Regulatory framework for AI accessed 30 Sep 2026
  9. FCA, Regulatory Initiatives Grid accessed 30 Sep 2026
  10. reginfo.gov, Unified Agenda of Federal Regulatory and Deregulatory Actions accessed 30 Sep 2026
  11. CEI, Ten Thousand Commandments 2025 (Federal Register data for 2024) accessed 30 Sep 2026
  12. CEI, Ten Thousand Commandments 2026 (Federal Register data for 2025) accessed 30 Sep 2026
  13. CUBE, The Cost of Compliance Report 2025 accessed 30 Sep 2026
  14. Visualping pricing (free plan) accessed 30 Sep 2026
  15. Changeflow pricing (free tier) accessed 30 Sep 2026

See which of this month’s changes apply to you.

Book a session on the regulators and markets you name.

Book a demo