Why Excel and Email Are No Longer Enough for Global EAP and IIS Programs

For many Expanded Access Programs (EAPs) and Investigator-Initiated Studies (IIS), the operational infrastructure starts simply: an Excel spreadsheet to track requests, email to coordinate with stakeholders, shared folders for documents, and perhaps a few locally developed templates.

At a small scale, this can appear to work.

But as EAP and IIS programs expand across countries, products, indications, investigators, and internal teams, the same tools that once seemed flexible can become a significant operational—and compliance—constraint.

The problem is not that Excel and email are bad tools. They are simply being asked to perform a job they were never designed to do: manage complex, global, cross-functional programs involving sensitive information, regulated processes, critical decisions, and requirements for security, traceability, oversight, and consistent execution.

For global EAP and IIS teams, this raises an important question: when does a collection of everyday productivity tools stop being sufficient and a purpose-built, validated platform become essential?

The Spreadsheet Becomes the System

A spreadsheet often begins as a tracker.

Over time, more columns are added. New tabs appear for different countries or products. Status fields multiply. Comments become increasingly important. Separate versions are created for different teams.

Eventually, the spreadsheet is no longer simply tracking the process. It is the process.

That creates an immediate challenge: the organization is relying on a document rather than a true system of record.

Teams must determine which version is current, whether information has been updated, who changed a field, and whether another stakeholder is working from the same data. Maintaining the tracker itself becomes part of the workload.

For global EAP and IIS programs, where a single request or proposal may move through multiple internal and external stakeholders, those limitations become increasingly consequential.

Email Hides the Workflow

If Excel becomes the database, email frequently becomes the workflow engine.

A request arrives. Someone forwards it to another team. Questions are sent back to the investigator or physician. Documents are attached. An approval is requested. Another stakeholder is copied into the conversation.

Each individual action may be perfectly reasonable.

The problem emerges when hundreds or thousands of those actions collectively constitute a global program.

Critical program information becomes distributed across inboxes and email threads. Teams must reconstruct what happened, who is responsible for the next action, and whether something is waiting for a response.

The process depends heavily on individuals knowing what to do next—and remembering to do it.

A dedicated platform turns those informal handoffs into structured workflows, with defined responsibilities, statuses, controls, and next steps.

Security Risks Grow With Every Spreadsheet, Attachment, and Inbox

EAP and IIS programs may involve sensitive and confidential information, including physician and investigator information, program documentation, scientific information, and, depending on the process, personal or patient-related data.

When this information is distributed through spreadsheets, email attachments, local downloads, and shared folders, controlling access becomes significantly more difficult.

Files can be forwarded beyond the intended audience. Attachments can remain indefinitely in inboxes or on local devices. Multiple copies of sensitive information can exist across an organization. Access may persist after someone's role changes. Teams may have limited visibility into who has viewed, downloaded, changed, or shared information.

These risks become even more challenging when programs operate internationally, where organizations may also need to consider different privacy and data-protection requirements.

Security therefore cannot simply be an IT consideration layered onto an EAP or IIS process. It needs to be part of the operating model itself.

A purpose-built platform can provide capabilities such as role-based access controls, centralized information management, controlled authentication, audit trails, and defined data-management practices—reducing reliance on uncontrolled copies of information moving between individuals.

Compliance Requires More Than a Process Document

Global EAP and IIS programs operate within environments where organizations need to demonstrate that processes are being followed consistently.

A standard operating procedure may define what should happen. But Excel and email do not inherently ensure that it doeshappen.

A spreadsheet may allow someone to skip a field. An email may bypass an expected reviewer. A document can be replaced without a clear history. A required step can depend on an individual remembering to complete it.

That distinction becomes important when an organization needs to demonstrate not simply that a process exists, but that the process was followed.

Purpose-built technology can embed requirements directly into workflows. Required information can be enforced. Review steps can be configured. Responsibilities can be defined. Actions can be timestamped. Exceptions can be identified.

In other words, compliance moves from something the organization has to reconstruct after the fact to something supported systematically as the work occurs.

A Validated System Provides Confidence in the Process

For processes subject to applicable regulatory and quality requirements, implementing technology is not simply a matter of replacing spreadsheets with software.

The system needs to be appropriate for its intended use and, where required, validated accordingly.

A validated system provides documented evidence that the technology performs consistently as intended within its defined use. This can include documented requirements, testing, controlled configuration and change management, appropriate access controls, auditability, and supporting validation documentation.

That distinction matters.

A sophisticated-looking application without the appropriate validation and quality framework may simply replace one operational risk with another.

Organizations evaluating technology for EAP and IIS programs should therefore look beyond features and ask more fundamental questions:

Is the platform designed for regulated life sciences processes? Does it support the organization's applicable compliance requirements? Can it provide appropriate audit trails and access controls? Is there documented validation evidence? How are system changes tested and controlled? Can the organization demonstrate that the system remains fit for its intended use?

For a global program, these are not secondary technology questions. They are fundamental requirements for establishing trust in the system supporting the process.

Global Programs Magnify the Problem

EAP and IIS processes rarely operate identically everywhere.

Country requirements can differ. Documentation may vary. Review pathways may change depending on the type of request, product, indication, or geography. Different internal stakeholders may need to participate at different stages.

Trying to represent this complexity through spreadsheet columns, email instructions, and local knowledge creates an operational burden that grows with every new market.

This is where flexibility can become fragmentation.

One country develops its own tracker. Another team introduces a different template. A business unit creates another process. Before long, the organization may have multiple interpretations of what is supposed to be a global program.

A purpose-built platform can provide a common global framework while accommodating the variations that genuinely need to exist—and doing so within controlled, documented processes.

Oversight Should Not Require Manual Reconstruction

Program leaders need more than a list of open requests.

They need to understand the health of the program.

Where are requests accumulating? How long are different stages taking? Which items require attention? Are there recurring bottlenecks? How does activity differ by geography, product, indication, or program? Are required process steps being completed?

When information is spread across spreadsheets, inboxes, and folders, answering those questions often requires manual consolidation.

That means reporting becomes retrospective: teams spend time assembling a picture of what has already happened rather than seeing what is happening now.

A dedicated platform can capture structured information as work occurs, making operational visibility an inherent part of the process rather than a separate reporting exercise.

Traceability Matters

EAP and IIS programs involve decisions, documentation, communications, and handoffs that organizations may need to understand well after the original activity occurred.

With spreadsheet- and email-driven processes, reconstructing that history can be difficult.

Which information was available when a decision was made? Who completed a particular review? Which document version was considered? When was additional information requested? When was it received? Who changed a status—and when?

The answers may exist—but they may be distributed across files, inboxes, and individual recollections.

Purpose-built technology can create a more coherent and auditable record of program activity by capturing workflow events, decisions, documentation, and communications in context.

That improves not only efficiency, but organizational confidence in the integrity of the process.

Manual Processes Consume Highly Skilled People

There is also a human cost.

EAP and IIS teams contain people with specialized medical, scientific, operational, and program expertise. Their time is valuable.

Yet spreadsheet- and email-based processes can require them to spend significant portions of that time on administrative coordination: updating trackers, searching for correspondence, checking statuses, following up on missing information, consolidating reports, managing document versions, and moving data between systems.

The question is not simply whether these activities can be performed manually.

It is whether they are the best use of the team's expertise.

Automation and structured workflows can remove much of that administrative friction while allowing experts to focus their attention where judgment is actually required.

The Risk Increases as Programs Succeed

One of the paradoxes of spreadsheet-based processes is that they often appear adequate until the program grows.

Then volume increases. More countries participate. More stakeholders become involved. More sensitive information is exchanged. Reporting expectations rise. Leadership wants greater visibility. Compliance requirements become more difficult to manage consistently.

The operating model that supported the program at its beginning becomes increasingly difficult to sustain.

Organizations then face a choice: continue adding people and controls around an inherently manual process—or improve the infrastructure supporting it.

That is why technology decisions for EAP and IIS should not be based solely on today's volume. They should consider the operating, security, quality, and compliance model the organization will need as its programs evolve.

From Productivity Tools to Purpose-Built Infrastructure

Excel, email, and shared drives will continue to have important roles in life sciences organizations.

But there is a fundamental difference between using those tools within a program and using them to operate the program.

Global EAP and IIS programs increasingly require infrastructure capable of supporting structured intake, configurable workflows, secure information management, role-based access, document control, stakeholder coordination, audit trails, reporting, program-level visibility, and applicable compliance and validation requirements.

A dedicated, validated platform brings those capabilities together.

Instead of asking teams to connect spreadsheets, inboxes, folders, manual controls, and institutional knowledge, the process itself becomes connected, controlled, traceable, and visible.

The result is not simply a more modern way of working.

It is a more scalable and defensible operating model—one that gives EAP and IIS teams greater visibility, consistency, security, and control while providing organizations with greater confidence that their global programs are operating as intended.

Excel and email may be where many EAP and IIS programs begin.

But when those programs become global, complex, and subject to increasing security and compliance expectations, they should not be where they remain.

Next
Next

OEAP West 2026 Recap: Expanded Access Enters a New Era of Operational Excellence