The valuation question that ends careers is never "what is it worth". It is "how did you get to sixty two dollars on the day we bought, and who signed that". If the honest answer is that the model has been edited eleven times since, the discount rate was changed by an analyst who has left, and the peer set was rebuilt without a note, the position has no defence. Not a weak defence. None. The number was right or wrong by luck, and the process that produced it cannot be examined, which for most mandates is the more serious finding.
Reconstruction is the standard I hold a valuation file to. Nine months after the fact, with the analyst unavailable, can a colleague open the file and rebuild the exact fair value that supported the trade, using only what is in the file? Almost no model I have inherited passes that test on the first attempt. The failures are always the same three: inputs with no source, changes with no record, and approval with no scope.
What reconstruction actually requires
A model is reconstructible when every number in it falls into one of three buckets, and the bucket is written down next to it. Bucket one is a filed figure, meaning it came from a specific statement in a specific filing and can be tied back to it. Bucket two is a derived figure, meaning it is arithmetic on bucket one and the formula is visible rather than hard-coded. Bucket three is a judgement, meaning a human chose it and owns it.
The whole discipline is in keeping bucket three small and labelled. Terminal growth is a judgement. The fade path on returns on invested capital is a judgement. The equity risk premium is a judgement even when you take it from a published series, because choosing that series over another one is the judgement. Revenue for the last completed year is not a judgement, and any model where it has quietly become one has a bigger problem than governance.
The practical test I apply before a file goes to committee: delete every cell that is a hard-coded constant with no note, and see whether the model still runs. What survives is the model. What you had to delete was the part nobody could have defended anyway.
Citing a third-party score without absorbing it
Most desks now have at least one external composite in the workflow, and the Company Valuation Engine is a fair example of what one looks like. Its screen fuses fundamental ratios, technical momentum and sentiment signals into a single composite verdict per company, then ranks names on that composite. At the capture shown below the header strip read 4,420 companies covered, of which 2,207 sat below fair value, 614 within range and 1,599 above, with strong buys at zero.

That twelve-name gap between the covered count and the scanned count is not an error worth chasing. It is a reminder of what an external composite is: a live population that moves between refreshes. Absorbing it into your fair value means your fair value inherits a refresh cycle you do not control and cannot document. Citing it means something narrower and much safer.
The citation rule I use has three parts. Record the reading, the panel it came from, and the moment it was taken. Record what the reading did to the decision, which for a third-party composite should almost always be routing rather than pricing: it moved the name into the work queue, or it flagged a disagreement worth a paragraph. Record the disagreement explicitly when the composite and your own model point opposite ways, because that paragraph is the single most useful thing in the file when the position goes wrong. An external score that agrees with you adds nothing to the record. One that disagreed and was overruled, with the reasoning captured, is what a reviewer is actually looking for.
The change log entry that survives a review
Change logs fail because they log the wrong thing. "Updated WACC" is not a log entry. It records that a keystroke happened. The entry has to carry enough for a reader who was not there to decide whether the change was reasonable, which means four fields and no fewer.
- The input that changed, with its old and new value, both stated.
- The trigger, meaning what happened in the world or in the filings that justified touching it. "New 10-K" is a trigger. "Rerun" is not.
- The effect on fair value, in currency and in percent. If an input moves fair value by less than a percent, that is worth knowing too, because it tells the reader the input is not load-bearing and future arguments about it are wasted time.
- Who made it, and whether it required a second approval under your thresholds.
Thresholds are what makes this workable rather than ceremonial. Below some fair value impact, an analyst changes an input and logs it. Above it, the change needs a second name. I have seen five percent work well as that line for equity models. The point of the threshold is not control for its own sake, it is that it concentrates review attention on the handful of changes per quarter that actually move the number, instead of spreading it evenly over three hundred edits that do not.
Sign-off as two signatures with different jobs
One signature on a valuation is a formality, because the person signing is usually the person who built it. Two signatures work only when they certify different things, and the split I would defend is analyst and reviewer certifying separate claims.
The analyst certifies that the inputs are what they claim to be: filed figures tie to filings, derived figures are formulas, judgements are labelled and sourced to a stated policy. That is a factual claim, and it can be checked by sampling five inputs at random and tracing them.
The reviewer certifies something else entirely, which is that the judgement set is inside house policy and the model is inside the sensitivity band the policy permits. The reviewer is not being asked whether they agree with the fair value. They are being asked whether the fair value could have been produced by someone following the rules. Those are different questions and conflating them is why review often becomes a second opinion contest rather than a control.
Both signatures need to be against a frozen artefact, not a live file. Whatever your archive format, the requirement is that the thing signed cannot change afterwards. Screens with an export control make this straightforward: the exported file, timestamped and stored, is the state of the world the decision was made against, and a screenshot of the panel serves the same purpose for a reading that has no export.
Where the process fails anyway
Two failure modes survive everything above, and it is worth naming them so nobody believes the controls are doing more than they are.
The first is the honest but unlogged intuition. An analyst has been following a company for four years, and the terminal growth number they typed reflects that history rather than the sentence they wrote to justify it. The log is complete, every field is filled, and the actual reason is not in the file. There is no control that fixes this. The closest thing is a culture where writing "this is my judgement from covering the name, here is what would change my mind" is an acceptable log entry, which at least records the falsifier.
The second is version drift in the inputs rather than the model. Your model is frozen and signed, and the third-party feed underneath it refreshed twice since. If you cited a composite score, or a verdict, or a mispricing figure, and you did not stamp the reading, then your frozen model is quietly resting on a number that no longer exists. This is the argument for citing external composites in prose with a date and a value rather than linking them live into a cell. A linked cell is convenient right up to the review, and at the review it is the thing that cannot be reconstructed.