Ensurva blog IT

7 min read

Shadow SaaS spending: how to find and stop the software costs hiding in your accounts

Darren McMurtrie

Co-Founder

Key takeaways

  • Shadow SaaS is the software you are paying for that nobody official approved, and it hides in the bank feed and expense claims.
  • Unauthorised software is a security exposure your team cannot manage, because they do not know it exists.
  • It grows when getting software approved is harder than putting it on a card. That is a process problem, not an employee one.
  • Each tool you find has three outcomes: adopt it officially, consolidate it, or cancel it.

The subscription your sales team signed up for without telling IT. The productivity tool a developer added to their expense claim. The collaboration platform someone trialled eighteen months ago that never got cancelled. Shadow SaaS spending is the software your business is paying for that nobody officially approved, tracks, or sometimes even knows exists.

It’s a bigger problem than most finance and ops leaders expect when they first look at it. Not because individual tools cost much on their own, but because there are so many of them, they multiply across teams, and they keep growing whether or not anyone is watching.

What shadow SaaS actually costs

The visibility problem is where shadow SaaS spending starts, but the financial consequences run further than most businesses realise.

The first cost is the spend itself. Subscriptions accumulate. Teams find tools that solve an immediate problem, put them on a card, and move on. Nobody checks whether the same problem has already been solved somewhere else in the business. Nobody checks whether the tool still gets used six months later.

Employees use SaaS applications without obtaining IT approval in 80 per cent of cases.

Electroiq, Shadow IT Statistics 2026

That figure reflects how normalised unsanctioned software has become. At that scale, shadow SaaS isn’t an edge case: it’s the default behaviour for most of your workforce. The business is making software purchasing decisions constantly, just not the ones the business knows about.

The second cost is duplication. When teams buy tools independently, the same category often gets bought multiple times. Two project management platforms. Three different video tools. A note-taking app bought by marketing, another by product, and a third by the exec team. Each purchase looked reasonable in isolation. Combined, they represent money spent twice or three times on the same capability.

Businesses waste an average of more than USD 135,000 each year on duplicate SaaS licences that employees don’t use, according to research by Gartner and Flexera.

Electroiq, Shadow IT Statistics 2026, citing Gartner and Flexera

$135,000 per year is a number that tends to get finance leaders’ attention. More importantly, it’s a number most businesses arrive at without anyone having made a deliberately wasteful decision. The waste is structural, not intentional.

The security risk you can’t see

Unauthorised software doesn’t just waste money. It creates security exposure that your team can’t manage if they don’t know it exists.

Every SaaS tool your employees sign up for independently connects to something: their email, your customer data, shared documents, internal communications. When staff members create accounts on unauthorised platforms, they’re extending your data footprint beyond what your security policies cover. If that tool has a breach, or if it’s shared with a vendor who has a breach, your data is involved.

The risk has become materially more significant as AI tools proliferate. When an employee pastes customer data into an AI writing tool to draft a proposal, or connects an AI coding assistant to your internal repos, the data exposure is real and often irreversible.

Shadow AI-related security incidents increased the average cost of a data breach by USD 670,000 compared with incidents where no shadow AI was involved.

IBM, Cost of a Data Breach Report 2025

That figure is specific to AI tools, but the underlying mechanism applies to any unauthorised software. The problem isn’t the tool; it’s the combination of data access and missing visibility. When you don’t know a tool exists, you can’t monitor it, can’t apply security controls, and can’t deactivate it when someone leaves the business.

That last point matters more than it looks. When an employee with five different SaaS accounts across unsanctioned tools leaves the company, offboarding them from the tools HR knows about does nothing about the others. Their logins remain active. If they had admin access on any of those platforms, they retain it.

Where shadow SaaS comes from

Blaming employees for using unauthorised software misunderstands the problem. Shadow SaaS grows when the friction of getting official software approved is higher than the friction of buying it yourself.

If your procurement process requires three approvals and takes two weeks, and an employee can trial a tool for free and upgrade with a card in five minutes, they’ll do the thing that takes five minutes. This is rational behaviour, not irresponsible behaviour.

The conditions that create shadow SaaS are usually one of three things. First: a legitimate need without an obvious official solution. The employee genuinely needed a tool, looked at what the business provided, didn’t find it, and solved the problem themselves. Second: a provisioning process that’s too slow or too opaque. The employee asked for a tool, didn’t hear back, and found an alternative. Third: a culture where individual productivity is rewarded more than process compliance. When nobody notices or cares that software is being bought outside the approved list, the list becomes meaningless.

All three are fixable. But they require different fixes.

How to find the shadow SaaS in your accounts

You can’t fix what you can’t see. The starting point is building visibility.

The most reliable signal is your financial data. Bank feeds, credit card statements, and expense claims contain every SaaS subscription your employees are paying for, including the ones nobody sanctioned. Pull three months of data and look for:

This exercise reliably surfaces a list of tools that is significantly longer than the one IT manages. The gap between those two lists is your shadow SaaS exposure.

The second signal is your SSO login data if you use one. Tools that employees connect to via Google or Microsoft SSO will often appear there even if they’re not in your approved list. Compare what’s in your SSO provider’s connected applications against your approved software inventory.

The third signal is exit interviews and IT offboarding checklists. When an employee leaves and IT goes to revoke access, the tools they don’t have access to are often the ones that surface. It’s not a proactive method, but the data is there if you capture it systematically.

What to do when you find it

Finding unsanctioned software gives you three choices per tool: adopt it officially, find a consolidated alternative, or cancel it.

Adoption makes sense when the tool is genuinely useful, doesn’t duplicate something you already have, and can be brought under your security and access management policies. Moving it from personal card to company procurement and adding it to your approved software list takes the risk from invisible to managed.

Consolidation makes sense when the tool solves the same problem as something you already have. The question to ask is not “why are they using this instead of our official tool?” but “what does our official tool not do that drove them to find an alternative?” The answer is usually a feature gap or a usability problem. Sometimes the shadow tool is simply better, and the right decision is to adopt it and retire the official one.

Cancellation makes sense for tools that are genuinely redundant, that the employee no longer uses, or that represent a security risk the business isn’t willing to accept.

The conversation with the employee matters. If you cancel a tool someone actively uses without a viable alternative in place, they’ll find another one. The goal isn’t compliance enforcement; it’s bringing spend and risk into visibility.

Stopping new shadow SaaS from forming

Visibility into your current shadow SaaS is a starting point, not a permanent fix. New tools will keep appearing as long as the conditions that created the existing ones persist.

The most effective structural change is making the approved path easier than the unapproved path. This means: a visible, maintained list of approved tools; a clear request process with a reasonable turnaround time; and ideally a way for employees to propose new tools through a channel that actually gets reviewed.

Spend controls help too. Setting a threshold below which software purchases on expense claims get flagged for review, rather than automatically approved, catches new tools before they become embedded. The threshold needs to be low enough to capture monthly SaaS charges (most start below $100/month) but practical to review.

Regular software audits, quarterly or twice yearly, catch the tools that slip through. They also send a signal to the organisation that software spend is taken seriously.

Ensurva connects to your accounting system and surfaces new vendor payments automatically, so shadow SaaS shows up as an unrecognised vendor rather than disappearing into the noise of the bank feed. You can review and classify new software spend without waiting for a quarterly audit to discover it. For an overview of the broader SaaS management picture, the SaaS spend management guide covers the full lifecycle from discovery through rationalisation.

Get started with a 14-day free trial