Skip to content
Licenses5 min read

What shadow IT actually costs

The number is rarely the subscriptions themselves. It is the renewals nobody owns and the accounts nobody closes.

Shadow IT gets discussed as a security problem, and it is one. But when finance asks what it costs, the honest answer is rarely the subscriptions themselves. The spend is real, and it is usually not the largest number in the room.

The subscriptions are the visible part

A team buys a tool on a card for €40 a month. Multiply by however many of those exist and you get a figure — meaningful, but bounded, and the one most articles stop at.

What makes it worse than the arithmetic suggests is that card-bought software renews silently. Nobody negotiated it, nobody set a reminder, and the renewal lands as an already-charged line on a statement. A subscription with no owner does not get canceled when the project ends; it gets canceled when someone notices, which is on average several renewals late.

The larger numbers

Duplicate capability. Three teams solving the same problem with three vendors is three contracts, three security reviews and no volume discount. Consolidation is usually the single largest saving available, and it is invisible until the tools are in one list.

Seats for people who left. Covered in every offboarding conversation and still the most reliable waste in the estate. Deprovisioning an account often does not remove it from the bill; the seat stays paid until someone edits the plan.

The renewal you couldn't negotiate. Walking into a renewal without knowing your own usage means accepting the vendor's number. Knowing that 40% of seats were inactive last quarter changes the conversation, and you can only know that if the usage data was being collected before the renewal.

Compliance drag. Every unknown vendor holding company data is a subprocessor you cannot name in a questionnaire. That does not appear in a budget line; it appears as a delayed enterprise deal, and it costs considerably more than the subscription did.

Why it isn't a policy problem

The instinct is to ban card purchases. This reliably fails, for a reason worth sitting with: people buy tools outside the process because the process is slower than the work. Making the process stricter makes the gap wider, and the spend moves further out of view rather than going away.

What works better is making the estate visible without asking anyone to declare anything. The data already exists — in the card statements, in the AP ledger, in the OAuth grants people approved against the company directory. Every one of those is a signal that a tool exists, and none of them requires cooperation.

The order to work it

  1. Find it. Card and AP data first, OAuth grants second. That is most of the estate, without a single survey.
  2. Name an owner. Every tool gets one, and the owner is the person who answers at renewal. Unowned tools are what accumulate.
  3. Measure use before renewing. Seats assigned is not seats used, and the difference is your negotiating position.
  4. Consolidate deliberately. Not everything — duplicates in the same category, where the switching cost is lower than the second contract.

None of this requires a ban. It requires the list to exist, and for the list to be current on the day a renewal lands rather than the day someone audits it.

← All resources

Up in minutes. As far as you want to take IT.

Connect once. Inventory your software in minutes. Define policies when you’re ready. Enforce them when you’re confident: start with logging, move to coaching, block what needs blocking.

See a live environment