What shadow IT actually costs
The number is rarely the subscriptions themselves. It is the renewals nobody owns and the accounts nobody closes.
Shadow IT gets discussed as a security problem, and it is one. But when finance asks what it costs, the honest answer is rarely the subscriptions themselves. The spend is real, and it is usually not the largest number in the room.
The subscriptions are the visible part
A team buys a tool on a card for €40 a month. Multiply by however many of those exist and you get a figure — meaningful, but bounded, and the one most articles stop at.
What makes it worse than the arithmetic suggests is that card-bought software renews silently. Nobody negotiated it, nobody set a reminder, and the renewal lands as an already-charged line on a statement. A subscription with no owner does not get canceled when the project ends; it gets canceled when someone notices, which is on average several renewals late.
The larger numbers
Duplicate capability. Three teams solving the same problem with three vendors is three contracts, three security reviews and no volume discount. Consolidation is usually the single largest saving available, and it is invisible until the tools are in one list.
Seats for people who left. Covered in every offboarding conversation and still the most reliable waste in the estate. Deprovisioning an account often does not remove it from the bill; the seat stays paid until someone edits the plan.
The renewal you couldn't negotiate. Walking into a renewal without knowing your own usage means accepting the vendor's number. Knowing that 40% of seats were inactive last quarter changes the conversation, and you can only know that if the usage data was being collected before the renewal.
Compliance drag. Every unknown vendor holding company data is a subprocessor you cannot name in a questionnaire. That does not appear in a budget line; it appears as a delayed enterprise deal, and it costs considerably more than the subscription did.
Why it isn't a policy problem
The instinct is to ban card purchases. This reliably fails, for a reason worth sitting with: people buy tools outside the process because the process is slower than the work. Making the process stricter makes the gap wider, and the spend moves further out of view rather than going away.
What works better is making the estate visible without asking anyone to declare anything. The data already exists — in the card statements, in the AP ledger, in the OAuth grants people approved against the company directory. Every one of those is a signal that a tool exists, and none of them requires cooperation.
The order to work it
- Find it. Card and AP data first, OAuth grants second. That is most of the estate, without a single survey.
- Name an owner. Every tool gets one, and the owner is the person who answers at renewal. Unowned tools are what accumulate.
- Measure use before renewing. Seats assigned is not seats used, and the difference is your negotiating position.
- Consolidate deliberately. Not everything — duplicates in the same category, where the switching cost is lower than the second contract.
None of this requires a ban. It requires the list to exist, and for the list to be current on the day a renewal lands rather than the day someone audits it.
← All resources