How to Audit SaaS Subscriptions for Your Business
The average mid-market firm runs about 120 SaaS applications. Around 32 percent of those licenses go unused, per Zylo's 2026 SaaS Management Index.
For a 75-person company spending $300 per user per month on software, that math produces roughly $30,000 per year in pure waste. Nobody signed a check for that. It crept in one subscription at a time.
Here is how to find it, cut it, and keep it from coming back.
Why SaaS Sprawl Happens
It starts small. Someone on the sales team needs an e-signature tool. Marketing signs up for a scheduling platform. Finance grabs a contract management app. The operations lead buys a project tool because the one IT manages doesn't work the way she wants.
Each one costs under a hundred dollars a month. None of them triggers a purchase order. And because they auto-renew, they outlive the person who bought them, the project they were bought for, and anyone's memory of why they exist.
AI tools added another layer in 2025. Zylo tracked a 181 percent increase in AI application counts within business SaaS portfolios last year. A 40-person team that adopted five AI tools in 2025 probably has eight now, with a few that nobody opened after month one. For more on what unchecked AI tool adoption looks like from a security standpoint, the breakdown of AI agent sprawl covers the exposure in detail.
Shadow IT accounts for roughly 42 percent of SaaS purchases, meaning nearly half of what your team uses bypassed IT governance entirely. The security and compliance implications are real. So is the cost.
Step 1: Find Everything You Are Paying For
This is harder than it sounds. Subscriptions hide in three places, and no single source catches them all.
Corporate cards and expense reports. Pull 90 days of charges. Filter for recurring transactions between $5 and $500 per month. Then look for larger one-time charges in the $100 to $5,000 range that could be annual billings. Look through expense reimbursements too. That's where shadow subscriptions on personal cards show up.
Finance and accounts payable. Invoiced contracts from Slack, Salesforce, Adobe, or any enterprise vendor show up here. Finance sees the invoices but not the usage. Cross-reference with what's in your SSO system.
Your SSO and identity provider. Pull all active app assignments from Okta, Microsoft Entra ID, or Google Workspace. Every OAuth grant an employee authorized is a SaaS app with access to something. Some of them have access to a lot.
Combine all three sources into one spreadsheet. For each tool, capture: tool name, monthly cost, annual cost, seats paid, billing owner, primary department, and renewal date. Don't try to decide what to cut yet. Just get everything on one list.
For context on where cloud spending tends to leak beyond SaaS licenses, see the breakdown of where growing businesses overpay for cloud.
Step 2: Separate Active from Dead
Once you have the full list, go tool by tool through the admin panel of anything costing more than $100 per month. Most SaaS platforms show last-login dates under Settings or Team Management.
Flag anything where fewer than half the paid seats logged in within the last 30 days. That's your underutilization list.
Then look for redundancy. Two project management tools. Two document signing tools. Two video platforms. Mark every pair.
Two categories emerge: zombie subscriptions where nobody logs in, and overlapping tools where different teams adopted separate solutions that do the same thing.
Step 3: Cut the Dead Weight
Zombie subscriptions are straightforward. Cancel immediately. Export any data first, then cancel. Do not downgrade to a free tier to stay safe. That's how zombie tools come back.
Redundant tools require a 30-day consolidation window. For each duplicate pair, pick the winner based on three factors: which one has more daily active users, which one covers more of the team's actual workflow, and which one costs less at your current seat count. Don't pick based on which tool looks better in a features comparison. Pick based on which one your team already uses more.
Give users 2 to 4 weeks to migrate. Set a hard cutoff date. On that date, cancel the subscription. If someone genuinely needs it later, they can re-subscribe. In practice, they don't.
For over-provisioned tools that are actually used, wait for the renewal date. Come in 90 days before renewal with real usage data and a credible alternative. Vendors negotiate. They prefer a smaller renewal over a cancellation. That approach typically produces 15 to 30 percent rate reductions on your largest contracts.
Step 4: Set Up Governance So It Doesn't Come Back
A one-time audit solves today's problem. It doesn't address the conditions that created it.
Sprawl returns because there's no gate on new purchases. Every month someone approves a new subscription somewhere, and by the time the next audit happens, the list has grown back.
Two things prevent this. First, a lightweight purchase approval process. A dedicated Slack channel where any new software request needs a thumbs-up from ops or finance works for most teams under 100 people. It takes 90 seconds per request and creates a record of what was bought and why.
Second, a quarterly 20-minute review. New subscriptions added since last quarter? Any tools with zero logins? Any renewals in the next 60 days? That's the whole agenda. Teams that run this quarterly turn the annual audit into a confirmation exercise instead of a six-hour excavation.
For companies spending more than $10,000 per month on software, a dedicated SaaS management platform like Zylo, Torii, or Auvik SaaS Management automates discovery and tracks usage continuously. That investment usually makes sense around $10,000 to $15,000 per month in total software spend, where savings from better visibility exceed the tool cost. Below that threshold, a spreadsheet with a quarterly owner works fine.
Where IT Governance Fits In
The audit itself takes a few hours for a 50-person team with one person focused on it. What most teams struggle with is the ongoing part.
Assigning a tool owner for every application in the stack. Maintaining a renewal calendar that triggers 90 days before every contract. Reviewing usage monthly on the largest contracts. Making sure employees who leave immediately lose access across all 120 applications, not just the ones IT knew about.
That's not a quarterly project. It's an ongoing operational responsibility that compounds when it's handled inconsistently. A departed employee still holding active credentials to eight cloud platforms is a security incident waiting to happen.
A managed IT partner with SaaS management in their service scope handles this continuously. Shadow IT discovery, access deprovisioning on day one of a departure, usage reviews ahead of renewals, and SSO governance are all part of a properly scoped managed services engagement.
The audit gets you visibility into where you are today. Governance is how you stay there.
Frequently Asked Questions
How long does a SaaS audit take for a growing business?
For a 50-person company with one person focused on it, expect 4 to 6 hours for the initial discovery pass. Pulling records from finance, corporate cards, and your SSO system takes most of that time. The review of actual usage and the decisions about what to cut take another 2 to 3 hours.
How often should a business audit SaaS subscriptions?
Once per year for a comprehensive pass. A quarterly 20-minute check keeps sprawl from rebuilding between annual audits. For teams spending more than $10,000 per month on software, monthly check-ins on the highest-spend and usage-based tools catch cost creep before it compounds.
What is the average wasted SaaS spend for a mid-size business?
Research from 2025 and 2026 puts average wasted SaaS spend at around $135,000 per year due to unused licenses for SMB-sized organizations. For a company paying $250 per employee per month across 80 employees, that's $240,000 in annual software spend. If 30 percent is wasted, that's $72,000 in recoverable budget sitting in auto-renewing subscriptions.
What should we do with apps employees added without IT approval?
Evaluate them on the same criteria as approved tools: who is using them, what data do they access, and what does it cost? If they are genuinely useful and pass a security review, sanction them and bring them into governance. If they duplicate something you already have or expose sensitive data outside your approved environment, shut them down. The goal is not to penalize the behavior. It's to get everything visible and under management.
Can a growing business manage SaaS sprawl without a dedicated tool?
Yes, up to a point. A spreadsheet-based process works well for most teams under 75 people. Above that, the number of tools, seats, renewals, and access changes makes manual tracking error-prone. Dedicated SaaS management platforms become cost-effective around $10,000 to $15,000 per month in total software spend, where the savings from better visibility typically exceed the tool cost.
SaaS audit and ongoing governance is part of what a well-run managed IT engagement covers. If you want help getting your software stack inventoried, access controlled, and renewal calendar set up, reach out to talk through your situation.