If you're the IT lead or engineering manager at a 50–500 person Indian company, you probably have a rough mental list of the tools your team uses. Notion, Slack, Google Workspace, maybe a Jira license, some AWS services. The problem is that mental list is almost certainly wrong by at least 30%.
The real SaaS stack lives across 4 corporate cards, 2 personal cards that get expensed, a handful of UPI autopay mandates nobody flagged to finance, and roughly a dozen OAuth integrations your Google Workspace admin console is quietly tracking. Finance sees the credit card charges. You see the support tickets. Nobody sees all of it at once.
SaaS audit 90-day plan audit domains, to run a complete SaaS audit on your own stack. You can work through it manually with your team or use it to scope what an automated tool needs to pull for you. Either way, by the end you'll know exactly where the waste is sitting and what to do about it in the next 30 days.
Why Most Indian IT Teams Fail Their Own SaaS Audit
The average 100-person Indian company runs somewhere between 30 and 50 SaaS tools at any given time. Almost none of them have a central registry. That's not a criticism — it's just how growth happens. A sales team signs up for a prospecting tool. A designer buys a Figma seat on their card. DevOps spins up a monitoring service on an AWS sub-account. Each decision made sense in isolation. Nobody drew the map.
When audit time comes, the failure mode is always the same: finance can see the charges but not the usage, IT can see the tickets but not the contracts, and the actual tool owners have left or moved teams. The three data sources that would give you a complete picture — inbox invoices, SSO provider logs, and bank/card feeds — are sitting in three different systems with three different owners.
GST reconciliation makes this worse for Indian teams specifically. When your SaaS invoices arrive from vendors across 6 different billing entities, some in USD, some via Indian resellers with GSTINs, and some through international payment links that issue no India-compliant invoice at all, the ITC (input tax credit) trail breaks down fast. A single missed GSTIN on a vendor invoice can disqualify that month's ITC claim — which, at 18% GST on a ₹1 lakh/month SaaS spend, is ₹18,000 left on the table.
The average Indian SMB renews 60% of its SaaS stack on autopilot — with no utilisation review. The cost isn't just the wasted spend; it's the GST credit that never gets claimed.
Audit failures aren't really process failures. They're visibility failures. The checklist below is structured to close that visibility gap, domain by domain.
How to Structure a SaaS Audit: Five Domains That Matter
50 questions is a lot to dump in a spreadsheet and call it an audit. The way to make this usable is to split the work across 5 distinct domains, each with its own data source and its own owner.
- App Discovery (Q1–10): What tools exist. Source: SSO logs, admin consoles, bank feeds, email invoices.
- Contract and Vendor Visibility (Q11–20): What you agreed to and with whom. Source: contract storage, procurement records, legal sign-off trails.
- reclaim unused licenses. Source: API-level usage data from Google Workspace, Microsoft 365, Slack, and individual vendor dashboards. SaaS renewal calendar: When things renew, what they cost in INR, and whether your GST invoices are clean. Source: renewal emails, finance ledgers, invoice archives.
- Shadow IT Detection (Q41–50): What's running outside IT's knowledge entirely. Source: OAuth grant logs, expense report line items, inbox invoice scanning.
In a 50–500 person company without a dedicated IT procurement function, ownership typically falls across 3 people: the IT lead handles discovery and utilization, finance owns renewal hygiene and spend, and whoever runs operations or HR owns the contract visibility side. Shadow IT, by definition, doesn't have a clear owner — which is exactly why it's the hardest domain and the most rewarding one to audit.
Done manually across all 5 domains, a 100-person company should budget 3–5 working days. Automated tools (more on that in a later section) compress this to under an hour for the discovery-heavy domains.
Run a free SaaS spend audit — find every hidden subscription
Domain 1 — App Discovery: Questions 1–10
This domain answers the most basic question: what tools are we actually paying for?
- Q1: Does your SSO provider (Okta, Azure AD, Google Workspace SSO) have a complete list of connected applications?
- Q2: Have you pulled the Google Workspace Marketplace apps installed by users in the last 90 days?
- Q3: Is AWS Cost Explorer broken down by service tag, and do those tags map to teams?
- Q4: Have you reviewed the Slack app directory for third-party integrations your team has approved?
- Q5: Is there a Microsoft 365 app usage report for the last 30 days?
- Q6: Which corporate cards have active recurring SaaS debits, and who manages each card?
- Q7: Are there any UPI autopay mandates set up against company accounts for SaaS tools?
- Q8: Have you pulled a bank statement filter for international USD/EUR recurring charges in the last 6 months?
- Q9: Does your employee onboarding checklist name every tool a new hire gets provisioned on? Is that list up to date?
- Q10: Does your offboarding checklist confirm deprovisioning from every tool — or just the obvious ones?
One specific technique worth calling out: pull Gmail invoice labels. Search your shared finance inbox for terms like "invoice", "receipt", "subscription renewed", and "billing" filtered to the last 12 months. Every unique sender domain that appears is a potential SaaS vendor. This surfaces tools that finance never formally approved because they were bought on a team budget or a personal card and expensed after the fact.
Watch out: Tools bought on personal cards and expensed ad hoc are the most common gap in Discovery. They won't appear in your SSO logs or admin console. You'll only find them in expense report exports — search for line items categorized as "software" or "subscriptions" across the last 4 quarters.
Key takeaway: No single data source gives you the full app inventory. You need at least three — SSO logs, card/bank feeds, and inbox invoice scanning — to get close to complete.
Domain 2 — Contract and Vendor Visibility: Questions 11–20
Knowing a tool exists isn't the same as knowing what you agreed to.
- Q11: Where are vendor contracts stored? Is there one location or are they split across email threads, Google Drive folders, and someone's downloads?
- Q12: Who signed each contract — personal email, company email, or a procurement alias?
- Q13: What are the exit clauses for your top 10 tools by spend? When does the cancellation window open before auto-renewal?
- Q14: Are auto-renewal terms explicitly documented in your contract log, or buried in click-wrap terms?
- Q15: What percentage of your SaaS stack is on annual or multi-year commits vs. monthly billing?
- Q16: For annual contracts, what is the total committed spend for the next 12 months — in INR?
- Q17: Do you have a named account manager or renewal contact at each of your top 5 vendors by spend?
- Q18: For tools handling sensitive customer data, has the vendor provided a data residency or data processing agreement (DPA)?
- Q19: Do vendor security commitments (SOC 2, ISO 27001, or equivalent) cover your India-regulated data under RBI or SEBI guidelines if applicable?
- Q20: Are contracts formalized as MSAs (Master Service Agreements) or are you operating on click-wrap terms and purchase orders?
The classic example here is any Zoho or Freshworks annual deal. Both vendors typically have a 60-day written cancellation notice window before auto-renewal — meaning if you decide mid-November that you want to switch tools, and your renewal is January 1, you're already past the cutoff. Most teams discover this only when they call support and are told the renewal has already been processed.
Domain 3 — License Utilization and Usage Tracking: Questions 21–30
This is where real money gets recovered.
- Q21: For Google Workspace, how many provisioned seats vs. active seats does your admin console show right now?
- Q22: For Microsoft 365, have you pulled the Microsoft 365 admin center's Active Users report filtered to the last 30 days?
- Q23: For Slack, how many paid seats do you have vs. members who sent a message in the last 30 days?
- Q24: For your CRM (Salesforce, HubSpot, Zoho CRM), how many licensed users logged in at least once in the last 90 days?
- Q25: Do you have last-login timestamps for every user on every paid tool?
- Q26: What's your threshold for "inactive" — 30 days, 60 days, 90 days? Is it written down somewhere?
- Q27: How many seats across your entire stack have had zero logins in the last 90 days?
- Q28: For any tool with feature tiers, are you on a plan tier where you actually use the features that justify the upgrade?
- Q29: Are any teams on an Enterprise plan primarily because IT never reviewed whether the Pro plan covers their use case?
- Q30: What is the total INR value of seats across all tools that haven't been used in 90+ days?
Let's put numbers to Q30. Slack's standard plan runs roughly ₹750 per seat per month for Indian accounts. A 100-person company with 25 inactive seats that nobody has reviewed is burning ₹18,750 per month — ₹2.25 lakh per year — on nobody. That's before you account for similar patterns in your CRM, project management tool, and design suite.
The metric to track consistently is the gap between your paid seat count and your active user count. It's the most actionable number in a SaaS audit, and most admin consoles surface it natively if you know where to look.
Action: Before your next renewal, pull a 90-day active-user report from every tool above ₹5,000/month. Any tool where fewer than 40% of paid seats logged in is a candidate for right-sizing or cancellation.
Key takeaway: Last-login timestamps are the fastest utilization proxy available. A 90-day inactivity threshold, applied consistently across your stack, typically surfaces 15–25% of seats as reclaimable.
Domain 4 — Renewal Calendar and Spend Hygiene: Questions 31–40
- Q31: Which tools auto-renew in the next 30 days — and who is the named decision-maker for each?
- Q32: Which tools auto-renew in the next 31–60 days?
- Q33: Which tools auto-renew in the next 61–90 days — and do you have time to renegotiate any of them?
- Q34: Is there a single calendar or system that owns renewal dates, or are they scattered across email reminders and individual calendar entries?
- Q35: Does every Indian SaaS vendor in your stack issue GST-compliant invoices with their GSTIN printed on the invoice?
- Q36: Do vendor invoices include the correct HSN or SAC code for IT/software services (typically SAC 9983 or 9984 for software services)?
- Q37: Does your company's GSTIN appear on every invoice you're claiming ITC against? Have you verified this with your CA recently?
- Q38: Which tools are billed in USD or EUR, and what is their INR equivalent at the current exchange rate?
- Q39: What is your total annualized FX exposure on USD-billed SaaS tools, and has finance modeled a 5% INR depreciation scenario?
- Q40: Does finance have a single SaaS line item in the P&L, or are subscriptions scattered across 20+ expense categories?
Q35–Q37 are the ones most Indian IT teams skip entirely because they feel like a finance problem. They're not. When an AWS or Atlassian invoice arrives without your company's GSTIN, the ITC claim fails — and at 18% GST, that's real money. At ₹50,000/month in SaaS spend, a non-compliant invoice set costs ₹9,000/month in lost ITC, or ₹1.08 lakh over a year.
For Q31–Q34, our AI CIO renewal alert engine automates exactly this. It surfaces every renewal 60 and 30 days out, assigns an owner, and flags contracts where the cancellation window is about to close. If you're managing this manually right now, a shared Google Calendar with renewal events is a reasonable starting point — but it only works if someone owns the discipline of keeping it updated.
Domain 5 — Shadow IT Detection: Questions 41–50
This is the domain that surprises people most. Not because shadow IT is shocking, but because of how much of it there typically is.
- Q41: Have you searched your shared finance inbox for invoice emails from vendors not on your approved tool list?
- Q42: Have you searched individual team inboxes (with consent and appropriate access) for recurring software invoice patterns?
- Q43: Is there a keyword filter running on your email that flags new "subscription" or "payment receipt" threads from unknown SaaS vendors?
- Q44: Have you cross-referenced the vendors in your inbox invoice scan against your approved vendor list?
- Q45: Have you reviewed the OAuth app grants in your Google Workspace admin console under Security > API Controls?
- Q46: How many third-party apps have OAuth access to your Google Workspace data right now — and when did IT last review that list?
- Q47: Are there browser extensions installed on company devices that have broad data access permissions?
- Q48: Have you pulled expense report line items categorized as "software", "tools", "subscriptions", or "online services" from the last 12 months and matched each to an approved tool?
- Q49: Are there department-level SaaS purchases (marketing tools, design tools, analytics platforms) that were bought without an IT approval ticket?
- Q50: Does your company have a written SaaS procurement policy — and when was it last communicated to team leads?
Q45 is the one that consistently produces the most surprised reactions when we walk through it with customers. A typical 100-person company's Google Workspace admin console shows 60–120 OAuth app grants, of which IT can identify fewer than half. Each one is a third-party tool with some level of data access — calendar read, email read, Drive access — that was authorized by a user, not by IT.
Q50 is the structural answer to the whole domain. If there's no written procurement policy — or if the last one was written when the company had 20 people — shadow IT will keep regenerating itself regardless of how good the audit is.
Action: Go to your Google Workspace Admin Console, navigate to Security > API Controls > App Access Control, and filter for "has access to Google data." Any app with "Trusted" status that IT didn't explicitly approve is a shadow IT signal worth investigating.
Running the Audit Manually vs. Letting AI CIO Do It
Here's an honest estimate for the manual version: a thorough audit across all 5 domains for a 100-person company takes 3–5 working days. That's pulling admin console reports, cross-referencing bank statements, chasing down contract storage locations, and interviewing department heads about tools their teams use.
And you'll still miss things. Tools on personal cards that get expensed informally won't appear in your admin console. Tools that someone signed up for with a personal email won't show in your SSO logs. OAuth grants that were authorized 18 months ago and never reviewed are invisible to a manual process unless you specifically know to look for them.
What the automated version looks like: our AI CIO ingests Gmail invoice threads, SSO provider logs, and bank/card feeds, then produces a consolidated view of every active subscription, its annualized cost in INR, renewal date, and last-login data for the seats it can access via API. The discovery questions (Q1–10 and Q41–44) resolve automatically. Renewal hygiene (Q31–37) populates a live calendar. License utilization (Q21–30) pulls from Google Workspace and Microsoft 365 APIs.
You still need a human for the contract review, the procurement policy, and the vendor conversations. But the discovery and monitoring work — which is 60% of the audit effort — compresses from days to minutes.
The fastest starting point is the free SaaS spend audit. Connect your work Gmail in 30 seconds and get an immediate read on every recurring subscription your inbox has captured. It answers Q41–Q44 before you've opened a single spreadsheet.
What to Do With Your Audit Results: A 30-Day Action Plan
An audit that produces a spreadsheet and no action is just an expensive guilt trip. Here's how to convert findings into savings within a month.
Week 1 — Cut the obvious waste. Terminate or pause any tool with zero active logins in the last 90 days. Don't overthink it. If nobody's used it in 3 months, canceling it and restoring it later if needed costs less than the subscription itself. For annual contracts where you're mid-term, at least remove inactive seats to the minimum allowed tier and set a reminder not to renew at full count.
Week 2 — Right-size the tools you're keeping. For every tool where active usage is under 60% of provisioned seats, open a conversation with the vendor. Most Indian SaaS vendors — including those on our marketplace — will negotiate mid-term seat reductions or plan downgrades rather than lose the customer. You won't always win, but you often will.
Week 3 — Fix the GST invoicing. Consolidate every vendor where you're missing a GSTIN-compliant invoice. For international tools billing in USD, check whether they have an Indian reseller or billing entity — many do. For the ones that don't, document the import of services treatment for IGST purposes so your CA isn't surprised at quarter-end.
Week 4 — Lock the renewal calendar. Set 60-day and 30-day alerts for every tool above ₹5,000/month. Assign a named owner to each renewal decision. Make sure cancellation windows are marked explicitly in the calendar entry, not just the renewal date. This single step prevents the majority of accidental auto-renewals that show up in the next audit.
The best time to renegotiate a SaaS contract is 90 days before renewal. The second best time is right after you finish this audit.
Key takeaway: A SaaS audit without a 30-day action plan is just documentation. The money is in the execution — cut, right-size, consolidate, and lock the calendar before the next renewal cycle hits.
Frequently asked questions
How do I find all the SaaS tools my company is paying for in India?
The most reliable starting points are your corporate card statements, Google Workspace or Microsoft 365 admin console, and your email inbox filtered for invoice keywords like "receipt," "subscription renewed," and "billing." For tools bought on personal cards and expensed, you'll need to pull expense report exports and search for line items categorized as software or online services. OAuth app grants in your Google Workspace Security settings reveal tools that were connected directly without a formal purchase. Connecting your work Gmail to the Easexpense free SaaS spend audit surfaces most of these automatically within 30 seconds, without requiring API setups or integrations.
What is a SaaS audit checklist and why does an Indian IT team need one?
A SaaS audit checklist is a structured set of questions that maps every software subscription a company pays for, verifies who uses it, checks contract terms, and flags upcoming renewal dates. Indian IT teams need one specifically because GST compliance, ITC eligibility, and rupee-denominated budgeting add layers that generic global templates don't cover. An invoice without your company's GSTIN, or with the wrong SAC code, can disqualify an ITC claim entirely. The checklist in this article is structured around those India-specific requirements across all 5 audit domains.
How often should a company run a SaaS audit?
Quarterly is the practical answer for a growing company. The most important triggers beyond the calendar are any team headcount change above 10%, a fundraise that expands the budget, or a quarter-end budget review where finance is scrutinizing the P&L. Manual audits are genuinely time-consuming, so quarterly discipline is hard to maintain. Automated monitoring tools reduce the formal quarterly audit to a 30-minute review of new findings rather than a multi-day data-gathering exercise, which is the realistic path to making it a habit.
What is shadow IT and how do I detect it in a 100-person Indian startup?
Shadow IT is any software a team member or department has purchased and is using without IT or finance approval. Common signals include OAuth app grants in your Google Workspace admin console under Security > API Controls, recurring charges on personal expense reports categorized as "tools" or "subscriptions," and Gmail invoice threads from vendors not on your approved vendor list. Querying your SSO provider for unknown app integrations is one of the fastest detection methods. In practice, most 100-person Indian startups find 8–15 unapproved tools when they first run a structured shadow IT check — the number is rarely zero.
Can I claim GST input tax credit on SaaS subscriptions bought from Indian vendors?
Yes, provided the vendor issues a GST-compliant tax invoice with their GSTIN, the correct HSN or SAC code for IT services (typically SAC 9983 for information technology services), and your company's GSTIN clearly printed on the invoice. Many SaaS vendors, particularly those billing through international payment links or who are early-stage and haven't formalized their invoicing, don't issue India-compliant invoices by default. For international vendors billing in USD, the applicable treatment is typically IGST on import of services, which your CA should document correctly. Consolidated GST invoicing through a procurement layer like Easexpense resolves the compliance gap for vendors where direct compliant invoicing isn't available.
What SaaS audit tools are available for Indian companies?
Options range from fully manual spreadsheet audits using bank exports and admin console reports, to inbox-connected tools that read invoice emails automatically. Easexpense's free SaaS spend audit connects to Gmail and surfaces every recurring subscription without requiring integrations or API credentials from IT. For ongoing monitoring rather than a one-time audit, the Easexpense AI CIO automates renewal tracking, license utilization reporting, and spend analytics continuously so the audit becomes a live dashboard rather than a periodic exercise. Our AI CIO page walks through what that monitoring layer looks like in practice.
How much money can a SaaS audit save a 100-person Indian company?
Based on patterns across Easexpense customers, companies typically find 15–25% of their SaaS spend is either unused, duplicated, or on an oversized plan tier. For a company spending ₹20 lakh per year on SaaS, that translates to ₹3–5 lakh in recoverable spend annually. The biggest single line items are usually seats on collaboration tools like Slack or Zoom and unused CRM licenses where sales headcount turned over and seats were never reclaimed. Add the ITC that wasn't being claimed due to non-compliant invoicing, and the total recoverable amount is typically higher than the utilization savings alone.
