If you're the CFO, COO, or finance lead at a 100-person Indian company, here's a scenario you've probably lived through: someone in marketing signs up for a project management tool on their corporate card, someone in engineering signs up for a different one, and six months later both teams are paying for the same category of software that nobody talks to each other about. Then the annual renewal hits at 2 a.m. on a Sunday and ₹1.8 lakh leaves the account before anyone notices.
The problem isn't that your team is irresponsible. It's that SaaS is designed to be bought without friction. No purchase order, no vendor meeting, no three-quote process. Just a credit card and a checkbox. That frictionless experience is great for the vendor. For your finance function, it's a slow leak that compounds every quarter.
CFO SaaS procurement playbooky you can actually implement: the request workflow, approval matrix, budget thresholds, and governance cadence. Not a 40-page corporate document nobody reads. A working framework you can adapt this week.
Why Most Indian Companies Have No SaaS Procurement Policy
SaaS buying in most Indian mid-market companies happens at the team level, in isolation. Marketing grabs a social scheduling tool. Engineering spins up a monitoring service. Sales onboards a sequencing platform. Each decision makes sense in the moment. The problem is that nobody has a complete picture.
A 100-person company typically runs 40 to 60 active SaaS subscriptions. Fewer than 20 of those are usually on finance's radar. The rest live on departmental credit cards, personal cards that get expensed, or old payment methods that nobody thinks to audit.
SaaS license reclamation license rightsizing audit in the same category (two project management tools, three video conferencing subscriptions). Auto-renewals firing on annual plans nobody reviewed. Lost GST input credit because the invoice came from a foreign vendor without a local GSTIN. And if you're ever subject to an income tax or GST audit, unexplained SaaS purchases with no business justification documentation create a compliance headache.
Most companies only realise they need a policy after one of two trigger events: a surprise annual renewal that blows a quarterly budget, or a departing employee whose personal email was the login for three paid tools that the company now can't access or cancel.
Key takeaway: Without a policy, SaaS buying defaults to whoever has a card and a problem to solve — and finance only sees the damage after the fact.
What a SaaS Procurement Policy Actually Covers
Let's be clear about scope first. A SaaS procurement policy covers cloud software, SaaS subscriptions, AI tools with per-seat or usage-based pricing, and API-metered services. It's not limited to "software licences" in the traditional sense. If your team is paying a monthly bill to any service that runs in a browser or via an API, it falls under this policy.
A workable policy has 4 pillars: request, evaluation, approval, and ongoing review. Each pillar has a named owner and a defined SLA. That's it. You don't need a procurement committee or a separate IT governance board unless you're at 500+ employees.
What the policy is not: a bureaucratic gate that slows a ₹500/month note-taking app to a four-week review cycle. If your policy is more painful than just buying the tool, teams will bypass it. The entire design principle is speed for low-risk, low-cost tools and scrutiny for high-cost or high-risk commitments.
There's also a distinction worth making between a procurement policy and a vendor contract policy. Procurement governs how you decide to buy. Vendor contracts govern the terms under which you buy. Both matter, but this article focuses on procurement. Vendor contract management is a follow-on layer once you know what you're buying.
Run a free SaaS spend audit — find every hidden subscription
Step 1 — The SaaS Request Workflow
Every SaaS purchase starts with a request. The request form is the front door of your policy, and if it's ugly and complicated, people will climb through a window instead.
Keep the intake form to 8 fields or fewer. A form that takes more than 4 minutes to complete is a form that creates shadow IT. The core fields:
- Tool name and vendor URL
- Business justification (one paragraph, not an essay)
- Estimated annual cost in INR (including GST or the equivalent FX amount)
- Data classification — does this tool touch customer data, employee data, or neither?
- Alternatives considered — what did you compare this against?
- Requested start date
- Named business owner (who is accountable for this tool post-purchase?)
The role split matters: the business owner raises the request, IT or ops validates the security and integration fit, and finance approves the spend. These don't have to be three different people at a 50-person company, but the three questions need to be answered regardless of who answers them.
Set SLA targets by spend band. Tools under ₹10,000/year should clear review in 48 hours. Tools above that threshold get a 5-working-day review. If the request is urgent, there's a fast-track path (covered in the next section) with a post-purchase review rather than a pre-purchase gate.
Action: Build your intake form in Google Forms or Zoho Forms today. Share the link in Slack and pin it to your finance channel. The barrier to adoption is almost entirely about making it easy to find.
Step 2 — Building Your Approval Matrix
The approval matrix is where most policies either work or fall apart. Too few tiers and everything needs CFO sign-off. Too many tiers and nobody knows whose desk a request is sitting on.
A practical starting point for an Indian SMB with 50 to 200 employees:
- Up to ₹5,000/year: Self-approve (requestor confirms it's not a duplicate tool)
- ₹5,001 to ₹25,000/year: Team lead approval
- ₹25,001 to ₹1,00,000/year: Department head approval
- Above ₹1,00,000/year: CFO or COO sign-off
Alongside the spend tiers, layer in a mandatory IT security review for any tool that stores customer PII or has a US or EU data residency clause. Under India's Digital Personal Data Protection Act (DPDP Act), this is no longer optional due diligence. It's a legal consideration.
A procurement policy without a mandatory security review for PII-handling tools isn't a policy — it's a paper trail that won't hold up when something goes wrong.
For urgent requests, build in a 24-hour fast-track path. The tool can be purchased, but a post-purchase review happens within 5 working days. This prevents the policy from being seen as a blocker during crunch periods while maintaining accountability.
Key takeaway: Your approval matrix should make low-cost, low-risk tools fast to approve and save real scrutiny for decisions above ₹1 lakh — where the renewal risk and compliance exposure are actually significant.
Step 3 — Budget Thresholds and Annual Spend Limits
Approval matrices tell you who decides. Budget thresholds tell you how much each team is allowed to decide on.
A practical benchmark for Indian SMBs: set per-department SaaS budgets at 2% to 4% of the department's annual headcount cost. So if your marketing team costs ₹80 lakh/year in salaries and benefits, their SaaS budget is ₹1.6 to 3.2 lakh/year. This ratio scales reasonably across functions and gives finance a defensible number to work from during annual planning.
When a request comes in over budget, the department head has two options: offset it by cancelling another tool or escalate to the CFO with a written justification. Both options create accountability. Neither option is a hard no.
One thing many Indian companies miss: GST input credit changes the effective cost of any SaaS tool billed with a valid GSTIN. An ₹18,000/year subscription from a vendor with a local GSTIN effectively costs your company ₹15,254/year after reclaiming the 18% GST. A foreign vendor billing in USD with no Indian GST registration gives you no input credit. When you're choosing between comparable tools, that difference is real money.
Foreign vendor payments also trigger other compliance requirements. Payments above ₹5 lakh to foreign vendors may require Form 15CA and Form 15CB for TDS on foreign remittances, along with a CA certification in some cases. Your policy should flag any foreign SaaS commitment above this threshold for a finance review before the purchase is made, not after.
Watch out: If your company is paying for 15+ foreign SaaS tools and hasn't reviewed TDS on foreign remittances, there's likely a compliance gap. Check with your CA before the next renewal cycle.
Step 4 — Vendor Evaluation Checklist
Not every SaaS tool needs a 20-point evaluation. But any tool above ₹25,000/year or touching customer data deserves a structured look before you commit.
The minimum checklist for Indian companies:
- Security certifications: SOC 2 Type II or ISO 27001 as a baseline. If the vendor can't provide either, that's a red flag for enterprise use.
- Data residency: Where is the data stored? If it's EU or US only, does that create a conflict with your customer contracts or DPDP Act obligations?
- GST invoice compliance: Does the vendor issue a GST-compliant invoice with a valid GSTIN? Many foreign SaaS vendors don't. That means you lose 18% in input credit every billing cycle.
- Auto-renewal and cancellation terms: What's the notice window to cancel or downgrade? Some vendors require 60 to 90 days' written notice. Miss that window and you're locked in for another year.
- Price escalation clauses: Does the contract allow the vendor to raise prices at renewal without renegotiation? Industry standard is a cap at 5% to 7%; anything above that needs a conversation.
- Integration fit: Does this tool connect to what you already use? A tool that duplicates data from your CRM without a sync creates manual work and data quality issues.
- Customer references: Two Indian customer references at a similar company size. Not logos on a website — actual calls.
For vendor comparison across categories, our SaaS comparison pages give you India pricing and honest head-to-head guidance across the tools we see most often in Indian mid-market stacks.
Step 5 — Ongoing Governance: Renewals, Reviews, and Reclamation
Buying the tool is the easy part. Governing it over time is where most policies break down.
Start with the renewal calendar. Flag every subscription 60 days before its renewal date. 30 days sounds like enough time, but it isn't — especially if you need to get a competitor quote, negotiate a downgrade, or route a cancellation request through the approval chain. 60 days is the minimum for real optionality.
Run a quarterly licence utilisation review. Pull the active user count from each tool and compare it to the number of licences purchased. Any tool with under 60% active users in the past 90 days is a candidate for downsizing or cancellation at the next renewal. Most companies that do this exercise for the first time find 3 to 5 tools that fit this profile immediately.
Shadow IT is the harder problem. Teams that bypassed the process didn't do it out of malice — they did it because the process felt slow or unclear. An amnesty period, where teams can self-declare tools they purchased outside the policy without penalty, surfaces the hidden stack and brings it into governance. Run this once at policy launch and annually thereafter.
Every approved tool must have a named business owner who answers for the renewal decision. Not the team, not the department — one person. When that person leaves the company, the tool goes back through the intake process. This prevents the most common source of zombie subscriptions: tools that belonged to someone who left 18 months ago.
Book a 15-minute call with our team to see how Easexpense surfaces renewal dates, licence utilisation, and shadow IT automatically — before the money leaves your account.
Key takeaway: Governance is a calendar discipline, not a one-time event. The companies that control SaaS spend long-term are the ones that review utilisation quarterly and flag renewals at 60 days, not 5.
The Downloadable SaaS Procurement Policy Template
Here's what a complete policy package looks like. You don't need a consultant or a formal procurement team to build these. Each component can be a Google Doc, a shared spreadsheet, or a form — the format matters less than having it at all.
One-page policy summary. Purpose, scope, roles, and spend thresholds in plain language. This goes in the employee handbook and is the document you share at the all-hands when you launch the policy. If it's longer than one page, trim it.
Intake request form. 8 fields maximum, as described in Step 1. Hosted in Google Forms or Zoho Forms with email notification to the relevant approver on submission.
Approval matrix table. Rows by spend band, columns by approver role, with a column for data classification requirements. Scale the spend bands based on company size: what makes sense at 50 people (₹5,000 self-approve) needs adjustment at 200 people.
Vendor evaluation scorecard. A weighted criteria sheet: security (30%), commercial terms (25%), GST compliance (20%), integration fit (15%), references (10%). Assign a score of 1 to 5 on each criterion and multiply by the weight. Any tool scoring below 3.5 overall goes back for more due diligence before approval.
Renewal review checklist. 10 questions to answer before approving any renewal: Is utilisation above 60%? Have we compared pricing with a competitor in the past 12 months? Is there a cheaper tier that covers actual usage? Has the data residency situation changed? Has the business owner confirmed they still need this tool? And so on. The checklist takes 15 minutes to complete and consistently surfaces savings.
Before you roll out the policy, though, you need a baseline. You can't set sensible thresholds or identify duplicates if you don't know what you're currently paying for. That's where an audit comes first — not the policy.
Run a free SaaS spend audit — find every hidden subscription
Common Mistakes When Rolling Out a SaaS Procurement Policy
The policy failing in practice is almost always more costly than not having one, because it creates the illusion of governance without the substance. Here are the failure modes we see most often.
Making it too strict. A policy that routes a ₹2,000/month productivity tool through a 6-week approval cycle will be ignored within 3 months. Teams will buy on personal cards and expense it, or find a free tier that's slightly worse but entirely off the books. Speed for low-risk tools is not a compromise — it's the design.
No named owner, no enforcement. Policies without an internal owner die in the wiki. Somebody — usually in finance ops or IT — needs to own the intake queue, chase approvals, and run the quarterly reviews. Without that person, the process decays quietly.
Ignoring the existing stack. Most policies are designed to govern new purchases while the legacy subscriptions continue leaking money on autopilot. The first version of your policy should include a one-time audit of everything already in the stack. Our AI CIO product was built specifically to surface this layer — the tools that predate any governance process.
Forgetting mobile app subscriptions. In Indian startups especially, a meaningful number of SaaS purchases happen through iOS or Android apps, charged to a personal Apple ID or Google account and expensed later. These are almost never captured in a standard procurement review. Add a line to your expense policy that requires SaaS app purchases above ₹500/month to go through the intake process, even if they were charged to a personal device.
Not training the team. A PDF buried in the company drive is not a policy launch. A 30-minute all-hands where you walk through the intake form, explain the spend thresholds, and answer questions — that's a policy launch. Do it once properly and adoption is dramatically higher. Skip it and the first person who finds the process inconvenient will create the workaround that everyone else follows.
Action: Schedule a 30-minute all-hands within 2 weeks of finalising your policy. Walk through one example purchase request end-to-end so the team knows exactly what to expect. Record it for new joiners.
Frequently asked questions
What is a SaaS procurement policy and does my Indian company need one?
A SaaS procurement policy is a written set of rules that governs how your company researches, approves, pays for, and reviews software subscriptions. If your company has more than 20 employees and pays for more than 10 SaaS tools, you almost certainly need one. Without it, you're likely paying for duplicate tools, missing GST input credits, and renewing subscriptions nobody actively uses. The policy doesn't need to be complex — a one-page summary, a simple intake form, and a clear approval matrix are enough to get meaningful control. The alternative is continuing to discover costs retroactively, which is consistently more expensive.
What spend thresholds should I use in my SaaS approval matrix?
A common starting point for Indian SMBs: self-approve up to ₹5,000/year, team lead approval up to ₹25,000/year, department head up to ₹1,00,000/year, and CFO or COO sign-off above that. Adjust the bands based on your company's revenue and risk tolerance — a ₹50 crore revenue company can probably push the self-approve threshold higher than a ₹5 crore company. The goal is to keep low-risk, low-cost tools moving quickly while adding genuine scrutiny to bigger commitments. Review the thresholds annually, because what feels right at 50 people needs recalibration at 150.
How do I handle foreign SaaS vendors that don't issue GST-compliant invoices?
Under Indian GST rules, purchases from overseas SaaS vendors are treated as an import of services and attract GST under the reverse charge mechanism. Your finance team needs to self-invoice and deposit the GST directly with the government — you can then claim this as input credit if the purchase is for business use. Payments above ₹5 lakh may also trigger Form 15CA and Form 15CB requirements for TDS on foreign remittances, and a CA sign-off may be needed. Where a comparable Indian SaaS option exists with a local GSTIN, prioritise it — the 18% input credit alone changes the effective cost materially over a full year.
How often should we review our SaaS subscriptions under the policy?
A quarterly utilisation review works well for most companies: check active users against licences purchased and flag anything below 60% usage for the next renewal decision. Annual renewals should be flagged at least 60 days in advance so there's real time to negotiate, downgrade, or cancel without being locked in by a short notice window. Do a full policy and stack review once a year — retire tools that no longer serve a purpose, consolidate vendors where possible, and update your approval thresholds if company size or risk profile has changed. The quarterly cadence keeps costs under control; the annual review keeps the policy itself honest.
What is shadow IT and how does a procurement policy help control it?
Shadow IT refers to SaaS tools that employees sign up for and pay for — often on personal cards and expensed later — without going through any approval process. It's extremely common in Indian startups and mid-market companies where teams move fast and the procurement process, if one exists at all, feels slow. A procurement policy helps by creating a fast, low-friction intake path so teams aren't tempted to go around it. Running a periodic spend audit, either manually through expense reports or automatically via inbox-scanning tools, surfaces shadow IT already in the system. A one-time amnesty period at policy launch — where teams can self-declare unapproved tools without penalty — is the most effective way to bring the hidden stack into governance quickly.
Can a small Indian startup with 30 to 50 employees benefit from a SaaS procurement policy?
Yes, and this is often the best time to establish one. At 30 to 50 people, your SaaS stack is complex enough to cause real cost leakage but small enough that rolling out a lightweight policy takes a week rather than 3 months. Starting with a simple 2-tier approval matrix and a shared renewal calendar gives you governance without bureaucracy. The habits and ownership structures you establish at this stage are much easier to maintain than retrofitting governance onto a 150-person company with years of untracked subscriptions already in the system. Think of it as building the plumbing while the walls are still open.
What should be included in a SaaS vendor evaluation checklist for Indian companies?
At minimum: data residency and security certifications (SOC 2 or ISO 27001), whether the vendor issues a GST-compliant invoice with a valid Indian GSTIN, auto-renewal and cancellation terms, and price escalation clauses. For tools that process customer data, check alignment with India's Digital Personal Data Protection (DPDP) Act — this is increasingly relevant as enforcement frameworks develop. Integration with your existing approved stack matters too, because every siloed tool creates manual data work somewhere. Two Indian customer references at a similar company size are a practical final step — not logos on a case study page, but actual 15-minute calls with someone whose context matches yours.
