Find software at discounts Savings, Analyze spending.

See your SaaS savings live

15-minute call. We'll walk through your actual stack and show you the leak.

← All articles
Procurement21 May 2026·16 min read

Shadow IT SaaS Audit: Why 80% of Mid-Market Firms Don't Know What They Pay

Most 50–500 person Indian companies are paying for SaaS they've forgotten about, can't see, or never approved. One of our customers found ₹14L/year in ghost subscriptions. Here's how that happens — and how to stop it.

Lakhendra Kushwah

Lakhendra Kushwah

Co-founder & CEO, Easexpense

A CFO reviewing a spreadsheet of SaaS subscriptions at a desk, several unknown tool logos visible on a laptop screen, warm office lighting, Indian business setting

SaaS spend management India-person Indian company, there's a reasonable chance your SaaS spend is 20-30% higher than your finance team thinks it is. Not because someone's being dishonest. Because SaaS was designed to be bought without asking permission, and most Indian mid-market companies have never built a system to catch that.

Gmail-based subscription discoveryngaluru, came to us believing they spent roughly ₹55 lakh annually on SaaS. After we ran a full audit through their card statements and connected their Gmail-based subscription discovery, the real number was closer to ₹69 lakh. The ₹14 lakh gap wasn't fraud. It was structural invisibility.

SaaS vendor review processSaaS renewal negotiation timing renewal calendareadsheet can't catch it, and what a real audit process looks like. If you run finance or operations at a growing Indian company, this is a problem worth understanding before your next renewal cycle hits.

CFO SaaS procurement playbook

SaaS sprawl across Indian businessesaim unused SaaS licensess">SaaS license rightsizing audit is wasting money-customer base, the average mid-market company has 23% more active SaaS subscriptions than their finance team knows about. That's not a rounding error. At a 200-person company spending ₹50-60 lakh on software, that's ₹10-14 lakh sitting in a blind spot.

decentralized SaaS purchasing costssion at the heart of modern SaaS: the product is built to be adopted by individuals and teams, but the budget that pays for it lives somewhere else entirely. A developer can spin up a new cloud sandbox in 4 minutes. The finance team finds out 3 months later when they're reconciling a Stripe charge that doesn't match any PO.

The average Indian SMB renews 60% of its SaaS stack on autopilot, with no utilisation review and no one accountable for the decision.

SaaS price increases Indiant auto-renewal price increasesrs have optimised aggressively for frictionless adoption and silent auto-renewal. Indian mid-market companies, most of which don't have a full-time IT procurement function, are the ideal target for that model.

What Shadow IT Actually Looks Like in an Indian SMB

Indian SaaS buying behavior employees bypassing a formal IT department with established procurement controls. That framing doesn't fit most Indian companies in the 50-500 employee range. There often isn't a formal IT procurement function to bypass.

SaaS finance integrations India. consolidated SaaS billinge it's ₹4,000 a year and the approval process would take longer than the task she needs it for. A developer spins up an AWS sandbox environment for a proof of concept and forgets to terminate it after the project wraps. The head of sales buys a LinkedIn Sales Navigator seat for a new hire using the departmental Axis Bank credit card, and the subscription outlives the employee by 8 months.

TDS and forex on SaaS issued to personal email addresses cannot be claimed as Input Tax Credit under GST. Every shadow purchase your team makes on a personal card is a double cost: the subscription fee plus 18% GST you'll never recover.

GST on SaaS India They feel like getting work done. The GST compliance gap is the part that stings most on review: invoices going to personal emails mean your company's GSTIN never appears on the purchase, and that 18% Input Tax Credit is gone permanently. On ₹5 lakh of shadow SaaS spend, that's ₹90,000 in unclaimed ITC every year, on top of the wasted subscriptions themselves.

Run a free SaaS spend audit — find every hidden subscription

Three Ways Ghost Subscriptions Survive Undetected for Months

There are three distinct mechanisms that keep ghost subscriptions alive long after anyone would consciously choose to renew them.

Auto-renewals on rotating departmental cards. When a ₹8,000/month project management tool is charged to whichever card had available credit that quarter, no single person is watching that line item consistently. The charge looks plausible every month and nobody flags it.

Employee offboarding without licence revocation. This is the most common source of waste we find. A sales manager leaves the company. Her Salesforce seat, her Zoom Webinar licence, and her Grammarly Business account all keep renewing. HR closes the email account. Finance doesn't touch the subscriptions. At typical SaaS price points, a single unrevoked departing employee can represent ₹15,000-40,000 in annual waste, depending on their tool stack.

Free trials that converted silently. A product manager starts a 14-day trial of a design tool for one sprint. The trial converts to a paid plan at ₹3,200/month. She's moved on to the next project and forgotten entirely. The card keeps getting hit for the next 11 months before anyone notices, which works out to roughly ₹35,000 in spend on a tool with zero active users.

Key takeaway: Ghost subscriptions don't persist because people are careless. They persist because SaaS billing is optimised for continuity, and most Indian SMBs have no counter-system watching for it.

Why Finance Teams Can't Catch This With a Spreadsheet

The instinct is to say: just audit the card statements. The problem is that card statements are genuinely unhelpful for this purpose.

Merchant names on statements don't map to tool names. "Paddle" appears as the billing entity for dozens of different SaaS products. "Stripe" is used by hundreds more. When your finance analyst sees a ₹6,800 charge from "Paddle" on the marketing team's card in October, there's no obvious way to know which tool that is without tracing it manually, which requires knowing who made the original purchase.

INR conversion lag compounds the problem on international subscriptions. A tool priced at $49/month appears as different INR amounts each month depending on the exchange rate, making month-on-month comparison unreliable. A 12% increase in billed amount might be a price hike or it might just be currency movement. Finance can't tell without going deeper.

4–6 credit/debit cards across which SaaS spend is scattered in a typical 200-person Indian company Source: Easexpense customer dataset, 2024

In a typical 200-person company, SaaS charges are scattered across 4-6 different cards: the corporate card, 2-3 departmental cards, and at least 1-2 personal cards that get reimbursed. No one person has visibility across all of them simultaneously. Manual reconciliation requires someone to own the process full-time, and that person doesn't exist in most SMBs. The task falls to a finance executive who has seventeen other priorities and does a partial reconciliation once a quarter, if that.

What a Real SaaS Audit Found at a 200-Person Company

Back to the Bengaluru company. When we broke down the ₹14 lakh gap, it split into three roughly equal categories.

Zombie tools: approximately ₹5.2 lakh. These were subscriptions for products nobody had logged into in over 6 months. A video editing suite bought for a product launch campaign that ended. Two separate webinar platforms that had both been replaced by Zoom. An HR chatbot pilot that never moved beyond the pilot stage but kept auto-renewing at ₹12,000/month.

Duplicate overlapping tools: approximately ₹4.8 lakh. Three different teams were paying for separate instances of tools with near-identical functionality. The engineering team had a Notion teams plan. The product team had Confluence. The operations team was using Coda. All three do largely the same job for this company's use case. None of the three teams knew the others existed.

Unused seat licences on active tools: approximately ₹4 lakh. These were legitimate tools the company genuinely needed, but they'd been overprovisioned. A 40-seat Slack Pro plan for a team of 28 active users. A design tool with 12 licences where only 6 people logged in during the previous quarter. Seats that had been assigned to employees who'd since left and never been reclaimed.

The customer's reaction wasn't embarrassment. It was relief. Having a clear picture of what was running, what it cost, and what could be cut gave the CFO something she hadn't had before: actual data to make vendor consolidation decisions with. The conversation shifted from "we should probably look at our SaaS spend" to "here are the 11 specific things we're cancelling this month."

See your SaaS savings in 15 minutes — book a quick call

The Compounding Cost: It's Not Just the Subscription Fee

The subscription fees are the visible part. There are at least three additional cost layers that make shadow IT significantly more expensive than the raw spend number suggests.

Lost GST Input Tax Credit. At 18% GST on domestic SaaS and on many international subscriptions billed through Indian entities, companies that don't capture invoices to their GSTIN are leaving real money behind. For a company with ₹8 lakh in shadow SaaS spend, that's ₹1.44 lakh in ITC that's gone. Not deferred. Gone.

Vendor price escalation is the less obvious one. SaaS tools bought through individual accounts miss volume pricing that's available through consolidated procurement. We've negotiated 15-35% discounts with anchor vendors including Microsoft, Google, AWS, Slack, and Zoho, pricing that's only available because we're purchasing in volume across our customer base. A team lead buying a single-seat Zoho plan on a personal card pays list price. The same seat bought through our marketplace costs materially less.

Action: Map every SaaS invoice from the last 90 days against your company GSTIN. Any invoice issued to a personal email or individual name represents unclaimed ITC. Recapturing this going forward requires a single change: route purchases through an entity with your GST number on the account.

Security and compliance exposure deserves a separate mention. For companies approaching ISO 27001 or SOC 2 certification, tools that IT doesn't know about are an immediate finding. An auditor asking for a complete software inventory will surface every shadow tool, and each one is a gap that needs to be explained or remediated. Dealing with this before an audit is far cheaper than dealing with it during one.

Our AI CIO surfaces this continuously rather than as a one-time event, flagging new recurring charges as they appear and alerting operations when a tool hasn't been logged into in 30 days.

Key takeaway: The true cost of shadow IT is the subscription fee, plus lost GST ITC, plus list-rate pricing, plus compliance exposure — a combination that typically runs 30-50% above the face-value spend number.

How to Run a Shadow IT SaaS Audit Without Disrupting Your Team

This can be done without a consultant and without a long project. Four steps.

Step 1: Pull card statements from all company and departmental cards for the last 90 days. Tag every recurring charge. If the merchant name isn't recognisable, spend 2 minutes finding the underlying tool. Build a single flat list: tool name, monthly cost, which card, who requested it.

Step 2: Cross-reference against your HR system. For each tool on the list, is there still an active employee who originally requested it? If the requester has left, flag the subscription immediately. If nobody can identify who requested it, that's a zombie candidate.

Step 3: Check renewal dates on your top 20 tools by spend and map them to a 12-month calendar. Renewals that appear in the next 60 days need a decision now, not the week before they hit. This step alone has saved our customers significant money, because you go from reactive to having time to negotiate or cancel.

Step 4: Consolidate invoicing to a single procurement account with your company's GSTIN on record, so that ITC is capturable going forward. This is the structural fix that prevents the same problem from rebuilding itself next year.

Easexpense automates steps 1, 3, and 4 directly. The Gmail-based discovery surfaces recurring subscriptions without requiring manual card pulling, the alerts engine flags renewals 30-60 days out, and consolidated billing ensures every invoice comes to a single GST-registered account. Step 2, the HR cross-reference, still benefits from a human in the loop, at least initially.

What Changes After You Have Full SaaS Visibility

Finance gets a single consolidated invoice with proper GST, one clean document instead of 40 separate card charges from merchants your accountant has never heard of. The reconciliation time that was eating 6-8 hours a month drops to near zero.

Renewals surface 30-60 days early. This sounds simple, but the operational difference is significant. Instead of a tool auto-renewing on a Tuesday because nobody noticed the date, your team gets a structured decision point: renew, renegotiate, or cancel. Vendors who know you're reviewing the renewal behave differently in price conversations than vendors who know you're about to auto-renew by default.

IT and operations get a live catalog of approved versus unapproved tools. This isn't about locking teams out of things they need. It's about knowing what's running so you can make deliberate decisions about it. The catalog also becomes useful for onboarding: instead of a new hire figuring out which tools the company uses by asking around, there's an approved list they can access immediately.

Founders and CFOs can finally make vendor consolidation decisions with actual data. "Should we standardise on Microsoft 365 or Google Workspace?" is a different conversation when you know exactly how many seats of each you're paying for, what they cost individually versus what a consolidated plan would cost, and which teams are using what. Without that visibility, the consolidation conversation is mostly guesswork.

For purchasing after the audit, our marketplace is where that consolidation happens — pre-negotiated pricing across 40-plus vendors, GST-clean invoicing, and renewal tracking built in from the start.

The Honest Caveat: An Audit Is a Starting Point, Not the Finish Line

Shadow IT grows back. If you run a one-time audit and don't change the procurement pathway, you'll be in the same position 18 months from now. The audit surfaces the problem. The process change is what fixes it.

The goal isn't to make SaaS procurement harder. It's to make the approved route faster and easier than the personal card route. If a team lead can get a tool approved, purchased with a proper GST invoice, and provisioned in 24 hours, they'll use that route. If the approved route takes 2 weeks and requires a committee sign-off on a ₹3,000/month tool, they'll use the personal card and you'll be back here next year.

Action: After your audit, establish one simple rule for new SaaS purchases: any recurring spend above ₹2,000/month routes through the central procurement account. Below that threshold, personal card reimbursement is fine — but the invoice must go to the company GSTIN. This single change captures most of the ITC you're currently losing.

What makes visibility sustainable is not policy, it's infrastructure. Renewal alerts that fire automatically 45 days out. Consolidated billing that doesn't require anyone to manually chase invoices. A marketplace that's stocked with tools teams actually want to buy, at prices that are at least as good as what they'd find on their own. When the system works in the team's favour, compliance is a byproduct, not a battle.

That's what we built Easexpense to do. We're not a policy enforcement tool. We're a procurement layer that processes the SaaS payments, owns the vendor relationships, and surfaces the renewals before they become surprises. Eighty-plus Indian companies trusted us with that responsibility, and 95% of them are still with us. That number matters more to us than any feature list.

Frequently asked questions

What is a shadow IT SaaS audit and how do I run one for my company?

A shadow IT SaaS audit maps every software subscription your company is paying for, including tools bought on personal or departmental cards without central IT approval. You start by pulling 90 days of card statements from all company and departmental cards, tagging every recurring charge, and building a flat list of tool names, costs, and card owners. Cross-reference that list against your active employee roster to identify subscriptions tied to people who've left, then check renewal dates on your top tools by spend. The goal is to surface zombie tools with no active users, duplicate tools doing the same job across teams, and over-provisioned seat licences on otherwise legitimate subscriptions. A connected tool like Easexpense can surface the initial picture in under 48 hours; the slower part is the decision-making about what to cancel, consolidate, or renegotiate.

How much money do mid-market Indian companies typically waste on forgotten SaaS subscriptions?

In our experience working with 80-plus Indian SMBs, waste typically runs between 18% and 30% of total SaaS spend. For a 200-person company spending ₹50-60 lakh annually on software, that translates to ₹10-18 lakh in recoverable savings. The split we see most often is roughly one-third zombie tools that nobody uses, one-third duplicate tools doing overlapping jobs across teams, and one-third unused seats on legitimate subscriptions that were over-provisioned or never reclaimed after employees left. These figures don't include the compounding costs of lost GST Input Tax Credit and list-rate pricing on individually purchased tools, which can add another 15-20% on top of the raw subscription waste.

What's the difference between shadow IT in an Indian SMB versus a large enterprise?

In large enterprises, shadow IT typically means employees circumventing an existing IT department that has formal procurement controls, vendor lists, and approval workflows. In Indian mid-market companies of 50-500 employees, there often isn't a formal IT procurement function to bypass in the first place. Shadow spend accumulates not because people are deliberately circumventing policy, but because no policy exists and team leads use whatever card is available to get work done. The structural cause is different, which means the fix is also different: the answer isn't stricter enforcement of rules that don't exist, it's building a procurement layer that's faster and more convenient than the personal card route.

How does unapproved SaaS spending affect our GST Input Tax Credit claims?

When SaaS invoices are issued to a personal email address or an individual's name rather than your company's GSTIN, you cannot claim Input Tax Credit on that purchase under GST rules. At 18% GST on most domestic SaaS subscriptions and on international subscriptions billed through Indian entities, this is a meaningful recurring cost. A ₹5 lakh annual spend on shadow tools means ₹90,000 in unclaimed ITC every year, permanently lost rather than deferred. The fix is straightforward: ensure that every SaaS purchase, regardless of which card is used for payment, generates an invoice addressed to your company's GSTIN. Routing purchases through a central procurement account with your GST registration on file is the cleanest way to ensure this consistently.

How long does it take to complete a SaaS audit for a 200-person company?

A manual audit conducted by pulling card statements and cross-referencing HR data typically takes two to four weeks when someone owns the process part-time alongside other responsibilities. With a connected tool that links to Gmail-based subscription discovery and your payment layer, the initial inventory can surface in under 48 hours. The timeline that people tend to underestimate is the decision-making phase: what to cancel, what to consolidate, which teams to consult before cancelling tools they may still be using quietly. Budget two to three weeks after the audit data surfaces to work through the cancellation and consolidation decisions properly, especially if multiple department heads are involved.

What tools should I cancel after a shadow IT audit, and how do I avoid disrupting teams?

Start with the clear-cut cases: subscriptions tied to employees who've left the company, free trials that auto-converted more than six months ago with no recorded activity, and duplicate tools where two or more teams are paying separately for products with near-identical functionality. For tools that a team might still be actively using, check login data for the last 60 days before making any cancellation decision, and give 30 days' notice with an approved alternative offered before cutting access. The disruption risk is usually overstated in practice: most teams don't miss tools they've genuinely forgotten about, and the ones that do push back quickly, which is itself useful information about what's actually being used.

Is there a way to prevent shadow IT SaaS spending from accumulating again after an audit?

Yes, but the solution is changing the purchasing path rather than adding more policy. If the approved procurement channel is faster and easier than a personal card, most team leads will use it without being asked twice. A consolidated marketplace with pre-negotiated pricing, instant GST invoicing, and visible renewal dates removes the main reasons people go around the system in the first place. Automated alerts for new recurring charges on company cards provide an early warning layer, so shadow spend that does appear gets caught in weeks rather than quarters. The combination of a convenient approved channel and continuous monitoring is what makes the improvement stick beyond the initial audit.

Frequently asked questions

What is a shadow IT SaaS audit and how do I run one for my company?
A shadow IT SaaS audit maps every software subscription your company is paying for, including tools bought on personal or departmental cards without central IT approval. You start by pulling 90 days of card statements, tagging recurring charges, and cross-referencing them against active employees and approved vendor lists. The goal is to surface zombie tools, duplicate functions, and licenses tied to people who've left.
How much money do mid-market Indian companies typically waste on forgotten SaaS subscriptions?
In our experience working with 80-plus Indian SMBs, the waste typically runs between 18% and 30% of total SaaS spend. For a 200-person company spending ₹50–60L annually on software, that can translate to ₹10–18L in recoverable savings. The split is usually between zombie tools no one uses, duplicate tools doing the same job across teams, and unused seats on otherwise legitimate subscriptions.
What's the difference between shadow IT in an Indian SMB versus a large enterprise?
In large enterprises, shadow IT usually means employees bypassing an existing IT department with formal procurement controls. In Indian mid-market companies of 50–500 employees, there often isn't a formal IT procurement function at all. Shadow spend accumulates not because people are circumventing policy, but because no policy exists and team leads simply use whatever card is handy. The structural problem is different, which means the fix is also different.
How does unapproved SaaS spending affect our GST Input Tax Credit claims?
When SaaS invoices are issued to a personal email or an individual name rather than your company's GST number, you cannot claim Input Tax Credit on that purchase. At 18% GST on international and domestic SaaS subscriptions, this is a meaningful cost. A ₹5L annual spend on shadow tools could mean ₹90,000 in unclaimed ITC every year, on top of the subscription cost itself.
How long does it take to complete a SaaS audit for a 200-person company?
A manual audit done by pulling card statements and cross-referencing HR data typically takes two to four weeks when someone owns the process part-time. With a connected tool that links to your Gmail-based SaaS discovery and payment layer, the initial picture can surface in under 48 hours. The slower part is the decision-making: what to cancel, what to consolidate, and how to restructure purchasing going forward.
What tools should I cancel after a shadow IT audit, and how do I avoid disrupting teams?
Start with clear-cut cases: subscriptions tied to employees who've left, free trials that auto-converted more than six months ago with no activity, and duplicate tools where two teams pay for products with overlapping functionality. Before cancelling anything a team actively uses, give 30 days' notice and offer an approved alternative. The disruption risk is usually overstated; most teams don't miss tools they've forgotten they had.
Is there a way to prevent shadow IT SaaS spending from accumulating again after an audit?
Yes, but it requires changing the purchasing path, not just the policy. If the approved procurement channel is faster and easier than a personal card, most team leads will use it. A consolidated marketplace with pre-negotiated pricing, instant GST invoicing, and visible renewal dates removes the main reasons people go around the system. Ongoing automated alerts for new recurring charges on company cards provide an early warning layer on top of that.

Next step

See exactly how much your team can save on SaaS.

One quick 15-minute call. We'll walk through your actual stack live and show you where the leaks are.

Or send us a note →

Keep reading

Procurement

The 90-Day SaaS Audit Plan for Growth-Stage Companies

Most growth-stage companies are paying for 30 to 60 SaaS tools without a clear picture of what is actually being used. This 90-day audit plan breaks the work into manageable weekly steps, so your finance or ops team can recover budget, fix renewals, and build a procurement process that holds.

Procurement

The SaaS Vendor Review Process Finance Teams Will Actually Trust

Most SaaS vendor reviews die in a spreadsheet no one updates. This guide walks through a quarterly review process with the right metrics, stakeholder roles, and decision criteria to make finance teams take the output seriously.

Procurement

SaaS Procurement Policy for Growing Indian Companies

Most Indian mid-market companies buy SaaS the same way they order lunch — whoever is hungriest hits checkout first. This guide gives you a practical procurement policy template: request workflows, approval matrices, and budget thresholds you can adapt tomorrow.

Find software at discounts Savings, Analyze spending.
Easexpense LLC:
1007 Orange St 4th floor, Wilmington, DE 19801, United States

Easenode Tech Private Limited:
B, 23, Sector 63 Rd, B Block, Sector 63, Noida, Uttar Pradesh 201301

Go to top