The SaaS Spend Audit Playbook
How to find the forgotten contracts, overlapping tools, and hidden spend that don't show up until someone goes looking.
I spent years on the vendor side of enterprise software, and I can tell you that nearly every company I sold into had SaaS spend they weren't fully aware of. Not because anyone was hiding anything, but because SaaS purchasing happens in enough different places, on enough different cards, that no single person naturally sees the whole picture. This is the audit process I'd recommend running, roughly once a year, whether or not anything seems obviously wrong.
From fragmented buying to one inventory
Fragmented stack
No single person sees the whole picture, so spend hides in plain sight.
One reconciled inventory
Grouped by function, with an owner and a decision attached to every tool.
Where the hidden spend actually hides
Before running the audit, it helps to know what you're looking for:
- Tools purchased directly by a department on a company card, never routed through procurement or IT
- Free trials that converted to paid plans automatically, without anyone deciding to buy
- Duplicate tools, where two teams independently bought something that does roughly the same job
- Contracts inherited from an acquisition or a team reorg, with no clear current owner
- Tools kept "just in case" after the project that justified them ended
Step 1: Pull every source of truth you have, separately
Don't start with a single list. Pull:
- Corporate card and expense statements, filtered for recurring software charges
- Your accounting system's vendor list
- SSO or identity provider logs, showing what tools employees are actually authenticating into
- Any existing contract repository, however incomplete
Step 2: Reconcile the lists against each other
This is where the real discoveries happen. Tools that show up in card statements but not in your contract repository are your blind spots. Tools that show up in SSO logs but nowhere on the spend side may be free tiers quietly attached to paid ones, or shadow purchases routed through an individual's account.
Step 3: Group by function, not by name
Once you have a fuller list, group tools by what they actually do: analytics, project management, e-signature, and so on. Overlaps become obvious fast. It's common to find three or four tools doing substantially the same job across different teams, each with its own renewal date and its own notice period.
Step 4: Assign an owner to everything you find
An audit that produces a list nobody owns just becomes next year's blind spot again. Every tool that comes out of this process needs a named owner, even if the immediate decision is simply "keep as is."
Step 5: Decide, don't just document
For each overlap or forgotten contract, make an actual decision: consolidate, cancel, renegotiate, or keep. A completed audit with no decisions attached is a spreadsheet, not a savings plan.