Skip to content

The real cost of Shadow IT (and how to bring it under control)

Shadow IT is not a discipline problem, it is a friction problem. What unapproved tools actually cost in wasted spend, security exposure and compliance risk — and the five steps that bring them back under governance without slowing teams down.

Shadow IT is a permanent feature of the modern workplace, not a phase.

As teams adopt tools outside IT’s oversight, organisations lose visibility, take on avoidable risk and spend money they cannot properly account for. What starts as a harmless shortcut — “we just needed something quickly” — becomes a blind spot hiding security, compliance and financial problems.

This article covers why Shadow IT takes hold so easily, what it costs, and how to regain control without slowing the business down.

What is Shadow IT?

Shadow IT is any hardware, software, cloud service or SaaS application used without IT’s knowledge or approval.

Sometimes it is minor. A team signs up for a free project tool rather than waiting for a formal request, just to see whether it helps.

Sometimes it is not. A department moves customer data into an unapproved database — or an AI tool — to meet a deadline.

However small the initial decision, the moment a tool sits outside your governance framework nobody can confirm who has access to it, where the data lives, or whether the service meets your security and compliance requirements.

The scale of the problem

Shadow IT is not an edge case. It is most of the portfolio.

The average enterprise now runs 305 SaaS applications. Very few IT functions would name a number that high if asked to guess, and the gap between the number IT believes and the number finance can see in card statements is the working definition of Shadow IT.

The waste is measurable. Across the average organisation, 46% of SaaS licences go unused — only 54% are actually used. Set against an average annual SaaS spend of $55.7M per organisation, that is roughly $19.8M a year on licences nobody opens.

The newest layer is AI. Spend on AI-native applications at large enterprises grew 393% year on year, and use across the wider AI category grew 181%. These tools are adopted faster than any category before them, they are frequently free at the point of use, and they routinely process exactly the data you would least like to see leave.

The hidden costs of Shadow IT

1. Financial waste

When teams buy tools independently, spending loses structure. Duplicate subscriptions, unused licences and silent renewals accumulate without anyone deciding they should.

A common shape: marketing pays for a reporting platform, product teams adopt something similar, IT already runs an enterprise analytics suite, and finance sees three renewals with no explanation of what distinguishes them. Nobody made a bad decision. The organisation still bought the same capability three times.

2. Security vulnerabilities

Unapproved applications bypass security controls. Weak or absent multi-factor authentication, unencrypted data, unreviewed integrations and uncontrolled access all widen the attack surface at once.

Consider a team storing customer information in an unapproved note-taking app because it helps them co-ordinate. That app integrates with dozens of third-party services by default. Because IT does not know it exists, nobody reviews those connections. If a breach happens, the data was already outside your control before you had any way of knowing.

OAuth is the part most often missed. Every “sign in with” and every third-party integration creates a standing grant, and those grants outlive the person who consented to them. A leaver’s account can be disabled while their grant to a third-party application still holds read access to a shared drive.

3. Compliance and audit exposure

Unapproved systems may store data in the wrong jurisdiction, lack usable audit trails, or fail to meet GDPR, HIPAA or PCI-DSS requirements.

A salesperson syncs EU customer data into a US-hosted plugin because it works better with their mail client. The transfer happens immediately. The compliance breach is continuous from that moment, and it is invisible until someone goes looking.

Without reliable discovery, IT cannot detect personal licences holding corporate data, and cannot assess the risk attached to them.

4. Operational inefficiency

Shadow IT fragments work. Service desks support tools they were never trained on. Integrations break because nobody knew they existed. Data spreads across platforms with no agreed source of truth.

Even simple collaboration gets slower. Which tool is the team using? Do I have access? Where is the current version? Repeated across departments, that friction is a real productivity cost — it just never appears on a budget line.

Why Shadow IT happens

Shadow IT almost never comes from deliberate concealment. It happens when the formal process introduces more friction than a team is willing to absorb.

Most people simply want to move at the speed of their work. If getting IT sign-off is slow or feels arbitrary, departments find their own tools. The motive is usually good: people want to use technology that helps them do their jobs.

Freemium pricing accelerates it, because adoption requires no approval and no purchase order. Hybrid work makes it easier to operate outside IT’s line of sight. And without dedicated discovery, IT learns about new software only when something breaks or an unexplained cost appears.

How to regain control over Shadow IT

1. Discover what is being used

Visibility is the foundation. Few organisations appreciate the scale of their Shadow IT until they look, and the answer is rarely small.

No single signal is sufficient. Identity data tells you what people sign into with a corporate account, but misses anything signed up for with a work email and a separate password. Vendor APIs give you authoritative licence lists, but only for applications you already know about. Browser telemetry catches what people actually use, including the applications nobody has told procurement about.

CerteroX SaaS Management converges three signals for exactly this reason: identity provider sync from Entra ID and Okta, 47 vendor API connectors pulling authoritative user and licence lists directly from the vendor, and a browser extension that detects SaaS domains with per-user attribution and time-on-app. Applications resolve against a catalogue of more than 35,000, so what comes back is a named application with a category and a risk profile, not a domain string.

The same mechanism finds Shadow AI. AI tools are classified from application feature tags in the catalogue rather than from a hardcoded list, so the detection set grows as the market does. The Shadow AI dashboard ranks adoption risk by the share of your organisation using each tool — ten people on a given assistant is a different problem from a thousand.

Discovery also has to cover consented access, not just accounts. OAuth grant discovery surfaces every third-party application someone has authorised against your tenancy, scored from 0 to 100 on data sensitivity, scope, how the consent was given and how long it has been dormant. Grants can be revoked directly, or automatically through a workflow.

2. Centralise visibility and ownership

Once the picture is visible, every application needs a clearly accountable owner — someone who understands its purpose, its usage, its cost and its risk level.

This does not mean taking autonomy away from departments. It creates a shared responsibility model: teams keep control of their tools, and IT keeps the wider environment safe, compliant and coherent. In practice that means recording four distinct owner types — application, business, technical and data owner — because the person who champions a tool is rarely the person who should answer a data protection question about it.

Ownership only holds if the underlying record is complete: what was purchased, what is assigned, what is available, and what is oversubscribed.

3. Build practical governance policies

With ownership established, governance becomes a question of clarity. Policies should define how new tools are bought, which risks require review, how data is handled, how access is granted and removed, and how renewals are assessed.

Not every application needs the same scrutiny. Systems handling sensitive data warrant a proper assessment against data sensitivity, compliance exposure and business criticality. Low-risk internal tools should follow a lighter path — if the process treats a whiteboard app like a payroll system, people will route around it, and you are back where you started.

Budgets belong in the policy too. Per-application budgets with warning and critical thresholds turn a spending conversation into an alert rather than a year-end surprise.

4. Enable teams, do not restrict them

Shadow IT grows when teams cannot get what they need quickly enough. Fixing it means improving the sanctioned route, not tightening the restrictions on the unsanctioned one.

With visibility you can publish a catalogue of approved tools and shorten approval cycles. Clear guidance on when a tool needs deeper review removes the guesswork that makes people give up and use a card instead.

Where a tool genuinely should not be used, say so explicitly and act on it: applications can be marked as managed, blocked or ignored, and a workflow can alert, revoke access or start deprovisioning on detection. A clear “no” is better than silence, because silence is indistinguishable from permission.

When IT offers speed and transparency, teams follow the approved process. When it does not, they do not.

5. Review and optimise continuously

Shadow IT is not a one-time clean-up.

Regular review lets you retire unused licences, consolidate overlapping vendors, reassess risk and keep pace with regulatory change. Unused licence detection at 30 or more days of zero usage, overlap detection ranked by recoverable saving, and upcoming renewals shown with their actual utilisation rate turn that review from a workshop into a work queue.

Offboarding deserves particular attention, because it is where Shadow IT quietly regenerates. A per-user offboarding checklist showing every licence held, the connector status behind each revocation and whether it is pending, in progress or complete — with the monthly cost of whatever is still open — is the difference between believing someone was offboarded and knowing it.

Continuous review also shows you where demand is repeatedly forming. If three teams adopt the same category of tool in a quarter, that is a signal to expand the approved catalogue before the workarounds return.

Get visibility and control of Shadow IT

Shadow IT thrives when it delivers tools faster than IT can. Left alone, it drains budgets, weakens security and scatters data across a landscape nobody can see.

The long-term answer is not to restrict teams but to meet them where they are: improve visibility, offer clear guardrails, and make the sanctioned route the fastest one available.

Every major shift in enterprise technology has followed the same pattern. Users moved first and governance adapted afterwards. Shadow IT is no different, and neither is Shadow AI. The organisations that come out of it well are the ones that learn from that history, reduce friction, and design processes that help people rather than obstruct them.

Related reading

Other posts covering the same ground.

From reading to evidence

Put the hardest claim here
to a technical person.

Everything argued above is checkable. Name the publisher, the billing account or the platform you would argue with, and the session is built around it — the reasoning attached, not a summary slide.

No gated download at the end of it.