Buying verdict

How to Audit Your SaaS Spend (6 Steps)

This walkthrough audits SaaS spend in six steps: pull every recurring charge, map owners and seats, cut duplicates and shadow tools, then calendar renewals.

An open laptop on a desk showing a rising bar chart with an upward arrow, with rows of small people-shaped tokens standing in front of it
What's in this verdict
  1. Before you start
  2. Step 1: Pull every recurring charge into one list
  3. Step 2: Assign an owner and a purpose to each line
  4. Step 3: Find the duplicates and the shadow tools
  5. Step 4: Right-size seats against real usage
  6. Step 5: Match each plan tier to what you actually use
  7. Step 6: Build a renewal calendar and set the review cadence
  8. Where the recovered money usually comes from
  9. Worked example: a 40-person team audits its stack
  10. Seats, licenses and active users are three different numbers
  11. What counts as one tool and what counts as two
  12. Reading a statement when the charge does not say what it is
  13. Shadow IT is a symptom, not a discipline problem
  14. Who should own the audit in a small business
  15. When consolidating costs more than it saves
  16. Turning the audit into a budget you can defend
  17. Common mistakes when auditing SaaS spend
  18. Troubleshooting: when the audit stalls
  19. Your SaaS spend audit checklist
  20. The bottom line

Most software spending decisions are made one tool at a time, and that is exactly why the total gets away from a company. Each individual subscription looked reasonable on the day someone signed up for it. The problem is that nobody ever looks at all of them together, on one page, with a total at the bottom. A SaaS spend audit is that page. It is a portfolio exercise, not a cancellation exercise, and the distinction changes what you find.

The difference shows up immediately. Reviewing one subscription tells you whether that tool is worth its price. Reviewing the whole portfolio tells you that three tools are doing the same job, that you are paying for eleven seats belonging to people who no longer work here, that a charge under an unrecognizable name has been billing quietly for two years, and that four contracts renew inside the same six weeks with nobody watching for them. None of that is visible from inside a single tool’s billing page.

What follows is a six-step audit you can run in an afternoon: pull every recurring charge, map owners and seats, find the duplicates and the shadow tools, right-size the seats, match tiers to real use, and build a renewal calendar so auto-renewals stop making decisions on your behalf. The per-tool cost breakdowns elsewhere on VetLoft tell you what any single category should cost. This walkthrough is about the number they add up to.

Key takeaways

  • Audit the portfolio, not the tools. One list of every recurring charge, with a total at the bottom, surfaces duplication and dead seats that no single billing page can show you.
  • Collection is the hard part. Pull thirteen months of records so annual charges appear, and check personal reimbursements and app store receipts, not just the company card.
  • An owner per line is the sharpest filter you have. A recurring charge that no named person will claim is almost always either a duplicate, a leftover, or a forgotten trial.
  • Seats are where the quiet money sits. Paid licenses outlive the people they were bought for, so compare each tool's seat count against recent sign-ins rather than against headcount.
  • Finish with a calendar, not a cancellation list. A renewal date plus a decision date set well ahead of it is what stops next year's audit finding the same charges again.

Before you start

An audit rewards ten minutes of setup more than almost any other back-office exercise, because the whole thing succeeds or fails on how completely you collected the charges. Before you open a spreadsheet, gather four kinds of access, since chasing them mid-audit is what turns an afternoon into a week.

First, financial records covering the last thirteen months: statements for every company card, the bank account for direct debits and transfers, and any payment processor or personal card that has ever been reimbursed for software. Thirteen months matters, because a twelve-month window can miss an annual charge entirely if it lands on the wrong side of the boundary. Second, an export from your accounting software filtered to software and subscription categories, which catches things your card statements describe badly. Third, admin access to the tools you already know about, because seat counts and last sign-in dates come from inside each product. Fourth, a current list of employees and contractors, including everyone who has left in the past year.

Set aside an afternoon for the first pass and expect the collection to take longer than the analysis. You are building an asset you will reuse every quarter, so put it somewhere shared and durable rather than in a personal file. If you want a running total as you work, put your monthly software spend and your candidate cuts into the savings helper on this page and let it size the exercise while you read.

Step 1: Pull every recurring charge into one list

The first step is pure collection, and the discipline is to gather without judging. Every recurring software charge goes on the list, including the ones you are certain are fine, because the value of the exercise comes from completeness. A list missing four charges is not an audit, it is an opinion.

Work through the sources in order. Card statements for thirteen months, scanning for anything that repeats. The bank account for direct debits, standing transfers and anything paid by invoice rather than card. Your accounting export, which often names a vendor more clearly than the statement does. App store and platform receipts, which are easy to forget and frequently sit under a personal account. Expense reimbursements, where the shadow spend usually lives. And finally, a quick check with each team lead for tools they use daily that have not appeared anywhere yet.

For every charge, capture the same eight columns: the product name, what the charge is called on the statement, the amount, the billing cycle, the payment method, the renewal or next-charge date, the number of seats, and a blank owner column you will fill in during Step 2. Resist the urge to add commentary at this stage. The list is a record, not an argument.

Two collection habits prevent most of the pain. Record the statement description alongside the real product name, because next quarter you will be matching statement lines again and the mapping is the tedious part. And convert everything to a monthly equivalent in one extra column, dividing annual charges by twelve, so the total at the bottom actually means something. That total is your baseline. Most teams have not seen it before, and it is usually the moment the audit justifies itself. Our breakdown of what business software really costs covers why the per-seat sticker price is only part of that number.

Step 2: Assign an owner and a purpose to each line

With the list built, the next step is the fastest filter in the entire audit: every line gets one named human and one sentence explaining what it does for the business. Not a department, not a shared inbox, and not “everyone”. A person, by name, who would notice and object if the tool disappeared next Tuesday.

This works because unclaimed spending is nearly always dead spending. When a charge has no owner, one of a small number of things is true. It belongs to someone who left. It was a trial that turned into a subscription without a decision. It duplicates a tool the team actually uses. Or it is genuinely useful and simply nobody has thought about who owns it, which is worth knowing too. Any of those outcomes is more useful than the ambiguity you started with.

The one-sentence purpose is equally revealing. If the owner cannot describe what the tool does in a single plain sentence, that is a signal about how central it really is. Write the purpose in terms of the job rather than the product category, because “stores signed contracts where finance can find them” tells you something that “document management” does not. You will use those job descriptions directly in Step 3, so it is worth writing them properly now.

Mark every line with a provisional verdict as you go: keep, review, or cut. Keep is for tools with a clear owner, a clear job, and no obvious overlap. Review is for anything you suspect but have not confirmed. Cut is reserved for charges nobody will claim at all. Do not act on any of these yet. The verdicts are a working hypothesis that the next four steps will test, and acting early is how teams cancel something a workflow quietly depended on.

Step 3: Find the duplicates and the shadow tools

Now sort the list by the job description rather than by vendor, price or category, and look at every job with more than one tool attached. This is where the largest single recovery usually hides, and it is invisible in any per-tool review, because each of the duplicates looks perfectly justifiable on its own.

Real duplication rarely looks like two identical products. It looks like feature overlap between tools bought for different reasons. A project tool that also stores files, a chat tool that also stores files, and a document tool that exists to store files. A help desk with a built-in knowledge base sitting beside a separate wiki subscription. A CRM with email campaign features running alongside a dedicated email marketing tool. A project management tool with time tracking built in, next to a standalone time tracking subscription. Each pairing arrived logically. Together they are one capability billed twice.

For each overlapping group, ask three questions. Which tool does the work actually flow through day to day? Are the others being used by one team out of habit, or by the whole company for something the primary tool genuinely cannot do? And what would break if you consolidated, in terms of integrations, historical records and people’s routines? Some duplication survives this test honestly, because two teams can have genuinely different needs. The point is to make it a decision rather than an accident.

Shadow tools are the second half of this step. These are the charges nobody claimed in Step 2: subscriptions under personal emails, accounts set up by a contractor who has finished, tools bought during a crisis two years ago and never revisited. Track down the human connected to each one before cancelling anything, because occasionally the unclaimed charge turns out to be the thing quietly holding a workflow together. When it is genuinely dead, note the monthly value and move on. When it is genuinely useful, the fix is not cancellation but consolidation into a company-owned account with proper billing and admin access.

Step 4: Right-size seats against real usage

Seats are the most reliably wasteful line in a software stack, and the reason is structural rather than careless. Seats get added the moment someone joins or a project ramps up, because adding them is frictionless and urgent. They almost never get removed, because removing them is nobody’s job and never urgent. Over a couple of years of ordinary staff turnover, the gap compounds quietly.

The check itself is simple. Open each tool’s admin console, find the current paid seat count, and find the last sign-in date for every user. Most business tools expose both. Compare the seat list against your current staff list first, which catches departures immediately, then compare it against sign-in activity, which catches the subtler case of an active employee who was given a license and never used it. A sixty or ninety day window of no activity is a reasonable threshold for a conversation, not an automatic cut.

Three distinctions save you from mistakes here. A paid seat is what you are billed for. A provisioned license is what has been assigned to a person, which can be fewer. An active user is someone who has actually signed in recently, which is usually fewer still. Vendors bill on the first number, teams think in terms of the second, and only the third reflects the value you are getting. Audit the difference between all three, not just the headline seat count.

Watch for the tools where seat sprawl accumulates fastest. Anything deployed to everyone by default is a candidate, including a business password manager or a business VPN, where the default instinct is to provision the whole company and never revisit it. So are tools with per-user pricing that were rolled out during a growth spurt, and anything where an admin can add seats without a purchase approval. Note the reclaimable monthly value for each tool and add it to your running total. Do not release the seats yet; finish the audit first so you are making one set of coordinated changes rather than several uncoordinated ones.

Step 5: Match each plan tier to what you actually use

Tier drift is the quietest of the five leaks, because nothing about it looks wrong. The tool works, the team is happy, the bill arrives. The only problem is that you are on a plan sized for a company you are not, usually because someone upgraded for one specific feature or limit that has since stopped mattering.

For each remaining tool, answer one question: what exactly did we buy this tier for? There is usually a single concrete answer, such as a particular integration, a user limit, a reporting feature, a storage or record cap, or an approval workflow. Once you have named it, check whether that thing is still being used, and by whom. A business intelligence subscription bought at a higher tier for scheduled reports that nobody opens is a downgrade candidate. So is a plan upgraded for a headcount limit you have since fallen below. Our free versus paid comparison walks through the same reasoning at the bottom of the tier ladder.

Look for the reverse case too, since an audit that only ever cuts is not an audit. Sometimes a team is working around a limit with manual effort that costs more in hours than the higher tier costs in money, or is paying for a separate tool to do something the current plan’s next tier includes outright. Both are places where spending slightly more reduces the total. The goal is a stack sized to reality, not the smallest possible bill.

Two cautions. Check what a downgrade actually removes before you commit, because some plans drop admin controls, audit logs, integrations or historical data retention at lower tiers, and finding that out afterwards is expensive. And check the timing, since a downgrade partway through a prepaid annual term often does nothing until renewal. Where the tool is worth keeping and the tier is genuinely too high, the renewal conversation is frequently more productive than the downgrade button, which is what the negotiation walkthrough on VetLoft is for.

Step 6: Build a renewal calendar and set the review cadence

The first five steps recover money once. This one is what stops you finding the same problems next year, and it is the step teams most often skip because it produces no immediate saving. Skipping it is why so many audits are a one-off event rather than a habit.

Build a calendar with one entry per subscription, carrying five fields: the renewal date, the billing cycle, the annual value, the named owner from Step 2, and a decision date set comfortably before the renewal rather than on it. The decision date is the field that does the work. A reminder that fires on the renewal day is a notification about a charge you can no longer prevent. A reminder that fires well before it is a chance to change the outcome, whether that means renegotiating, downgrading, consolidating or leaving.

Give annual contracts the widest margin, because some carry a notice requirement that has to be met before the renewal itself, and the length of that window varies by agreement rather than following any standard. Do not assume a figure. Open each subscription’s own terms or account settings, find what it actually says, record it against that line, and set the decision date to clear it with room to spare. Where the terms are unclear, ask the vendor in writing and keep the answer with your calendar entry.

A desk calendar standing on a wooden desk with a single date circled in blue ink, a pen resting beside it
The renewal date is not the useful date. The decision date, set far enough ahead that you can still change the outcome, is what turns an audit into a habit.

Then set the cadence. A full audit annually, rebuilt from source records. A lighter quarterly pass that scans new charges, releases seats for departures and looks at the renewals landing in the next few months. And a standing offboarding check, so that whenever someone leaves, their seats across the whole stack get released the same week. That last one is the highest-return habit in the entire exercise, because it prevents the largest leak from ever forming. Run your own numbers through the savings helper to see what the recurring version of this is worth over three years rather than one.

Where the recovered money usually comes from

Once the six steps are done, the recoverable spend sorts itself into five recognizable buckets, and knowing their rough order helps you aim the next audit faster. The chart below shows the split for the illustrative stack used in the worked example that follows, so both charts describe the same set of findings rather than two unrelated ones.

What the recovered spend was made of

Illustrative split of one audit's recoverable monthly spend, for the worked example below. Shares sum to 100.

Duplicates 35% Dead seats 25% Shadow 18% Tiers 14% Renewal 8%
Overlapping tools doing one job, 35% Seats with no recent sign-in, 25% Unclaimed and forgotten charges, 18% Plans tiered above real use, 14% An annual renewal nobody caught, 8%

Illustrative figures from a single worked example, not a survey of the market, and every stack differs. Treat the ordering as the useful part: duplicates and dead seats generally return the most money for the least disruption.

Published percentages for how much SaaS spend is wasted circulate widely, and this walkthrough does not repeat any of them, because they come from very different samples, definitions and company sizes, and quoting one as a general fact would be inventing precision that does not exist. Your own number is the only one worth acting on, and the six steps above produce it. What travels reliably between companies is the shape rather than the size: the same five buckets show up almost every time, in roughly this order, because they come from the same structural causes rather than from any particular team’s carelessness.

That ordering has a practical use. If you have limited time, spend it on the two largest buckets. Duplicate tools and dead seats between them tend to account for the majority of the recoverable total, and both are low-risk, since consolidating an overlap removes no capability and releasing a departed employee’s license removes nothing at all. Tier drift and orphaned renewals are worth chasing, but they take longer per dollar recovered and carry more chance of an unwanted side effect.

Worked example: a 40-person team audits its stack

Numbers make the method concrete, so here is one audit end to end. Every figure is illustrative and internally consistent, chosen to show the arithmetic rather than to describe any real company, and your own stack will look different.

A forty-person services business runs the six steps for the first time. Step 1 turns up 58 separate recurring software charges, spread across two company cards, one founder’s personal card, a bank direct debit and two app store accounts, totalling an illustrative $5,000 a month, or $60,000 a year. Nobody in the company had seen that total before, and the average charge works out at roughly $86 a month, which is precisely why no individual line ever triggered a review.

Step 2 finds nine lines with no owner at all. Step 3 groups the list by job and exposes two clear overlaps, a second project tool that one team adopted independently and a standalone file-sharing subscription doing what the main platform already does, worth an illustrative $350 a month combined. It also confirms that four of the unclaimed lines are genuinely dead, including a contractor’s design subscription and a monitoring tool from a project that ended, at $180 a month together. Step 4 compares seats against sign-ins and finds 22 paid seats across six tools with no activity in sixty days, most belonging to people who had left, worth $250 a month. Step 5 identifies two plans tiered above real use, at $140 a month. Step 6 catches an annual contract renewing in five weeks that nobody was tracking, at $80 a month equivalent.

Illustrative monthly recovery by finding

Monthly value of each finding in the worked example. Bars are drawn from each value against the largest one.

Duplicate tools consolidated$350
Dead seats released$250
Shadow tools cancelled$180
Plans downgraded a tier$140
Renewal caught in time$80
Total recovered$1,000

Widths for the five findings are each value against the largest ($350). The total bar is shown full width as a summary of the five above it, not as a comparison against them.

The five findings total $1,000 a month. That is $12,000 a year and roughly $36,000 across a three-year horizon, and it is 20 percent of the $5,000 monthly spend the audit started from, leaving an ongoing bill of $4,000 a month. Not one capability the business actually relies on was removed to get there, because the duplicates were consolidated onto surviving tools, the released seats belonged to people who had gone, and the shadow tools were genuinely idle. The downgrades were the only findings that required a real judgement call, and the renewal was caught rather than cancelled, which bought a decision instead of forcing one.

The part worth copying is not the total. It is that the largest single line, the duplicate tools, was invisible from inside any of the individual subscriptions and only appeared once the whole portfolio sat on one page. Put your own spend and your own candidate cuts into the savings helper to run the same arithmetic on your figures.

Seats, licenses and active users are three different numbers

Almost every seat-related mistake in an audit comes from collapsing three different numbers into one. Keeping them separate is a small discipline that pays for itself immediately.

The paid seat count is what the vendor bills you for, and it is the number on the invoice. The provisioned license count is how many of those seats have actually been assigned to a named person inside the admin console, which is often lower, because seats bought for a planned hire or a busy season sit unassigned and still bill. The active user count is how many of those assigned people have signed in recently, which is lower again, because a license can be assigned to someone who has never opened the tool.

Each gap tells you something different. Paid seats above provisioned licenses is pure overbuy and the easiest thing in the audit to fix, since releasing an unassigned seat affects nobody. Provisioned licenses above active users is an adoption question rather than a billing question, and it might mean the tool is not doing the job you bought it for, which is a bigger finding than the seat cost. Only when you have both gaps measured can you tell whether you are overpaying or whether a rollout quietly failed.

Record all three numbers in your inventory rather than just the billed count. Next quarter, the change in each is a more informative signal than the total spend, because it tells you whether the stack is growing because the company is growing or because nobody is watching.

What counts as one tool and what counts as two

Duplication is only visible if you have decided what a tool is, and the answer that makes an audit work is the job rather than the product. Two subscriptions that do the same job are duplicates even if their vendors sit in different categories, and one subscription that does three jobs is three entries in your grouping even though it is one line on the statement.

Write the job as a plain sentence describing the outcome, not the software category. “Keeps the record of every customer conversation.” “Holds signed contracts where finance can find them.” “Tells us which invoices are unpaid.” Once every tool has a sentence like that, sort by sentence and the overlaps are obvious, because two tools claiming the same outcome cannot both be the answer.

The multi-job case is the one people miss. Modern business software bundles aggressively, so your CRM may include email campaigns, your project tool may include time tracking and file storage, and your ecommerce platform may include an email tool and a basic point of sale. Every bundled capability is a potential duplicate of a standalone subscription elsewhere on your list. List the jobs a tool actually covers in practice, not the full feature matrix from its marketing page, since a capability nobody uses is not a substitute for the tool people do use.

This framing also protects you from over-consolidating. If two tools genuinely serve different jobs that merely sound similar, the sentence test shows it, and you keep both with a documented reason. An audit that records why you kept something is more useful next year than one that only records what you cut.

Reading a statement when the charge does not say what it is

A real obstacle in Step 1 is that card statements are frequently unhelpful. Software charges appear under a parent company name, a payment processor, an abbreviation, or a billing entity that shares nothing with the product you actually use. Teams routinely abandon an audit here, and the workarounds are straightforward.

Start with the accounting export rather than the raw statement, because a bookkeeper has often already matched and renamed the transaction, and a bookkeeping service will usually have coded software subscriptions consistently. Where that fails, search your email for the amount and the date, since receipt emails carry the real product name and arrive within a day of the charge. Where that fails too, search the exact statement descriptor, which is usually enough to identify the billing entity behind it.

If a charge still resists identification, cancel the guessing rather than the charge. Contact the card issuer for the merchant details, or ask the team directly with the amount and date attached, because someone usually recognizes it. Never cancel a charge you cannot identify on the assumption it is dead, since unidentifiable and unimportant are different things and the expensive version of this mistake breaks something in production.

Once you have identified a descriptor, record it permanently next to the product name in your inventory. That mapping is the single most time-saving artifact the audit produces, because next quarter it turns statement reconciliation from detective work into matching.

Shadow IT is a symptom, not a discipline problem

The unclaimed charges an audit surfaces are usually described as a governance failure, and treating them that way makes the next audit harder. People buy software with their own card because they had a real problem and the official route was slow, unclear, or did not exist. Punishing that behaviour does not stop it; it just moves the spending further out of view.

The productive response has three parts. Identify the owner and the problem the tool was solving, because that problem is real information about a gap in your stack. Decide whether the tool is genuinely useful, which is a normal evaluation, not a verdict on the person who bought it. And if it stays, consolidate it into a company-owned account with company billing, admin access and a named owner, so it is a managed subscription rather than a shadow one.

Rows of small painted figures in office clothing standing on a desk beside a partly open laptop
Every line in a software inventory belongs to someone. Charges without a named owner are the fastest thing an audit finds and the easiest thing to fix.

The prevention is equally practical. Make the sanctioned route fast enough that nobody needs to work around it, and give people a clear answer about who can approve a small subscription and how long it takes. A lightweight rule such as a low spending threshold anyone can approve, with a note to a shared list, prevents far more shadow spend than a policy that requires three approvals for a small monthly tool. The list is the important half of that rule, not the threshold.

Who should own the audit in a small business

In a company small enough not to have a procurement function, the audit needs one owner or it will not happen twice. The right owner is whoever already sees the financial records, which in most small businesses means the person handling the books, the finance lead, or an operations generalist. They do not need to make the keep-or-cut decisions; they need to build and maintain the inventory and drive the calendar.

Decisions should sit with the tool owners identified in Step 2, because they are the only people who know what would break. The audit owner brings the list, the numbers and the renewal dates. The tool owner brings the judgement. Splitting it this way avoids the two failure modes: a finance-led audit that cuts something operationally critical, and a team-led audit where nobody ever volunteers their own tool for review.

Give the audit owner three standing responsibilities rather than a project. Keep the inventory current when new subscriptions appear. Run the offboarding seat check whenever someone leaves. And send the decision-date reminders to the named owners with the annual value attached, so each renewal reaches a person who can act on it. That is a modest ongoing commitment, perhaps an hour a month, and it is what converts a one-off recovery into a permanent one.

Where the company is too small for even that, the fallback is a recurring calendar entry for a quarterly hour with the inventory open. Less structure, same effect, as long as the inventory itself is written down somewhere durable and not reconstructed from memory each time.

When consolidating costs more than it saves

Not every duplicate is worth removing, and an audit that ignores switching costs will recommend changes that lose money. Before consolidating two tools onto one, price the move honestly against the saving.

The costs that matter are rarely the subscription. They are the hours spent migrating records, the retraining for whichever team is losing its familiar tool, the integrations that have to be rebuilt, the historical data that may not transfer cleanly, and the productivity dip while people adjust. Our migration walkthrough covers what that work actually involves. A consolidation saving a small monthly amount but costing weeks of disruption is a bad trade, and saying so in the audit notes is a legitimate finding.

Three factors usually decide it. The size of the annual saving relative to the disruption, which is why the annual figure rather than the monthly one is the right number to weigh. The depth of the data in the tool you would retire, since a system holding years of customer history is far more expensive to leave than one holding last quarter’s files. And whether the surviving tool genuinely does the job, or merely lists the feature, which is worth verifying with a short structured trial before committing.

When the answer is no, record it. A documented decision to keep an overlap because consolidation costs more than it saves is a real audit outcome, and it stops the same debate consuming an hour next year.

Turning the audit into a budget you can defend

The audit produces something more useful than a list of cuts: a defensible software budget. Once every line has an owner, a job, a tier justification and a renewal date, you can forecast next year’s software spend rather than discovering it a month at a time.

Build the forecast from the inventory in three layers. The committed layer is everything under an annual contract that will renew, which is known cost with known dates. The variable layer is per-seat spending that moves with headcount, which you can project from your hiring plan by multiplying planned additions by your average per-seat cost across the tools everyone gets. The discretionary layer is everything you could stop within a month, which is your actual flexibility if conditions change. Most teams are surprised by how small the discretionary layer really is, and that is exactly the kind of thing worth knowing before you need it.

A printed sheet of ruled rows with empty checkboxes lying on a wooden desk beside a laptop, a pencil and a cup of black coffee
The audit's real output is a maintained inventory, not a one-time list of cuts. Rows, owners and dates are what make the second audit take an hour instead of an afternoon.

Add two tracking numbers that make the budget meaningful over time. Software spend per employee, which tells you whether the stack is scaling with the business or ahead of it, and the number of active tools, which tends to creep upward far faster than anyone expects. Neither number has a correct value, and there is no benchmark worth quoting, since a design studio and a field services company will differ enormously. Their usefulness is entirely in the trend within your own business, measured the same way each quarter.

Common mistakes when auditing SaaS spend

The same handful of errors cost teams either money or stability on almost every first audit, and all of them come from treating the exercise as a cancellation sprint rather than an inventory.

  • Auditing only the company card. Software charges hide in personal reimbursements, app store receipts, bank direct debits and a founder's personal card. An audit that covers one payment method finds part of the stack and reports a total that is confidently wrong.
  • Using a twelve-month window. Annual subscriptions are the ones most likely to have drifted, and a twelve-month lookback can miss one entirely depending on where the boundary falls. Thirteen months costs nothing extra and closes the gap.
  • Cutting before finishing the inventory. Cancelling as you go means making decisions without seeing the overlaps, which is how a tool gets cancelled and its replacement gets cancelled in the same afternoon. Collect everything, then decide.
  • Confusing seat count with headcount. Matching seats to your employee list catches departures but misses the employee who was given a license and never used it. Sign-in activity is the number that reflects value received.
  • Ignoring what depends on the tool. A subscription that feeds your accounting, your CRM or a reporting flow can break work when it stops, even when the data survives. Map the dependencies before you touch anything.
  • Stopping at the savings. An audit without a renewal calendar and an owner recurs from scratch every year, and the same charges come back. The calendar is what makes the recovery permanent rather than temporary.

Troubleshooting: when the audit stalls

Most audits stall in one of a few predictable places. Here is what each looks like and how to get moving again.

You cannot get a complete list of charges. This is the most common stall, and it usually means one payment method is missing rather than that the task is impossible. Work backwards from the tools instead of forwards from the statements: list every product the team uses, then find the charge for each. Combining both directions, statement to product and product to charge, closes the gap faster than either alone, and the leftovers in each direction are exactly the interesting cases.

Nobody will claim a tool, but you are not confident it is dead. Do not cancel on silence. Instead, check the admin console for recent sign-in activity, look for integrations pointing at it from other tools, and search email for recent notifications from the product. If all three are quiet, a safer intermediate move than cancelling outright is to remove all but one administrative seat, wait one billing cycle, and see whether anyone surfaces. Where you are ready to cut, our cancellation walkthrough covers doing it without losing your data.

The tool is on an annual contract you cannot exit. Mid-term exits generally do not stop the current obligation, so the realistic action is to record the renewal date and any notice requirement, set the decision date well ahead of it, and treat the finding as next year’s saving rather than this year’s. Note the annual value against the calendar entry so the decision gets the attention its size deserves when it arrives.

The savings look real but the team resists. This usually means the audit produced numbers without context. Bring the job descriptions and the dependency notes to the conversation, not only the monthly figures, and let the tool owner make the call on their own tool. Resistance also sometimes carries real information: the person defending a duplicate may be the only one who knows what the surviving tool cannot do.

The audit finished and nothing changed. Cuts that are agreed but not executed are the most common way an audit produces zero. Assign each agreed action to a named person with a date, put the seat releases and downgrades in the same week so they are one coordinated change, and verify on the following statement that the charges actually stopped. An unverified cancellation is a charge waiting to reappear.

Your SaaS spend audit checklist

Use this as the save-this asset and work top to bottom. It is written so the second audit is an update rather than a rebuild.

  • Collected thirteen months of card, bank, accounting, app store and reimbursement records, so annual charges appear alongside monthly ones.
  • Listed every recurring charge with product name, statement descriptor, amount, billing cycle, payment method, renewal date and seat count, plus a monthly equivalent column and a total.
  • Assigned one named owner and one plain-sentence purpose to every line, and flagged every unclaimed charge for investigation.
  • Grouped the list by job rather than category, and reviewed every job with more than one tool attached for genuine overlap.
  • Identified the shadow tools, traced each to a person, and decided consolidate or cancel rather than assuming either.
  • Compared paid seats, provisioned licenses and active users in each admin console, and listed the seats with no recent sign-in.
  • Checked every plan tier against the specific feature or limit it was bought for, including the cases where a higher tier would cost less overall.
  • Mapped the dependencies for anything you plan to cut: integrations, reports, workflows and the people who rely on it.
  • Built the renewal calendar with renewal date, cycle, annual value, owner and a decision date set well ahead of each renewal.
  • Set the cadence: a full audit annually, a light pass quarterly, and a seat check every time someone leaves.
  • Executed and verified each agreed change, with a named person and a date, then confirmed on the next statement that the charges actually stopped.

The bottom line

A SaaS spend audit is not a cost-cutting exercise dressed up with a spreadsheet. It is the only way to see a set of decisions that were each made in isolation as the single portfolio they actually became. Every tool on your list was bought by someone sensible for a reason that made sense that week. The waste is not in any of those decisions; it is in the fact that no one has looked at them together since. That is what the six steps fix: pull every recurring charge into one place, attach a name and a purpose to each line, group by job so the duplicates and the unclaimed charges become visible, compare paid seats against people who actually sign in, check each tier against the reason it was chosen, and put every renewal on a calendar with a decision date ahead of it. The recovered money is the immediate reward, and it is usually substantial the first time. The lasting reward is quieter: an inventory somebody maintains, an owner attached to every subscription, and renewals that arrive as decisions rather than as charges. Run the six steps once, put your own figures through the savings helper to see what your version is worth over three years, and make the calendar the part you keep.


Every figure in this walkthrough is illustrative and used to show how the arithmetic works, not a quoted price, a market benchmark or a survey result. Software pricing, plan tiers, seat terms and contract notice requirements are set by each vendor and change without warning, so confirm your own numbers in your account settings and your own agreements before acting. VetLoft has no commercial relationship influencing what appears here, and nothing above is financial, legal or tax advice.

Frequently asked questions

How do I audit my SaaS spend?

You audit SaaS spend by treating the whole portfolio as one bill rather than working tool by tool. Pull thirteen months of card, bank and accounting records so annual charges surface alongside monthly ones, and put every recurring software charge into a single list with its cost, billing cycle, renewal date and payment method. Then give each line a named owner and a one-sentence purpose, because a charge nobody claims is the cheapest thing you will ever cut. Group the list by the job each tool does to expose duplicates and shadow tools, compare paid seats against recent sign-ins to release dead licenses, check each plan tier against the features you actually use, and finish by building a renewal calendar with a decision date set well ahead of each renewal. The order matters: inventory first, judgement second, cancellations last.

How long does a SaaS spend audit take?

A first full audit for a small business is usually an afternoon of focused work, occasionally a day if charges are spread across several cards, several people and a couple of app stores. The slow part is almost never the analysis; it is the collection, because software charges hide in personal reimbursements, in app store receipts, on a founder's card and inside a payment processor that bills under a name that does not resemble the product. Once the list exists, owners and duplicates fall out quickly, seat checks take a few minutes per tool in each admin console, and the renewal calendar is a single sitting. Every audit after the first is far shorter, because you are updating a list rather than building one, which is the main argument for doing it on a schedule instead of in a panic.

What percentage of SaaS spend is usually wasted?

There is no honest single number, and any specific percentage quoted as a general fact should be treated with suspicion, because waste depends entirely on how fast the company has grown, how many people can buy software, and how long it has been since anyone looked. Published waste figures circulate widely, but they come from very different samples and definitions, so this walkthrough does not repeat them. What is reliable is the shape rather than the size: the recoverable money concentrates in duplicate tools, seats belonging to people who left, forgotten charges nobody claims, plan tiers provisioned above real use, and annual renewals that rolled over unnoticed. The useful exercise is measuring your own number. Run the six steps, total the lines you can genuinely cut, and divide by your monthly software spend.

How do I find duplicate software tools in my stack?

Group your inventory by the job each tool does rather than by the category the vendor claims, because duplication almost never looks like two identical products. It looks like a project tool that also stores files, a chat tool that also stores files, and a document tool that stores files, so three subscriptions are quietly paying for the same capability. Write a one-line job description for each tool, sort the list by that job, and look at every group with more than one entry. For each group, ask which tool the work actually flows through, whether the others are used by one team out of habit, and what would break if the overlap were consolidated. Some duplication is legitimate, since two teams can genuinely need different tools, but it should be a decision rather than an accident.

What is shadow IT and how does it show up in a spend audit?

Shadow IT is software bought outside whatever purchasing process the company thinks it has, usually with a card, usually by someone solving a real problem quickly. In an audit it shows up as recurring charges nobody on the team can immediately explain, subscriptions under a personal email, tools that arrive through expense reimbursements rather than the company card, and accounts still billing for a contractor who finished months ago. Treat it as a signal rather than a discipline problem, because people generally reach for their own card when the official route is slow or unclear. The audit response is to identify the owner, decide whether the tool is genuinely useful, consolidate it into a company-owned account with proper billing and admin access if it is, and cancel it cleanly if it is not.

Should I cancel or downgrade an underused tool?

Downgrade when the tool still does necessary work and you are simply paying for a tier above your real use, and cancel when the capability is genuinely covered elsewhere or nobody has used the tool in months. The distinction matters because the two mistakes are symmetrical. Cancelling something a workflow quietly depends on breaks the work and often costs more to unwind than the subscription saved, while downgrading a tool you meant to leave means paying a smaller bill forever. Right-sizing seats sits between the two and is usually the safest first move, since releasing licenses for people who left removes cost without removing capability. Before either decision, confirm what depends on the tool, export anything you would want to keep, and check the billing cycle so the change lands where it saves money.

How often should a small business audit its software spend?

A practical rhythm for most small businesses is a full audit once a year, a lighter review each quarter, and a standing check whenever someone leaves the company. The annual pass is the one that rebuilds the inventory from source records, re-checks owners, and re-examines every tier. The quarterly pass is much shorter: scan new charges since last time, release seats for departures, and look ahead at the renewals landing in the next few months. The offboarding check matters most of all, because unused seats accumulate silently and are the easiest money in the whole exercise to leave on the table. If a full audit feels too heavy to repeat, that usually means the inventory was never written down in a form you can update, which is a fixable problem.

What should a SaaS renewal calendar include?

A useful renewal calendar records, for every subscription, the renewal date, the billing cycle, the annual value, the named owner, and a decision date set comfortably before the renewal rather than on it. The decision date is the part that does the work, because a reminder that arrives on the renewal day tells you about a charge you can no longer prevent. Give annual contracts the widest margin, since some carry a notice requirement that must be met well before the renewal itself, and confirm each tool's own terms in its account settings rather than assuming a standard window. Add the owner so the reminder reaches a person rather than a shared inbox, and add the annual value so the size of the decision is visible at a glance.

Ivan Petrucci · Software reviewer

Ivan has migrated teams across dozens of SaaS tools and now tests them hands-on, scoring for real workflows instead of feature checklists.

Free, no obligation

Get software demos and quotes

Tell us what you are shopping for. We will match you with vendors who can send demos and pricing for your team.

We will connect you with software vendors. No spam.