TL;DR

  • Shadow IT consists of any software, app, or cloud service employees use without going through formal IT or procurement approval
  • Employees frustrated with clunky tools and processes may resort to shadow IT as a means to work faster and easier
  • Every use of shadow IT creates unnecessary risk; sensitive data ends up on random servers and costs can rise exponentially when subscriptions and licenses are unmanaged
  • Shadow IT is a symptom of friction within the system; procurement is often where that friction starts
  • Procurement's visibility makes it well placed to see where shadow IT is hiding; clean it up by running a discovery audit, consolidating tools, and retiring what's redundant or unused
  • An audit tends to reveal fragmented, unmanaged spend; working with a GPO like Una can help bridge the gap by bringing pre-negotiated contracts and centralized visibility to certain categories

Every company thinks its tech stack is neat and tidy right up until the truth comes out: a marketing team using a free design tool nobody in IT has heard of, a sales rep expensing an AI note-taking app on a personal card, a whole department running its workflow through a platform finance only discovered when the renewal invoice bounced.

Welcome to shadow IT, the quiet second technology stack running inside almost every organization, parallel to the one IT actually knows about.

What Is Shadow IT?

Shadow IT refers to any software, app, or cloud service employees use without going through formal IT or procurement approval. It ranges from harmless, like a free app one person uses to organize their to-do list, to serious, like an entire department running core work through an unvetted platform storing sensitive data nobody in security has checked.

Most organizations assume it's a handful of stray subscriptions. Audit it properly, and the number is usually in the dozens, sometimes hundreds.

Why Shadow IT Happens

Mostly, people are trying to work faster than the official process allows. Formal approval can take weeks, but a deadline this afternoon can't. A credit card or a free trial solves the immediate problem in minutes. Frustration with clunky sanctioned tools pushes people toward workarounds too, and cloud subscriptions have made this far easier than it used to be: entering a card number and clicking accept takes less effort than filing a ticket. 

Often, it's genuinely well intentioned. Someone finds a tool that helps, shares it with the team, and within months a department has quietly standardized on shadow software.

How Shadow IT Creates Risk

Unvetted software hasn't been through the checks sanctioned tools go through, such as encryption standards and access controls (IT checks), and basic vendor due diligence (procurement checks).

Sensitive data can end up on servers nobody has evaluated, and the exposure usually only becomes visible after something goes wrong. Regulated industries carry extra risk here, since data handling requirements don't bend for tools nobody assessed.

Then there's the cost. Multiply a few unnecessary subscriptions across a few thousand employees, add departments duplicating the same category without knowing it, and the number gets uncomfortable fast. All of it is purchased at full retail price with no negotiated terms. 

Every unmanaged subscription is also a renewal nobody's tracking and a login that often stays live long after the employee who set it up has left. Data ends up scattered across disconnected systems too, which makes integration harder and leaves IT with an incomplete picture of what actually touches company information at any given time.

Is It Procurement's Fault?

Partly. A six-week approval process for a $30-a-month tool practically guarantees people will route around it. That said, plenty of shadow IT comes from a simple awareness gap, where people don’t realize a free trial on a personal card should involve procurement.

Shadow IT is a symptom of friction somewhere in the system, and procurement is often where that friction starts.

Is It Procurement's Job To Clean It Up?

Yes, though not alone. Procurement has visibility few other functions do, since spend and card data pass through it in some form, which makes it well placed to see where shadow IT is hiding. 

But the cleanup works best as a joint effort: IT and security assess the technical risk, procurement handles the contract and spend side, and finance makes sure everything gets tracked once it's back in view. If you run it purely as a procurement exercise, the security dimension gets missed. But if you run it purely as an IT lockdown, you risk pushing the behavior further underground.

How To Clean It Up

Start with a discovery audit: expense reports, card statements, single sign-on logs, and a direct conversation with department heads, since asking questions often surfaces more than any system report. Sort what you find into three buckets: 

  1. Keep and bring under a proper contract
  2. Consolidate where several teams are paying separately for the same category
  3. Retire what’s redundant or unused. 

Move everything worth keeping off individual cards and onto centrally negotiated agreements, which is usually where the first real savings show up. Give teams notice and an alternative before switching anything off, since a punitive cleanup just teaches people to hide the next workaround better. Assign an owner to everything that survives, and add SaaS access to the offboarding checklist so logins don't stay live indefinitely.

How To Stop It Proliferating Again

A cleanup without a process fix is a temporary reset. Try the following ways to prevent it from happening again:

  • Build a genuine fast lane for low-risk, low-value purchases, so small requests don't face the same review as major platforms. 
  • Give people one simple, visible way to request new software, with procurement, security, and finance looped in automatically behind the scenes. 
  • Run a recurring audit every quarter or two to catch shadow IT sprawl while it's still small, rather than leaving it to build for years until an audit forces the reckoning.

None of this stops shadow IT completely, but it keeps the gap small enough to manage rather than letting it quietly become someone else's emergency.

The Wider Problem With Isolated Purchases

A shadow IT audit has a habit of surfacing a wider truth: fragmented, unmanaged spend rarely stops at software. The same pattern shows up across office supplies, shipping, and a dozen other indirect categories, purchased in isolation, at full price, with nobody negotiating on the company's behalf. 

That's the exact gap a GPO like Una is built to close, bringing pre-negotiated contracts and centralized visibility to the categories a lean procurement team simply doesn't have the bandwidth to chase down one subscription at a time.

Contact us to learn more.

In this Article
Primary Item (H2)