Costanalyst
Blog / Playbooks 9 min read

How to Audit SaaS Spend - A One-Week Best-Practice Checklist

July 2026 · Costanalyst

Spend Console
Sample data
Connected AWS GCP Azure SaaS
Find savings in
Identified

projected this month if unattended

Spend by team

Budget forecast

Projected EoQ $124k
With savings
Read-only · Sample data

To audit SaaS spend, pull every source of software payments (corporate card feed, AP ledger, expense reports, SSO logs), build one inventory of applications with owner, cost, renewal date and contract terms, then measure real seat utilization against what you pay for. Rank the findings in dollars, cancel or downgrade before the next renewal date, and convert the audit into a monthly review so the waste does not grow back. A first pass on a company with 40 to 200 applications usually takes a finance or IT analyst about a week, and most of that week is spent on data collection rather than analysis.

What follows is the sequence a US finance or IT team can run start to finish, with the steps in the order that produces the fastest dollar result.

What is a SaaS spend audit?

A SaaS spend audit is a structured review of every software subscription a company pays for, checking who owns it, who uses it, what it costs annually, when it renews, and whether the contract terms still match how the tool is used. It differs from a general expense review because it treats each subscription as a recurring contract with a renewal deadline, not a one-time charge.

The output is not a report. The output is a ranked list of actions with a dollar value and a date attached to each: cancel this, downsize that from 250 seats to 160, consolidate these two overlapping tools at the March renewal. If your audit ends in a spreadsheet nobody acts on, the exercise cost you a week and saved nothing.

How do you find every SaaS subscription the company pays for?

You find every subscription by combining four independent data sources, because no single one is complete. Card and AP data show what you pay but miss free tools and mislabel resellers. SSO logs show what people log into but miss anything bought outside identity. Expense reports catch personal-card purchases. The vendor and contract file shows terms nothing else records.

Run all four in parallel on day one and reconcile them into a single list. The overlap between sources is where the findings live: a tool in the card feed but not in SSO is usually owned by one person with no governance, and a tool with 300 active users on a 120-seat contract is a true-up exposure.

Data sourceWhere it comes fromWhat it revealsWhat it misses
Corporate card feedAmex, Brex, Ramp, Chase business card statementsMonthly and annual charges, the long tail of small tools, exact amounts and billing datesCharges routed through a reseller or marketplace, anything paid by invoice or ACH
AP ledger / GLQuickBooks, NetSuite, Bill.com, your software expense accountsLarge invoiced contracts, annual prepaid renewals, who approved the paymentCard-funded subscriptions coded to a generic expense account, purchases under approval thresholds
SSO / identity logsOkta, Entra ID, Google Workspace app access reportsActual login activity per user per app, apps nobody told IT about, departed employees still provisionedTools with local logins and no SSO, which is most of the cheap long tail
Expense reportsExpensify, Ramp, Concur reimbursement linesShadow IT bought on personal cards and reimbursed, usually the riskiest categoryAnything an employee paid for and never expensed
Contract and vendor filesSigned order forms, MSAs, procurement emailTerm length, auto-renewal clause, notice period, price escalators, seat minimumsVerbal or click-through agreements with no filed document

Reconciling five sources by hand is where most audits stall. Pulling the billing feed automatically and normalizing vendor names is exactly the job that SaaS spend management tooling exists to do, and it turns a two-day merge into a filter. The same principle applies on the receipt side, where software that reads receipts and categorizes them automatically stops reimbursed subscriptions from disappearing into a "miscellaneous" bucket.

What should a SaaS spend audit checklist include?

A complete checklist covers seven items per application: internal owner, annual contract value, billing frequency, contracted seats, active seats in the last 30 days, renewal date, and cancellation notice period. If you only have capacity for three fields, use annual cost, active seats, and renewal date, because those three drive every decision you will make.

  • Owner. A named person, not a department. Unowned tools never get cancelled.
  • Annual contract value. Normalize everything to a yearly number so a $49 per month tool and a $38,000 annual contract sit on the same scale.
  • Contracted vs active seats. The gap is your immediate savings target.
  • Renewal date and notice period. A 30 or 60 day notice window is what makes a cancellation possible or impossible.
  • Tier and entitlement. Whether you are on a plan whose features you actually use.
  • Data sensitivity. Which tools hold customer data, since those need a security review before renewal anyway.
  • Overlap tag. The category the tool belongs to, so duplicates surface when you sort.

How do you measure whether SaaS seats are actually being used?

Measure utilization as active seats divided by contracted seats over a rolling 30 day window, using the vendor's own admin export as the primary source and SSO login data as the cross-check. Anything below 70 percent utilization is a downsize candidate at renewal. Anything below 40 percent usually means the tool was bought for a team that never adopted it.

Define "active" before you start, and be strict about it. A user who logged in once in 30 days is not an active user of a $60 per seat per month tool. Most vendor admin panels expose a last-active date per user; export it, join it to your HR roster, and three categories fall out immediately: departed employees still holding licenses, employees who never logged in after provisioning, and employees who use the tool weekly. Only the third group justifies a paid seat. Tracking that continuously rather than once a year is the core of SaaS license management.

Departed-employee seats are the single most common finding. Offboarding usually removes SSO access, which stops the login, but does not remove the billable seat inside the vendor. The company keeps paying for a license nobody can even use.

How do you find duplicate and overlapping SaaS tools?

Group every application by function (project management, design, e-signature, video, note-taking, BI, customer support) and look for any category with more than one paid vendor. Overlap is almost never intentional. It happens when two departments buy independently, or when a team keeps a legacy tool running after a company-wide standard is chosen.

Two project management tools can be legitimate if engineering and marketing genuinely work differently. What is rarely legitimate: paying for two e-signature vendors, three video conferencing platforms, or a standalone tool whose entire function is already included in a suite you already pay for. Check the entitlements of your largest contracts first, since the feature you are buying separately is often bundled into a tier you already own.

Why do renewal dates matter more than price?

Renewal dates matter more than price because a SaaS contract you cannot exit is a fixed cost regardless of what you negotiated. Most US SaaS agreements auto-renew for another full term unless you give written notice 30 to 90 days before the anniversary. Miss that window and a tool you decided to cancel in February bills you for another twelve months in March.

Build a rolling 12 month renewal calendar during the audit, and put a reminder at the notice deadline, not the renewal date. Sort it by contract value. The four or five largest renewals in the next two quarters are where negotiation leverage exists, and leverage requires lead time: you need 60 to 90 days to run a usage analysis, get a competitive quote, and tell the vendor you are considering alternatives. Walking into a renewal call the week it expires means paying the uplift.

How do you rank what to cut?

Rank findings by annual dollars saved divided by disruption, and execute in that order. Cancelling an unused tool with zero active users is pure savings with no disruption, so do it first. Downsizing seats is next: it is a contract amendment, not a migration. Consolidating two overlapping tools saves the most but requires a data migration and user retraining, so it belongs on a quarter-long plan.

Put a dollar figure on every line and a date next to it. "Cancel Vendor A, $14,400 per year, effective at the April 12 renewal, notice due March 13" is an action. "Review video tools" is not. The tactical playbook for executing those cuts is covered in more depth in our guide on how to reduce SaaS spend.

What do teams miss most often in a SaaS audit?

The three most commonly missed items are shadow IT bought on personal cards and reimbursed through expense reports, seats belonging to departed employees that offboarding never released, and annual prepaid tools that are invisible when you look only at monthly spend. Each hides in a different place, which is why the multi-source pull at the start is not optional.

Annual prepaid contracts are the sneakiest. If you build your inventory from a single month of card data, every tool billed once a year in a different month is simply absent. You will conclude your software spend is 20 to 30 percent lower than it is. Always work from twelve months of transaction history, never one.

How do you make the audit continuous instead of annual?

Make it continuous by moving the three inputs (billing feed, SSO activity, renewal calendar) into a system that refreshes them automatically, then reviewing exceptions monthly instead of rebuilding the inventory yearly. The monthly review should take under an hour: new vendors that appeared, seat counts that grew, renewals inside the next 90 days, and any month-over-month change above a threshold you set.

An annual audit finds the same waste every year because nothing prevents it from re-accumulating between audits. Continuous monitoring changes the shape of the problem: you catch a new tool the month it first bills, and you catch a seat expansion before it renews at the higher count. Pair it with spend attribution so every subscription has a department attached, which is what cost allocation gives you, and budget owners start policing their own line items. If you are evaluating what to run this on, our comparison of the best SaaS spend management tools covers the practical differences.

The bottom line

Pull twelve months from every payment source, join it to SSO activity and your HR roster, and build one inventory with owner, cost, seats, and renewal date. Cut the zero-usage tools immediately, downsize the underutilized ones at renewal, and plan consolidations a quarter out. Then automate the data collection so the next review takes an hour rather than a week. The first audit usually pays for itself in cancelled seats alone, but the durable win is the monitoring you leave behind.

See where your cloud and SaaS money is leaking

Connect your cloud and SaaS spend read-only and see your savings in dollars. Transparent pricing, no card to start.