Montro
SaaS Intelligence14 min read

Your SaaS Spend Hides Your Shadow AI Exposure: A CFO's Blind Spot

Your SaaS Spend Hides Your Shadow AI Exposure: A CFO's Blind Spot
AuthorAnkur Arora
Published on2 Mar 2026

Finance already has the best shadow IT signal in the organisation. Most CFOs just are not reading it that way.


Expense reports, credit card statements, and invoice data contain a near-complete picture of what employees are actually paying for, including the AI tools they subscribed to on company cards without going through IT, the SaaS tools three people in operations adopted six months ago, and the ChatGPT Plus subscriptions that show up as $20 line items under 'miscellaneous software.'


Individually, each of these looks trivial. Aggregated across a team or a business unit, they add up to a shadow IT exposure that most organisations have never explicitly quantified, and that is becoming a governance liability faster than most finance functions have recognised.


The connection between SaaS spend visibility and shadow AI governance is not a technology problem. It is a data interpretation problem. The spend data Finance already holds is an AI inventory, it just has not been read as one.


What the Expense Data is Actually Telling You


Pull three months of company card transactions and invoice data for any mid-market organisation and you will find the same pattern: a long tail of small SaaS subscriptions, most of them under £50 per month per seat, spread across dozens of vendors, approved by line managers who did not think to flag them to IT because individually they looked insignificant.


Run the same data through a different lens - which of these vendors offer AI features, which are AI-native tools, which are processing company or customer data, and the picture changes materially. What looked like a £400-per-month miscellaneous software line becomes a set of unreviewed AI tools processing sales data, customer communications, and internal documents without any data processing agreements in place, without any entry in the Article 30 record of processing activities, and without any of the governance that the EU AI Act will require from August 2026.


This is the CFO's shadow IT blind spot. Not the tools IT does not know about, Finance often has those in the expense data already. The blind spot is the failure to read that spend data as a governance signal rather than just a cost figure.


Why SaaS Spend Visibility and Shadow IT are the Same Problem


SaaS management started as a spend discipline: find the unused licences, eliminate the duplicates, renegotiate the renewals. Those are still legitimate objectives. But the saas inventory problem has changed character since AI features became standard in most SaaS products.


When an employee signs up for a project management tool on a company card, that subscription appears in the expense data. When that same tool ships an AI summarisation feature six months later, the subscription price may not change, the line item in the expense report looks identical, and the AI processing begins running on company data without any additional procurement event. The spend data captures the tool. It does not capture the AI activation. The gap between those two is where shadow IT becomes shadow AI.


Gartner estimates that 30% or more of enterprise software spend represents waste, licences for tools that are unused, duplicated across departments, or no longer needed. That same visibility gap that produces licence waste is also the gap that produces an incomplete saas governance picture. An organisation that cannot tell you which SaaS tools are actively in use cannot tell you which of those tools have active AI features, which are processing personal data, or which are creating regulatory exposure under GDPR, DORA, or the EU AI Act.


The Financial Exposure Finance is Not Quantifying


Most CFOs who have looked seriously at their SaaS spend have focused on the cost side: how much is wasted on unused licences, where are the duplicate tools, which renewals can be renegotiated. These are real savings. But they are the smaller part of the financial exposure.


The larger exposure sits in the regulatory risk that ungoverned SaaS and shadow AI creates. A single unsanctioned AI tool processing customer data without a data processing agreement is a GDPR liability, fines up to €20 million or 4% of global turnover for the most serious violations. If the organisation is in financial services, the same tool may be an undocumented ICT service arrangement under DORA, with its own enforcement exposure. And from August 2026, AI tools falling into high-risk categories under the EU AI Act carry their own set of deployer obligations that cannot be satisfied for tools the organisation does not know it is running.


Finance is already doing most of the data collection required to assess the governance exposure. Tracking SaaS spend for cost reasons produces the same underlying dataset; vendor names, subscription values, renewal dates, business unit attribution - that a governance classification exercise starts from. The additional step is the classification layer: reading what is in the spend data against regulatory risk rather than just against budget. That is not a finance function. But the foundation for it sits in Finance's systems already.


Why Finance and IT are Reading the Same Data Differently


The reason most organisations have not connected their SaaS spend data to their shadow IT exposure is not a technology gap. Finance owns the expense data and reads it as a cost report. IT owns the application inventory and reads it as a security and operational concern. Neither team is systematically asking the question that sits between their two views: which of the tools in the spend data are AI tools, what are they doing with company data, and what governance obligations does that create?


It gets asked first by a CFO who has just watched a peer take a regulatory fine, or a CISO handed a DORA compliance project. At that point the spend data becomes considerably more useful. Cross-referenced against a SaaS governance framework that classifies applications by data sensitivity, AI capability, and regulatory obligation, it stops being a cost report and starts being a risk register.


The CFOs who have made this shift describe the same experience: the spend data they already had contained most of what they needed. What was missing was the classification layer, the ability to look at a £20 ChatGPT Plus subscription and understand that it represents an ungoverned AI tool processing work data on a consumer account, with no DPA, no Article 30 entry, and no EU AI Act classification. That classification does not come from the expense system. It comes from combining the spend data with an application taxonomy that understands what each tool does and what governance it requires.


What the Spend Data Covers - and Where It Stops


Expense and invoice data gets you further than most CFOs expect when used as a shadow IT discovery signal. It captures tools employees paid for on company cards, subscription renewals that went through accounts payable, and vendor invoices that IT never reviewed. In many organisations, that covers 40–60% of the actual SaaS estate, the portion that went through some form of financial process, even if not a formal procurement one.


What it cannot capture is the portion that cost nothing to adopt. Free-tier tools, browser extensions, personal account sign-ups where the employee used their own payment method, none of these appear in company financial data. Harmonic Security's Q3 2025 analysis found that 11.84% of sensitive data exposures occurred through personal or free-tier AI accounts, none of which would appear in any expense report or invoice system.


This means spend data is the right starting point for a SaaS inventory exercise, not the complete answer. It surfaces the tools with a financial footprint. The tools without one; the free-tier AI applications, the personal account sign-ups, the browser extensions, require additional discovery signals: SSO logs, email metadata, browser telemetry. Finance's expense data is the fastest and most accessible signal to start with, but treating it as comprehensive misses a meaningful slice of the exposure, specifically the slice that tends to involve the most sensitive data.

The CFOs I speak to who have a good SaaS spend visibility all describe the same experience when they first run that data through a governance lens. They only expected to find a handful of AI tools, but ended up finding fifty. This happened not because the employees were hiding something, but because a €20 line item under the miscellaneous software does not look like a governance decision.


What surprises people most is not the volume, it is how long the tools have been running in the organisation. Six months, a year, sometimes longer; processing customer data, employee records, internal documents - under no DPA, with no Article 30 entry, and no one in legal or compliance was aware that the tools existed. The spend data had it all, and nobody had asked it the right question. - Ankur Arora, Co-Founder, Montro

What a CFO Needs from a SaaS Management Programme


Spend visibility and licence optimisation are table stakes now. Every tool in the SaaS management category offers some version of both. What most do not offer, and what the regulatory environment now demands, is a programme that connects the spend data to the governance question sitting inside it.


Specifically, a programme that is fit for purpose in 2025 needs to answer four questions that a cost-only approach cannot:


  • Which tools in our SaaS estate have active AI features, not just which tools were procured as AI tools, but which have gained AI capabilities since they were adopted?
  • Which of those tools are processing personal data, and do we have data processing agreements in place that cover the AI processing specifically?
  • Which tools fall into regulated categories under the EU AI Act, DORA, or GDPR, and which obligations does that create for us as the deployer?
  • What is the complete SaaS inventory, not just what appears in procurement and expense data, but what is discoverable through SSO logs, email metadata, and browser signals?


A SaaS management programme that answers these four questions is doing software inventory management for 2025, not 2020. The CFO who commissions this work is not doing an IT project. They are building the financial and governance foundation that every other compliance programme in the organisation needs to work from.


Frequently Asked Questions


Why does Finance have better shadow IT data than IT?


Because shadow IT usually has a financial footprint before it has an IT footprint. An employee who adopts a SaaS tool without going through IT often pays for it on a company card or gets it expensed. That transaction appears in Finance's data before IT ever knows the tool exists. The limitation is that free-tier tools and personal account sign-ups leave no financial trace, but for the portion of shadow IT that costs money, Finance typically has the earliest and most complete record of it.


How do I turn expense data into a shadow IT inventory?


Start by pulling three to six months of company card and invoice data and filtering for software and subscription vendors. Cross-reference each vendor against a taxonomy that identifies which are SaaS tools, which have AI features, and which category of data they typically process. What emerges is a working list of tools that went through a financial process without going through IT review, which is the definition of shadow IT with a cost footprint. This is not a complete SaaS inventory, but it is the fastest starting point for one and requires no new tooling to produce.


What is the regulatory risk of ungoverned SaaS spend?


Ungoverned SaaS spend creates compounding regulatory exposure across frameworks, and the frameworks stack. For any organisation processing personal data, ungoverned SaaS tools are likely undocumented processors under GDPR Article 28, creating liability without a breach needing to occur. For financial services firms, unregistered ICT service arrangements violate DORA Article 28.3. From August 2026, ungoverned AI tools in high-risk categories create EU AI Act deployer exposure. Each framework has its own fine tier, but the more significant point is that the same ungoverned tool typically violates multiple frameworks simultaneously, the regulatory risk does not add, it compounds.


Can SaaS governance be a CFO-led initiative rather than an IT one?


Yes, and increasingly it needs to be. The regulatory frameworks driving the urgency - DORA, GDPR, the EU AI Act, all have financial consequences that land on the organisation's balance sheet, not just on IT's operational metrics. A CFO who owns the saas governance initiative has access to the spend data that makes discovery faster, the budget authority to commission the work properly, and the reporting line that makes the findings actionable at board level. IT provides the technical execution. Finance provides the mandate and the data.


What is the difference between SaaS spend management and SaaS governance?


Spend management answers: what are we paying for, is it being used, can we pay less? Governance answers: what are we using, what does it do with our data, and are we compliant in how we use it? The two start from the same data, the SaaS inventory, but draw different conclusions from it. Most organisations have some form of spend management. Very few have extended it into governance, which means they have the foundation but have not built the structure on top of it. The tools that were adequate for spend management alone are not automatically adequate for governance, governance requires the AI classification layer, the regulatory mapping, and the continuous discovery that spend management never needed.

Ankur Arora

Ankur Arora

Co-founder

Fifteen years of enterprise digital transformation across telecoms, media, consumer goods, and agriculture - and a front-row seat to AI adoption outpacing governance at every organisation he worked in. He built Montro so the next firm doesn't have to learn that lesson the hard way.

Blog

Read next

Explore more from our library

View all
M&A and SaaS Due Diligence In The AI Era
SaaS Intelligence10 min read

M&A and SaaS Due Diligence In The AI Era

Your due-diligence playbook lists 60 SaaS contracts. The target firm has 200 SaaS tools in active use. The 140 you didn't see in the data room are coming with the deal. So are the…

Read article

Stay informed on EU AI governance

Monthly updates on regulatory changes, compliance trends, and platform releases

By subscribing you agree to our Terms and Conditions and Privacy Policy

Montro AI governance dashboard showing tool risk tiers