Editorial note: Tuning Digital runs no active affiliate programmes. This guide was produced with AI assistance and checked against UK regulator and government security guidance. It is general operational information, not legal, security or procurement advice.

A useful SaaS audit produces a reliable inventory and a named next action for every service. It does not begin with an assumed savings percentage or a rush to cancel accounts. Start by reconciling what the organisation pays for, who uses it, what data it handles, when the contract renews and what would break if it disappeared.

This checklist is designed for a first-pass operational review. A short session can surface missing owners, renewal risks and obvious duplication, but it is not a substitute for a full security, data-protection, legal or financial assessment.

SaaS Audit Quick Checklist

Build one inventory from finance, identity, procurement and team records. Assign an owner, normalise the cost, check usage and renewal terms, map data and integrations, then choose a documented action.

  • Discover: reconcile invoices, cards, expenses, SSO, app marketplaces, contracts and department lists.
  • Assess: record purpose, ownership, users, cost, renewal, access controls, data, integrations and logs.
  • Act: keep, right-size, replace, retire or investigate—each with an owner and deadline.

What Should a SaaS Inventory Record?

AreaMinimum fieldsWhy it matters
IdentityService, URL, purpose, department, business owner, administratorShows who can explain and approve its use
CommercialBilling owner, currency, billing cycle, annualised cost, contract end, renewal and notice datesPrevents decisions arriving after a contractual deadline
UsagePaid seats, assigned seats, active-user definition, active users, last checkedSeparates entitlement from measured use
AccessSSO, MFA, provisioning, administrators, service accounts, offboarding routeSurfaces unmanaged identities and access dependencies
DataData categories, personal data, location, processor terms, sub-processors, retention and exportSupports data-protection and exit review
OperationsIntegrations, API keys, critical workflows, logs, alerts, recovery and exit ownerReduces disruption and improves incident readiness
DecisionKeep, right-size, replace, retire or investigate; owner; deadline; evidenceTurns the inventory into controlled work

1. Find the Services

No single source is likely to contain the complete stack. Start with accounts payable, corporate cards, expense claims and purchase orders. Search at least a full billing cycle appropriate to the organisation so annual charges are not missed.

Then compare those payments with the identity provider, SSO catalogue, browser or endpoint app discovery where authorised, procurement records, OAuth-connected apps, departmental lists and any existing information-asset register. Record a service even when its cost is zero: free tools can still hold business or personal data and create access risk.

Do not silently treat every unmatched payment as waste. It may be a legitimate annual service, a usage-based platform, a marketplace charge under a parent vendor or an essential tool with few users.

2. Confirm Owners and Renewal Terms

Assign a business owner who can explain why the service exists and an administrator who controls access. The cardholder or invoice recipient is not automatically the business owner.

Capture the contract end date, automatic-renewal rule, cancellation notice period, committed seats or spend, early-termination terms and the date by which a decision is required. Keep the source document or a link to it. If the terms are unclear or material, route them to the appropriate procurement or legal reviewer.

A renewal reminder should fall before the notice deadline with enough time to collect usage evidence and alternatives. A generic quarterly review is not a substitute for contract-specific dates.

3. Compare Usage and Cost

Normalise each recurring charge into one reporting currency and annual period, while retaining the original currency and billing basis. Separate subscription fees from implementation, support, consumption and tax where the records allow.

For seats, record paid, assigned and active users separately. Define “active” for the service: a login may be meaningful for a daily collaboration tool but misleading for software used only at month-end. Use the vendor's admin data, identity logs and the owner's explanation together.

Calculate the cost of the current commitment and any evidence-based right-size option. Avoid promising a saving until the contract, minimum commitments and operational impact have been checked.

4. Review Overlap Without Forcing Consolidation

Group services by the job they perform, then ask whether two tools truly duplicate one another. Similar category labels do not prove interchangeability. Different teams may rely on distinct workflows, permissions, integrations or records.

For each possible consolidation, document:

  • the users and workflows that would move;
  • required features, data formats and integrations;
  • migration, training and parallel-running effort;
  • accessibility, security and data-protection requirements;
  • contract consequences and total switching cost.

Consolidate only when the replacement meets the requirements and the expected benefit exceeds the change cost and risk. Otherwise, record why both services remain.

5. Check Access, Data and Auditability

The UK National Cyber Security Centre's guidance on using SaaS securely emphasises robust identity, managed access and monitoring. For each important service, check unique user identities, MFA or SSO support, administrator roles, joiner/mover/leaver processes, service identities and whether unused access is removed.

Check which logs and alerts are available, whether they are enabled, who monitors them and how long they are retained. The NCSC's cloud audit guidance says customers should understand the audit information provided, its format and retention, and whether it is sufficient to investigate incidents.

If the service processes personal data, record the purpose, categories, roles, contract, sub-processors, locations or transfers, retention, deletion and exit arrangements. The ICO's current controller–processor contract guidance covers required terms, sub-processors, security, end-of-contract provisions and audits. The ICO notes that this guidance is under review following the Data (Use and Access) Act, so check its status when relying on it.

Scope warning: this inventory helps route questions; it does not by itself establish UK GDPR compliance or security assurance. Escalate material findings to the responsible specialists.

6. Record One Next Action

Use a controlled set of outcomes:

  • Keep: the service is needed and the current commitment is justified.
  • Right-size: retain it but change seats, tier, term or configuration.
  • Replace: move to an approved alternative under a documented migration plan.
  • Retire: exit safely and close the commercial and technical records.
  • Investigate: evidence or ownership is missing; assign a deadline rather than guessing.

Every action needs a named owner, due date and evidence. Record who approved the decision and when it was completed. That audit trail is more useful than a spreadsheet filled with colour but no accountable action.

How to Cancel a SaaS Service Safely

Before cancelling, confirm that the organisation can meet its recordkeeping, contractual, operational and data obligations. A sensible exit checklist includes:

  1. confirm the owner and authorised approver;
  2. review notice, termination, export, retention and deletion terms;
  3. export required records and test that they can be opened or restored;
  4. identify integrations, automations, webhooks, API keys and service accounts;
  5. migrate users, workflows and ownership where required;
  6. revoke access and credentials in a controlled order;
  7. request or verify data deletion where appropriate;
  8. stop billing and retain cancellation evidence;
  9. update the inventory, architecture, processor and recovery records.

Do not delete a service solely because its login count is low. It may hold statutory records, support an infrequent critical process or be required for recovery.

How Often Should You Audit the Stack?

Choose a risk-based cadence. Review before every material notice deadline, and check high-risk, high-cost or rapidly changing services more frequently than low-risk tools. Trigger an extra review after an incident, acquisition, restructuring, major workforce change, new data use or material vendor change.

A spreadsheet is sufficient when it remains complete, controlled and actively owned. A management platform may help when discovery, renewals, access reviews or workflow automation can no longer be maintained reliably by the existing process. Choose from documented requirements rather than an arbitrary subscription count.

Final Checklist

A defensible SaaS audit answers six questions for every service: what is it, who owns it, who uses it, what does it cost, what data and access does it involve, and what happens next?

Start with evidence, not a target saving. Reconcile multiple sources, respect contract deadlines, verify security and data considerations, and document the decision. That produces a stack that is easier to operate and review even when the correct outcome is to keep the service unchanged.

Frequently Asked Questions

What is a SaaS stack audit?

A SaaS stack audit is a documented review of the software services an organisation uses, who owns and accesses them, what they cost, when they renew, what data they handle and whether they should be kept, changed or retired.

How long does a SaaS stack audit take?

A small stack can be inventoried quickly, but a defensible audit takes as long as needed to reconcile billing, usage, contracts, access and data handling. Treat a short session as triage, not a complete security or compliance review.

What columns should a SaaS inventory include?

Record the service, business owner, administrator, purpose, billing owner, annualised cost, paid and active users, contract and renewal dates, notice period, identity controls, data categories, integrations, risk notes and next action.

How often should a SaaS stack be reviewed?

Use a risk-based cadence and review before contractual notice deadlines. High-risk or fast-changing services need more frequent checks than low-risk tools. Recheck immediately after incidents, restructures or material changes in data use.

Should every unused SaaS account be cancelled immediately?

No. Confirm ownership, contractual obligations, data export and retention needs, integrations, records, access dependencies and an exit plan before cancellation. Document the decision and completion evidence.