SaaS Sprawl: Root Causes, Hidden Costs, and How to Fix It
Governance
All articles
13 July 2026 8 min read0 comments

SaaS Sprawl: Root Causes, Hidden Costs, and How to Fix It

The average company runs 130+ apps. Here's why SaaS sprawl happens and the systematic approach to bringing it back under control.

SaaS sprawl — the uncontrolled proliferation of software subscriptions across an organisation — is now the default state rather than the exception. The average company with 100–500 employees runs between 100 and 175 distinct SaaS applications. Fewer than 60% of those were formally approved by IT.

Root Causes

Sprawl emerges from the intersection of three trends. First, SaaS procurement is increasingly decentralised — individual contributors can sign up for free tiers that convert to paid subscriptions without ever involving IT or Finance. Second, free tiers and short trials lower the barrier to adoption so far that trying a tool feels consequence-free. Third, most organisations have no effective discovery mechanism, so the problem compounds invisibly until a finance audit or a security incident surfaces it.

The Hidden Costs

The obvious cost is the subscription fees for unused or duplicated tools. But there are less visible costs: the security risk of ungoverned apps processing company data, the compliance exposure of tools your DPO hasn't reviewed, the integration debt of tools that connect to your core systems without proper oversight, and the productivity cost of employees managing their own tool stack rather than using a coherent set of approved solutions.

The Fix

The solution is not a one-time audit — it's a sustainable governance programme. Discovery (knowing what's being used), approval (a fast enough process that people don't bypass it), and periodic review (removing tools that no longer earn their cost) are the three ongoing activities that keep sprawl from returning.

Quantifying the Sprawl Problem

Before you can fix SaaS sprawl, you need to know its scale. Run a full discovery exercise across all three channels — SSO logs, financial data, and browser-based discovery — and count the total number of distinct tools in use. Cross-reference against your approved software list to calculate the shadow IT percentage. Then group tools by category and identify the number of categories with more than two tools. These two numbers — shadow IT percentage and duplicate category count — are your baseline metrics for measuring sprawl reduction over time.

In most organisations running this exercise for the first time, the shadow IT percentage is 35–50% of total tools in use, and there are 5–10 categories with significant tool duplication. This is the scale of the governance gap that needs to be closed — useful context for building the business case for a sustained SaaS management investment.

Prioritising the Cleanup

With a full discovery list in hand, prioritise cleanup by annual cost and risk rather than trying to address every tool at once. Start with the highest-cost duplicate categories — where two or more tools do the same thing and the consolidated saving is largest. Then address the highest-risk ungoverned tools — those that process sensitive data without a signed DPA or security review. Then work through the longer tail of low-cost, low-risk tools that are simply cluttering the inventory.

A realistic cleanup timeline for a company with significant sprawl is 6–9 months for the first meaningful reduction, and 12–18 months to reach a well-governed state. Set quarterly milestone targets — a 20% reduction in shadow IT percentage per quarter — and report against them to maintain momentum and leadership engagement.

Preventing Sprawl from Returning

The governance structures that prevent sprawl are the same ones described throughout this article: a fast approval process, a pre-approved software catalogue, regular discovery cycles, and clear ownership for periodic reviews. But culture matters as much as process. Organisations where employees understand why governance matters — data security, compliance obligations, cost efficiency — comply more readily than those where governance feels arbitrary.

Invest in the "why" communication alongside the "what" process design. Share the results of your discovery exercise (anonymised) with the broader organisation: "We found 85 tools you weren't aware of, including six that were processing customer data without Data Processing Agreements. Here's what we're doing about it and how you can help." Transparency about the problem and the solution builds the employee partnership that makes governance sustainable.

Share X / Twitter LinkedIn

See Liceo in action

Track every licence, cut waste, and automate renewals — in one platform.

Discussion

Comments are moderated before appearing publicly.

No comments yet. Be the first to share your thoughts.

Leave a comment

Not published. Used for moderation only.

0/3000 characters

Ronke

Liceo product guide · AI assistant

Hi, I'm Ronke, Liceo's product guide. I can help you understand how we bring licence, vendor, and spend visibility together, or walk through plans and integrations. What are you trying to solve today?

Ronke shares verified product info only. For custom quotes or contracts, book a demo.