How to Audit Your Software Stack in a Week: A Finance Playbook
Every finance team says they should audit their software stack. Almost none do it more than once a year, and half of those first attempts stall out at week three when the spreadsheet gets too big. The audit is not hard. It is boring, mechanical, and requires ignoring a lot of noise. Five days, one owner, three data sources.
What is the goal of a SaaS audit?
A software audit is not an inventory exercise. Inventory is a byproduct. The goal is a ranked list of vendors with a decision on each: keep, cancel, downgrade, renegotiate, or investigate. Everything else the audit produces is in service of that list.
Three outputs matter:
- A complete vendor list. Every recurring software payment, from any source.
- Utilization per vendor. Active seats or usage divided by paid seats or capacity.
- A ranked action list. Sorted by dollar impact, with one owner per action.
If the audit ends with a spreadsheet but no decisions, it did not happen.
What data do you need before day 1?
You need admin or reporting access to three systems. Get access rights sorted the week before, not day-of, because provisioning delays are the most common reason the audit slips to two weeks.
- Accounting system. QuickBooks, NetSuite, Xero, or equivalent. Access to vendor bill history for the last 12 months.
- Corporate card provider. Brex, Ramp, Airbase, or your bank card. Access to card statements for the last 12 months.
- Identity provider. Okta, Google Workspace, Entra. Access to the app inventory and last login timestamps.
Optional but valuable: your GRC or security tool for the officially tracked vendor list, and your procurement system for open POs.
The audit will not fail because you missed one of these. It will fail because you tried to substitute one of them (usually a spreadsheet from IT) and it was three months out of date.
The five-day audit schedule
| Day | Focus | Output |
|---|---|---|
| 1 | Data pull | Three raw exports in one folder |
| 2 | Reconciliation | One merged vendor list with source, amount, frequency |
| 3 | Utilization | Login and seat counts joined to the vendor list |
| 4 | Categorization | Every row tagged owner, category, decision candidate |
| 5 | Recommendations | Ranked action list with dollar impact |
One owner, five days, one deliverable. Anything you can defer to week two, defer.
How do you reconcile the three data sources?
Day 2 is the hardest day because vendor names never match across systems. "Zendesk, Inc." on your AP export is "ZENDESK*SUPPORT" on your card statement and "zendesk.com" in Okta. Three techniques handle 95% of the matching.
- Domain-based match. Extract the vendor domain from each source (from the payment memo, the merchant name, or the SSO app URL). Match on domain.
- Fuzzy string match. For anything the domain match misses, run a simple string-distance match. This catches "Docusign" versus "DocuSign, Inc." level differences.
- Manual review of the top 30. For any vendor above $10K annual, verify the match by hand. This is where all the money is; getting it wrong once costs more than the whole audit takes.
Anything charging in AP or on cards but not in the identity provider is either a headless tool (no user login, like a data pipeline) or shadow IT with individual accounts. Both need investigation but for different reasons.
What utilization metric actually matters?
Utilization is not seats provisioned. It is seats used in the last 90 days.
- For per-seat SaaS. Active users in the last 90 days, from the SSO login report or the tool's own admin console. Divide by paid seats.
- For usage-based SaaS. Actual consumption (API calls, storage, compute) in the last quarter, compared to committed capacity.
- For flat-fee SaaS. Was the tool logged into at all in the last 30 days? If not, the tool is a cancellation candidate regardless of price.
Anything under 40% is a downgrade candidate. Under 20% is a cancel candidate unless someone will actively defend the seats. The 90-day window matters because 30-day windows miss part-time users and 180-day windows include people who left.
How do you rank the action list?
Sort by projected annual savings, but weight by ease of execution. A common rubric:
- Easy cancels. Utilization under 20%, contract billing monthly, no business owner willing to defend it. Cancel this quarter.
- Downgrades. Utilization 20 to 60%, per-seat pricing, renewal in the next two quarters. Reduce seats at renewal.
- Renegotiate candidates. Utilization variable, but priced above benchmark, or renewing this year with material size. Prepare the negotiation brief.
- Consolidation candidates. Two or more tools with functional overlap. Pick one, plan the migration.
- Keep. Utilization above 70%, priced fairly, business critical.
The top 20 items by dollar impact will drive 80% of realized savings. Do not spend day 5 on the long tail; put it in a backlog and revisit at the next audit.
Who owns each action after the audit?
The audit ends when every action has a named owner and a date. Not "finance" or "IT." A person.
- Cancel actions. Owned by the finance owner who ran the audit. They cut the contract or notify the vendor.
- Downgrade and renegotiate actions. Owned by whoever owns that vendor at renewal, usually the business owner with finance in support.
- Consolidation actions. Owned by the head of the function using the tools, with a due date at the earlier of the two renewals.
- Investigate actions. Owned by the finance owner, with a two-week due date to convert to one of the above.
If a row has no name and no date, it is not an action. It is a note.
What does the audit report look like?
The final deliverable is short. Five pages, plus the underlying spreadsheet.
- Page 1. Executive summary. Total spend, count of vendors, dollar value of cancel, downgrade, renegotiate.
- Page 2. Top 20 actions ranked by dollar impact, with owner and date.
- Page 3. Category breakdown. Where the money is by function.
- Page 4. Shadow IT summary. What was found that finance did not know about.
- Page 5. Recommended cadence going forward.
The report is for the CFO and the exec team. The spreadsheet is for the person executing. Do not conflate them.
The mistake to avoid
Most finance teams turn the audit into a research project. They build a beautiful vendor taxonomy, spend two weeks debating category names, and never make it to the actions page. The audit is not the goal. The action list is the goal. Everything else is scaffolding. Do it in a week or do not do it, because a three-month audit is stale before it lands and the stack has already drifted by another 6%.
Frequently asked questions
Who runs the audit?
One finance owner, usually FP&A or the controller, with a light dotted line to IT for the SSO pull. It is not a cross-functional project. A committee will slow it from one week to one quarter and produce a worse result. Business owners are only pulled in for the last day when reviewing recommendations.
What tools do you need to run the audit?
Zero net-new tools. You need admin access to your accounting system, your corporate card provider, and your identity provider. A spreadsheet handles the reconciliation for up to about 60 vendors. Past that, dedicated vendor spend software pays back in the first cycle.
What if we do not have SSO?
The audit still works but takes longer and finds less. Without SSO you cannot measure utilization directly, so you fall back on billing frequency and asking business owners. Expect the audit to find 60 to 70% of what a full audit with SSO would find. Getting SSO rolled out is the highest-ROI prep for the next audit.
How often should you audit the stack?
Full audit annually, tied to budget season. Quarterly refresh on the top 20 vendors by spend. Monthly discovery scan on new card charges and new SSO apps. The full audit becomes cheaper each year because the baseline is already clean.
What savings should we expect in the first audit?
Cancelable spend in a first audit is usually 15 to 25% of total SaaS. Another 10 to 15% is renegotiable at renewal. For a company at $2M annual software spend, that is $500K to $800K identified in the first cycle. Realized savings depend on execution, but 60 to 70% of identified savings typically land in the first year.
See every renewal 90 days out
Bryorex pulls contracts, invoices, and SSO logins into one calendar so nothing auto-renews without a decision.
Request early access