The Number on the Invoice That Wasn’t in the Model

Q3 2025. A PE-backed healthcare platform acquires a regional clinic network for £85M. Finance models the synergy case: £12M in procurement savings from license consolidation.

Six months post-close, the integration team finds:

The procurement synergy case reversed: not £12M in savings, but a £5.4M liability to unwind and restructure.


What Shadow IT Actually Is

1. Contractual liability: Contracts signed by business units without legal review, often with auto-renew clauses and penalties for early termination.

2. Seat allocation inaccuracy: The license count reflects current seats, not actual users. Contractors who left 6 months ago. Deactivated accounts that still appear in the license count.

3. Duplicate functionality: Two departments running Jira and Asana. Marketing running HubSpot and Marketo and an instance they stood up in 2021 that nobody remembers.

4. Forgotten renewals: Trials that auto-converted. Annual commitments signed by someone who left the company.


Why Due Diligence Doesn’t Find Shadow IT

Standard IT due diligence asks: “What SaaS contracts do you have?” The target answers from their vendor management system or finance record.

The problem is that shadow IT by definition isn’t in those systems. It’s in:

To find shadow IT, you need to look at signals that aren’t in the IT questionnaire: API integration logs showing which SaaS apps are authenticating against the directory, browser extension telemetry, license assignment data from directory systems.


The Shadow IT Risk Register

CategoryRiskTypical Finding
Auto-renew contracts past notice windowFinancial£40K-500K in uncancellable commitments
Duplicate SaaS platformsOperational20-40% licensing waste
Contracts without IT governanceSecurityUnpatched SaaS with company data
Personal account credentials for work toolsComplianceGDPR/CCPA exposure

Discovery sprint available for acquisitions in progress. 48-hour turnaround. Request shadow IT assessment.