Request a quote
Emergency SectorsCareers About us Blog Get in touch
NLNederlandsENEnglish
Two colleagues at a table with a laptop between them in a warmly lit office

Shadow IT: not disobedience, a gap in what you offer

Somewhere in your organisation there is a subscription nobody in IT knows about, paid on a personal credit card, with company data in it. That is not an incident. It is the predictable result of a request process that takes longer than the patience of someone with a deadline.

Updated August 2026 8 min read Written by the ITproposal team
Short answer

Shadow IT is any piece of software or service used for work without IT knowing about it. In practice, at an organisation of a hundred people that quickly amounts to a few dozen subscriptions.

It almost never comes from defiance. It comes from someone needing something, IT taking four weeks, and a credit card being in the drawer. The cause is the lead time, not the people.

The problem is not the tool but what is missing around it: no data processing agreement, no backup, no offboarding, and nobody who knows it exists when it goes down.

What it is and why it appears

Shadow IT is any piece of software, storage or service used for work without the IT organisation knowing about it. A project planner a team bought for itself. A file-sharing service the marketing department keeps its imagery in. A forms service that job applications arrive through. An AI assistant on a personal account.

The picture that goes with it is one of staff circumventing the rules. That picture is rarely right. What actually happens is this: someone needs something, requests it, hears that an assessment and a procurement round are attached, looks at the date the project has to be finished, and solves it themselves for nine euros a month.

Seen that way, shadow IT is not a behaviour problem but a measurement. It measures the gap between what people need and what they can get in time through the official route. An organisation with a lot of shadow IT does not have disobedient staff; it has a request process too slow for the work that depends on it.

That also explains why clearing up without addressing the cause does not work. Switch everything off and something new appears within six months — only better hidden, because now everyone knows it is being watched.

What actually goes wrong

The tool itself is usually not the problem. What is missing is everything that would normally stand around it.

  • There is no data processing agreement. If personal data is in it — client names, applicants, sickness reports — then under the GDPR you are responsible for processing you have no agreement about. That is a shortcoming you cannot repair on the day someone asks about it.
  • There is no backup. Not because the service lacks one, but because nobody on your side has checked. If the supplier folds or the account is lost, the content is gone and your recovery plan says nothing about it.
  • Offboarding passes it by. You disable someone's account in your own environment and assume they are out. The subscription in their name, created with their personal email, keeps working — including the files in it.
  • Nobody knows it exists. You find out when it goes down. Then a team is at a standstill with a service that has no contract, no contact and no support arrangement, and it lands at a service desk that knows nothing about it.
  • The payment is on a personal card. When the person leaves, so does the payment. Usually you discover that at the moment the service is cut off.

There is a side to this that gets mentioned less often: duplicate spend. In nearly every inventory we run, two or three departments turn out to hold their own subscription to something that could have been bought once, or to something already included in the licences that were there anyway.

How to map what is running

You do not need to buy a separate product for this. The information already sits in four places you probably have, and together they cover most of it.

  • Your identity provider. If someone signs in to a service with their work account, that is recorded. The enterprise applications overview in your environment is therefore your best single source, and it is already there.
  • Outbound traffic. Your firewall or network management sees which services are being connected to. That produces noise, but the recurring names stand out.
  • The books. Search expense claims and credit card statements for amounts between five and a hundred euros that recur monthly. This is the dullest source and often the most productive.
  • Just ask. One round of team leads asking "what do you use that we might not know about" yields more than a scan, provided it is clear that the answer will not cause trouble. That last part is the condition, and it is not optional.

Expect the list to be longer than you thought. At an organisation of a hundred people a few dozen services is normal, and most of them are harmless. That is precisely why you need the list: without an overview you cannot tell which three matter.

What you do with the list

There are three outcomes per service, and the split between them is almost always skewed in the direction people do not expect.

  • Adopt it. The service does the job, it is genuinely used, and there is nothing wrong with it beyond having been out of view. Move it to a business account, arrange the data processing agreement, connect sign-in to your own identities and put it in the records. This is the outcome for most of the list.
  • Replace it. Something in your existing licences already does the same thing. Then the conversation is not "this is not allowed" but "this is already included and we will set it up for you". Without that second half it will not work.
  • Switch it off. It holds data that does not belong there, or the supplier cannot be assessed. This is the smallest category, and the only one where you take something away without giving something back. So do it last, and with a date and an alternative attached.

What you record in all three cases is who owns it on your side. Not IT — the department that uses it. IT manages the access and the contract; whether the service is still needed belongs to whoever works with it. That is the same division of roles as under service governance.

Why it comes back if you only clear up

An inventory is a snapshot. If the cause stays in place, the list is full again a year later, and that is not a failure of the clean-up but the predictable outcome.

One thing makes the difference: the lead time on a request. As long as someone with a deadline has to wait four weeks for an answer, the credit card stays faster. What we see organisations that keep a grip on this actually do:

  • A short route for small things. Under a certain amount and with no personal data: an answer within a week, one page, no procurement round. Save the heavy assessment for where it belongs.
  • A list of what is already allowed. Someone who can look up that the service they want is already approved asks for nothing and gets to work. That is a gain for both sides.
  • No is allowed, but with an alternative. A refusal without a replacement is the direct cause of the next round of shadow IT. That is not a threat, it is what happens.
  • Look again twice a year. A half-yearly round of the same four sources costs half a day and keeps the list accurate.

One category is growing fastest and belongs here for the same reason: AI assistants on personal accounts. That is shadow IT in its purest form — no subscription, no invoice, no trace — and the approach is the same: make sure there is an approved way before you try to close the unwanted one. That is worked out further in AI in the workplace.

Frequently asked

Questions we get about this

The ones that come up most often once this is on the table.

How much shadow IT is normal?

At an organisation of a hundred staff we typically find a few dozen services that are not in the records. That sounds alarming and usually is not: most of it is a planner, a design tool or a small conversion service with no personal data in it. The question is not how many there are but which three of them hold data that does not belong there. Without an inventory you cannot draw that distinction, and then the discussion becomes a matter of feeling.

Do we have to switch off everything we find?

No, and for us that is usually the smallest category. Most services are fine and were merely out of view; you adopt those onto a business account with a data processing agreement attached. Some can be replaced by something already in your licences, and then the offer to set it up belongs with it. You switch off where data is held that does not belong there — and even then with a date and an alternative, because otherwise it comes back in another form.

How do we find what is running without buying a separate product?

With four sources you probably already have. Your identity provider shows which services people sign in to with their work account. Your firewall sees what is being connected to. The books show small monthly amounts on expense claims and credit cards. And a round of the team leads often yields the most, provided it is clear that an honest answer will not cause trouble. Together those four cover most of it.

Who is responsible for a service a department bought itself?

Under the GDPR the organisation is the controller, regardless of who pressed the button. That is exactly why "the department did that themselves" is not a defence towards a regulator or a client. In practice we put ownership with the department using the service — they judge whether it is still needed — and management of access and contract with IT. Both on paper, because an owner who is written down nowhere is not an owner.

Related services

Where this sits with us

The services this subject falls under.

Want to know what runs out of view at your place?

An inventory across those four sources costs half a day and produces a list that is yours, even if you do nothing further with it.

Practical IT knowledge in your inbox

New guides on management, security and the workplace, written by the people doing the work. No sales talk, and you can unsubscribe in one click.

We use your address for the newsletter only. Privacy policy.