Accountability should be shared, but it must be explicit. Procurement should govern buying terms, HR should trigger joiner and leaver updates, IT should manage system visibility and access, and finance should monitor spend and renewal exposure. Cross-functional ownership is what turns SaaS control from a one-time cleanup into an ongoing discipline.
Why This Matters for Security Teams
Unnecessary SaaS spend is rarely just a finance problem. It is usually a control problem created by fragmented ownership: procurement negotiates, HR changes the workforce, IT manages access, and finance sees the bill after the fact. That split is why unused licenses, duplicate tools, and zombie accounts persist. NIST SP 800-53 Rev. 5 treats access and configuration control as ongoing responsibilities, not one-time approvals, which is the right model for SaaS governance as well. NIST SP 800-53 Rev 5 Security and Privacy Controls
The risk is amplified when software purchases are tied to individual teams rather than a shared inventory and renewal process. In NHI Management Group research, only 5.7% of organisations have full visibility into their service accounts, and the same visibility gap often appears in SaaS estates through shadow subscriptions and orphaned access. The lesson is clear: spend reduction depends on identity hygiene, lifecycle discipline, and renewal governance working together. In practice, many organisations discover wasted SaaS only after a renewal is signed or a post-incident access review exposes how many tools were still active.
How It Works in Practice
The cleanest operating model is shared accountability with clear handoffs. Procurement owns buying terms, standard clauses, and vendor consolidation. HR owns the joiner, mover, and leaver triggers that tell downstream systems when access should change. IT owns app discovery, identity integration, and access removal. Finance owns renewal calendar control, budget alerts, and variance review. None of these teams can reduce waste alone.
Practitioners usually get better results when they build one workflow around four controls:
- Inventory first: reconcile contracts, payment records, SSO logs, and directory groups to find duplicate or inactive subscriptions.
- Trigger changes from HR events: joiners, role changes, and terminations should update entitlements automatically, not by ticket alone.
- Enforce access discipline: remove stale accounts, unapproved guests, and shared logins before the next billing cycle.
- Gate renewals: require business owner validation and usage evidence before finance approves auto-renewal.
This is also where NHI discipline helps. SaaS spend often inflates because machine identities, API keys, and service accounts keep SaaS integrations alive long after the business case has expired. NHIMG has documented how secrets and access sprawl create persistent exposure, as seen in the Salesloft OAuth token breach and the BeyondTrust API key breach. Those cases show why access ownership and spend ownership cannot be separated for long. These controls tend to break down in large federated enterprises because no single system contains both contract data and real usage data.
Common Variations and Edge Cases
Tighter spend control often increases process overhead, requiring organisations to balance savings against speed and autonomy. That tradeoff becomes visible in business units that buy SaaS with low-dollar card payments, in M&A environments where tool stacks overlap, and in regulated teams that need rapid procurement exceptions.
Current guidance suggests a few common exceptions need explicit handling. Shared departmental subscriptions should have named business owners, even if finance pays centrally. Sandboxed or short-term tools should use expiry dates and review checkpoints, or they become permanent waste. Employee-owned apps used for work should be classified separately from approved enterprise services so they do not hide under general spend. Best practice is evolving on how much automation to place in procurement versus IT, but the principle is stable: someone must own the approval path, someone must own the access path, and someone must own the renewal decision.
NHIMG’s SaaS governance lessons align with broader identity findings from incidents such as the Snowflake breach, where identity and access visibility became business-critical, not just operationally useful. Organisations that treat renewals as finance-only reviews usually miss the access sprawl underneath, while teams that treat it as IT-only often miss contract lock-in and cost exposure.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
OWASP Non-Human Identity Top 10 address the attack and risk surface, while NIST CSF 2.0, NIST AI RMF and NIST Zero Trust (SP 800-207) set the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| OWASP Non-Human Identity Top 10 | NHI-03 | Unrotated and orphaned access often sustains redundant SaaS spend. |
| NIST CSF 2.0 | PR.AC-4 | Least-privilege access review supports removing inactive SaaS entitlements. |
| NIST AI RMF | AI RMF governance applies to cross-functional accountability and lifecycle oversight. | |
| NIST Zero Trust (SP 800-207) | SC-2 | Zero Trust limits standing access that keeps unnecessary SaaS active. |
Track SaaS-integrated NHI credentials, revoke unused access, and tie renewal reviews to identity cleanup.
Related resources from NHI Mgmt Group
- Who is accountable when AI spend grows faster than revenue and there is no finance-grade metering?
- How do Finance and IT share accountability for SaaS renewals and spend?
- How should security teams reconcile SaaS spend data across finance, contracts, licenses, and usage before renewal decisions?
- Who is accountable when fraud controls fail across registration, deposit, and withdrawal flows?