Join our Newsletter — 33% off our NHI Course

Who is accountable when shadow procurement creates an unmanaged device in the fleet?

Accountability usually sits with the team that owns asset governance, because they are responsible for ensuring purchased hardware enters inventory, is assigned, and is tracked through its lifecycle. Central IT still needs a control process that surfaces unreported purchases quickly. Procurement, finance, and operations should share the same inventory record to prevent gaps.

Why This Matters for Security Teams

Shadow procurement turns a purchase problem into an identity and asset-control problem. When a device is bought outside the approved channel, it can arrive without enrollment, ownership metadata, patch coverage, or logging, which means no one can confidently answer who is responsible when it appears in the fleet. That ambiguity weakens lifecycle governance and delays containment.

Current guidance from the NIST Cybersecurity Framework 2.0 and the Ultimate Guide to NHIs — Regulatory and Audit Perspectives both point to the same operational reality: assets must be discoverable, attributable, and governed through a shared control process. NHI Mgmt Group notes that only 5.7% of organisations have full visibility into their service accounts, which is a useful warning sign for unmanaged device issues too, because the same visibility gap often exists across endpoints and embedded systems.

The immediate risk is not just the device itself, but the control failure that allowed procurement, finance, and operations to diverge on what was bought and who should own it. In practice, many security teams encounter this only after the asset has already connected to the network and created audit, support, or incident-response debt.

How It Works in Practice

Accountability should be assigned to the team that owns asset governance, but effective handling depends on shared controls across procurement, finance, and operations. The owning team is accountable for ensuring every purchased device enters the inventory record, receives an owner, and is tracked through onboarding, use, transfer, and retirement. Central IT, meanwhile, needs detection and escalation controls that surface unreported purchases quickly.

A practical model usually includes:

  • Procurement approval that requires an asset record before purchase is finalised.
  • Finance reconciliation that flags invoices without matching inventory entries.
  • Automated discovery from endpoint management, network access control, or zero trust telemetry to find devices that never enrolled.
  • Conditional access or quarantine steps for unknown devices until ownership is confirmed.
  • Lifecycle ownership that defines who patches, tracks, and offboards the device once accepted.

This is where the logic in NHI Lifecycle Management Guide and the NIST Cybersecurity Framework 2.0 becomes useful: governance works only when assets are traceable from acquisition to retirement. For additional control depth, teams can map device intake and monitoring to NIST SP 800-53 Rev 5 Security and Privacy Controls, especially inventory, accountability, and continuous monitoring requirements.

Where this guidance breaks down is in distributed buying models, such as subsidiaries, site-specific purchasing, or contractor-led procurement, because the record of ownership fragments before central governance ever sees the device.

Common Variations and Edge Cases

Tighter asset control often increases approval overhead, so organisations have to balance speed against assurance. In some environments, the purchasing team may initiate the transaction, but accountability still remains with asset governance until the device is formally accepted into the fleet. That distinction matters when budgets are decentralised or when business units buy hardware for operational resilience.

There is no universal standard for this yet, but best practice is evolving toward a shared source of truth rather than a single team owning every step. For example, operations may validate the device in the field, finance may confirm spend, and central IT may enforce technical admission controls. The accountable team is the one that can prove the device was either recorded and managed or flagged and isolated.

This is also why audit evidence matters. The Ultimate Guide to NHIs — Key Challenges and Risks and Top 10 NHI Issues both reinforce a broader pattern: visibility gaps become control gaps. For unmanaged devices, that means the first priority is not blame assignment but rapid reconciliation, containment, and lifecycle assignment.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

OWASP Non-Human Identity Top 10 and CSA MAESTRO address the attack and risk surface, while NIST CSF 2.0, NIST SP 800-53 Rev 5 and NIST Zero Trust (SP 800-207) set the governance and control requirements practitioners need to meet.

Framework Control / Reference Relevance
NIST CSF 2.0 ID.AM Asset management is the core control family for unmanaged devices.
NIST SP 800-53 Rev 5 CM-8 Inventory controls directly address devices entering the fleet without approval.
NIST Zero Trust (SP 800-207) Zero Trust requires each device to be identified before access is granted.
OWASP Non-Human Identity Top 10 NHI-08 Unmanaged devices create hidden identity and lifecycle risks similar to NHI sprawl.
CSA MAESTRO MAESTRO emphasizes governance for autonomous and distributed assets with clear accountability.

Maintain an authoritative asset inventory and reconcile shadow purchases quickly.