Vendor risk
What is shadow IT?
In short
Shadow IT is any software, service, or device used for work without the knowledge or approval of the people responsible for security and IT. It matters for compliance because a vendor nobody knows about cannot be risk-assessed, monitored, or offboarded.
Definition
Shadow IT is technology — typically SaaS applications, but also devices, browser extensions, and cloud accounts — adopted and used for work outside the visibility or approval of the organization’s IT and security functions.
Background
Shadow IT is rarely malicious. A team signs up for a scheduling tool with a corporate card, a designer connects a plugin to shared storage, an engineer starts a trial that needs read access to the code repository. Each decision is reasonable in isolation and none of them route through a review, because self-service SaaS is designed to need no procurement. The result accumulates quietly: most organizations are using meaningfully more third-party services than any list they maintain would show.
Why it matters
Every framework that addresses third parties assumes you know who they are. An unknown vendor is not assessed, not covered by a data processing agreement, not included in an access review, and not offboarded when a project ends or an employee leaves — so its access can outlive both. It also breaks incident response: when a vendor discloses a breach, the first question is whether you use them, and shadow IT means the answer is a guess. Auditors treat an incomplete vendor inventory as a control failure rather than an administrative gap.
Step by step
- Start from records you already have: expense and card statements, SSO and identity-provider logs, and the OAuth grants users have approved against your email and file storage.
- Read what your own domain publishes — domain-verification records, mail senders, and the third-party origins your website loads — since adopting a service often leaves a public trace.
- Reconcile the findings against your vendor register and record what is genuinely new.
- Assess and tier what you found by the data it can reach, not by what it costs.
- Give people a fast, obvious way to request a tool, because a slow approval path is what produces shadow IT in the first place.
- Re-check on a cadence: this is a recurring reconciliation, not a one-time cleanup.
Examples
- A marketing team runs a survey tool holding customer email addresses that never appeared in any vendor review.
- A former contractor’s account still has access to a file-sharing service that was never in the offboarding checklist because nobody knew it existed.
- A breach notification arrives from a vendor and nobody can say for certain whether the company is affected.
Common mistakes
- Treating shadow IT as a discipline problem to be solved with a policy, rather than a visibility problem to be solved with discovery.
- Blocking tools without offering a sanctioned alternative, which moves usage further out of sight instead of reducing it.
- Discovering once, fixing the list, and never reconciling again.
- Assuming a free tier is low risk; the cost of a service says nothing about the data it can reach.
FAQ
-
Is shadow IT always a security problem?
- Not always a breach waiting to happen, but always a control gap. The service may be perfectly well run. The problem is that you cannot assess, monitor, or offboard something you do not know you use, so the risk is unmanaged rather than necessarily high.
-
How do we find shadow IT without installing an agent?
- A surprising amount is visible from records you already control or that are already public: card and expense data, SSO and OAuth grants, and your own domain’s DNS records and website. Those will not find everything, but they turn a blank page into a review.
-
What do auditors expect here?
- That your third-party inventory is complete and maintained, that vendors are tiered by risk, and that reviews happen on a cadence. A register that is obviously shorter than reality is a finding.
Free tools and downloads
Next step
Do this in Keel, not a spreadsheet
Keel is the AI-native GRC platform for SMBs: one control-and-evidence graph across SOC 2, ISO 27001, HIPAA, PCI DSS, NIST CSF, and more. Start free, no credit card.