The main cause of shadow IT is not recklessness - it is an approval process slower than the deadline the team is working to. A review that takes six weeks guarantees people route around it, and you lose visibility of exactly the tools you most wanted to see.
Tier first
- Low - no company data beyond a name and email, no integration. Target: approved same day, basic checks only.
- Medium - business data, no personal or regulated data, limited integration. Target: a few days.
- High - personal, financial or regulated data; or integrated with core systems; or your service depends on it. Full review.
Publish the tiering questions so requesters can self-assess and arrive with the right evidence. Most requests are low tier, and clearing them quickly is what buys you cooperation on the ones that matter.
Every tier
- What business problem does this solve, and does an approved tool already do it? Duplicate tooling is common and is a cheap saving.
- Who is the internal owner?
- What data will actually go into it - ask for specifics, not categories.
- Cost and contract length.
Medium and high
- Data location, including backups and support access from other regions.
- Sub-processors - who else touches the data, and how are changes notified?
- Security evidence - an assurance report or certification. Read it: check period, scope, criteria and exceptions, not just that it exists.
- Authentication - does it support SSO and MFA? A tool without SSO creates a credential set outside your identity lifecycle, which is a permanent cost.
- Breach notification commitment and timeline.
- Data export and deletion on termination, in a usable format.
Assess suppliers before the contract, not after
GRC Copilot runs structured vendor assessments, tracks assurance evidence and expiry, and connects supplier risk to the controls that depend on them.
Try GRC Copilot free Generate an AI-powered assessment Download checklist Book a demo
High tier only
- Formal vendor risk assessment and a security schedule in the contract.
- Data protection agreement where personal data is involved, plus a transfer mechanism if it leaves the jurisdiction.
- DPIA where the processing is high risk.
- Availability requirements and what happens when the supplier is down.
- Exit plan - can you get the data out, in what format, at what cost?
The integration question everyone forgets
Ask what the tool will be granted access to. An application requesting broad OAuth scopes into your mail or file storage is a bigger decision than the subscription itself - it can read everything the granting user can, indefinitely, and it survives password changes.
Review OAuth scopes as carefully as contract terms. Integration approvals are now a larger inbound risk channel than purchasing, and they frequently bypass procurement entirely because no money changes hands.
Keeping it fast
A single form feeding a tracked queue, published turnaround times, pre-approved tools listed publicly so nobody re-requests them, and a named approver with a deputy. If your process cannot answer a low-tier request within a day, it will be bypassed - and speed here is genuinely a security control.
Frequently asked questions
What about free tools?
Same data risk, weaker contractual protection, often worse terms. Tier by data access, not by cost.
How do we find tools already in use?
Expense analysis, identity provider logs and OAuth grants in your major platforms.
Do we reassess approved tools?
High tier annually; others on change. Track certificate expiry so lapses surface automatically.
Who should approve?
Security for the risk view, with the business owner accepting residual risk. Security should not own a business decision.
Key takeaways
- Slow approval creates shadow IT - speed is a security control.
- Tier by data access and integration, not by cost.
- Review OAuth scopes as carefully as contract terms.
- Publish the approved list so nobody re-requests.