← Resources/TemplateInternal IT Support

Shadow IT Audit Template: Discover and Govern Unauthorised Tools

16 April 2026·6 min read

# Shadow IT Audit Template: Discover and Govern Unauthorised Tools

Shadow IT refers to any software, SaaS application, hardware, or cloud service used by employees without formal IT approval. It's rarely malicious - employees adopt tools to get work done faster - but it introduces real risks: data leakage, compliance violations, unpatched vulnerabilities, and wasted spend.

This template gives your IT team a structured, repeatable process to surface shadow IT, assess risk, and bring tools into governance.


Part 1: Audit Scope & Preparation

1.1 Define Audit Scope

Before starting, agree on what you're auditing:

Scope ItemIn Scope?Notes
SaaS / web applications☐ Yes / ☐ No
Browser extensions☐ Yes / ☐ No
Mobile apps (corporate devices)☐ Yes / ☐ No
Cloud storage (personal Dropbox, Google Drive, etc.)☐ Yes / ☐ No
AI tools (ChatGPT, Copilot, Gemini, etc.)☐ Yes / ☐ No
Hardware (personal USB drives, routers)☐ Yes / ☐ No
Automation tools (Zapier, Make, n8n)☐ Yes / ☐ No

1.2 Assign Audit Roles

RoleResponsibilityAssigned To
Audit LeadCoordinates discovery, owns final report
Network/Security AnalystDNS, firewall, proxy log analysis
IT SupportEmployee survey, device scans
Department LiaisonsGather tool lists from each team
Legal/ComplianceAssess regulatory risk of findings

1.3 Notify Stakeholders

  • Brief HR and legal before surveying employees (privacy considerations)
  • Communicate audit purpose to department heads - frame it as enabling, not punitive
  • Set audit timeline and share with all stakeholders

Part 2: Discovery Methods

Use multiple methods in parallel - no single source gives the full picture.

Method A: Network & DNS Log Analysis

Goal: Identify domains and services accessed from the corporate network.

Steps:

  1. 1Export DNS query logs from your DNS resolver (Cloudflare, Cisco Umbrella, Pi-hole, etc.) for the past 30–90 days
  2. 2Export proxy/firewall logs for outbound HTTP/HTTPS traffic
  3. 3Filter for non-approved domains - compare against your approved software list
  4. 4Group by category: productivity, storage, communication, AI, development, finance

What to look for:

  • File sharing: dropbox.com, wetransfer.com, box.com (personal accounts)
  • AI tools: chat.openai.com, claude.ai, gemini.google.com, perplexity.ai
  • Communication: discord.com, telegram.org, whatsapp.com (web)
  • Project management: notion.so, airtable.com, monday.com (unapproved instances)
  • Development: replit.com, codesandbox.io, vercel.com (personal projects)
  • Finance: expensify.com, wave.com (outside approved tools)

Method B: SSO & OAuth App Audit

Goal: Find apps employees have authorised using corporate Google/Microsoft accounts.

Steps:

  1. 1In Google Workspace Admin: Security → API Controls → App Access Control → View list
  2. 2In Microsoft 365 Admin: Azure AD → Enterprise Applications → All Applications
  3. 3Export the full list of third-party apps with OAuth access
  4. 4Note the permissions granted (read email, read files, send on behalf, etc.)
  5. 5Flag apps with broad permissions (e.g., "read all files") that are not IT-approved

Risk indicators:

  • •App has access to email or calendar data
  • •App was authorised by a single user, not IT
  • •App has no privacy policy or is from an unknown vendor
  • •App requests write/delete permissions

Method C: Employee Survey

Goal: Surface tools employees use that don't appear in logs (e.g., personal devices, offline tools).

Survey template - send to all staff:

*IT is conducting a routine software audit to better support the tools you use. Your responses help us approve tools faster and ensure your data stays secure. This is not disciplinary.*

>

1. List any apps, websites, or software you use regularly for work that you did not receive from IT.
2. What do you use each tool for? (e.g., note-taking, file sharing, project tracking)
3. Do any of these tools store company data or customer information?
4. Have you connected any of these tools to your work email or Google/Microsoft account?

Distribute via: Internal email, Slack/Teams, or your intranet. Allow 5–7 business days for responses.

Method D: Endpoint Scan

Goal: Find installed software on managed devices.

  • Run an installed applications report from your MDM (Intune, Jamf, etc.)
  • Export browser extension lists from managed Chrome/Edge profiles
  • Compare installed software against your approved software catalogue
  • Flag software installed outside of IT's deployment process

Part 3: Risk Assessment

For each discovered tool, complete this assessment:

Shadow IT Risk Scoring Matrix

FactorLow (1)Medium (2)High (3)Score
**Data sensitivity**No company dataInternal dataCustomer / confidential data
**User count**1–2 users3–10 users10+ users
**Permissions granted**None / read-onlyRead + writeFull access / admin
**Vendor security posture**SOC 2 certifiedUnknownKnown vulnerabilities
**Regulatory relevance**NoneInternal policyGDPR / HIPAA / PCI

Total score: 5–7 = Low Risk | 8–11 = Medium Risk | 12–15 = High Risk

Per-Tool Assessment Log

Use one row per discovered tool:

Tool NameURL / AppDeptUsersData StoredRisk ScoreRecommended Action

Recommended Actions:

  • •Approve - meets security standards, add to approved catalogue
  • •Conditional Approve - approve with restrictions (e.g., no customer data)
  • •Replace - approved alternative exists; migrate users
  • •Block - unacceptable risk; revoke access and notify users
  • •Investigate - needs further review before decision

Part 4: Remediation Steps

4.1 For Tools to Block

  1. 1Revoke OAuth access via Google/Microsoft admin console
  2. 2Add domain to DNS/proxy blocklist
  3. 3Notify affected users with explanation and approved alternative
  4. 4Document the decision and rationale in your software register

4.2 For Tools to Approve

  1. 1Complete a vendor security review (see checklist below)
  2. 2Negotiate a business agreement / DPA if personal data is involved
  3. 3Add to your approved software catalogue
  4. 4Configure SSO and enforce through your IdP
  5. 5Set up centralised billing and licence management

Vendor Security Review Checklist:

  • SOC 2 Type II report available (or equivalent)
  • Data Processing Agreement (DPA) signed
  • Data residency confirmed (EU/US/other as required)
  • Breach notification process documented
  • Supports SSO / SAML
  • MFA available and enforceable
  • Data export and deletion capability confirmed

4.3 For Tools to Replace

StepAction
1Identify the approved alternative
2Communicate migration plan to affected users with timeline
3Provide training or documentation for the approved tool
4Set a hard cutoff date for the shadow tool
5Block the shadow tool after cutoff
6Confirm data has been migrated or deleted from the old tool

Part 5: Ongoing Governance

A one-time audit is not enough. Build processes to catch shadow IT continuously.

5.1 Approved Software Catalogue

Maintain a living catalogue of all approved tools:

ToolCategoryOwnerReview DateSSO Enabled

Publish this catalogue on your intranet so employees can check before adopting new tools.

5.2 Software Request Process

Make it easy to request new tools - shadow IT often happens because the official process is too slow.

  • Create a simple software request form (< 5 fields)
  • Set a target SLA for review: 5 business days for standard tools, 10 for high-risk
  • Assign a named owner for each request
  • Communicate decisions back to requestors with reasoning

5.3 Recurring Audit Schedule

ActivityFrequency
DNS/proxy log reviewMonthly
OAuth app auditQuarterly
Employee surveyAnnually
Endpoint software scanQuarterly
Full shadow IT audit reportAnnually

5.4 Employee Awareness

  • Include shadow IT policy in onboarding
  • Send annual reminder of approved tools and request process
  • Share examples of shadow IT risks (without naming individuals)
  • Recognise teams that proactively flag tools for review

Audit Report Template

Use this structure for your final audit report:

Executive Summary - Key findings, total tools discovered, risk breakdown, top recommendations

Discovery Summary - Methods used, response rates, data sources

Findings - Full tool inventory with risk scores

Remediation Plan - Actions taken and pending, owners, deadlines

Governance Recommendations - Process improvements to prevent recurrence

Appendix - Raw data, survey responses, vendor assessments


Shadow IT is a symptom of unmet needs. The goal of this audit is not to lock everything down - it's to understand what employees actually need and provide secure, supported alternatives.

shadow-itauditsaas-managementcompliance