# Shadow IT Audit Template: Discover and Govern Unauthorised Tools
Shadow IT refers to any software, SaaS application, hardware, or cloud service used by employees without formal IT approval. It's rarely malicious - employees adopt tools to get work done faster - but it introduces real risks: data leakage, compliance violations, unpatched vulnerabilities, and wasted spend.
This template gives your IT team a structured, repeatable process to surface shadow IT, assess risk, and bring tools into governance.
Part 1: Audit Scope & Preparation
1.1 Define Audit Scope
Before starting, agree on what you're auditing:
| Scope Item | In Scope? | Notes |
|---|---|---|
| SaaS / web applications | ☐ Yes / ☐ No | |
| Browser extensions | ☐ Yes / ☐ No | |
| Mobile apps (corporate devices) | ☐ Yes / ☐ No | |
| Cloud storage (personal Dropbox, Google Drive, etc.) | ☐ Yes / ☐ No | |
| AI tools (ChatGPT, Copilot, Gemini, etc.) | ☐ Yes / ☐ No | |
| Hardware (personal USB drives, routers) | ☐ Yes / ☐ No | |
| Automation tools (Zapier, Make, n8n) | ☐ Yes / ☐ No |
1.2 Assign Audit Roles
| Role | Responsibility | Assigned To |
|---|---|---|
| Audit Lead | Coordinates discovery, owns final report | |
| Network/Security Analyst | DNS, firewall, proxy log analysis | |
| IT Support | Employee survey, device scans | |
| Department Liaisons | Gather tool lists from each team | |
| Legal/Compliance | Assess regulatory risk of findings |
1.3 Notify Stakeholders
- Brief HR and legal before surveying employees (privacy considerations)
- Communicate audit purpose to department heads - frame it as enabling, not punitive
- Set audit timeline and share with all stakeholders
Part 2: Discovery Methods
Use multiple methods in parallel - no single source gives the full picture.
Method A: Network & DNS Log Analysis
Goal: Identify domains and services accessed from the corporate network.
Steps:
- 1Export DNS query logs from your DNS resolver (Cloudflare, Cisco Umbrella, Pi-hole, etc.) for the past 30–90 days
- 2Export proxy/firewall logs for outbound HTTP/HTTPS traffic
- 3Filter for non-approved domains - compare against your approved software list
- 4Group by category: productivity, storage, communication, AI, development, finance
What to look for:
- File sharing: dropbox.com, wetransfer.com, box.com (personal accounts)
- AI tools: chat.openai.com, claude.ai, gemini.google.com, perplexity.ai
- Communication: discord.com, telegram.org, whatsapp.com (web)
- Project management: notion.so, airtable.com, monday.com (unapproved instances)
- Development: replit.com, codesandbox.io, vercel.com (personal projects)
- Finance: expensify.com, wave.com (outside approved tools)
Method B: SSO & OAuth App Audit
Goal: Find apps employees have authorised using corporate Google/Microsoft accounts.
Steps:
- 1In Google Workspace Admin: Security → API Controls → App Access Control → View list
- 2In Microsoft 365 Admin: Azure AD → Enterprise Applications → All Applications
- 3Export the full list of third-party apps with OAuth access
- 4Note the permissions granted (read email, read files, send on behalf, etc.)
- 5Flag apps with broad permissions (e.g., "read all files") that are not IT-approved
Risk indicators:
- •App has access to email or calendar data
- •App was authorised by a single user, not IT
- •App has no privacy policy or is from an unknown vendor
- •App requests write/delete permissions
Method C: Employee Survey
Goal: Surface tools employees use that don't appear in logs (e.g., personal devices, offline tools).
Survey template - send to all staff:
*IT is conducting a routine software audit to better support the tools you use. Your responses help us approve tools faster and ensure your data stays secure. This is not disciplinary.*
>
1. List any apps, websites, or software you use regularly for work that you did not receive from IT.
2. What do you use each tool for? (e.g., note-taking, file sharing, project tracking)
3. Do any of these tools store company data or customer information?
4. Have you connected any of these tools to your work email or Google/Microsoft account?
Distribute via: Internal email, Slack/Teams, or your intranet. Allow 5–7 business days for responses.
Method D: Endpoint Scan
Goal: Find installed software on managed devices.
- Run an installed applications report from your MDM (Intune, Jamf, etc.)
- Export browser extension lists from managed Chrome/Edge profiles
- Compare installed software against your approved software catalogue
- Flag software installed outside of IT's deployment process
Part 3: Risk Assessment
For each discovered tool, complete this assessment:
Shadow IT Risk Scoring Matrix
| Factor | Low (1) | Medium (2) | High (3) | Score |
|---|---|---|---|---|
| **Data sensitivity** | No company data | Internal data | Customer / confidential data | |
| **User count** | 1–2 users | 3–10 users | 10+ users | |
| **Permissions granted** | None / read-only | Read + write | Full access / admin | |
| **Vendor security posture** | SOC 2 certified | Unknown | Known vulnerabilities | |
| **Regulatory relevance** | None | Internal policy | GDPR / HIPAA / PCI |
Total score: 5–7 = Low Risk | 8–11 = Medium Risk | 12–15 = High Risk
Per-Tool Assessment Log
Use one row per discovered tool:
| Tool Name | URL / App | Dept | Users | Data Stored | Risk Score | Recommended Action |
|---|---|---|---|---|---|---|
Recommended Actions:
- •Approve - meets security standards, add to approved catalogue
- •Conditional Approve - approve with restrictions (e.g., no customer data)
- •Replace - approved alternative exists; migrate users
- •Block - unacceptable risk; revoke access and notify users
- •Investigate - needs further review before decision
Part 4: Remediation Steps
4.1 For Tools to Block
- 1Revoke OAuth access via Google/Microsoft admin console
- 2Add domain to DNS/proxy blocklist
- 3Notify affected users with explanation and approved alternative
- 4Document the decision and rationale in your software register
4.2 For Tools to Approve
- 1Complete a vendor security review (see checklist below)
- 2Negotiate a business agreement / DPA if personal data is involved
- 3Add to your approved software catalogue
- 4Configure SSO and enforce through your IdP
- 5Set up centralised billing and licence management
Vendor Security Review Checklist:
- SOC 2 Type II report available (or equivalent)
- Data Processing Agreement (DPA) signed
- Data residency confirmed (EU/US/other as required)
- Breach notification process documented
- Supports SSO / SAML
- MFA available and enforceable
- Data export and deletion capability confirmed
4.3 For Tools to Replace
| Step | Action |
|---|---|
| 1 | Identify the approved alternative |
| 2 | Communicate migration plan to affected users with timeline |
| 3 | Provide training or documentation for the approved tool |
| 4 | Set a hard cutoff date for the shadow tool |
| 5 | Block the shadow tool after cutoff |
| 6 | Confirm data has been migrated or deleted from the old tool |
Part 5: Ongoing Governance
A one-time audit is not enough. Build processes to catch shadow IT continuously.
5.1 Approved Software Catalogue
Maintain a living catalogue of all approved tools:
| Tool | Category | Owner | Review Date | SSO Enabled |
|---|---|---|---|---|
Publish this catalogue on your intranet so employees can check before adopting new tools.
5.2 Software Request Process
Make it easy to request new tools - shadow IT often happens because the official process is too slow.
- Create a simple software request form (< 5 fields)
- Set a target SLA for review: 5 business days for standard tools, 10 for high-risk
- Assign a named owner for each request
- Communicate decisions back to requestors with reasoning
5.3 Recurring Audit Schedule
| Activity | Frequency |
|---|---|
| DNS/proxy log review | Monthly |
| OAuth app audit | Quarterly |
| Employee survey | Annually |
| Endpoint software scan | Quarterly |
| Full shadow IT audit report | Annually |
5.4 Employee Awareness
- Include shadow IT policy in onboarding
- Send annual reminder of approved tools and request process
- Share examples of shadow IT risks (without naming individuals)
- Recognise teams that proactively flag tools for review
Audit Report Template
Use this structure for your final audit report:
Executive Summary - Key findings, total tools discovered, risk breakdown, top recommendations
Discovery Summary - Methods used, response rates, data sources
Findings - Full tool inventory with risk scores
Remediation Plan - Actions taken and pending, owners, deadlines
Governance Recommendations - Process improvements to prevent recurrence
Appendix - Raw data, survey responses, vendor assessments
Shadow IT is a symptom of unmet needs. The goal of this audit is not to lock everything down - it's to understand what employees actually need and provide secure, supported alternatives.