There are many companies that incorrectly believe that they have full control over their software ecosystem. It is important to realize that fully 53% of enterprise applications are completely unapproved by IT.
As regulatory deadlines for DORA and the EU AI Act approach, this enormous volume of shadow IT represents a legal and financial risk that needs to be addressed immediately.
This article provides a framework for establishing the specific operational processes necessary to effectively manage SaaS vendor risk, calculate total cost of ownership, and ensure compliance of third-party providers for all businesses.
SaaS Vendor Management Rules: DORA, NIS2, and AI
Going Beyond Basic Security Checks
Third-party risk management has historically relied heavily on basic security documentation. Companies would request a software vendor provide them with either a SOC 2 Type II or ISO 27001 certification. Once the vendor provided this, the procurement department would approve the software as secure.
This one-dimensional approach is no longer sufficient for enterprise business today. There are now numerous new laws being imposed on how businesses manage their external vendors. The Digital Operational Resilience Act (DORA) now requires financial institutions to keep and maintain a Register of Information for all technology vendors. You must be able to account for exactly where your data is going.
If you continue to rely entirely on basic questionnaires for vendor evaluation, you will likely fail your next audit. To manage modern SaaS vendor risk, it has become necessary for companies to actively map out fourth-party risks within their vendor ecosystem. You must know who your primary vendors' sub-processors are and how they are hosting your sensitive data.
Evaluating the Risks of Artificial Intelligence
The rapid integration of artificial intelligence capabilities into business software has introduced an entirely new level of risk. In addition to other tools, the way vendors are utilizing AI agents to conduct business on behalf of their clients continues to grow. AI agents now use proprietary algorithms to scan company data, review private communications, and send commands without human intervention.

Traditional security assessments do not account for this level of risk. You are required to establish additional testing protocols for vendors who are using AI. Therefore, your risk department should obtain a model usage statement from the vendor to ensure that the vendor does not use your proprietary information to create a publicly available model.
Also, you need to validate runtime controls; you should constantly ask vendors of AI whether or not they have a mechanism to stop their application from making changes to your environment if they're unauthorized. You want to ensure that there is a human user that has the ability to prevent an AI agent from making unauthorized alterations to your systems.
The Financial Cost of Software Sprawl
Stopping High Costs and Waste
Globally, enterprises are spending hundreds of billions on software every year, with the average company spending nearly $9,600 per employee annually. But software usage rates continue to be abysmally low – as of this writing, 51% of all licensed paid applications are sitting idle.
In addition, software providers have raised their prices aggressively on an annual basis. According to some recent estimates, vendors raise their prices for renewal on average between 8.7-12.3% annually. Without proper SaaS vendor management, a company could see their software costs double in a very short period of time without any added value to the organization.
For instance, companies are projecting anywhere from 18-26% savings through the proper management of SaaS vendor relationships. These companies have established automated renewal alerts and have been reclaiming inactive user accounts.
How to Calculate the Real Cost of Vendors
The cost to purchase software is not the price on the license alone—what does the vendor actually cost the client? Operational Carry Cost (OCC) allows an organization's financial team to measure the true cost of a vendor and highlights the total cost that a vendor is placing on an organization's internal resources (e.g., employees, IT support, etc.).
To derive your OCC, add together the annual license fee, technical integration costs, and the employee training costs then divide that number by the number of active users using the tool daily. This formula is relatively straightforward but may greatly change how executive management views a software tool.
An inexpensive tool can be very costly in terms of OCC if it requires continual IT support and custom-development engineering. A mapping of OCC for your top 20 vendors makes it clear which platforms are costing you money and which ones provide you with scale.
How to Track and Manage Your SaaS Vendor Lifecycle
Finding Hidden Software in Your Company
You cannot manage what you cannot see, and many employees are using corporate credit cards to purchase tools outside of the official IT purchasing process. In order to control this type of spending, you need to establish an automated discovery process that will allow you to catalog all instances of software in use at your organization.
To create this process, you'll want to connect your identity provider directly to the system that tracks software usage. You'll need to export system logs from either your Okta or Azure AD identity provider, and filter that log to show only SAML application log-ins that have occurred in the last 30 days.

After you have gathered all SAML log-in records for the previous 30 days, you can then cross-reference those log-in records with your corporate expense tracking systems such as Ramp or Brex. This process will reveal any active log-ins associated with hidden credit card transactions, thus identifying the total extent of your shadow IT issue.
Sorting Vendors by Risk Level
When treating all vendors equally, the business as a whole suffers. For example, onboarding a vendor at a large financial institution can take anywhere from 60 to up to 120 days, effectively obstructing forward-thinking teams from piloting new solutions or responding to changes in the marketplace.
It is, therefore, imperative to classify all vendors based on the types of data they access. A design tool that is only saving marketing images should not be reviewed as strictly as a payroll system that is processing and storing banking account information.
Applying a tiered structure gives you the flexibility to require a high level of security review (ISO 27001 certification) and a new legal contract with your high-risk vendors, all while granting a 3-day period using low-risk tool fast approval via basic SIG Lite evidence.
Aligning Contract Renewal Dates
A small procurement team has a difficult time working with hundreds of individual vendors because there are too many random contract renewal dates to manage. In order to negotiate better prices and terms from your vendors, the concept of aligning your contract expiration dates to give you leverage over your vendors is called "co-termination."
Choose 90 days before the end of your fiscal year. When any vendor has a contract up for renewal before that date, have that vendor extend their contract short-term to push their contract expiration date into your target window.
If you align 20 or 30 major vendor renewals to be due at the same time, you can now leverage those vendors to compete for your budget. This gives you the ability to ask for better pricing and volume discounts on those vendors, as you have control over the timing of your purchases.
Best SaaS Vendor Management Software and Tools
Larger enterprises utilize dedicated SaaS platforms as their software management tools and innovation automation, and to provide their teams with the ability to better manage the discovery of SaaS applications and infrastructure usage.
1. Zylo

Zylo is an elite dedicated software management platform used by enterprise teams to enforce a strict renewal discipline, and track the lifecycle of license usage within global offices.
2. Vendr
Vendr has a different approach to software management, as Vendr focuses heavily on negotiation and procurement.

Vendr provides a database of over 20,000 benchmarks of price and terms of similar products, allowing your organization to see what price and terms other similar organizations have received for the same software contract.
3. Vertice
Vertice is a combination of cloud business process tracking and software asset management (SAM). Vertice products enable businesses to gain visibility of software license costs by comparing their cloud-based SaaS solutions against each other and showing the historical price inflation trends across a customer's entire software portfolio.

This enables companies to forecast what they can expect their software vendors to increase in price before the annual renewal notices arrive.
4. CloudEagle
CloudEagle is focused on providing mid-sized businesses with fast setup times and clearly defined, transparent pricing models.
The CloudEagle platform offers businesses a centralized hub for managing their software contracts and spending, which can be set up in a matter of minutes. The CloudEagle platform allows users to quickly and easily visualize their software usage and understand its licensing structure.
5. InvGate Asset Management
InvGate Asset Management is designed to bridge the gap between software tracking and IT help desk services. IT support staff can use InvGate Asset Management to access a centralized repository of hardware and the specific software applications installed on those devices.
6. Costanalyst
Costanalyst provides an all-in-one solution for financial departments.
It combines the tracking of cloud expenditure with the tracking of the software ledgers, making it an easy process for finance leaders to identify stale accounts and close them out quickly.
7. UpGuard
Businesses seeking enterprise-wide compliance and security will utilize specialized risk management platforms in order to fulfill their compliance requirements.

UpGuard enables continuous monitoring for vendors who have a data breach incident and alerts security teams when a vendor misconfigures their externally facing servers.
8. Venminder
Venminder has a full suite of capabilities to manage third-party risk for enterprise, especially in relation to compliance.
Venminder helps organizations visualize their vendors' supply chains, and it assists in the challenging document collection required to complete a security audit.
9. SecurityScorecard
SecurityScorecard provides external ratings on the security of software providers. This enables your internal audit department to quickly assess whether or not the vendor possesses adequate safety controls prior to sending a formal questionnaire.
Final Thoughts on Managing Third-Party Risks
Third-party software management is no longer a simple matter of administration — it is now regarded as one of the main defensive operations for modern organisations. With new regulations related to digital resilience (the process of enabling an organisation's supply chain by providing it with ample security and the ability to use artificial intelligence) coming into effect, organisations are expected to demonstrate that they can maintain control over their supply chain.
Using static, manually tracked spreadsheets and email chains for SaaS vendor management will inevitably lead to failure. To maintain actual control over your software, you must implement automated identity logging, carry out unified expense tracking and create deep insight into your users' behaviour. By using risk-tiering, you can eliminate the costs associated with the inflation of prices while effectively protecting your sensitive data.
Organisations that prioritise strategic risk management as a priority will result in the cutting of hundreds of thousands of dollars in wasted budget funds. Those organisations that do not recognise that the expanding shadow IT phenomenon is generating severe legal liability and unmanageable operational costs will face harsh penalties and unmanageable costs.
Common Questions About Software Risk Management
What is preventing software from being deployed by the traditional procurement cycle?
The traditional procurement cycle applies the highest security assessment to each and every purchase.
Therefore, when a project team considers the appropriate security measures to implement for a relatively innocuous scheduling software tool, the process becomes quite slow due to the highest level of scrutiny being placed upon it.
By applying a risk assessment-based tiering model, it allows you to eliminate these time-consuming dependencies as you are assessing the data risk by applying a risk tiering classification to the data in your procurement process.
How does the decentralised purchasing process create risks associated with third-party software?
When employees make a purchase with either their own personal credit cards or within the corporate credit card environment, it presents challenges to IT and legal as they have no access to the terms and conditions of the contract.
As the contracts for these software tools are hidden, the 3rd-party corporate software provider could potentially contain sensitive customer data and not have basic security measures in place.
If that vendor has a data breach, your organisation bears the liability for any customer data lost in the security breach, even though you were not even aware that this data was at risk.
Why are AI suppliers more difficult to assess than traditional suppliers?
While most suppliers store and transfer data based on direct-user input, 3rd-party AI software systems will take that input and make independent decisions based on the new data created from it.
To adequately assess such vendors, one must implement completely different methods of assessment, including verification of "stop controls" that run in the AI vendor's runtime environment as well as proof from the vendor that they will not train any external model using your company’s proprietary data.


