WHY IT HAPPENS
Speed beats process, every single time
A marketer needs a transcription tool by Tuesday. Procurement takes two weeks. They use a corporate card, tick the consent box, and the tool is live in nine minutes. The org just acquired a vendor, a data processor, and a renewal — without a ticket, a contract, or a DPA.
WHY FINANCE MISSES IT
It looks like a coffee, not a contract
€18 on a corporate card lands in the GL as 'software, miscellaneous'. Nothing flags it. Twelve months later that same €18 has compounded into 240 seats across 40 teams — and finance is still booking it under miscellaneous.
WHY IT MISSES IT
If it never asked for SSO, IT never saw it
Modern SaaS doesn't need IT's help to onboard. No AD join, no MDM enrolment, no firewall ticket. The browser is the install. Without device-side telemetry and IdP OAuth-grant ingestion, IT only sees the apps that asked permission — never the ones that just took it.
WHY SECURITY MISSES IT
Unknown apps have unknown data
An app you don't know about cannot be in your asset register, your DPIA, or your SOC2 scope. It can still be processing customer PII, exporting source code, or storing access tokens. The first time security hears its name is usually in the breach notification.
WHY PROCUREMENT MISSES IT
There is no PO to track
Procurement governs what flows through procurement. Shadow IT skips the front door entirely — card, click, consent. The vendor invoices the cardholder, not AP. There is no PO, no MSA, no renewal calendar. Procurement is asked to negotiate down a tool they have never heard of, three days before auto-renew.