SaaS subscription management: How to track and control spend

Software spend may already be one of your largest discretionary cost lines, even if no one made a deliberate decision for it to become one. Finance carries P&L accountability for a portfolio of tools it didn't procure and often can't fully see, while business units sign up for new subscriptions every week without a purchase order or a budget gate.

Getting that spend under control is a finance problem before it's a software one. The approaches below are general guidance for UK and European finance teams, not tax or legal advice, so check entity-specific obligations with your advisers.

Key takeaways

  • SaaS subscription management is a finance function: the majority of SaaS spend is now controlled by business units rather than IT.

  • Close to half of all purchased SaaS licences go unused.

  • UK and European compliance obligations add layers that generic SaaS management advice ignores.

  • Proactive renewal management has the biggest impact because vendor price increases now routinely exceed budget assumptions.

  • Virtual cards assigned to individual subscriptions give finance a payment-level kill switch. Cancelling a card can stop future charges without relying on a vendor portal.

  • These six shifts move SaaS subscription management from a reactive cost problem to a governed finance function.

Why SaaS subscriptions are harder to control than they look

UK and European mid-market finance teams face a particular version of this problem. VAT treatment of cross-border SaaS purchases, GDPR obligations on every tool that touches personal data, and Making Tax Digital requirements for digital record-keeping each add a compliance layer that finance has to manage directly. Much of that software spend also sits outside any formal procurement process, so finance carries the cost of purchases it never saw approved.

The average organisation now runs roughly 130 to 305 SaaS applications, depending on whether you count managed tools or total discovered applications (Vertice and Zylo's 2026 index respectively). On average, seven new applications enter the company environment every month.

SaaS procurement has been decentralised by default. Business units account for around 70% of SaaS spend, per Zylo's 2025 index, while IT controls just over a quarter. Departments adopt tools directly, often without finance in the loop. A significant portion of that spend is shadow IT, entirely invisible to central governance.

Only around 54% of purchased SaaS licences are actively used, per Zylo's 2026 index, so a large share of software budget pays for access nobody touches.

Audit the estate you can't fully see

Most finance teams discover during their first audit that their actual SaaS footprint is much larger than expected. A complete audit gives you the baseline for any later cost control work.

Pull financial records from every payment channel

Pull all recurring charges from company card statements, direct debits, purchase orders, and employee expense claims submitted for reimbursement. Some vendors use generic billing descriptors, so you may need to investigate individual line items instead of relying on keyword filtering alone.

It's also worth consulting IT about enterprise agreements and asking department heads which tools are in active use but don't yet appear in financial records. If you need a broader framework for categorising recurring spend, this spend analysis guide can help structure the review.

Build a structured subscription inventory

Consolidate everything into a single register. Each entry should capture the vendor name and product, a named contract owner, the number of licences purchased versus active users, the annual or monthly cost, the renewal date, the contractual cancellation notice period, and whether the tool processes personal data.

Under Financial Reporting Standard 102 (FRS 102), annual prepaid SaaS subscriptions should be treated as prepaid expenses and amortised monthly over the subscription period rather than expensed in full at the point of payment. The most recent FRS 102 periodic review was completed in March 2024, with significant amendments that businesses must implement by 1 January 2026.

A complete register gives you the foundation. Preventing new uncontrolled subscriptions from entering the estate is the next priority.

Enjoying what you're reading?

We publish new articles like this every week. Subscribe to our newsletter to stay informed.

Catch SaaS sprawl before the card is charged

Finance has the strongest control point before the purchase happens. Once a subscription goes live and a card is charged, finance is already reacting to the spend.

Most UK finance teams can use a tiered approval approach, with thresholds shaped around their own risk appetite and tool mix. For example, subscriptions below £50 per month might require only a department manager's sign-off from a pre-approved vendor list. Between £50 and £500, a finance controller review may make sense. Above £500, or for multi-year commitments, CFO or board approval may be proportionate.

Any tool that processes personal data should trigger a Data Protection Officer review regardless of cost because the General Data Protection Regulation (GDPR) obligations aren't cost-dependent. If you're reviewing where those thresholds should sit, strong budget controls make it easier to set guardrails without slowing every purchase down.

Shifting to pre-purchase approvals is harder to implement than it sounds, especially in organisations where teams are used to buying tools independently. The first few weeks will surface friction, but that usually means the process is working.

For example, virtual cards assigned to individual subscriptions, with one card per vendor, create a payment-level control. Each subscription is tied to a specific cardholder and visible on a single dashboard. Finance can cancel the card to stop future charges.

Spendesk is an all-in-one spend management platform consolidating company cards, expense management, accounts payable, procurement, and budgeting. In this context, linking each recurring virtual card to one vendor gives finance a direct way to contain spend quickly, without chasing shared credentials or relying on someone to remember which portal controls the billing. See how this works with .

This also gives finance more control when employees leave. Finance can cancel the card tied to the subscription without logging in to the vendor's portal. There's no need to recover a password or depend on someone remembering that the subscription exists.

The ghost subscription problem is common in growing teams. Departed employees often leave behind active, unmonitored subscriptions.

Hallam Agency faced exactly this. After implementing Spendesk, their finance team gained immediate control over any recurring payment when an employee left and could keep or cancel each subscription directly.

If your approval process takes days, employees will purchase on personal cards and submit expense claims. That reintroduces the shadow IT problem.

Stop renewals from compounding budget damage: The 90/60/30-day framework

Renewals are where the budget damage compounds. SaaS inflation peaked at 14.7% in November 2025, precisely during Q4 enterprise renewal cycles, and remained elevated at 13.2% in March 2026, according to Vertice's inflation data. Unplanned SaaS cost increases forced 61% of organisations to cut projects or initiatives, per Zylo's 2026 index.

BetterCloud's State of SaaSOps report shows that only 30% of organisations have an effective purchasing and renewal process in place, and 40% still track renewal dates manually on spreadsheets or calendars. A structured renewal calendar changes that.

  • 90 days before renewal assess whether the tool is still needed and whether all purchased licences are actively used. Check last-login dates. If a significant portion of users haven't logged in within the past 30 days, those licences are candidates for reclamation.

  • 60 days before renewal use your usage and cost data to right-size or renegotiate the contract. This is the main negotiation window, and SaaS inflation data gives you support when pushing back on price increases.

  • 30 days before renewal issue a formal, written decision to renew, downgrade, or cancel. Retain the decision record for audit purposes.

Does your current process give you 90 days of lead time on every renewal, or do some auto-renew before anyone reviews them?

Your SaaS portfolio also carries compliance obligations that generic management advice often overlooks.

Compliance is where a UK and European SaaS estate gets complicated

Your SaaS portfolio creates obligations across VAT, Making Tax Digital, and GDPR that finance has to manage directly.

VAT treatment of SaaS subscriptions

Most SaaS offerings are treated as electronically supplied services under UK VAT rules, subject to VAT at the standard rate of 20%. For B2B transactions with non-UK SaaS vendors, the reverse-charge mechanism applies. No VAT appears on the supplier's invoice, and you account for VAT on your own VAT return.

Incorrectly charged VAT is the practical trap. VAT charged in error isn't recoverable as input tax, so if a non-UK supplier charges UK VAT on a B2B supply, you can't reclaim it and HM Revenue & Customs (HMRC) will look to recover it from the supplier instead. You should verify VAT has been correctly applied on every cross-border SaaS invoice and request corrected invoices where necessary. Are your VAT receipts and records complete enough to survive an HMRC enquiry?

All VAT-registered businesses must keep VAT records and submit VAT returns using Making Tax Digital (MTD) compatible software. The digital-link requirement means SaaS subscription costs captured in a spend management platform must flow digitally into your VAT accounting software. Manual re-keying of data between systems isn't MTD-compliant.

Tools like Spendesk create the clean, digital audit trail that MTD requires, with purchase records and payment data captured at source rather than reconstructed at month-end. For example, Tom Libbrecht, VP Finance at Silverfin, credits the platform with letting the team scale "without adding anything to the back-office because it's that far automated." This level of automation gives finance a more reliable path from subscription payment to VAT record.

GDPR vendor due diligence

Both UK GDPR and EU GDPR require Data Processing Agreements (DPAs) with any SaaS vendor that processes personal data. Before approving a new subscription, you'll want to check whether the tool processes personal data, including employee data or financial data linked to identifiable individuals, request the vendor's DPA, confirm where data is stored, and, if data is held outside the UK or EU, ensure Standard Contractual Clauses or a UK International Data Transfer Agreement is in place. It's also worth adding the vendor to your Records of Processing Activities (ROPA).

The UK is a third country from the EU's perspective after Brexit. If a group-wide SaaS tool processes data from EU subsidiaries that is accessible by UK personnel, additional safeguards under Article 46 of EU GDPR are required for those data flows. The requirements increase when your SaaS portfolio spans multiple legal entities and currencies.

Multi-entity groups multiply every SaaS obligation

If you operate across the UK and continental Europe, group-wide SaaS licences create entity-level complexity. Licences held by the UK parent need a clear intercompany recharge mechanism for transfer-pricing compliance and accurate entity-level P&L reporting. Do your intercompany recharges for group-wide SaaS licences reflect the actual usage split across entities?

Currency exposure adds another layer of operational friction. Group-wide tools invoiced in USD require a consistent FX translation policy, and VAT must be handled correctly in each jurisdiction. The UK reverse-charge treatment differs from VAT treatment in individual EU member states.

A single platform that consolidates entity-level spend removes the need to reconcile across separate banking relationships and currencies. Take Pierre Frey: they run five international entities on Spendesk and have eliminated paper expense claims entirely, including cash advances. If that's becoming a bigger issue for you, multi-entity management is a useful next step.

AI is the fastest-growing line you're not governing yet

European businesses spent €33.8 million on AI tools, a 96% year-on-year increase. The share of European companies using AI tools grew from 59% to 73% in the same period. Most significantly for subscription management, 70% of AI purchases are now made as recurring subscriptions, up from 43% in early 2023.

How many AI subscriptions are running in your organisation right now, and who approved them? AI subscriptions are the fastest-growing, least-governed category in your SaaS estate. They often carry consumption-based pricing, where costs scale with usage in ways that aren't apparent at sign-up. In the past year, 78% of IT leaders reported unexpected charges tied to consumption-based or AI features, according to Zylo's 2026 index.

Real customer portfolios show the scale of AI subscription sprawl. Niji, a digital innovation consultancy, found itself managing 104 subscriptions through Spendesk, including over 80 AI licences. That kind of visibility helps finance see subscription growth early, before scattered AI spend turns into a month-end surprise.

Your SaaS governance framework needs to account for AI tools specifically, for the financial risk, and for the GDPR implications of feeding company data into third-party AI models without a reviewed DPA. If AI-related spend is accelerating faster than your controls, this guide to AI tools for finance can help frame the conversation.

From recurring surprise to governed finance process

The visibility gap finance teams face comes down to timing more than volume: whether finance can see subscriptions before renewal dates pass, before personal data flows into a new tool, and before another recurring payment quietly hits the P&L. When accountability sits with finance but purchasing happens across the business, the answer isn't tighter month-end detective work. It's earlier control through a complete register, proportionate approvals, clear renewal ownership, and a payment method that lets finance act quickly when a subscription no longer belongs in the stack.

That shift is what turns SaaS spend from a recurring surprise into a governed finance process. When every subscription has an owner, a renewal date, a compliance review, and a controllable payment method, finance can reduce waste without becoming the bottleneck. The practical goal is simpler: finance gains visibility and can act faster, so fewer subscriptions quietly drain budget or create compliance risk.

If you want to turn those controls into a repeatable workflow, see how Spendesk handles . It gives finance teams a single place to track recurring payments and assign ownership, so finance can step in quickly when spend needs to stop.

Frequently asked questions about SaaS subscription management

How should finance handle subscription notice periods?

The safest approach is to capture the contractual cancellation notice period in the subscription register and review it as part of the 90/60/30-day renewal process. That gives finance enough lead time to avoid drifting into an automatic renewal before anyone makes a decision.

What evidence should finance retain when a subscription is renewed or cancelled?

Issue a formal, written decision 30 days before renewal and retain that decision record to support audit preparation. In practice, that means keeping a clear record of who owns the tool, what decision was made, when it was made, and how it links back to the contract terms and renewal date.

When should finance involve IT in SaaS subscription management?

IT is most useful during the audit stage and when a tool is in active use but doesn't yet appear in financial records. Finance may also need IT input on enterprise agreements, access patterns, or whether a tool is still being used across teams.

How should shared licences be handled across multiple entities?

Where a group-wide licence supports more than one legal entity, finance needs a clear intercompany recharge mechanism and an accurate view of the usage split. Without that, entity-level P&L reporting and transfer-pricing support become harder to defend.

What should finance check before approving a SaaS tool that handles personal data?

Before approval, finance should check whether the tool processes personal data, request the vendor's DPA, confirm where data is stored, and make sure the right transfer safeguards are in place if data sits outside the UK or EU. Adding the vendor to the organisation's Records of Processing Activities can also help keep the compliance trail complete.

Curious how Spendesk works?

Try an interactive demo to see spend control and approvals end-to-end.

Get a free tour