How to run a SaaS spend audit and map records before you cancel tools

A SaaS spend audit lists every software subscription a company pays for, using the AP vendor ledger, card statements, expense reports and the single sign-on app list, then decides what to keep, consolidate or cancel. Before cancelling anything, map what records each tool holds and export what matters, because retired systems often hold years of history.

Why a SaaS spend audit is the moment to map company records

A SaaS spend audit finds every software subscription the company pays for and decides which to keep, consolidate, downgrade or cancel. It is also the last time someone with budget authority looks at each tool before it is switched off, which makes it the right moment to note what history each system holds and to export anything worth keeping.

Cancelled tools take their history with them. A help desk dropped at renewal, a CRM replaced after an acquisition or a chat workspace moved to a cheaper plan can each remove years of records that later matter for audits, disputes, the company's own AI projects and, for some companies, a data license. The guide on checking message history before downgrading Slack or Teams shows how that happens with chat. Because the audit already produces a systems list, adding a few records columns costs very little.

Where to find every system the company pays for

No single source catches everything, so combine them.

SourceWhat it catchesWhat it misses
Accounts payable vendor ledgerInvoiced subscriptions and annual contractsTools paid by card or expensed
Corporate card statementsMonthly self-serve subscriptionsTools on personal cards
Expense reportsTools employees bought and claimedFree tools that still hold company data
Single sign-on or identity provider app listTools connected to company loginsTools with their own passwords
IT asset register or MSP reportManaged and installed softwareShadow IT outside IT's view
Contracts folderTerms, renewal dates and data clausesClick-through agreements nobody saved
Department head interviewsDaily-use tools and retired tools with archivesTools people have forgotten they still pay for

How to turn the vendor ledger into a records map

  1. Export two years of software spend. Pull general ledger detail for software, hosting and storage accounts, then add card and expense data. Normalize vendor names so each tool is one row.
  2. Tag each tool by function. Finance, sales, support, engineering, operations, HR, communication or storage.
  3. Add the records columns. For each tool, note what it holds, the earliest year of history, the admin owner, whether a full export works, the renewal date and the notice period.
  4. Mark a decision. Keep, consolidate, downgrade or cancel. Every downgrade or cancellation gets an export decision before notice goes out.
  5. Find the retired systems. Ask about tools cancelled in earlier years whose exports, backups or archived mailboxes still exist; these often hold the oldest history the company has.
  6. Give the map to the owner. The result is a one-page view of what the company runs and what it remembers.

An Illustrative row from a finished map looks like this:

ColumnIllustrative entry
ToolHelp desk platform
FunctionCustomer support
Records heldTickets, replies, internal notes, satisfaction ratings
History from2017
Admin ownerSupport operations lead
Export testedYes, full export with attachments
Renewal and noticeRenews in March; written notice required
DecisionConsolidate into the CRM; export before cancelling

For the finance side of the map, the finance systems inventory template for fractional CFO onboarding provides a column layout.

SaaS audit timeline: what to do before and after cancelling

Work backward from each renewal date so no tool lapses before its records are dealt with.

WhenWhat to doWho
12 weeks before renewalConfirm usage, owner and notice periodController or AP lead
10 weeks beforeInterview the owner about the records, their start date and what depends on themCFO with the department head
8 weeks beforeTest a full export with attachments and metadata on a sampleIT admin or MSP
6 weeks beforeDecide keep, consolidate, downgrade or cancel; check holds and contract termsCFO, with counsel if needed
4 weeks beforeGive notice if cancelling; schedule the final exportAP lead and IT admin
Final 2 weeksRun and verify the full export; store it where it can be read laterIT admin
4 weeks afterOpen the archive and confirm it is complete and readableRecords owner
Every quarterRepeat for the next renewals and update the mapController

Who to talk to

  • Controller or AP lead: the vendor ledger, card data and the renewal calendar.
  • IT lead or managed service provider: admin access, the SSO list, export mechanics and storage.
  • Department heads: what each tool holds, what is still used and what was retired.
  • Counsel: legal holds, contract terms on data, recordings and personal data.
  • Owner or CEO: final calls on archive cost and anything with value beyond day-to-day operations.

What to say to department heads

What to preserve before a tool is cancelled

  • A full export of records with attachments, comments and timestamps
  • User and team mapping, so records can be tied to roles later
  • Audit logs and admin settings, including any retention rules
  • The status of any legal hold or retention obligation
  • The contract, order form and data processing terms
  • For call and meeting recording tools, the consent notices and settings in force when calls were recorded

Recordings need extra care. Federal law generally allows a recording when one party to the communication consents, under the Wiretap Act, 18 U.S.C. 2511, but California requires the consent of all parties to record a confidential communication under Penal Code section 632, and other states set their own rules. Keep evidence of how consent was captured alongside the export. This is general information, not legal, tax or financial advice. Ask your own counsel before relying on recordings for any purpose.

Where data licensing fits after the audit

A finished records map answers most of the first questions SourceX asks when it qualifies a company: size, history, data breadth and rights. Strong candidates usually run 10-15 or more systems with several years of connected history. If headcount reached 50+ full-time employees at peak (contractors excluded) and the map shows that kind of depth, the owner may want to consider licensing some records to AI labs and data buyers before the oldest systems are switched off. The who qualifies page sets out the baseline, and the company fit checker offers an early, non-binding indication. One-time proceeds can also help pay for the company's own AI work, which the guide on how to fund AI initiatives at a mid-sized company covers.

Fractional CFOs who run these audits across several clients are well placed to make introductions. A partner only introduces the company and passes on basic fit information; the partner never exports, uploads or describes its records. Partners earn 25% of the eligible platform fees SourceX actually collects from the referred company's licensing deals, capped at $100,000 per referred company. Rewards are payable only after the buyer pays and SourceX receives its fee, and no reward is guaranteed.

Next step

Run the audit on next quarter's renewals and build the records columns in from the start. If a client's map looks deep, the fractional CFO referral page explains what happens next, and you can register as a partner whenever you are ready.

  1. Step 1Share your linkSend your personal link to a company you know.
  2. Step 2Company appliesThe company applies itself at /apply.
  3. Step 3Buyer selects and paysThe buyer selects and pays for the data and SourceX receives its fee.
  4. Step 4You get your rewardYour share of SourceX fees becomes payable.

Common questions

How often should a company run a SaaS spend audit?

A full audit once a year works for most mid-sized companies, with a rolling check of each tool about three months before its renewal date. The annual pass catches new tools bought on cards and expense reports; the rolling check catches the notice periods that otherwise roll a contract over for another term. Keep the records map updated at each pass.

What is the difference between a SaaS spend audit and software asset management?

A spend audit is a periodic project that starts from money: what the company pays, to whom and for what. Software asset management is an ongoing discipline that tracks licenses, installations, usage and compliance across the software estate. The audit is often the first step that shows a company it needs the ongoing discipline, and both benefit from the same records columns.

Do we need to export data from a tool we are only downgrading?

Usually it is worth it. Cheaper plans can limit how much history users can see or search, remove admin export features or change retention settings. Check the vendor's current plan terms before downgrading, and take a full export while the higher plan is still active, since restoring access later may not be possible or may cost more than the savings.

Who owns the data in a cancelled SaaS tool?

Generally the company owns the records it created, but the vendor contract controls access, export rights and how long the vendor keeps data after cancellation. Read the data and termination clauses before giving notice, take a complete export into storage the company controls, and ask counsel about anything involving personal data, client data or recordings.

Can the records map be shared with SourceX?

Only by the company, and only if it chooses to explore licensing. A partner who helped with the audit introduces the company and shares basic fit information, never the map's contents or any records. The company then completes its own data inventory directly with SourceX, and redaction rules are settled with the company before anyone touches the data.

Free resources

By SourceX Partnerships Team · Published 2026-10-09 · Updated 2026-10-09

Know a US company with valuable proprietary data?

Become a referral partner from anywhere we support, get your link and introduce an owner or authorized decision-maker.

Refer a company →

I own a business

Explore licensing your company's data to AI developers worldwide. Start a short assessment; no uploads needed.

Start an assessment