Skip to content

Subscriptions · July 7, 2026

Subscription audit: find and kill zombie SaaS spend in one afternoon

A subscription audit is a systematic pass through your card and bank statements to list every recurring charge, assign each one an owner, and cancel or renegotiate the ones nobody would miss. Done properly it takes one afternoon, and here is the step-by-step walkthrough, with a checklist table you can copy.

What counts as a zombie subscription

A zombie subscription is a recurring charge that keeps billing after its reason for existing has gone: the champion who bought it left, the project ended, the team migrated to a competitor, or the seats outnumber the humans. It still renews because cancellation requires someone to notice, and renewal requires nothing. Industry estimates of SaaS waste commonly land somewhere between 10 and 30 percent of total SaaS spend; treat that range as directional rather than a measurement of your stack, but if you have never audited, the honest prior is that some of your spend is feeding zombies right now.

Cancellation requires someone to notice. Renewal requires nothing.

The one-afternoon subscription audit, step by step

Step 1: Export 3 months of card and bank statements (30 min)

Pull CSV exports from every company card and any bank account that pays vendors directly. Three months is the minimum that catches quarterly billing; add the same month last year if you want annual renewals too. Do not forget the odd cards: the founder's card that bootstrapped the company, the marketing card, the one in the ops drawer.

Step 2: Identify the recurring charges (45 min)

Sort by merchant and look for the same name at a regular interval. Same amount monthly is the easy case; also catch usage-based vendors (same merchant, varying amount) and annual charges that appear once. A spreadsheet pivot on merchant name gets you 90 percent of the way. Expect surprises: most teams find charges they cannot immediately explain, which is exactly the point of the exercise.

Step 3: Map every subscription to an owner and seat count (60 min)

For each recurring merchant, record: what the product does, who owns it internally, how many seats you pay for, and how many people actually used it last month (most admin panels show active users). This is the slowest step and the highest-value one. Any subscription where the answer to "who owns this?" is silence goes straight to the flag list.

Step 4: Flag zombies, overlaps, and price increases (30 min)

Work the list with four filters: no owner (zombie), no active users in 30 days (zombie), two tools doing the same job (overlap), and unit price higher than three months ago (creep). Price increases are easy to miss because the merchant name never changes; compare the earliest and latest charge amounts for every vendor, and check seat counts, since quiet seat growth raises the bill just as effectively as a rate change.

Step 5: Cancel, downgrade, renegotiate (45 min)

Zombies with no owner get cancelled today; there is nobody to object. Underused tools get downgraded to fewer seats or a lower tier. For overlaps, pick a winner and set a migration deadline. For vendors that raised prices, email them: annual prepay discounts and "we are reviewing alternatives" recover real money more often than people expect. Log the expected monthly savings next to each action so the afternoon has a number attached.

Step 6: Set renewal alerts so the list stays clean (30 min)

The audit decays immediately: next month someone signs up for a new tool on a card and the map is stale. Before you close the spreadsheet, set alerts for every known renewal date, for any new recurring merchant appearing on a card, and for any recurring charge whose amount rises. This is the difference between an audit and a control.

The audit checklist

Swipe the table sideways to compare all columns.

SaaS subscription audit checklist with time estimates and outputs
Step Time Output Done when
1. Export statements 30 min CSVs from every card and account No card unaccounted for
2. Find recurring charges 45 min One row per recurring merchant Every repeat merchant listed
3. Map owners and seats 60 min Owner, seats, active users per row No blank owner cells
4. Flag zombies and creep 30 min Flag list with reasons Four filters applied to every row
5. Cancel and renegotiate 45 min Actions taken, savings logged Every flag has an action and date
6. Set renewal alerts 30 min Alert per renewal, new merchant, price rise Next renewal cannot surprise you

Total: about four hours. Block the afternoon, put the controller or the ops owner on it, and do it as a pair if the stack is large; one person reads statements, the other chases owners in Slack.

Stopping the zombies from coming back

The audit fixes the stock; a little process fixes the flow. Three habits keep the list clean between audits. Require an owner at purchase time: no new subscription goes on a card without a named person and a budget line, which takes thirty seconds and eliminates the "who owns this?" archaeology next quarter. Prefer monthly billing for anything unproven; the annual discount is only a discount if you still want the tool in month eleven. And route every renewal above a threshold, say $1,000 a year, through a quick keep-or-kill decision by the owner rather than letting auto-renewal decide by default. None of this requires new software, just the rule that recurring spend always has a human attached to it.

Keeping it dead: from audit to monitoring

The first audit produces the savings; the monitoring keeps them. Continuous SaaS spend management watches the same card feeds you just exported and does steps 2, 4, and 6 automatically: it spots new recurring merchants as they appear, alerts before renewals, and flags price increases the month they happen, so the next audit is a 20-minute review instead of an archaeology dig.

Two follow-ups round out the control. Ghost subscriptions are also a fraud surface, not just waste; they are red flag number nine in our expense fraud red flags rundown. And subscription spend is the sneakiest source of budget misses, which is why it deserves its own line in your budget vs actual variance review rather than hiding inside a general software category.