Shadow IT, the vendors nobody told you about
Shadow IT is technology acquired and used without going through IT or procurement — the SaaS tool bought on a card, the trial that became a dependency, the plugin connected to a corporate account. In third-party risk terms it is a population of unassessed vendors that already hold data and access.
Why this is a vendor problem, not an IT one
Shadow IT is usually discussed as a governance or spend issue. From a third-party risk position it is simpler and worse: every shadow tool is a supplier with a contract nobody reviewed, a DPA nobody signed, and an inherent risk nobody scored. Your register says you have 180 vendors. You have 180 assessed vendors and an unknown number of unassessed ones.
The exposure is not hypothetical. Shadow tools are precisely the ones granted broad OAuth scopes into mail and file storage, precisely the ones without enforced single sign-on, and precisely the ones nobody offboards when the person who bought them leaves.
Finding it
Four sources, none complete alone. Expenditure — card and expense data, which catches paid tools and misses free ones. Identity — OAuth grants and SSO logs, which catch anything connected to the corporate directory. Network and DNS, which catch traffic to services nobody sanctioned. And the outside-in view: subdomains, certificates and mail records that reveal third parties operating on your behalf.
Discovery is a continuous obligation rather than a project, because the population regenerates the moment the audit stops. Once found, the useful step is not enforcement but triage: bring the ones that matter into the register, tier them on inherent risk, and remove the rest. At RiskXchange, discovering unmanaged vendors sits inside NOVA's onboarding pipeline for that reason — the output of discovery is a vendor record, not a report.
Common questions
Why is shadow IT a third-party risk issue?
How do you discover shadow IT?
Should shadow IT simply be blocked?
Related terms and pages
Definitions are the easy part. Evidence is not.
See what your vendors actually expose — scored, monitored and evidenced in one place.