TPRM glossary

Shadow IT, the vendors nobody told you about

Shadow IT is technology acquired and used without going through IT or procurement — the SaaS tool bought on a card, the trial that became a dependency, the plugin connected to a corporate account. In third-party risk terms it is a population of unassessed vendors that already hold data and access.

Why this is a vendor problem, not an IT one

Shadow IT is usually discussed as a governance or spend issue. From a third-party risk position it is simpler and worse: every shadow tool is a supplier with a contract nobody reviewed, a DPA nobody signed, and an inherent risk nobody scored. Your register says you have 180 vendors. You have 180 assessed vendors and an unknown number of unassessed ones.

The exposure is not hypothetical. Shadow tools are precisely the ones granted broad OAuth scopes into mail and file storage, precisely the ones without enforced single sign-on, and precisely the ones nobody offboards when the person who bought them leaves.

Finding it

Four sources, none complete alone. Expenditure — card and expense data, which catches paid tools and misses free ones. Identity — OAuth grants and SSO logs, which catch anything connected to the corporate directory. Network and DNS, which catch traffic to services nobody sanctioned. And the outside-in view: subdomains, certificates and mail records that reveal third parties operating on your behalf.

Discovery is a continuous obligation rather than a project, because the population regenerates the moment the audit stops. Once found, the useful step is not enforcement but triage: bring the ones that matter into the register, tier them on inherent risk, and remove the rest. At RiskXchange, discovering unmanaged vendors sits inside NOVA's onboarding pipeline for that reason — the output of discovery is a vendor record, not a report.

Common questions

Why is shadow IT a third-party risk issue?
Because every shadow tool is an unassessed vendor holding data or access. There is no contract review, no data processing agreement, no tiering and no offboarding — so the exposure sits entirely outside the controls the programme was built to apply.
How do you discover shadow IT?
Combine expense and card data, identity signals such as OAuth grants and SSO logs, network and DNS activity, and outside-in observation of subdomains, certificates and mail records. Each source is partial; expenditure alone misses every free tool, and identity alone misses anything never connected to the directory.
Should shadow IT simply be blocked?
Blocking without an alternative moves the activity somewhere less visible. The more effective response is to make the sanctioned route fast enough to be worth using, then triage what discovery finds: adopt what matters into the register and remove the rest.

Definitions are the easy part. Evidence is not.

See what your vendors actually expose — scored, monitored and evidenced in one place.