Back to Glossary

Entry · Business

Shadow IT

Shadow IT is technology used for organizational work that is unknown to, or unmanaged by, the people responsible for technology and security. It can include apps, cloud accounts, devices or AI tools. Staff often use it to solve a real work problem, but lack of visibility can create data, security, continuity and cost risks.

From the Money Master HQ dictionary, founded by Shihan Sheriff (FCMA, VP of Finance at Nomod, CFO at Esanjo Ventures). How these definitions are written.

What it means

A team needs to share large design files and uses personal cloud accounts because the approved system is slow. Work gets done, but the business may not know where client data sits or who can access it, which is a typical shadow IT problem.

The UK National Cyber Security Centre defines shadow IT as unknown assets used for business purposes outside normal asset-management and IT processes, notes that cloud and AI tools can be involved and advises a positive, no-blame response that helps uncover the reason for the workaround. Shadow IT is not always malicious, since a new tool can be convenient and genuinely useful.

The risk is that nobody has checked data handling, access, vendor terms, retention or whether the tool can be supported after a staff member leaves. Personal accounts are a particular continuity problem, because a company may not be able to retrieve files if the employee loses access or leaves, and shared credentials can make it impossible to know who changed a record.

Unapproved software can also hide spending, as free trials may turn into subscriptions on personal or company cards and similar tools bought by several teams can duplicate costs while central procurement misses them. Start with discovery, not blame: ask teams which tasks the approved systems fail to support, and review expense records, application inventories and other lawful technical signals to identify business-use tools.

CIS Control 2 calls for an inventory of authorized software and finding unauthorized or unmanaged software, which gives security staff a way to prioritise support and remediation and should be kept current as services and users change. Classify what each tool does and the data it holds, because a note-taking app with public information needs different review from one storing medical or customer records, and high-impact data and critical workflows come first.

Offer a usable approval route, since if every request takes months staff will keep finding workarounds, whereas an expedited review for low-risk tools and a clear route for unusual needs can reduce the incentive to go around the process. Some discovered tools may be approved after assessment while others need configuration changes, data migration or safe retirement, and a blanket ban can break a useful workflow without providing a replacement.

Data migration needs care, because downloading files to a laptop before deleting a personal cloud account may create another uncontrolled copy, so plan ownership, integrity, permissions and deletion evidence as appropriate. Review vendor access and terms for tools that remain, including who owns the account, whether the company can export its data and what happens if the provider shuts down, since technology choice is also a continuity decision.

An illustrative unapproved-tools share is identified unapproved tools divided by total tools found in a defined inventory, and nine of thirty is 30%, but the denominator is uncertain when undiscovered tools remain and a low-cost unapproved tool can carry high risk if it holds critical data, so count alone cannot rank the issues. Training should explain why approval matters and how to request help, using concrete examples instead of abstract warnings, since staff may not know that a browser extension can read customer information.

Managers play a role too, as they may encourage teams to use an unsanctioned service to meet a deadline, so give them a way to escalate blocked work before staff must choose between delivery and policy. Review after changes in employment or projects, because a tool originally adopted by one person may quietly become essential to a whole team and an access and ownership check during offboarding can reveal that dependency; for an owner, shadow IT is a visibility and workflow issue, so find what people actually use, understand why, assess the risk and provide a safe route that still lets them do their work.

In practice

Real-world examples.

1

Example

A team stores client drawings in a personal cloud account to bypass a slow approved system.

2

Example

Several employees expense separate subscriptions to the same unapproved app.

3

Example

A free AI tool receives customer data without a security or privacy review.

Formula

Calculation

Illustrative identified unapproved-tool share = unapproved tools found / all tools found in the inventory x 100. 9 / 30 x 100 = 30%; undiscovered tools may change the result. Suppose a later discovery sweep of expense records finds 6 more tools, all unapproved. The inventory now holds 30 + 6 = 36 tools, of which 9 + 6 = 15 are unapproved, so the share becomes 15 / 36 x 100 = 41.7%. The rise reflects better visibility, not necessarily worse behaviour, which is why the measure should be reported with the date and scope of the inventory.

Case study

Seen in the real world.

This entirely fictional example follows Palm Architects, an invented practice. Client drawings were scattered across personal storage accounts. IT talked with the teams, selected an approved sharing tool and migrated project files with access controls. It also created a quick request route for new needs. The example does not imply that every unapproved tool was discovered at once.

Watch out

Common mistakes.

  • Treating every workaround as misconduct before asking why staff needed it.
  • Banning a tool without offering a usable replacement or safe migration.
  • Assuming a low subscription price means little data or continuity risk.

Questions

People also ask.

What is shadow IT?

Work technology used outside the organisation's known, managed systems.

Why is it risky?

Unknown data locations, weak access, duplicate costs and unsupported dependencies.

How is it managed?

Discover actual use, assess risk and provide approved options and a practical request path.

Was this explanation helpful?

From the founder's library

Accounting Fundamentals: A Non-Finance Manager's Guide to Finance and Accounting, by Shihan Sheriff

Take it further with the book.

Build your financial confidence beyond this definition. Shihan's full-length guide, Accounting Fundamentals, takes the same plain-English approach and turns it into a complete, practical playbook for non-finance managers, business owners and students - with chapter-end quiz answers and presentation slides included.

US$2.24US$2.99

25% off with code MMHQ25, applied at checkout. Priced in USD - checkout may show the equivalent in your local currency.

View the book and save 25%
Last updated · October 8, 2026
Browse all terms →

Disclaimer

The information provided in this finance dictionary is for educational and informational purposes only. It should not be construed as financial, investment, legal, or tax advice. Always consult with a qualified professional before making any financial decisions. Money Master HQ makes no representations or warranties about the accuracy, completeness, or suitability of this information. Use of this content is at your own risk.