Every business we work with has money leaking out of software subscriptions. Not because anyone is careless, but because subscriptions are designed to be easy to start and quiet to keep. Someone signs up for a project tool during a busy quarter, three people get seats, the project ends, and the charge keeps landing on a company card for years. Nobody notices, because nobody owns the noticing.
The usual response is a purge. Somebody gets frustrated, spends a Saturday cancelling things, saves a few hundred dollars a month, and feels great. Then the leak starts again, because the conditions that created it never changed. What actually works is boring: a repeatable process on a schedule, with a person’s name attached. Here is how we run it, and how you can run it yourself.
Why the One-Time Purge Never Sticks
A purge treats the symptom. The cause is that subscriptions enter your business faster than anyone tracks them, through a dozen doors: a manager’s card, an app store account, a free trial that converted, a vendor that added a module to your bill. There is no central list, so there is no way to notice a charge that stopped earning its keep.
The fix is a recurring calendar entry, not a heroic weekend. We suggest twice a year, one hour each time, owned by one person, with three steps every time:
- Gather. Pull the statements and receipts described in the next section into one spreadsheet: vendor, amount, billing cycle, who owns it, what it does.
- Sort. Put every line into one of four buckets. Do not overthink it. Sort first, argue later.
- Act and record. Cancel, downgrade, or consolidate, then write down the decision and the date so next time you are updating a list instead of starting one.
The first pass takes longer, maybe half a day. The second pass takes an hour, because the spreadsheet already exists. That is the whole trick.
Where the Money Hides
If you only look at one place, you will find about half of it. Check all of these:
- Twelve months of credit card and bank statements. Twelve, not three, because annual renewals hide outside a quarterly view. Read the merchant names you do not recognize instead of skipping them.
- App store receipts. Apple and Google subscriptions bought on a company phone often never touch a business card statement in a recognizable form.
- Expense reports and reimbursements. This is where personal cards paying for business tools show up. It is also where you find out that two departments bought the same product.
- Browser saved logins and password manager entries. A list of every site your team has an account with is a good map of your software footprint, including free tools that hold company data.
- Your domain registrar and hosting account. Campaign domains, privacy add-ons, extra mailboxes, backup plans, certificates. These renew quietly and are easy to forget until the one that matters expires.
- Your main platform bill. Microsoft, Google, your accounting package, your phone system. Line items get added over time and rarely get removed.
What you are building here is an inventory, and it happens to be a security document too. The CISA Cyber Essentials guidance tells small organizations to maintain inventories of hardware and software assets to know what is in play and at risk from attack. NIST makes the same point in its Small Business Quick-Start Guide, advising businesses to understand what assets they rely on by creating and maintaining an inventory of hardware, software, systems, and services. Your billing statements are the cheapest starting point for that list you will ever find.
The Four Buckets: Keep, Downgrade, Consolidate, Cancel
Sorting is faster than deliberating. Every line gets one of four labels.
- Keep. Someone uses it weekly and would complain loudly if it disappeared. Leave it alone and move on.
- Downgrade. You are on a tier you do not need, usually because you bought it for one feature during one project. Fewer seats, a lower plan, or the version without the add-on you never turned on.
- Consolidate. You are paying two or three vendors for overlapping capability. Storage, video meetings, e-signature, and scheduling are the usual culprits, and often one of them is already included in a platform you pay for.
- Cancel. Nobody has logged in this year. Do not negotiate with yourself. Cancel it, note the date, and see if anyone notices.
One honest warning about consolidation. Moving everyone onto one platform saves money and simplifies security, but it is a project, not a click. Budget real time for exporting data and retraining people, and do not start it during your busy season. We wrote more about how these charges quietly compound in our year-end review of the cost of neglecting subscriptions.
Seats, Tiers, and the Annual Versus Monthly Question
The single most common leak we find is not an unused product. It is unused seats inside a product you genuinely need. You hired six people, two left, and the license count never came down. Most vendors will not reduce your bill on their own initiative, so pull the user list for every tool with per-person pricing and compare it to your current payroll. Look for former employees, contractors whose project ended, and duplicate accounts created when someone changed their email address.
On annual versus monthly, the honest answer is that it depends on your confidence. Annual billing is usually cheaper per seat, and it is a fine choice for tools you are certain about, like your email platform. Monthly costs more but keeps you flexible, which is the right call for anything new, anything tied to a single client, and anything you are still evaluating. The trap with annual is not the price. It is that a yearly charge only surfaces once, and it is easy to miss. If you commit to annual terms, put the renewal date in a shared calendar with a reminder 30 days ahead, so the decision to renew is an actual decision.
Forgotten Accounts Are a Security Problem, Not Just a Billing One
Here is the part most subscription cleanups miss. Cancelling the payment does not always close the account, and an abandoned account is a real risk. It usually has a weak or reused password, no multi-factor authentication, an email address nobody monitors for breach alerts, and company data still sitting in it. Nobody is watching it, which is exactly what makes it attractive.
CISA’s Cyber Essentials guidance is direct about this, advising organizations to identify and deactivate unused accounts, eliminate shared accounts, remove unnecessary privileges, and enforce strong password policies. NIST’s Small Business Quick-Start Guide frames it as a question to ask yourself about access: are we removing access when it is no longer needed? Both also push multi-factor authentication on every account that offers it. So while you have the list open, do three extra things: close accounts rather than just stopping payment, export any data you need first, and turn on multi-factor authentication for everything in the keep column. It is the same theme we covered in why cybersecurity is no longer optional for mid-sized businesses: the unglamorous housekeeping is the protection.
The Bottom Line
A subscription audit is not a cost-cutting stunt. It is operating hygiene that happens to return money. Do it twice a year, keep the spreadsheet, assign one owner, and require that every new subscription gets added to the list the day it is purchased. That last rule matters more than the cancellations, because it stops the next leak before it starts. What separates the businesses that keep the savings is that they put the second pass on the calendar before they finished the first.
If you would rather not spend an afternoon reading twelve months of statements, we do this with Denton County businesses regularly, and we will tell you plainly which tools you can drop, which you should keep, and which accounts need closing rather than cancelling. Contact us today.
Sources:
Comments are closed