Software License Audit Checklist: 12 Steps for Beginners
Table of contents
Many IT teams struggle to find a reliable answer to the question “What software are we actually paying for, and are we using it?”
Gartner’s 2026 Market Guide for Software Asset Management Tools found that 61% of procurement leaders describe their software data as disorganized, inaccurate, or in need of major improvement. G2’s Summer 2025 SaaS Spend Management Grid Report puts numbers behind what that disorganization costs: software subscriptions now average $8,800 per employee, up roughly 27.5% year over year, and 30–50% of SaaS licenses sit unused. Gartner’s long-standing research on shadow IT puts unsanctioned software at 30–40% of total IT spending in large organizations. Most companies are running a meaningful chunk of their software budget with little visibility.
A software license audit is how you find shadow IT, identify software sprawl across teams, and begin optimizing your software spend for the actual needs of your business. It’s also how you walk into a renewal conversation prepared, instead of renewing on autopilot.
Here’s a checklist to run a software license audit, designed for teams without an active Software Asset Management (SAM) strategy or dedicated tools in place.
1. Define what you’re trying to learn
Before taking any action, decide what question this software audit is meant to answer. Are you trying to cut costs? Reduce tool overlap across departments? Get ahead of a batch of renewals? Each unique goal changes what you prioritize in future steps, so be clear on the desired outcome.
2. Assign ownership and pull in finance
Name one owner for the audit process — usually whoever runs IT Ops — and loop in finance or procurement early, since they hold the actual invoices and contracts. Cross-functional input is crucial. A software audit run solely by the IT team tends to miss SaaS tools a department bought outside of standardized procurement processes.
3. Inventory every software asset in the environment
Complete full discovery: on-prem, cloud, SaaS, endpoints. You may be tempted to shortcut this step, but it’s the one that determines the quality of everything downstream. Getting an accurate inventory usually involves combining several approaches:
Agent-based discovery. A lightweight tool installed on managed endpoints (i.e., laptops, desktops, servers) tracks installed software and usage continuously. It’s the most accurate method and the only one that gives you real usage data, such as launch counts and last-used dates, but it requires deployment and ongoing maintenance. It also can’t see devices you don’t manage.
Agentless (network) discovery. Scans your environment via protocols like SNMP, WMI, or SSH, or queries existing systems you already have — Active Directory, Entra ID, SCCM, Intune — without installing anything new. It’s fast to stand up and covers broad territory quickly, but it typically shows what’s installed, not what’s actually used, and it misses devices that are offline or off-network at scan time. Remote employees who rarely connect through VPN can be invisible to a network scan for weeks.
SaaS-specific discovery. Traditional endpoint scanning doesn’t see cloud subscriptions at all, so SaaS needs its own methods:
- SSO/identity provider logs (Okta, Entra ID, Google Workspace) show what employees are actually logging into — often the fastest way to see real SaaS usage.
- CASB (Cloud Access Security Broker) tools, if you have one, catch both sanctioned and unsanctioned cloud app traffic.
- Expense and accounts payable reconciliation — cross-referencing corporate card statements and invoices against your official software list — requires no technical access at all and is frequently the single fastest way to surface subscriptions bought entirely outside procurement.
Manual spot-checks. Don’t skip this low-tech step. A fifteen-minute conversation with a department lead routinely surfaces tools that never show up in any technical scan, especially in smaller teams or departments without managed devices.
Most mature software asset management processes layer these methods. Relying on only one approach guarantees blind spots.
Tip: If your audit takes more than a week, run discovery at the start of the audit and again near the end. New software gets installed often, and the reconciliation described in step 7 is only as good as how current this inventory is.
4. Collect every entitlement and contract
Purchase orders, order confirmations, subscription receipts, contract terms. This tells you what you’re actually paying for and under what terms — seat counts, renewal dates, auto-renewal clauses, cancellation windows.
Tip: This step routinely takes longer than expected, because these records tend to live in inboxes and departed employees’ folders rather than one central place. A software asset management platform that connects to your accounting system can pull invoices and line items directly into a license record automatically, which removes a large portion of this step’s manual collection work going forward.
5. Map deployments and subscriptions to owners
Tie every license and subscription to a business unit, a team, or a named user in an ownership map.
If your inventory lives in a platform rather than a spreadsheet, this mapping is usually completed by the tool’s day to day functionality. SaaS seats get checked out to named users (or to specific devices) as part of normal provisioning, so the ownership record already exists by the time an audit rolls around instead of needing to be reconstructed from scratch.
6. Pull usage data, not just license counts
A license count tells you what you’re paying for. Usage data tells you what you’re getting for it. Wherever you can (SSO logs, admin consoles, usage dashboards), pull actual login and activity data alongside your license counts — this is the difference between “we have this tool” and “we’re getting value from this tool.”
The most convenient way to gather usage data is a platform that both tracks assigned seats and detects logins. For example, Reftab does this by cross-referencing license assignments against its discovery data — so a license with 50 allocated seats but only 20 recent logins gets flagged automatically, rather than requiring you to export two reports and compare them by hand to spot the optimization opportunity yourself.
7. Identify overlap and duplicate tools
Look for multiple teams paying for tools that solve the same problem — two project management platforms, three e-signature tools, redundant design or communication apps. Overlap is one of the most common findings in growth-stage companies, and it’s often the fastest, least controversial place to cut spend. Departments may have their own valid reasons for using SaaS A over SaaS B, but they should be documented and considered against budget, scalability, and training/knowledge transfer requirements.
8. Hunt for shadow IT
This is similar to Step 3’s discovery, but focused on software that doesn’t show up in any current system. Cross-reference expense reports and your identity provider’s login logs against your official software inventory. The gap between those two lists is your shadow IT — tools purchased outside procurement that nobody’s officially accounting for, which usually means nobody’s evaluating whether they’re worth keeping either.
Reftab, for example, flags any app it detects through browser activity or SSO login that hasn’t been formally added as a tracked application. A detected login sit in a review queue as “discovered” until someone approves it, ignores it, or converts it into a managed license record. This keeps shadow IT discovery as an always-on process, rather than a periodic project.
9. Right-size every subscription against actual usage
Now put steps 5–8 together: for every license and subscription, compare seats purchased to seats actively used. Downgrade tiers that are bigger than your usage justifies, reclaim unused seats before your next renewal, and consolidate overlapping tools into one.
Some software asset management platforms build this decision directly into the renewal workflow. When a license comes up for renewal, you’re prompted to review and adjust seat counts against actual usage before confirming the new term.
10. Build a renewal calendar
Map every contract’s renewal date, auto-renewal terms, and cancellation notice window into one calendar. This is the single highest-leverage output of the whole audit — a 60- or 90-day heads-up before a renewal is the difference between negotiating from a position of knowledge and getting auto-renewed into another year of a tool you’ve already decided to cut.
Reftab keeps this as a standing view rather than a one-time export — a timeline-style calendar of every upcoming license expiration with urgency indicators, plus configurable email alerts at whatever lead time you set (90 days, 30 days, 7 days). Once set up, it stays current on its own instead of needing to be rebuilt for next year’s audit.
Tip: As a secondary benefit, this organized data — nventory, entitlements, and usage — is what you’d hand over if a partner ever did request a formal compliance review. Getting organized for your own reasons happens to make you audit-ready for theirs too.
11. Calculate the savings opportunity
Document seats to reclaim, tools to consolidate, subscriptions to downgrade, renewals to renegotiate or cancel. Put a dollar figure next to each finding.
If your spend data already lives in one place, this step is closer to reading a chart than building one. At minimum, aim for identifying actual versus projected cost across the whole software portfolio, plus a valuation of unused licenses.
12. Document findings and set a recurring audit cadence
A one-time audit is a snapshot; the value compounds when it becomes an integrated process. Set a cadence, assign a permanent owner, and keep the findings somewhere durable rather than in one person’s spreadsheet.
Scheduled, recurring reports (licenses with no recent activity, disabled users who still hold an active seat, upcoming renewals) reduces the manual effort for this task. Some platforms also support formal, periodic access reviews — asking app owners to confirm who should still have access — which doubles as documentation if you ever need to show an auditor that this is a maintained process rather than a one-off.
The SaaS visibility solution
Every step on this list gets easier with a single source of truth for what software exists in your environment, who owns it, what it costs, and when it renews. Most SMB and mid-market IT teams are struggling with data scattered across spreadsheets, inboxes, and tools that don’t talk to each other.
Reftab brings software, licenses, and renewal dates into one place, so you can pull data from one source instead of five disconnected ones. Teams with that visibility don’t run this checklist once a year in a scramble. They run it continuously, because the data is already current.
Table of contents
Your IT inventory, finally under control
Try Reftab for free, no strings attached. 50 assets free forever.
Continue reading
Your assets, simplified. Begin your journey with us!
50 assets free forever with unlimited inventory & software tracking. Includes email alerts, mobile apps, reports, custom asset tags and more.

