We all know it; we all face it. The mischievous creature lurking in the shadows (no pun intended), Shadow IT. This is the story of how we as a TBMO devised a report that consolidates and automates the reporting of Shadow IT or as we have labelled it, Outside IT Spend. The reasoning behind this name change is to ensure discussions on this subject are less emotionally loaded and reduces the negative connotation for the business.
What is Shadow IT? In a nutshell, it is described as the use of IT systems or vendors by a department or user without the knowledge of IT. In recent years, Shadow IT spend has grown exponentially, largely driven by the surge in Cloud based consumer applications, social media and collaboration tools. It is important to note that while Shadow IT may not be inherently bad for the organisation, as many of the applications sourced may help drive employee productivity and innovation, it poses a large security risk to the firm due to the lack of visibility and validation by IT. It's also probably worth noting that in some cases the growth of Shadow IT could be seen as a reflection of the business' frustration with internal IT in not keeping up with demand for new technology. In either case, being able to quickly view and track Shadow IT spend helps IT understand both risks and opportunities.
As we commenced our journey down this path, we realised that by using existing Vendor Spend datasets, we could apply small tweaks devised alongside our Finance team to produce a Shadow IT dataset. The premise of these business rules lies in our TBM framework. Essentially, we have several Business Units which we consider 'In Scope' as they fall within the realm of 'authorised' technology spend. Therefore, by using the Vendor Spend report and filtering for all Technology Accounts, then highlighting all non-IT Business Units, we could establish which of these were contributing to Shadow IT spend.

As previously mentioned, Shadow IT can be beneficial in the sense that it may surface applications or products that the firm see as necessary. And here lies the true beauty of this report. Security can now track Shadow IT to surface potential risks while also allowing for IT Business Partners to have discussions with the business to better understand how IT can help facilitate their IT needs.
For any company looking to centralise and report on their Shadow IT Spend, we hope this story resonates with you. Moral of the story, small changes can lead to great things! Enjoy!
And a special thank you to my team at KPMG Australia for all the support and guidance along the way; @Jaitabh Jewel Sharma, @Quentin Kynoch, @Amanda Tang as well as our fellow TBM & Apptio compradres; @Tiffany Hu, @Jarno Jansen, @Debbie Hagen, @Sean Gomerdinger.
#CostingStandard(CT-Foundation)