How to Find Unauthorized AI Subscriptions on Your Corporate Cards: A 5-Step Audit
Your finance team approved Slack, Zoom, and Salesforce. Nobody approved the $20/month ChatGPT Plus seat your backend engineer expensed in January. Or the $30 Midjourney subscription your marketing lead categorised as "design software." Or the $25 Claude Pro account your product manager put on a personal card and forgot to expense entirely.
Multiply that across a 40-person organisation over 12 months, and you're not looking at a few hundred dollars. Gartner's research is explicit: organisations without centralised SaaS visibility overspend by at least 25% — a figure that will persist through 2027. For a Series A company spending $500,000 annually on software, that's $125,000 in pure waste. At Series B with $2 million in software spend, the number crosses half a million.
This is not a forecast. Zylo's 2026 SaaS Management Index, based on analysis of enterprise spending data, confirms that IT now controls only 15% of SaaS spend and 13% of applications. The remaining 85% lives in department budgets, individual corporate cards, and — most dangerously — personal cards reimbursed through expense reports under generic categories like "productivity tools" or "software."
Here is the five-step audit playbook to surface every unauthorised AI subscription before your next board meeting.
Step 1: Pull the Raw Transaction Data — All of It
The audit begins with a single data pull: every transaction across every corporate card, every expense report, and every accounts payable line item for the trailing 12 months. Do not filter by category, department, or amount. The AI subscriptions you need to find are deliberately miscategorised — if the data was clean, you would have found them already.
What to pull:
- Corporate card statements (all cardholders, all transactions)
- Expense reimbursement reports (including those under $50)
- Accounts payable vendor list with 12-month spend
- SaaS management platform data (if you have one — and if you don't, Zylo's data suggests you're in the 85% majority)
Why this matters: The median enterprise now runs 2,191 SaaS applications, according to the Zylo 2026 Index. ChatGPT alone is the most expensed application across their entire dataset. The transactions are there. They're just hiding under merchant descriptors that don't say "AI tool."
Step 2: Build Your AI Vendor Signature Library
This is the step most finance teams skip because they don't have the taxonomy. You need a list of AI vendor merchant descriptors — the exact strings that appear on bank statements when someone subscribes to these tools.
Common AI SaaS merchant descriptors include:
OPENAI * CHATGPT— ChatGPT Plus or TeamDRI* MIDJOURNEY.COM— MidjourneyANTHROPIC * CLAUDE— Claude Pro or TeamGOOGLE * GEMINI— Gemini AdvancedPERPLEXITY AI— Perplexity ProGITHUB COPILOT— GitHub CopilotJASPER AI— Jasper BusinessRUNWAYML— Runway video generationELEVENLABS— ElevenLabs voice AINOTION AI— Notion AI add-onGRAMMARLY— Grammarly AI (enterprise data risk)FIREFLIES.AI— Meeting transcription AIOTTER.AI— Meeting notes AI
And 50+ more. The problem is that DRI* MIDJOURNEY.COM looks like a generic digital purchase to accounting software, and OPENAI * CHATGPT might be categorised as "technology services" alongside your actual AWS bill. Without a signature-matching library, these transactions are invisible.
What to do: Cross-reference every transaction against a maintained AI vendor list. Flag any match — regardless of amount — for review. A single $20 ChatGPT seat found today prevents $240 in annual waste, multiplied by however many seats you never knew existed.
Step 3: Pattern-Match the Expense Report Descriptions
Personal card reimbursements are the hardest category to audit because you never see the merchant descriptor — only whatever the employee typed into the expense form. This is where the audit gets forensic.
Red-flag expense descriptions:
- "Productivity tool"
- "Software subscription"
- "Design tool"
- "Research assistant"
- "Writing tool"
- "AI helper" (some employees are surprisingly honest)
- Blank or single-word descriptions on recurring monthly amounts
- Any expense classified under a vague "Miscellaneous" or "Other" category
The pattern to hunt: Look for small, recurring monthly charges — typically $20 to $30 — with generic descriptions. These are AI tool subscriptions 80% of the time. Cyberhaven's research confirms the behaviour: employees expense these tools because they genuinely increase productivity, but they bypass procurement because the approval process is slower than the free trial expiration.
Step 4: Quantify the Financial Impact — Not Just the Total
Finding the subscriptions is step one. Making the case for governance reform requires financial modeling that speaks the language of the boardroom.
Build three numbers:
Annualised direct cost: Sum every identified AI subscription × 12 months. A 40-person company with 12 unauthorised AI seats at an average of $25/month = $3,600/year in direct cost. That's small. The real number is the next one.
EBITDA erosion from SaaS overspend: Apply Gartner's 25% overspend multiplier to your total software spend. If your total SaaS portfolio is $500,000 annually, and Gartner's data says 25% is waste without centralised visibility, the shadow AI component is likely $15,000 to $30,000 — not because the AI tools are expensive, but because the lack of visibility indicates a systemic procurement gap that extends far beyond AI.
Compliance exposure valuation: For every identified AI subscription, assess the data sovereignty risk. Is the tool processing customer data? Employee PII? Proprietary code? LayerX Security found that 77% of employees share sensitive company data via AI tools. Each unauthorised subscription is a potential regulatory exposure under GDPR, the EU AI Act, and SOC 2 — and IBM's 2025 Cost of a Data Breach Report pegs the average breach cost at $4.4 million.
Present these three numbers together. The direct cost gets attention. The systemic waste gets budget. The compliance exposure gets executive sponsorship.
Step 5: Deploy Detection — Because Manual Audits Don't Scale
The five-step audit is effective once. It is not sustainable quarterly or monthly — not at the scale of 2,191 applications across a growing organisation. Finance teams that run this audit manually will find the subscriptions, clean them up, and watch them reappear within six months as new AI tools launch weekly and employees continue to find productivity shortcuts.
The durable solution is transaction-level AI signature detection that runs continuously — scanning corporate card data as it arrives, flagging AI vendor signatures before the expense report is approved, and maintaining a live inventory of every AI tool across every department.
Binadox documented a technology startup preparing for IPO that discovered shadow IT applications represented 60% of their total software spending during pre-IPO preparation. The discovery happened during external audit — meaning it was found by someone outside the company, at the worst possible moment, with no time to remediate before it appeared in diligence materials.
The lesson is not that shadow AI is rare. It's that most companies don't look for it until someone else forces them to.
What a Live Audit Looks Like
The output of a properly instrumented AI spend audit is not a spreadsheet. It's a risk-classified inventory:
- HIGH RISK: ChatGPT Team seats with no DPA in place, processing customer support transcripts. Immediate remediation required.
- ELEVATED: Design team Midjourney subscriptions expensed on personal cards. Procurement review within 30 days.
- MONITORED: Grammarly AI licenses approved by IT but requiring annual data flow review.
- CLEAN: Enterprise-negotiated Copilot seats with data residency guarantees in place.
The Office of the CFO cannot manage what it cannot see. The five steps above make it visible. The question is whether you deploy them before your next board meeting — or after your acquirer's due diligence team finds the subscriptions first.
This briefing was prepared by the AuditSentinel Financial Intelligence Desk. Sources: Zylo 2026 SaaS Management Index, Gartner (SaaS spending forecast through 2027), Cyberhaven 2023 & 2024 studies, LayerX Security, IBM Cost of a Data Breach Report 2025, Binadox case study.