By Tanguy Duthion
·
August 8, 2026
If IT, finance, security, procurement and business teams do not make decisions together, SaaS costs more and creates greater exposure. The three figures I would keep in mind are 53% of SaaS licences remain unused, 35% of French security professionals identify unapproved applications as a concern, and regulations such as GDPR, NIS2 and DORA require shared monitoring of contracts, risks and data.
Put simply, SaaS governance alignment rests on a few things, but they must be written down and maintained over time:
I also set out the role of each stakeholder: IT, security, finance, procurement, legal/compliance, business teams and users. The key point is simple: without clear decision rules, each team works from its own perspective, and the SaaS portfolio becomes unclear, expensive and difficult to control.
Here is what the reader will find in the article:
| Topic | Key takeaway |
|---|---|
| Stakeholders | IT, security, finance, procurement, legal, business teams |
| Decision framework | RACI + charter + escalation |
| Oversight | monthly forum + quarterly reporting |
| Control | SaaS inventory, security, compliance, costs |
| Quantified priorities | > 90% of applications through governance, < 5% inactive licences |
| Renewals | review 90 to 120 days before expiry, especially above €25,000 per year |
In short: this is not just about coordination. It is about a simple framework for making better decisions, cutting unnecessary spend and keeping control of SaaS risks.
After establishing the alignment principle, one point still needs to be settled — simple in theory, but often unclear in practice: who decides, who acts and who arbitrates.
In a French mid-sized or large company, SaaS governance involves seven key stakeholders: IT, security, finance, procurement, legal/compliance, business teams, and end users and employee representatives. Each starts with a different priority. The aim is not to pile up roles, but to ensure that their decisions move in the same direction.
IT ensures the SaaS portfolio is coherent and aligned with the digital roadmap. The CISO focuses on data security, identity and access management, compliance with security frameworks and data residency in the EU. The CFO is primarily concerned with predictable OPEX and removing unused licences. Procurement manages supplier selection, contract negotiations and control of auto-renewal clauses. Legal/Compliance validates data processing, DPAs and clauses governing transfers outside the EU under GDPR, NIS2 and DORA. Business functions want tools suited to their needs, with enough autonomy. Finally, end users and employee representatives pay close attention to usability and the effect on everyday working practices.
These priorities often pull in different directions. This map therefore provides a starting point for arbitration and approval paths.
The logical next step is to formalise this view in a RACI matrix.
A RACI matrix clarifies, for each stage of the SaaS lifecycle, who executes (Responsible), who owns the outcome (Accountable), who must be consulted (Consulted) and who must be informed (Informed). Without this framework, approvals drag on and, over time, nobody knows who owns what.
| Governance activity | IT | CISO | CFO | Procurement | Legal / Compliance | Business |
|---|---|---|---|---|---|---|
| SaaS discovery & inventory | R/A | I | I | I | I | R |
| Definition of the business need | C | I | I | I | I | R/A |
| Security and risk assessment | C | R/A | I | I | C | C |
| DPIA, where required | I | C | I | I | R/A | C |
| Contract & DPA validation | C | C | C | R | R/A | C |
| Budget approval | I | I | R/A | C | I | C |
| Deployment & integration | R/A | C | I | I | I | C |
| Licence management and optimisation | R | I | C | C | I | R/A |
| Periodic review & renewal decision | C | C | R/A | C | C | R |
| Decommissioning & data deletion | R | C | I | I | R/A | C |
The RACI moves alignment from theory to a decision process that can be used every day.
This matrix should then be incorporated into a governance charter, a formal document approved by executive management. The charter defines the scope, applicable rules, escalation thresholds and review frequency, with at least one review per year. Without executive approval, this kind of document often ends up in a shared folder that nobody opens.
Once the roles are defined, the thresholds that escalate a decision must also be set.
Not all SaaS decisions carry the same weight. In practice, decision rights revolve around three situations.
Selecting an application. Business teams state the need. IT checks the consistency of the SaaS portfolio. The CISO validates security. The CFO and Procurement frame the budget and contractual terms. The final decision then depends on the level of risk, data sensitivity and total cost. Above the thresholds defined in the charter, the matter is escalated to the governance forum.
Accepting residual risk. The CISO and Legal/Compliance assess the risks, including their impact on regulatory compliance, and propose compensating measures. If a risk remains after that, the risk owner formally signs its acceptance.
Arbitrating in the event of disagreement. When business and security teams cannot agree, the escalation process should be written in advance. First, an operational decision at the initial level. Then, the governance forum if no consensus emerges. Finally, executive management for major risks. This path must appear explicitly in the charter.
Once roles and decision rights are defined, they need to operate day to day. This is where the operating model comes in. It turns rules into clear working habits. In practical terms, it relies on three straightforward levers: a forum, shared workflows and shared indicators. The forum makes decisions, workflows move requests forward and KPIs keep everyone on course.
The SaaS governance forum is the central point of passage. It sets the pace and prevents each team from going its own way. It brings together IT, the CISO, the DPO, Finance/controlling, Procurement, Legal and business representatives. Ideally, it is led by the CIO or by a dedicated SaaS governance manager. Its role is simple: make decisions, arbitrate and unblock issues.[3][2]
A 60-to-90-minute format is enough to maintain the cadence, provided the meeting gets straight to the point. The agenda covers KPIs, new requests, critical risks still open, upcoming renewals and exceptions to approve. This rhythm avoids rushed decisions. Above all, it puts everyone in front of the same facts at the same time.
The forum arbitrates; workflows execute.
A standardised workflow avoids a very common problem: two business departments want to adopt similar tools but follow two different processes. The result is longer lead times, grey areas and security or compliance rules applied differently depending on the team involved.[4][5][6][7][8]
The aim is therefore to have one reference process covering the entire SaaS lifecycle. It should cover:
Put differently, avoid improvisation. If the framework changes from one department to another, alignment quickly disappears.
KPIs make alignment visible. Without measurement, everyone assumes they are aligned; in practice, nobody is sure. A short, well-maintained dashboard is enough to manage the whole portfolio.
| KPI | Measure | Indicative target |
|---|---|---|
| Identified applications | Total SaaS applications identified, approved vs unapproved | Complete and up-to-date inventory |
| Share of approved applications | % of active applications that have completed the governance process | > 90% [1] |
| Unused licences | Number and cost (€) of licences with no usage for 90 days | < 5% of the estate [1] |
| Renewal savings (€) | Amount saved through negotiation or licence reduction | Quarterly tracking |
| Unresolved critical risks | High-risk applications without an active remediation plan | Priority tracking |
| Compliance review rate | % of applications that have undergone a GDPR/NIS2/DORA review | Systematic review of sensitive applications |
These indicators then feed three levels of reporting. Regular operational points between IT, security and business teams address urgent matters. Monthly governance forum meetings handle decisions affecting the portfolio. Finally, a quarterly report for the Executive Committee or IT leadership tracks changes in the estate, savings achieved and regulatory compliance status.[2][8][9]
From there, priorities become clearer: which risks to address first, which compliance topics to accelerate and where to act on spend.
The forum's decisions and shared KPIs become very concrete here. The focus moves from intent to execution: discovery, control, compliance and renewals.
Shadow IT does not usually come from a desire to bypass the rules. It appears mainly when teams move faster than the framework in place. A typical case is a marketing team subscribing to an email automation tool with a corporate payment card without going through IT. Customer data may then be processed outside approved systems, without a DPIA or clear data-hosting clause. The same risk exists for any tool introduced without security approval.
Another sensitive issue is employee departure. Accounts remain active in unreferenced tools after an employee leaves simply because there is no well-defined deprovisioning process between HR, IT and managers.
To correct this, IT takes ownership of discovery. It analyses SSO logs, expense claims and network traffic to identify undeclared applications. The CISO then assesses each tool: encryption, access controls, data location and incident management. Business owners provide context and confirm whether the tool meets a need that is already covered elsewhere. In practice, Avanoo automates this detection and cross-checks employee departures with active SaaS accounts to identify orphaned access.
Once undeclared usage has been identified, compliance is managed application by application. There is no magic wand: each tool must be examined individually.

Three regulations, three logics, but one SaaS portfolio to manage. The GDPR requires an up-to-date record of processing activities for every application handling personal data. NIS2 calls for documented management of digital-supplier risks, as well as evidence of incident detection, response and notification. DORA requires financial entities to maintain an up-to-date ICT third-party register that is accessible to supervisors.
| Regulation | Key SaaS requirement | Key deadline |
|---|---|---|
| GDPR | Record of processing activities (RoPA), DPIA for high-risk processing | 72 hours (data breach) |
| NIS2 | Supplier risk management, evidence of incident detection, response and notification | 24 hours (early warning) |
| DORA | ICT third-party register, contractual clauses, resilience tests | 4 hours (major incidents) |
To prevent all this from remaining on paper, every new SaaS request should trigger a data protection review before going live. Legal and compliance teams define the RoPA model. The CISO documents the supplier's technical and organisational measures. IT maps data flows. Annual reviews — or reviews aligned with contract renewals — then keep these registers up to date and ready for an audit.
The same oversight also helps manage renewals and cut spend that no longer makes sense.
40% of SaaS spend escapes procurement oversight, and 30% of licences are unused [1]. Put simply, this goes well beyond IT. It is a governance issue. If Finance does not know what IT has signed, and Procurement discovers an automatic renewal too late, nobody can regain control.
A shared renewal calendar already makes a major difference. If it is triggered 90 to 120 days before expiry for every contract above €25,000 per year, it becomes possible to avoid unwanted automatic renewals [1]. At each renewal, IT brings actual usage data, the business explains the expected value and Finance decides based on cost per active user.
After forums, workflows and KPIs, the final obstacle is often shared data. A common calendar changes little if each team still works from its own version of the facts. A SaaS platform addresses this by bringing information together in one place and giving everyone the same view in real time.

Avanoo centralises SaaS discovery, security, compliance and costs in a shared space. This common view directly supports forum decisions and executive reporting.
The table below shows how Avanoo translates the RACI, forum and workflows into the day-to-day work of each stakeholder:
| Stakeholder | Governance objective | Avanoo capabilities | Key KPI |
|---|---|---|---|
| IT | Control the SaaS application estate | Automated SaaS discovery, Shadow IT detection | Number of undeclared applications detected |
| CISO | Reduce data exposure | Application security score, data residency and usage | Number of high-risk applications |
| CFO | Optimise costs (€) | Unused-licence analysis, functional duplicate detection | Licence utilisation rate (%) |
| Legal / Compliance | Ensure GDPR, NIS2 and DORA compliance | Data-residency monitoring, detection of missing DPAs | Applications without an up-to-date DPA |
| Procurement | Manage supplier renewals | Renewal alerts, contract intelligence | Number of automatic renewals avoided |
| Business teams | Adopt suitable and secure tools | Adoption dashboards, approved-tool catalogue | Usage rate of approved tools |
In practical terms, the monthly governance forum uses Avanoo dashboards to review newly detected applications, the most critical security scores and upcoming renewals. The quarterly executive report — presented to the Executive Committee or IT leadership — draws on the same data to track risk, spend and governance maturity.
SaaS governance rests neither on a spreadsheet nor on the goodwill of one team. It relies on four mutually reinforcing pillars: stakeholders identified from the outset; documented roles and decision rights; repeatable routines such as the forum, workflows and checklists; and shared KPIs fed by reliable data.
To take action, the recommended sequence is straightforward:
SaaS governance becomes sustainable when the same reliable data supports the same decisions.
Co-fondateur & CEO
Tanguy Duthion is co-founder and CEO of Avanoo. Previously at Google and Asana, he founded Avanoo to help organizations regain control over their SaaS and AI usage.
See how Avanoo can map your SaaS and AI landscape, reduce risk, and optimize costs. A reliable platform with dedicated human support.