Ask a client how many apps their business runs and you’ll get a number. Ask IT, and you’ll get a different one. The gap between those two numbers is where compliance risk lives — and most advisory firms only find out it exists after a client gets an audit letter or a breach notice. A SaaS compliance checklist isn’t paperwork you run once a year. It’s the thing that closes that gap before it costs your client money, or costs you the relationship.
Why client stacks fail compliance without anyone noticing
Every client you advise is quietly accumulating software. A marketing hire signs up for a design tool on a personal card. A department head trials three project management apps and forgets to cancel two. Someone connects a free AI assistant to company files to save time on a deadline. None of it goes through procurement. None of it shows up on a license spreadsheet. And none of it gets reviewed against data-handling rules, access policies, or the contracts your client signed with their own customers.
This is shadow IT and shadow AI, and it’s a compliance problem before it’s ever a cost problem. An unauthorized tool with access to customer data is a gap in whatever standard your client is being held to — SOC 2, GDPR, HIPAA, or just the terms in their own client contracts. And because nobody signed off on the tool, nobody’s watching it.
Why it happens — and why annual reviews don’t catch it
The root cause is speed. Software is easy to buy and easier to forget. A free trial needs no approval. A team lead with a company card can be running five tools by lunch, and every one of them is a login, a data-sharing agreement, and a potential exposure. Multiply that across every department, every contractor, every client you serve, and a once-a-year spreadsheet review is already months behind the stack it’s supposed to be checking.
The other reason it happens: nobody owns the whole picture. IT sees the tools they provisioned. Finance sees the invoices that hit a card. Neither sees the free-tier tool a manager signed up for on their own. Shadow IT lives exactly in that blind spot — which is also exactly the client work an advisor is positioned to catch, if you’re checking for it rather than just totaling license costs.
The SaaS compliance checklist
Run this against every client stack, not just the ones flagged as high-risk. Shadow tools show up in the businesses that look the most buttoned-up too.
- Discover every app and AI tool in use — not just the ones on the approved list. Include tools bought on personal cards and trials nobody converted or cancelled.
- Map each tool to a real user and a real access level. A tool with nobody actively using it but full data access is a bigger risk than one everyone uses daily.
- Flag AI tools separately. Check what data gets fed into them at the model and seat level — this is the fastest-growing blind spot in most client stacks.
- Check every tool against the client’s actual obligations — their industry’s standard, their own customer contracts, their data residency requirements.
- Confirm who owns each renewal and contract, so nothing auto-renews under terms nobody re-checked.
- Document what you found and what changed, so the review is repeatable next quarter, not a one-off scramble.
What good looks like
A client stack that passes this checklist isn’t smaller — it’s known. Every app is mapped to a person and a purpose. Every AI tool’s data access is visible, not assumed. Nothing renews on autopilot, and nothing new gets added without someone noticing. That’s the difference between compliance as a document you produce once and compliance as a state the business is actually in.
This is also where the checklist stops being a chore and starts being a service line. Running this review by hand, once a year, off a spreadsheet, doesn’t scale past a handful of clients. Running it continuously, with every tool and every AI seat mapped automatically, turns into something you can package: a client-ready compliance report, delivered under your own brand, that clients pay for because it answers a question they can’t answer themselves.
Take this into your next client review
You don’t need new software to start. Begin with the first three items on the checklist by hand — ask every department what they’ve signed up for in the last quarter, pull the card statements, and compare against the approved list. The gap you find is usually bigger than the client expects, and that gap is the conversation that opens the door to a recurring, billable review.
When you’re ready to make that review repeatable across every client instead of rebuilding it from scratch each quarter, that’s exactly the shift from spreadsheet to service line.
