Audit

Combining an IT audit and a process audit at 150 employees

How to map both the cost and the reason at 150 employees, and decide what you build, cut or keep.

Berkan Alci, founder of YK TechnologiesBerkan Alci12 min readManagement, IT, finance and operations

In brief

  • 20% to 30% of IT spending is waste and more than half of SaaS licences go unused; an audit makes that figure visible (Flexera, 2024).
  • At 150 FTE you fall under NIS2 and you are heading towards 106 separate SaaS apps: too big to hold in one person's head, too small not to put right in a single round.
  • An IT audit gives you the cost, a process audit the reason; together they let you cut a step rather than negotiate it slightly cheaper.
  • Set a baseline that finance signs off on, otherwise you can prove no saving after the fact.
  • Work in waves with a go or no-go: large software projects run 45% over budget on average and deliver 56% less value (McKinsey and Oxford, 2012).

A company with 150 employees sits in an awkward zone. Big enough that no one holds the full picture in their head any more. Small enough that the waste never stands out, because it is spread across five or six departments that each assume someone else is keeping an eye on it.

Take a wholesaler in technical parts. A hundred and fifty people, a warehouse, an office and field sales team, a finance team, two people on IT. On an ordinary Tuesday an order gets stuck between sales and the warehouse, because someone retypes it by hand from one system into another. No one sees that as a problem. It is simply how things go.

An IT audit tells you what that Tuesday costs in software. A process audit tells you why that retyping exists. On their own, each gives you half the answer. Together you get the bill and the reason, and only then can you decide what to cut rather than what to negotiate slightly cheaper.

Why the two belong together

An IT audit maps four things: what you pay, which contracts are running, who actually uses the tools, and where the gaps in your security are. It is an inventory with price tags attached. Useful, but rudderless on its own, because an inventory does not tell you which tool you actually need.

A process audit does the opposite. It follows how the work really runs, not as the procedure describes it but as people do it every day. With the export to Excel because the report in the system is wrong. With the email to the colleague who is locked out of the system. With the double keying because two systems cannot talk to each other. That retyping of the Tuesday order appears in no procedure, and yet it happens a hundred times a week.

Put the two side by side and the pattern jumps out. A tool costs money because a process step calls for it. Cut the step and the cost goes with it. That is the reason to run both audits together and not one after the other. Anyone who audits IT first and only looks at the process months later is already negotiating contracts for steps that would have been better cut.

The biggest mistake you can make here is automating a bad process. Then you buy software to make a problem happen faster. You pay twice: once for the tool, and once for the time the messy process keeps eating, now with a subscription on top.

Why 150 employees is the tipping point

Below fifty employees, one person still knows the whole company. The owner or the IT lead knows which tools are running, who pays for what and where the passwords are. The waste exists there too, but it still fits in one head, and so it gets corrected as soon as it hurts.

At 150 that picture no longer holds. You have real departments, each with its own budget and its own bank card. Sales buys an add-on to the CRM, marketing a design tool, finance a reporting package, and no one ever puts the three side by side. This is called shadow IT, and at this scale it is not the exception but the default. Every department has its own small stack that no one knows centrally.

On top of that, no one owns the full stack. The IT lead knows the servers and the central systems, but not the subscription sales took out last quarter on a company card. The department heads know their own tools, but not what they cost together. That is exactly why the money leaks: everyone guards their own piece and no one the whole.

At this scale a legal line also comes into play. NIS2 brings companies from around 50 employees into scope, including a duty to report incidents (NIS2). A company with 150 FTE falls under it with certainty, whether it is ready or not. Security is then no longer an IT hobby but a legal obligation with a deadline.

This is exactly why you measure now and not next year. Big enough that the leaks have become structural and no longer close on their own. Small enough that you can map them in a single coordinated round, without an eighteen-month transformation project that brings costs of its own.

What you measure, by team

An audit that stays at the level of 'IT' misses half the money. The costs and the lost time are not in the server room but in what each team does day after day. So you measure by function, and for every department you look at both the bill and the work behind it.

Management

Management today too often decides on gut feel, simply because the numbers are missing. You cannot cut what you cannot see. An audit does not give you a dashboard of forty KPIs, but a single overview: what the technology costs, where the time goes, and which three moves return the most. A list short enough to sign and to act on the Monday after.

The second thing management takes from it is a grip on risk. No dependence on a single supplier, no surprises in an external inspection, and security that matches what NIS2 requires. These are not IT details, they are boardroom questions.

Finance

Finance often looks at the wrong number. The question is not what a system once cost to buy, but what the stack keeps consuming every month: the run rate. That is where the leak sits. 20% to 30% of IT spending is waste, and more than half of SaaS licences go unused (Flexera, 2024).

In practice, that means licences still running for people who have already left, subscriptions that renew automatically each year without anyone finding the cancel button, and three tools that do the same thing in practice because three departments bought them separately. Finance puts a figure on it, and that figure turns a vague feeling into a concrete conversation.

IT

IT manages a stack that no one ever designed as a whole. The average company runs around 106 SaaS applications (BetterCloud, 2024), and most crept in one tool at a time, year after year. Under that sprawl sits technical debt: outdated systems, integrations held together with tape, code no one dares touch any more. That debt amounts to 20% to 40% of the value of the entire technology estate, and 10% to 20% of the budget for new work goes on clearing it (McKinsey, 2020).

The second question for IT is access management. Who has access to what, and is that still right today? Across 150 people and well over a hundred applications, that is not an administrative formality but the core of your security. It is also the point where the IT audit and the HR audit meet, as becomes clear further on.

Operations

Operations is where the time goes, and time is the largest hidden cost of all, because it appears on no invoice. Knowledge workers lose nearly 20% of their working week, about one full day, to searching for internal information (McKinsey, 2012). Translate that to your operation: that is one day per person per week booked nowhere.

So measure not just the licence but the action. How often is the same piece of data retyped? How long does that Tuesday order sit idle between sales and the warehouse? Where does someone wait for an approval that has to come by email and is only read after lunch? That waiting time is real and it adds up, and it can almost always be solved without buying a single new tool.

Sales

Salespeople spend less than 30% of their time actually selling. The rest goes on admin, filling in the CRM and internal meetings (Salesforce). Anyone who reads that as 'the salespeople are not working hard enough' is looking at it wrong. The CRM is usually the problem: it is built to let management report, not to get the salesperson to a signature faster.

In the audit you follow a single quote from first contact to signed order. You then see in fine detail where the time leaks away: the double keying of customer details already held elsewhere, the building of a quote by hand, the chasing of an internal discount that someone has to approve. Each of those steps is a candidate to cut or automate, and each one gives the salesperson back time to spend on selling.

HR

HR seems far from IT, until you look at onboarding and offboarding. Hiring a new employee means creating accounts across dozens of applications. Letting someone go means closing all those accounts again. On a stack of well over a hundred apps that is manual work, and manual work almost always fails somewhere.

An account left open for someone who left months ago is not an HR detail. It is an open door in your security, and therefore an IT and security problem with a name on it. Onboarding and offboarding belong in the same audit as IT's access management, not in a separate HR folder that no one puts alongside the rest.

How you run it

Reckon on about four weeks, not a quarter. It starts with scope. You appoint one owner per department, someone who knows how the work really runs there and who is also given the time to take part. Without that owner it becomes an exercise for the IT department alone, and then you miss exactly the half that matters: the process as people actually run it.

Then you measure two things at once. On one side the hard numbers: costs, contracts, usage, who actually opened which licence in the past month. On the other side the process: mapped step by step, with the waiting time and the rework noted alongside. Those two tracks run in parallel, because a cost without the process behind it is a number without meaning, and a process without the cost attached is a story without weight.

Most of the truth sits not in the systems but with the people. Go and see the salesperson who complains about the CRM, the warehouse worker who retypes the order, the finance clerk who builds the same report by hand every month. In five minutes they will point out where it chafes, faster than any export ever will.

Next you score. Every step gets a cost and a time. That way you see not only what a tool costs per year, but also that the process step beneath it costs three people half a day every week. Only with both numbers side by side can you prioritise honestly, because sometimes the cheap tool is the most expensive step.

The result is a report with a baseline: a zero measurement of what the situation costs today, in euros and in hours. You have finance sign off on that baseline. It looks like a formality, but it is the most important step of all. Without a figure that management and finance both stand behind, you cannot later prove a single saving.

And then you decide on each next step, again and again: go or no-go. No big plan that you approve or reject in one go, but a series of separate decisions, each with its own price tag and its own return. The audit itself stays vendor-neutral. It tells you what to do, not which brand to buy. That is a difference that saves you a lot of money later.

The pitfalls

You now know the first pitfall: automating a bad process. Software does not straighten out a messy process, it sets it in concrete and puts a monthly invoice under it. Put the process in order first, and only then buy the tool that fits underneath.

The second is skipping the baseline. Anyone who jumps straight to solutions without first setting the zero measurement can never prove afterwards that anything was saved. No baseline, no mandate for the next step, and the saving is left to belief, which convinces no executive committee.

The third is auditing only IT and leaving the process untouched. Then you get a tidy list of licences to negotiate over, and you miss exactly the steps that make half those licences unnecessary. You save 10% on the price where removing the step would have cut the cost entirely.

The fourth is the big bang. Tackling everything at once, in one large transformation programme approved with a single signature. That is exactly how the projects that go wrong run. Large software projects run 45% over budget on average and deliver 56% less value than promised (McKinsey and Oxford, 2012). So work in waves, with a go or no-go after each wave, so you can stop as soon as a track returns nothing.

The baseline is not optional Without a zero measurement that finance signs off on, every later saving is a matter of belief rather than proof. Set the baseline before you touch a single tool or cancel a single contract.

What you are left with

After four weeks you are left with three things. A signed baseline, in black and white, that management and finance both stand behind. A prioritised list of what costs money and time, with the largest leak at the top. And at every item on that list a clear decision: build, cut or keep.

That is the real result, not the report itself. No document that disappears into a drawer until the next reorganisation, but a decision you can start work on the Monday after the audit. You know which three things to tackle first, what they cost and what they return. That Tuesday order that got stuck between sales and the warehouse: you now know what the retyping costs and whether it is worth removing.

This is how YK approaches it. Start with an IT FinOps audit that maps both the cost and the process together. Then build on in waves with a go or no-go, so you never again bet on one large signature, towards one platform you own that sits in your own repo and stays yours. And work through the run rate with the cost calculator before you take the first step.

Measuring is not the goal. Deciding is the goal, and you cannot decide on what you cannot see.

Want to apply this to your own situation?

Belgian, founder-led and built to hand over. One email is enough.