Software Licence Audit for Singapore SMEs: Cutting SaaS Sprawl Before 2027
To audit your software licences, export twelve months of company card and bank statements, match every recurring charge to a named internal owner and a specific business process, then cancel, consolidate or re-register each one. For a Singapore SME under 30 staff this takes about two working days and typically surfaces 15-30% of software spend going to tools nobody opens, duplicate seats for staff who have left, or accounts registered to someone's personal Gmail. Do it before your 2027 system changes start, not during them — because every tool you keep is a tool you will have to reconfigure, re-license and re-document when e-invoicing, payroll and hiring records all move at once.
Why does a licence audit belong before the 2027 work, not after?
The 2027 compliance calendar forces you into your systems anyway. E-invoicing changes how your accounting software sends documents. Payroll configuration changes with wage and CPF step-ups. Hiring documentation under the Workplace Fairness Act changes what your recruitment and HR tools have to retain and produce.
If you walk into that work carrying three overlapping project tools, two file stores and a CRM that only the sales manager logs into, you will pay to migrate all of it. Worse, you will document all of it — and a process document that references a tool you abandon six months later is dead on arrival.
The audit is cheap now and expensive later. Cutting a subscription in October costs one cancellation email. Cutting it in June 2027, after you have rebuilt an invoicing workflow around it, costs the rebuild.
How do you build the licence inventory when nobody has a list?
Almost no SME has a licence register. You are not starting from a system of record, you are starting from money leaving the bank. Work backwards from four sources:
- Card and bank statements, twelve months back. Twelve, not three — annual renewals hide in the months you don't check. Flag every recurring charge, including the SGD 12 ones.
- App store and PayPal receipts. Mobile subscriptions bought on a phone rarely appear on the company card.
- Your email admin console. List every third-party app connected to Google Workspace or Microsoft 365. This is where shadow tools confess — anything a staff member signed into with their work account shows up here even if the company never paid for it.
- Ask the team. One question in the group chat: what do you use every week that the company doesn't know about? Make it explicitly consequence-free, or you will get silence and keep the exposure.
Put the result in one spreadsheet with six columns: tool, monthly cost in SGD, renewal date, billing account owner, internal process owner, and what breaks if it disappears tomorrow. If you cannot fill the last two columns for a line item, you have found a problem rather than a tool.
What are you paying for twice without knowing it?
Duplication in small companies is rarely a deliberate decision. It accumulates. The repeat offenders:
- File storage you already own. A paid Dropbox sitting beside the Google Drive or SharePoint included in the subscription you already pay per seat.
- Video calls, three ways. Zoom, Google Meet and Teams, where two came free with existing licences.
- Seats for staff who have left. Offboarding usually removes the email account and forgets the eight tools billed separately.
- Trial tiers that quietly became paid. Someone's 2024 experiment, still renewing.
- Per-seat plans bought for the whole company so two people could use one feature.
While you are in the statements, check how GST appears on your overseas SaaS invoices — whether a vendor charges it, and how your bookkeeper treats the ones that don't, is worth a specific question to your accountant rather than an assumption.
What happens when a licence is tied to a person instead of the company?
This is the finding that matters more than the money. Go down your inventory and look only at the billing account owner column. Every line registered to a personal email address, a personal credit card or a staff member's phone number is a tool your company does not actually control.
The failure is predictable. The person leaves, or goes on long leave, or simply stops answering. You cannot reset the password because the recovery email is theirs. You cannot cancel the billing. You cannot add a user. If the tool holds customer data, you also cannot honour a PDPA access or correction request against it, because you have no administrative access to the data your company is responsible for.
Fix it with three rules, applied to every tool you keep:
- Billing goes to a company card and a shared finance address, never a personal one.
- The admin account is a company-domain account with at least two people holding recovery access.
- Every tool has one named internal process owner who is accountable for its renewal decision — and that person is not automatically the owner.
How do you decide what to keep, cut or consolidate?
Sort the inventory by annual cost, highest first, and put every line into one of four buckets:
- Keep and harden. Load-bearing, actively used, will survive 2027. Re-register ownership properly, enable MFA, record the renewal date.
- Consolidate. Does something a tool you already pay for also does. Migrate within 90 days, then cancel — in that order, never the reverse.
- Cut. No active users, or no process owner willing to defend it. Export your data first, then cancel.
- Decide later, with a date. Genuinely contested. Give it a named decision owner and a deadline inside this quarter. Items without a date never leave this bucket.
One discipline makes the difference: before you cancel anything, export the data and verify the export opens. A cancelled SaaS account is usually purged after a short grace window, and that is not a backup you get to retry.
What should the 2027 baseline look like when you are done?
Aim for one tool per job, each company-owned, each with a named owner and a known renewal date, all listed on a single page your bookkeeper and your successor can both read. Set a calendar reminder two weeks before every renewal above SGD 500 a year, and re-run the statement sweep each January — it takes an hour once the register exists.
The saving is real but it is the smaller prize. The larger one is that when the 2027 changes land, you are configuring a system you can fully describe, administer and hand over. That is the difference between a tech stack your business owns and one that merely runs on your premises.
Frequently asked questions
How long does a licence audit actually take for a 20-person company?
Roughly two working days spread over a week: half a day pulling statements and admin console reports, half a day chasing what the team actually uses, and a day on the keep-cut-consolidate decisions. Migrations off consolidated tools take longer and should be scheduled separately, usually within a 90-day window.
Can digitalisation grant support cover the tools we decide to keep?
Some pre-approved solutions attract support under Singapore's digitalisation schemes, but eligibility, claim windows and the categories covered change between cycles. Confirm current terms on the official listings before you commit to a vendor on the assumption of funding, and treat any grant as a discount on a decision you would make anyway — not the reason for it.
What if a staff member refuses to give up a tool we have decided to cut?
That usually means the tool is doing real work the replacement does not do, or that the person's workflow is undocumented. Ask what specific task breaks and have them show you. If the gap is genuine, keep the tool and register it properly; if it is habit, set a switch-over date and provide the training. What you should not accept is the tool continuing on a personal account outside the company's control — that is how shadow IT and PDPA exposure both start.
Ready to Transform Your Business?
Let Digital Perpetual help you automate, streamline, and grow.
Get Started with Digital Perpetual →