The IT Renewal Teardown Worksheet
Decide Every IT Renewal Before the Notice Window Closes
Put the recurring charge, contract terms, actual use, operating evidence, overlap, exit cost, and seller income in one worksheet.
Unlock the full document
This document is free. Leave a work email so we can send corrections and updated versions, and the full sheet unlocks below.
The recurring charge has no owner
Your predecessor, a board member, a department head, or someone who left in 2022 signed the contract. The charge still hits every month. Nobody can name the users, show what it does, or explain what stops if you cancel.
Count the security tools on your invoices. Put the necessity decision and dated operating evidence beside each charge.
Pull the contract, invoice, admin-console use, setup owner, and control evidence into one row. Controllers, CFOs, Executive Directors, firm administrators, and Solo IT Directors can complete the worksheet in about six hours across three sittings. Write unknown when the record is blank.
Seven facts behind every keep, reduce, replace, or retire decision
A teardown is a per-line examination of a recurring charge against five facts: what the contract actually says, what the product is actually used for, whether it is actually running, what else you own that does the same job, and what it would cost to leave.
Three things this document will never do. It will not tell you that twelve tools is too many; twelve may be right, six may be too many, and eighteen may be defensible in a regulated firm with three offices. It will not give you a target percentage of revenue, because that number does not exist in any form worth quoting, and the reasons are set out in the companion CFO worksheet. And it will not push you toward removal. A product stays when the evidence supports it. Keeping is a finding, and a documented keep is worth as much as a cancellation, because next year you will not have to re-argue it.
The discipline is symmetrical. You need evidence to cut and evidence to keep.
Use three sittings before your first decision date
Sitting one, about two hours: find everything. Do not evaluate anything. You are building a list.
Sitting two, about three hours: fill the contract facts and the use evidence. This is where the real work sits, and where you will find you cannot answer some of it. Good. Write unknown and move on. Sitting three, about one hour: decide. Six states, one owner, one date each.
Do the discovery step first and completely. Every teardown that starts from “the list of tools we know about” produces a clean report on the half of the spend that was already visible.
Part 1: Build the complete renewal calendar
Recurring technology charges hide in more places than an accounting system shows. Work all nine sources below. Each one catches a category the others miss.
| # | Source | What to pull | What it catches | What it misses |
|---|---|---|---|---|
| 1 | Accounts payable ledger | 13 months of vendor activity, sorted by recurrence | Invoiced subscriptions, hardware maintenance, support contracts | Anything paid by card, anything under a coding threshold |
| 2 | Corporate card and ACH statements | 13 months, every line under $500 included | Small monthly SaaS charges buried in “dues and subscriptions” or “office expense” | Charges on cards you do not control |
| 3 | Expense reimbursements | 13 months, searched for “subscription”, “annual”, “renewal”, “plan”, “license” | Shadow subscriptions on personal cards | Tools nobody expenses because they are free tier today |
| 4 | Identity provider app catalog | Full export of connected and assigned applications | Every tool someone integrated with single sign-on | Tools that never used SSO |
| 5 | Public DNS zone and MX records | Full zone file including TXT records | Mail provider, mail security vendor, marketing platform, and the domain-verification record left by every SaaS you ever onboarded | Tools that require no DNS change |
| 6 | OAuth and third-party app grants in Microsoft 365 or Google Workspace | List of apps with granted access, with grant dates and grantors | Tools staff connected to company data without a purchase order | Tools with no cloud data access |
| 7 | Cloud and app marketplace receipts | AWS, Azure, Google Cloud, Apple, Google Play marketplace line items | SaaS billed through a cloud bill as a single opaque line | Direct-billed vendors |
| 8 | Vendor mail | AP mailbox and shared mailboxes searched for “renewal”, “auto-renew”, “your invoice”, “receipt”, “subscription” | Renewals nobody forwarded to finance | Anything sent to a departed employee’s mailbox |
| 9 | Department heads, asked directly | ”List every tool your team uses that we pay for, and every tool your team uses that you think is free” | The gap between what is paid for and what is used | Nothing, if you ask everyone |
Use 13 months rather than 12. An annual charge that landed 12.5 months ago falls outside a calendar-year pull and it is the one most likely to auto-renew unnoticed.
Reconcile accounts payable with identity and admin records
Cross the identity provider app list against the AP and card lists. Three cases come out of it.
| Case | What it means |
|---|---|
| In SSO, on an invoice | Normal. Proceed to the worksheet. |
| In SSO, on no invoice | Either genuinely free tier, or somebody else is paying. The second case is the shadow subscription, usually living on a personal card reimbursed as a meal, a conference expense, or a general office line. Ask the grantor named in the OAuth record. |
| On an invoice, absent from SSO and the app list | Frequently a tool nobody has opened in a year. Also frequently a tool holding standing access to your data. |
One more search, worth doing once: check whether the account recovery address on each subscription is a mailbox that still exists. A subscription whose password reset goes to a deactivated mailbox cannot be cancelled by you without a vendor support case, and that is an exit cost you want to discover before a renewal rather than during one.
Part 2: Put contract dates and notice terms in Sheet 1
One row per recurring charge. Fill this from the contract and the invoice, never from memory and never from the vendor’s website.
| Line | Vendor | Product | Annual cost | Billing frequency | Term end date | Auto-renewal (Y/N) | Renewal term length | Notice period (days) | Notice method | Decision date | Seats or units billed | Internal owner | Contract location |
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 1 | |||||||||||||
| 2 | |||||||||||||
| 3 |
Enter the contract owner, term, notice date, and decision date
- Annual cost. The full annualized figure including any charge billed separately: platform fee, per-seat fee, support tier, overage, and the implementation amortization if you are still paying it.
- Term end date. From the order form. If the order form references a start date and a term length, calculate it and write the calculated date.
- Auto-renewal and renewal term length. Auto-renewal is nearly always yes; write it anyway, because writing it forces you to look. A one-year contract that renews into a three-year term is a different instrument from one that renews annually.
- Notice period. The number of days before term end by which you must give notice to stop the renewal. Common values run from 30 to 90 days. Some contracts require notice before the start of the final quarter of the term.
- Notice method. Email to a named address, portal ticket, certified mail, or notice to a specific legal address. A cancellation sent the wrong way has not been sent.
- Internal owner. A named human, never a department. If no name fits, that is a finding, and you record it as one.
- Contract location. The file path or system where the executed order form actually sits. Most organizations cannot produce the signed document for a third of their subscriptions.
Calculate the last day you can preserve every option
This is the single highest-return step in the whole worksheet, and it is clerical.
- Get the order form, never the proposal. The proposal is marketing. The order form is the instrument that was signed.
- Follow the incorporation clause. Most order forms are one page and incorporate a master agreement or terms of service by URL. The term, renewal, and notice language lives in that incorporated document under a heading like “Term and Termination”. Some vendors update linked terms, so save a PDF of the terms as they read today with the date you retrieved them.
- Compute the decision date, and diary that one. Decision date equals term end date, minus the notice period, minus fourteen days of working room. Put it in a shared calendar with the owner’s name in the title. Organizations miss windows because they diaried the renewal date instead.
- If you cannot find the terms, ask the vendor in writing. “Please confirm our current term end date, the renewal term length, the notice period required to prevent renewal, and the notice method.” Keep the reply. That email is now your record.
When you finish, sort the whole sheet by decision date ascending. Anything with a decision date inside 60 days goes to the front of the queue regardless of dollar value, because those are the only lines where delay removes your options.
Part 3: Put actual use and dated evidence in Sheet 2
One row per line, matched to Sheet 1 by line number.
| Line | Control or business need served | Seats billed | Accounts existing | Accounts active 90 days | Proof of operation (artifact) | Proof date | Overlaps with line # | Integration cost | Exit cost, known | Exit cost, internal hours | Exit cost, unknown | Adviser compensation |
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 1 | ||||||||||||
| 2 |
Write the control served before you evaluate the product
One sentence naming what the product does for the organization, phrased as an obligation or an operating need rather than as a product category.
Weak: “Endpoint security.” Strong: “Detects and isolates malicious activity on 196 laptops and servers, and answers the endpoint detection question on our cyber application and on two client security questionnaires.” Weak: “Compliance platform.” Strong: “Holds the evidence package our auditor requires in November.”
If nobody can write that sentence, the line is already in trouble. Write unknown and continue. You will resolve it in the decision step.
Put purchased seats beside active users
Three numbers, from three different places. Seats billed comes from the invoice, never from the contract (which may state only a minimum) and never from the console (which may show a different figure). Accounts existing comes from the product’s admin console; export the user list. Accounts active in 90 days comes from that same export, filtered on last login or last activity. Ninety days is a fair window. Thirty is too aggressive for seasonal roles and quarterly processes.
Then look for these five specific patterns.
| Pattern | How it shows | What to do |
|---|---|---|
| Disabled accounts still billed | Console shows suspended or disabled, invoice count unchanged | Reconcile at renewal; many vendors bill provisioned rather than active |
| Departed staff never deprovisioned | Accounts with last activity before a known departure date | Deprovision now, for security as much as for cost |
| Shared or generic accounts | ”frontdesk”, “scanner”, “info” | Decide whether the account is required, and who owns it |
| Seats bought for a project that ended | A block of accounts created on one date, never used since | True-down candidate |
| Real growth the invoice has not caught | Active accounts exceed seats billed | Fix this before the vendor’s audit clause does |
Check the true-down rules before you plan a reduction. Many subscriptions permit a seat decrease only at renewal, with notice. Some prohibit any decrease during a committed term. A few permit reduction only up to a floor stated in the order form. The reduction you can make is a contract question, and it belongs on Sheet 1.
Separate a paid license from an operating control
A license is a permission. A control is a thing that operates. The gap between them is where most of the “are they even working” question lives.
The test is a single question, and it is deliberately hard to fake: can somebody produce an artifact, generated by the product itself, carrying a date inside the last 90 days, showing the product did something?
| Product type | Artifact that proves operation | Artifact that proves nothing |
|---|---|---|
| Endpoint detection | Coverage report showing enrolled devices against total known devices, plus detection or policy-change records with dates | A license count |
| Backup | A restore test record: what was restored, when, elapsed time, who verified | A green backup job dashboard |
| Email security | Block or quarantine report for a named period, with volumes | The vendor’s marketing figure for global catch rate |
| Multi-factor authentication | Enforcement policy export showing scope and every exclusion | One user’s enrollment screenshot |
| Log management or SIEM | Ingest volume by source, plus the date a human last opened it and what they did | The fact that logs are being collected |
| Vulnerability scanning | The most recent scan report, with the date and the remediation status of the findings | A scanner that is licensed and scheduled |
| Compliance or GRC platform | The evidence package as it currently stands, plus the last login date | The implementation project plan |
Write the artifact name and its date into the sheet. If there is no artifact, write no evidence on record. That is a real finding and it is the most useful thing this worksheet will produce. Two notes on interpretation: a missing artifact does not prove a tool is idle, it proves nobody has checked, and a tool running perfectly while serving no named control is still a candidate for retirement.
Put two tools serving one job in the same comparison row
Overlap is common and it is not automatically waste. Two products can cover the same category at different depths for good reason. Overlap becomes waste when the second product serves no control that the first does not already serve at the level you require.
So the comparison is between the control sentences, never between the product categories.
| Common overlap pair | The question that resolves it |
|---|---|
| Mail platform’s included filtering and a separate mail security gateway | Run both for 30 days and compare what each caught that the other missed. Then decide on the measured difference. |
| Platform-included endpoint protection and a purchased detection product | Does the purchased one deliver triaged alerts to a human, and does the included one? |
| Identity provider MFA and a standalone MFA product | Is there a system the identity provider cannot cover, and is that system still in use? |
| SaaS backup included in a vendor plan and a third-party SaaS backup | Compare retention period, deletion protection, and restore granularity against your actual obligation |
| Two remote access or remote support tools | Which one does the outsourced IT firm use, which one do staff use, and does either need to exist |
| Password manager and identity provider credential vault | Which one holds the credentials that matter, including the break-glass accounts |
| VPN and a newer access product bought to replace it | Was the VPN ever turned off |
That last row is the most common overlap of all. A replacement gets purchased, the migration stalls at eighty percent, and the organization pays for both indefinitely because the last twenty percent is hard. Look for it specifically.
Record the staff hours and dependencies tied to the product
What it took, or would take, to make this product part of your environment: SSO configuration, directory sync, log forwarding, ticketing integration, agent deployment, and the staff hours already spent. This number matters in both directions. High integration cost argues against replacing a product that works, and it argues against adding a product that duplicates one.
Part 4: Price the exit before you choose it
Exit cost is guessed more often than any other figure on the sheet, and it is wrong in both directions: vendors overstate it during a renewal conversation, and buyers understate it when they are annoyed. Write it in three columns, in the same discipline a board memo uses: known, internal hours, unknown.
| Component | Where the number comes from |
|---|---|
| Remaining committed term | The order form. If you are 8 months into a 36-month term, that is contractual, and it is the first thing to check. |
| Early termination fee | The termination clause. Some contracts have none, and some have a full acceleration of remaining fees. |
| Data extraction | Can you export your data, in what format, and is there a defined window after termination before deletion. Ask in writing and keep the answer. |
| Retention obligation | If the product holds records you are required to keep for a period, exiting means moving those records somewhere that satisfies the obligation. |
| Integration teardown | SSO, directory sync, log forwarding, ticketing hooks, agent removal from every device. |
| Parallel running | The overlap period where you pay for both. Usually 30 to 90 days. Budget it. |
| Migration labor and retraining | Internal hours and any external help, plus retraining hours per affected person. Be honest about internal hours; they are real and they come out of somebody’s week. |
| Bundle effects | If the product is discounted as part of a bundle, removing it may raise the price of what remains. Ask the vendor for the unbundled price of the products you are keeping. |
| Control gap during migration | What covers the control while you switch, and for how long. This one has no dollar figure and it belongs in the unknown column with a description. |
An exit cost with a single number and no breakdown is an opinion. An exit cost with three columns is a finding, and it survives challenge in a budget meeting.
Part 5: Record who earns money from the renewal
Every line has a recommender: an IT provider, a broker, a consultant, a reseller, a partner firm, or an internal person with a preference. Record how that party is paid on this line.
Ask in writing, and use plain wording:
“For each product on the attached list, please state whether your firm receives any margin, commission, rebate, market development funds, partner tier credit, referral fee, or other compensation tied to our purchase or renewal of that product, and the approximate amount or percentage.”
Record the answer, the date, and who gave it. Three notes on how to use it.
A compensated recommendation can be entirely correct. This column is not an accusation and it should never be presented as one. What it changes is the burden of proof: a recommendation from a party paid on the purchase needs an independent statement of the requirement before it moves forward, and a recommendation from a party paid the same regardless does not carry that particular question.
Rebates and partner tier credits are usually invisible to the buyer and are frequently the largest component. Ask for them by name, since a question about “commission” alone can be answered truthfully with a no while a tier rebate exists.
A firm with no vendor compensation loses nothing by putting that in writing. A refusal to answer is itself an answer, and you record the refusal in the column.
Part 6: The lifecycle line
Some recurring costs are not subscriptions at all. They are the cost of running something past its support date, and they belong on the worksheet as a separate line with their own decision.
Standard support for Windows 10 ended on October 14, 2025. Microsoft ended technical assistance, software updates, and security fixes on that date. Commercial Extended Security Updates start at US$61 per device for the first year and double in each consecutive year.
That doubling structure is the part that matters for a budget. A device on ESU is a line whose cost is scheduled to rise on a known curve, which makes it directly comparable to the cost of replacing or repurposing the device. Record it this way:
| Field | Entry |
|---|---|
| Device count on Windows 10 | |
| Devices enrolled in ESU | |
| ESU cost, year one | |
| ESU cost, year two, at the stated doubling | |
| ESU cost, year three, at the stated doubling | |
| Devices that can be replaced, with cost | |
| Devices that cannot be replaced, why, and the compensating controls around them | |
| Named owner and target date |
The same structure works for any end-of-support item: a line-of-business application on an unsupported version, a firewall past its last firmware release, a server operating system in extended support, or a phone system nobody will patch again. Put each one on its own line. These are the items most likely to appear on a cyber insurance application and on a client security questionnaire, so the work is reusable.
Part 7: Put the decision, owner, and date in Sheet 3
Six states. One per line. Every line gets one, including the ones you are keeping.
| State | Use it when | What the row must contain |
|---|---|---|
| Keep | The control sentence is written, the evidence artifact exists and is current, use matches billing, and no alternative you already own serves the same control at the required level | The evidence artifact name and date. The next review date. |
| Renegotiate | The product earns its place; the terms do not. Price, term length, seat minimum, auto-renewal, or notice period | The specific terms you are asking to change, the decision date, and the walk-away position |
| Reduce | The product earns its place at a smaller quantity or a lower tier | Target quantity, the true-down rule from the contract, and the notice date |
| Replace | The control is still required and this product does not serve it, or something you already own does | The control that must be preserved, the replacement, the parallel-run period, and the exit cost line |
| Retire | The control is no longer required, or it is served adequately by something already paid for | The evidence that the control is covered or no longer needed, and who accepted the residual risk |
| Defer pending evidence | You cannot decide because the evidence does not exist yet | What evidence, who produces it, and by what date. Plus the decision date it must beat. |
That last row carries the weight of the whole sheet. A defer without a named evidence item, a named owner, and a date is a renewal with extra paperwork. Every deferred line must have a trigger that will actually fire, and the trigger date must sit before the contract decision date. If it cannot, the deferral is not available to you and the line must be decided on the evidence you have.
Record the disposition, owner, conditions, and date
| Line | Vendor | Decision | Rationale in one sentence | Evidence relied on | Owner | Action date | Annualized effect | Reviewed by |
|---|---|---|---|---|---|---|---|---|
Part 8: Four illustrative renewal decisions
The organization below is fictional and every number is illustrative. None of it is a benchmark for any real organization. It is a 90-person professional services firm with two offices, one IT person, and an outsourced provider.
Line 12: Endpoint detection and response
| Field | Entry |
|---|---|
| Annual cost | $34,200 |
| Term end / notice / decision date | March 31, 2027 / 60 days / January 15, 2027 |
| Control served | Detects and isolates malicious activity on 196 laptops and servers. Answers the EDR question on the cyber application and on two client security questionnaires. |
| Seats billed / accounts existing / active 90 days | 196 / 196 / 191. Gap: 3 spare laptops in storage, 2 conference room machines |
| Proof of operation | Console coverage report dated 12 days ago. Three detections in the last 90 days, each with a ticket number and a closure note. Policy last modified six weeks ago. |
| Overlap | Platform-included antivirus is present. It does not deliver triaged alerts to the outsourced provider; the purchased product does. |
| Exit cost | Known $0 termination. Internal 60 hours. Unknown: detection coverage during a migration. |
| Adviser compensation | Outsourced provider confirmed in writing, June 2026, that it earns a 12% margin on this renewal. |
Decision: KEEP. The control sentence is written, the evidence is current and independent of the vendor’s marketing, and the seat count reconciles. The provider’s margin is recorded and does not change the conclusion, because the evidence came from the console rather than from the provider. Next review: December 2026, before the January decision date.
Line 27: Password manager
| Field | Entry |
|---|---|
| Annual cost | $8,400 at 140 seats |
| Term end / notice / decision date | November 1, 2026 / 45 days / September 3, 2026 |
| Control served | Stores shared credentials for 31 client portals and the break-glass account for the identity provider. |
| Seats billed / accounts existing / active 90 days | 140 / 118 / 84 |
| Proof of operation | Vault access log shows daily use by 6 teams. Break-glass entry accessed and re-sealed in a documented test, May 2026. Contract permits reduction at renewal only, 45 days notice, floor of 50 seats. |
Decision: REDUCE to 95 seats. Illustrative saving of about $2,700 annually. The product is doing its job and the evidence is strong. The seat count was set during a 2023 headcount that no longer exists. Notice must be given by September 3 or the 140-seat count renews for a year.
Line 31: Secondary email security gateway
| Field | Entry |
|---|---|
| Annual cost | $11,900 |
| Term end / notice / decision date | February 15, 2027 / 30 days / January 2, 2027 |
| Control served | Attachment and URL filtering on inbound mail. Purchased in 2021. |
| Proof of operation | Quarantine report for the last 90 days shows 31 messages held. |
| Overlap | The firm upgraded its mail platform tier in 2024. That tier includes attachment detonation and URL rewriting, already paid for. A sample review of the 31 held messages found that all 31 were also flagged upstream by the included tier. |
| Exit cost | Known $0. Internal 12 hours to remove mail routing and update MX. Unknown: none material. |
Decision: RETIRE at term end, after a documented 30-day parallel comparison to confirm the sample result across a full period. The comparison is the condition, and the controller owns it. Illustrative saving of $11,900 annually. Note what produced this outcome: a tier upgrade bought three years later made an older purchase redundant, and nobody re-examined the older purchase because nothing forced them to.
Line 44: Compliance evidence portal
| Field | Entry |
|---|---|
| Annual cost | $19,500 |
| Term end / notice / decision date | December 1, 2026 / 60 days / September 18, 2026 |
| Control served | unknown. Purchased in 2024 to prepare for a client-driven audit. The person who owned it left in 2025. |
| Seats billed / existing / active 90 days, and proof of operation | 25 / 25 / 0. Last login 14 months ago. Evidence library contains 40 documents, all dated 2024. |
| Relevant fact | An audit is scheduled for November 2026. |
Decision: DEFER PENDING EVIDENCE. The evidence required: written confirmation from the auditor whether the evidence package must be delivered through this platform or can be delivered as files. Owner: the controller. Due September 5, 2026, which sits ahead of the September 18 decision date. If the auditor confirms files are acceptable, this line becomes RETIRE on the same day. If the platform is required, it becomes KEEP with a named internal owner assigned before renewal.
Put all four illustrative decisions on one page
| Line | Decision | Annualized effect (illustrative) |
|---|---|---|
| 12, endpoint detection | Keep | $0 |
| 27, password manager | Reduce | ($2,700) |
| 31, mail gateway | Retire | ($11,900) |
| 44, compliance portal | Defer pending evidence, resolves by September 5 | $0 to ($19,500) |
Four lines, four different outcomes, one purchase recommendation between them: none. That is the usual shape of a first teardown. The savings came from a seat count that had drifted and a product made redundant by something already owned, and the largest line on the page was kept because the evidence supported keeping it.
Part 9: Work the nearest decision dates first
Work the decision dates first. Anything inside 60 days gets handled this week regardless of dollar value, because that is the only category where waiting removes an option.
Take the free reductions before anyone proposes a purchase. Seat true-downs, deprovisioning departed staff, and retiring a product superseded by something you already pay for require no capital and no project.
Bring the no evidence on record rows to whoever owns them, and ask for the artifact by a date. Most resolve within two weeks, and the ones that do not are telling you something.
Write the keeps down properly. A documented keep, with its control sentence and its evidence artifact, stops the same conversation from starting over next year. It is also most of the answer to a client security questionnaire and to the controls section of a cyber insurance application.
Set the calendar. Every line gets a decision date in a shared calendar with a named owner. This single habit prevents more waste than any purchasing policy.
One question for whoever recommends your renewals. After you present the teardown, ask which lines they would have flagged, and why they did not. The answer tells you what kind of relationship you have.
Keep each completed row with the renewal approval
This worksheet is general guidance about examining recurring technology costs and contract terms. It is not legal advice, it is not accounting advice, and it does not interpret your contracts. Termination rights, auto-renewal enforceability, and notice requirements vary by contract wording and by state. Have counsel review any termination or non-renewal notice before you send it, particularly where an early termination fee or a multi-year commitment is at issue.
The Windows 10 and Extended Security Updates facts above are sourced to Microsoft through SBK’s source register, line 60. No other external figure appears here, and no percentage-of-revenue benchmark appears anywhere in this document, because none exists that would survive a question about its source, peer set, date, denominator, and limits.
SBK Consulting is a family-run, vendor-neutral IT advisory firm serving the New York, Connecticut, and New Jersey metro area since 2010, with more than 125 years of combined experience and a fully US-based team. Zero vendor partnerships, zero reselling, zero commissions or referral fees, which means we earn nothing on any decision this worksheet produces. We will give a second opinion on one renewal if that is useful to you. If you run the teardown yourself and never call, that is the outcome this document was built for.
(718) 407-4169