The short answer
There is no correct number of subscriptions. The useful audit is not about count but about overlap, orphaned tools nobody owns, data you are accountable for in systems you forgot, and records you must keep for six years after you cancel. Run it once a year.
Software subscriptions accumulate the way kitchen drawers do. Each individual addition was justified at the time; nobody ever removes anything; and after five years the total is a surprise to the person paying it.
The usual advice is to cancel what you do not use. That is fine as far as it goes, but the money is the least interesting output of this exercise. A subscription audit done properly finds three more valuable things: customer data you are legally accountable for in systems you had forgotten, access still held by people who left, and financial records about to be locked inside a tool you are cancelling.
Here is how to run one.
Step one: find everything, including what you forgot
Do not start from a list of the tools you use. That list is exactly the set of things you already know about, and the audit exists to find the rest.
Start from money instead. Pull twelve months of statements for every business card, every business bank account, and any personal card that has ever been used for a business tool. List every recurring charge. Twelve months is the minimum window because annual subscriptions appear only once.
Then add the things that do not show up as charges: free-tier accounts holding real data, tools bundled inside another product, and anything a former employee signed up for. Free tools belong in this inventory precisely because they cost nothing and are therefore never reviewed.
For each entry, record five columns: what it is, who owns it, what it costs and in what currency, what business data it holds, and when it renews.
Step two: the four questions that actually matter
Does anything overlap?
Overlap is the obvious one and usually the smallest saving. Two tools that both send email, two that both store files, two that both track tasks. The cost is not only duplicate fees — it is that half your information is in one and half in the other, and nobody is sure which is current.
Does every tool have an owner?
An orphaned tool is one no named person is responsible for. These are where the security problems live, because nobody is reviewing who has access, nobody notices an unusual login, and nobody applies the settings. If you cannot name an owner, either assign one or cancel it.
Which tools hold personal information?
This is the column most audits omit and the one with legal weight. Schedule 1 of PIPEDA makes an organization responsible for personal information in its possession or custody, including information transferred to a third party for processing, and requires contractual or other means to provide a comparable level of protection while the third party processes it [2].
You cannot provide comparable protection at a processor you have forgotten you are using. And the breach obligations follow that data: section 10.1 requires reporting breaches involving personal information under your control where there is a real risk of significant harm, and section 10.3 requires keeping a record of every breach involving personal information under your control [3]. “Under your control” includes a dormant account at a vendor you last logged into fourteen months ago.
Who still has access?
Go through each tool and list its users. In most small businesses this turns up at least one account belonging to someone who left, and at least one shared login. Both are worth more attention than the subscription fee.
The finding that justifies the whole exercise: in nearly every first audit, at least one tool holds customer personal information and has no owner, no recent login, and an active account. That is a live accountability problem, and you would not have found it by looking at your bank statement for savings.
Step three: the retention trap before you cancel
This is the step people skip, and it is the one that can genuinely cost you.
The Income Tax Act requires every person carrying on business, and every person required to pay or collect taxes, to keep records and books of account, in a form and containing information that will enable the taxes payable to be determined [1]. Those records must be retained until six years from the end of the last taxation year to which they relate [1]. Where a person required to keep records does so electronically, they must retain them in an electronically readable format for that retention period [1]. And if no return was filed for a taxation year, the six-year clock runs instead from the day the return for that year is filed [1].
So the invoicing tool you are about to cancel may be holding records you are required to produce years from now. Once the account closes, so does your access.
The same applies to sales tax. A registrant making a taxable supply must indicate to the recipient either the consideration and the tax payable in a manner clearly indicating the amount of tax, or that the amount charged includes the tax [4]. Those invoices are how you substantiate what you charged and what you paid. Losing them inside a cancelled tool is a self-inflicted problem.
The rule is simple: export before you cancel, verify the export opens, and store it where your accountant can find it. Not after. Many vendors cut off data access the moment billing stops.
Step four: cancel properly
Cancelling is more than clicking cancel. Work through this list for each tool you are removing.
- Export the data, in whatever format your accountant or your successor tool can actually use. Open the file and check it is not empty or truncated.
- Check what depends on it. Forms on your website, automatic emails, a payment flow, a calendar link a customer has bookmarked. This is where cancellations break things weeks later.
- Request deletion of personal information and get confirmation. Schedule 1 requires care in the disposal or destruction of personal information to prevent unauthorized parties from gaining access to it [2], and clause 4.5 limits retention of information beyond the purpose it was collected for [2]. A dormant account full of customer records is retention by neglect.
- Remove the payment method, so a “paused” account cannot quietly resume.
- Write down what you did and when, including where the export lives. In three years, you will need this and remember none of it.
What not to cancel
Two honest cautions, because aggressive consolidation causes its own damage.
Do not cancel a specialist tool because a general one nearly does the job. If a product is central to how you earn money, the last ten per cent of its capability is usually the part that matters, and you will discover which part only after it is gone.
Do not cancel security or backup tooling to reduce your count. It is unused by design. The absence of incidents is not evidence that you did not need it.
A note on vendor risk
While you are inventorying, it is worth asking which of these vendors will still exist in five years. ISED's figures give a sense of the churn: between 2017 and 2021, an average of 103,001 small businesses were created annually in Canada and an average of 94,197 disappeared annually [5]. Software vendors are drawn from a population with that kind of turnover.
You cannot predict which one goes. What you can do is know, for each tool holding something you depend on, how you would get your data out if you had to do it this week. If you do not know, that is the finding — and it is worth more than the subscription savings.
Turning it into a habit
Attach the audit to a date you already keep: fiscal year end, insurance renewal, whatever you will not forget. Add a smaller trigger whenever someone leaves the business, when the only task is removing their access everywhere.
The first pass takes a few hours, most of it spent reading statements. Every pass after that takes under an hour, because you are only reviewing what changed. The tools you cancel pay for the time; the orphaned customer data you find is the part that actually matters.