Cost control

How do I audit my business software subscriptions?

The money is the smallest part. The audit that pays is the one that finds customer data in a tool nobody has opened in a year, and the tax records sitting inside something you are about to cancel.

The short answer

There is no correct number of subscriptions. The useful audit is not about count but about overlap, orphaned tools nobody owns, data you are accountable for in systems you forgot, and records you must keep for six years after you cancel. Run it once a year.

Software subscriptions accumulate the way kitchen drawers do. Each individual addition was justified at the time; nobody ever removes anything; and after five years the total is a surprise to the person paying it.

The usual advice is to cancel what you do not use. That is fine as far as it goes, but the money is the least interesting output of this exercise. A subscription audit done properly finds three more valuable things: customer data you are legally accountable for in systems you had forgotten, access still held by people who left, and financial records about to be locked inside a tool you are cancelling.

Here is how to run one.

Step one: find everything, including what you forgot

Do not start from a list of the tools you use. That list is exactly the set of things you already know about, and the audit exists to find the rest.

Start from money instead. Pull twelve months of statements for every business card, every business bank account, and any personal card that has ever been used for a business tool. List every recurring charge. Twelve months is the minimum window because annual subscriptions appear only once.

Then add the things that do not show up as charges: free-tier accounts holding real data, tools bundled inside another product, and anything a former employee signed up for. Free tools belong in this inventory precisely because they cost nothing and are therefore never reviewed.

For each entry, record five columns: what it is, who owns it, what it costs and in what currency, what business data it holds, and when it renews.

Step two: the four questions that actually matter

Does anything overlap?

Overlap is the obvious one and usually the smallest saving. Two tools that both send email, two that both store files, two that both track tasks. The cost is not only duplicate fees — it is that half your information is in one and half in the other, and nobody is sure which is current.

Does every tool have an owner?

An orphaned tool is one no named person is responsible for. These are where the security problems live, because nobody is reviewing who has access, nobody notices an unusual login, and nobody applies the settings. If you cannot name an owner, either assign one or cancel it.

Which tools hold personal information?

This is the column most audits omit and the one with legal weight. Schedule 1 of PIPEDA makes an organization responsible for personal information in its possession or custody, including information transferred to a third party for processing, and requires contractual or other means to provide a comparable level of protection while the third party processes it [2].

You cannot provide comparable protection at a processor you have forgotten you are using. And the breach obligations follow that data: section 10.1 requires reporting breaches involving personal information under your control where there is a real risk of significant harm, and section 10.3 requires keeping a record of every breach involving personal information under your control [3]. “Under your control” includes a dormant account at a vendor you last logged into fourteen months ago.

Who still has access?

Go through each tool and list its users. In most small businesses this turns up at least one account belonging to someone who left, and at least one shared login. Both are worth more attention than the subscription fee.

The finding that justifies the whole exercise: in nearly every first audit, at least one tool holds customer personal information and has no owner, no recent login, and an active account. That is a live accountability problem, and you would not have found it by looking at your bank statement for savings.

Step three: the retention trap before you cancel

This is the step people skip, and it is the one that can genuinely cost you.

The Income Tax Act requires every person carrying on business, and every person required to pay or collect taxes, to keep records and books of account, in a form and containing information that will enable the taxes payable to be determined [1]. Those records must be retained until six years from the end of the last taxation year to which they relate [1]. Where a person required to keep records does so electronically, they must retain them in an electronically readable format for that retention period [1]. And if no return was filed for a taxation year, the six-year clock runs instead from the day the return for that year is filed [1].

So the invoicing tool you are about to cancel may be holding records you are required to produce years from now. Once the account closes, so does your access.

The same applies to sales tax. A registrant making a taxable supply must indicate to the recipient either the consideration and the tax payable in a manner clearly indicating the amount of tax, or that the amount charged includes the tax [4]. Those invoices are how you substantiate what you charged and what you paid. Losing them inside a cancelled tool is a self-inflicted problem.

The rule is simple: export before you cancel, verify the export opens, and store it where your accountant can find it. Not after. Many vendors cut off data access the moment billing stops.

Step four: cancel properly

Cancelling is more than clicking cancel. Work through this list for each tool you are removing.

  1. Export the data, in whatever format your accountant or your successor tool can actually use. Open the file and check it is not empty or truncated.
  2. Check what depends on it. Forms on your website, automatic emails, a payment flow, a calendar link a customer has bookmarked. This is where cancellations break things weeks later.
  3. Request deletion of personal information and get confirmation. Schedule 1 requires care in the disposal or destruction of personal information to prevent unauthorized parties from gaining access to it [2], and clause 4.5 limits retention of information beyond the purpose it was collected for [2]. A dormant account full of customer records is retention by neglect.
  4. Remove the payment method, so a “paused” account cannot quietly resume.
  5. Write down what you did and when, including where the export lives. In three years, you will need this and remember none of it.

What not to cancel

Two honest cautions, because aggressive consolidation causes its own damage.

Do not cancel a specialist tool because a general one nearly does the job. If a product is central to how you earn money, the last ten per cent of its capability is usually the part that matters, and you will discover which part only after it is gone.

Do not cancel security or backup tooling to reduce your count. It is unused by design. The absence of incidents is not evidence that you did not need it.

A note on vendor risk

While you are inventorying, it is worth asking which of these vendors will still exist in five years. ISED's figures give a sense of the churn: between 2017 and 2021, an average of 103,001 small businesses were created annually in Canada and an average of 94,197 disappeared annually [5]. Software vendors are drawn from a population with that kind of turnover.

You cannot predict which one goes. What you can do is know, for each tool holding something you depend on, how you would get your data out if you had to do it this week. If you do not know, that is the finding — and it is worth more than the subscription savings.

Turning it into a habit

Attach the audit to a date you already keep: fiscal year end, insurance renewal, whatever you will not forget. Add a smaller trigger whenever someone leaves the business, when the only task is removing their access everywhere.

The first pass takes a few hours, most of it spent reading statements. Every pass after that takes under an hour, because you are only reviewing what changed. The tools you cancel pay for the time; the orphaned customer data you find is the part that actually matters.

Frequently asked questions

How many software subscriptions should a small business have?

There is no right number, and any article giving you one is guessing. The meaningful questions are whether any two tools do the same job, whether every tool has someone who owns it, and whether you know what customer data each one holds. A business with twelve well-understood subscriptions is in better shape than one with four it has forgotten about.

What is the fastest way to find every subscription I am paying for?

Pull twelve months of statements for every card and bank account the business uses, including personal cards used for business, and list every recurring charge. Do not work from memory or from a list of tools you think you use — the point of the exercise is to find the ones you have forgotten. Then check for annual charges, which will only appear once in that window.

Does cancelling a tool end my privacy obligations?

Not automatically. While a processor holds personal information you are accountable for it, and Schedule 1 requires care in the disposal or destruction of personal information to prevent unauthorized parties from gaining access. Cancelling a subscription and walking away can leave your customer data sitting in a dormant account. Ask for deletion, and get confirmation.

How long do I need to keep records from a tool I am cancelling?

The Income Tax Act requires records and books of account to be retained until six years from the end of the last taxation year to which they relate, and where a person keeps records electronically, they must be retained in an electronically readable format for that period. If no return was filed for a year, the six years run from the day the return for that year is filed. Export before you cancel, not after.

Is a CSV export good enough to satisfy record retention?

It is much better than nothing and it may not be sufficient on its own. The Act contemplates records and books of account in a form that will enable the taxes payable to be determined, retained in an electronically readable format. A dump of raw rows with no context can fall short of that, particularly for invoicing and payroll data. Where the records matter, ask your accountant what form they want them in before you cancel.

What should I look for besides duplicate tools?

Four things. Tools nobody owns, which is where security gaps live. Tools holding customer data you had forgotten about, which is a live accountability problem. Seats for people who have left. And foreign-currency billing where you cannot tell what tax was charged, which quietly makes your bookkeeping harder every single month.

Should I cancel a tool that only one person uses?

Not necessarily — that is often a specialist tool doing a real job. The question is whether the job is genuinely specialist or whether the person simply never migrated. Ask what would break if it went away. If the answer is specific and important, keep it. If the answer is "nothing, I would just use the other one", you have found your cancellation.

How often should I run this audit?

Once a year is enough for most businesses, plus a smaller check whenever someone leaves. Tie it to a date you already keep — fiscal year end or insurance renewal — because an audit scheduled for "sometime" never happens. The first one takes a few hours; subsequent ones take under an hour because you are only looking at what changed.

Sources and evidence

Every link below was fetched and read on September 1, 2026. Where a source did not support a claim, the claim was cut rather than softened.

  1. Income Tax Act — full text R.S.C. 1985, c. 1 (5th Supp.) — s. 230(1) records and books of account; s. 230(4)(b) six-year retention; s. 230(4.1) electronically readable format; s. 230(5) where no return filed
  2. PIPEDA, Schedule 1 (Principles set out in the National Standard of Canada CAN/CSA-Q830-96) Clause 4.1.3 accountability for transfers; 4.5 limiting use, disclosure and retention; 4.7.5 care in disposal or destruction
  3. Personal Information Protection and Electronic Documents Act (PIPEDA) — full text S.C. 2000, c. 5 — s. 10.1 breach reporting for information under your control; s. 10.3 breach records
  4. Excise Tax Act — full text R.S.C. 1985, c. E-15 — s. 223(1) requirement to indicate tax on invoices and receipts
  5. Key Small Business Statistics 2024 — Innovation, Science and Economic Development Canada Annual creation and disappearance of small businesses, 2017–2021 averages

If your audit turns up five tools doing overlapping jobs, MapleWorkSuite lets you replace them one at a time rather than all at once — each app is switched on and billed separately, so consolidation can be gradual.

See all products See all products More articles