Skip to content
Sections
All notes

All notes · Discovery

Expense Claims and Card Data

The source nobody thinks to check, which finds the tools people cared enough about to pay for.

Discovery · Procedure

Somebody paying for a subscription themselves has told you something important: the tool was worth their own money. Finance data finds these and almost nobody looks.

The recommendations in “Expense Claims and Card Data” become easier to sustain when implementation work has visible owners, dates and review time. Teams evaluating this detailed page can use it to coordinate the operational side of AI adoption and identify where governance tasks are being missed, without treating activity data as evidence of misconduct or as a substitute for asking people why they chose a tool.

For an independent benchmark, compare the local approach with ICO artificial-intelligence guidance; the useful test is whether ownership, access and recovery remain proportionate and explainable when the usual expert is absent.

What to search

Expense claims for software subscriptions, by merchant name.

Departmental card statements.

Any procurement under the threshold that requires approval, which is where most of this sits.

One query against twelve months, and it takes an hour.

What it finds

Paid subscriptions to AI services, with the amount and the frequency.

Which department, from the cost centre.

How long it has been running, which indicates how embedded it is.

And occasionally a team-level subscription somebody set up for several people, which is a bigger finding than an individual one.

Why these matter disproportionately

Free-tier use is casual. Paid use is dependence.

Somebody paying monthly has integrated the tool into how they work, and removing it without a replacement will genuinely damage their output.

These are your highest-priority cases for providing something properly, and they are the ones a network log cannot distinguish from a one-off query.

The personal-payment signal

Where somebody is paying personally rather than expensing, that usually means they expected the claim to be refused.

Which is information about the approval process rather than about the person.

And it is also a data risk: a personal account has personal-account terms, which the terms note covers.

Handling it carefully

This data identifies individuals by construction.

Aggregate before it leaves finance: tool, department, count, total spend.

Do not approach individuals during discovery, which the discovery note argues and which matters more here because the evidence is personal.

What to do with the findings

For each paid tool: what is it doing, could an approved option do it, and what would switching cost the person.

Several will be worth adopting properly, which converts a shadow cost into a managed one and usually at a lower unit price.

Others will fail assessment, and those people need a replacement before anything is withdrawn.

The ongoing version

Add AI services to whatever merchant monitoring finance already runs.

A quarterly report of new AI-related spend is cheap and catches adoption early.

This is one of the few genuinely continuous discovery sources available.

What to check

Has anybody searched expense data for AI subscriptions?

Are there team-level subscriptions nobody approved?

How many people are paying personally, and why?

And does finance flag new AI spend routinely?

The point

Free-tier use is casual; paid use is dependence.

Somebody paying monthly has built the tool into how they work.

Underlying all of this

Everything in this collection reduces to four habits: find out what people are doing and why before deciding anything, provide something good enough that the approved route is the easy one, write rules about information rather than about tools, and monitor the destination rather than the content. None requires a product, and a programme doing all four controls more than one built on prohibition.

The recurring pattern

The recurring pattern across every section here is the same: the response that feels like control reduces it. A ban removes visibility rather than use. Content inspection drives activity to personal devices. A discovery exercise with consequences produces quiet answers. In each case the organisation ends up knowing less about a risk it believes it has handled.