Interviews

SaaS Sprawl Forces CIOs to Rethink Cloud Governance, Cost and Business Value

As SaaS adoption accelerates across the GCC, wider Middle East and South Africa, enterprises are confronting a new challenge: maintaining visibility and control without slowing innovation. Haider Amjed, Head of Technology for UAE at NTT DATA, argues that SaaS rationalisation must move beyond licence audits and cost cutting towards continuous portfolio management, with stronger attention to data governance, security, business value and AI readiness.

How serious has SaaS sprawl become for enterprises, and what are its biggest operational challenges?
In my view, SaaS sprawl has become a material enterprise issue, but the real problem is not simply the number of applications. It is the loss of visibility and ownership that comes with them. Across the GCC, the wider Middle East and mature markets such as South Africa, organisations have moved quickly to digitise functions and empower business teams to buy specialised tools. The result can be duplicate capabilities, fragmented data, multiple identities, disconnected workflows and recurring costs that nobody fully owns.

After two decades working in the UAE, I have seen the conversation shift from “how quickly can we adopt?” to “how do we maintain control without slowing the business down?” That is an important sign of market maturity. NTT DATA’s 2026 global cloud research found that only 14% of organisations had reached the highest level of cloud maturity, while complexity, cost management and modernisation remain significant challenges. Gartner is making a similar point: application rationalisation should be treated as a continuous business value discipline, not simply a cost cutting exercise.

The next phase of SaaS maturity is therefore less about buying more and more about governing better.

How can organisations identify redundant, overlapping or underutilised SaaS applications?
The first mistake is to treat SaaS rationalisation as a licence audit exercise. An organisation needs a view of each application’s business purpose, owner, users, cost, data, integrations, security profile and actual usage. I would combine procurement and finance records with identity and access data, application telemetry and business interviews. That often exposes three different problems: licences that are not being used, applications that duplicate another tool’s capability, and applications that are used but no longer deliver enough business value to justify their complexity.

The important part is to assess business fitness, not just usage. A low volume application may be critical to a regulatory process or a specialist team, while a heavily used application may still duplicate functionality available elsewhere.

Gartner’s 2026 guidance recommends prioritising rationalisation by business domain, fitness, change needs, known problems and cost rather than trying to assess the entire portfolio at once. I agree with that approach. For large enterprises across the GCC, Middle East and South Africa, a phased view by function or business unit gives CIOs faster evidence, clearer ownership and far less organisational resistance than a centrally driven target to remove a fixed percentage of applications.

What are the biggest security and compliance risks created by uncontrolled SaaS adoption?
The biggest risk from uncontrolled SaaS adoption is that the enterprise can lose track of where its data is, who can access it and what third parties are connected to it. Shadow applications can create unmanaged identities, excessive permissions, dormant accounts, unreviewed API or OAuth connections and inconsistent retention or backup practices.

Across the GCC and wider Middle East, data residency, sovereignty and evolving regulatory obligations are becoming increasingly important, particularly in government, financial services and healthcare. South Africa adds another important dimension through its mature financial services sector and established data protection environment. This means SaaS governance cannot be treated as a purely technical issue. It is increasingly a business, regulatory and risk management priority.

AI is amplifying this challenge because SaaS capabilities can move corporate information into AI enabled workflows faster than traditional governance processes can respond. Gartner has also highlighted the growing use of unapproved public GenAI tools within organisations.

For me, SaaS security needs to begin before an application becomes embedded in the organisation, not after procurement. Visibility, identity control, data governance and clear ownership must be built into the adoption process from the start.

How can IT teams balance employee demand for specialised tools with the need for greater application control?
I do not believe the answer is to centralise every technology decision or restrict employees to a small list of tools. That usually creates a different problem: people find workarounds. The better model is controlled freedom. Give employees access to an approved catalogue, but create a fast route for requesting specialist applications when there is a genuine business need.

Governance should be proportionate to risk. A tool handling public information should not go through the same process as a platform processing customer, financial or government data. I would use risk tiers, clear data handling rules, a named business owner and time bound approvals for experimental tools. Applications that prove their value can graduate into the managed portfolio; those that do not can expire rather than becoming permanent by default.

This matters even more with AI. Gartner found widespread evidence or suspicion of employees using prohibited public GenAI, illustrating the limitations of policy alone. The objective should not be to stop experimentation; it should be to make the governed route easier than the shadow route.

In my experience, the strongest IT organisations increasingly act as enablers and architects of choice, rather than gatekeepers of every application.

Is SaaS consolidation becoming a strategic priority for CIOs, and what should enterprises consider before retiring applications?
Yes, I believe SaaS consolidation is becoming a strategic CIO priority, but I would distinguish consolidation from simply reducing vendor numbers. Across the Middle East and South Africa, many organisations have spent the last decade accelerating cloud and SaaS adoption. The next stage is about making sure that technology estate is economically sustainable, secure and aligned to future business priorities.

Gartner’s 2026 research on enterprise applications explicitly places portfolio rationalisation, consolidation and decommissioning within the modernisation agenda. More importantly, agentic AI is beginning to change the economics of SaaS itself, as AI agents increasingly perform work across systems and reduce dependence on traditional application interfaces.

That changes the question for CIOs. Instead of asking, “How many applications do we have?”, they should ask, “Which capabilities and data flows do we genuinely need, and where is value being created?”

Before retiring an application, enterprises should assess critical processes, integration dependencies, data retention, contractual obligations, migration effort, employee adoption and vendor concentration risk. Replacing five specialist tools with one suite is not automatically progress if it reduces functionality or creates a new single point of dependency.

Successful consolidation should simplify the enterprise architecture while protecting business choice, resilience and future AI readiness.

What practical steps can organizations take to reduce SaaS sprawl without affecting employee productivity or business operations?
The practical answer is to avoid a big bang clean up. Start with visibility, establish ownership and then rationalise in waves. First, create a reliable inventory covering applications, users, spend, business owner, data classification, integrations and contract dates. Next, identify obvious quick wins: unused licences, duplicate tools, orphaned applications and subscriptions with no accountable owner. Then prioritise one business domain at a time and work with users to understand what would actually break if a tool disappeared.

This phased approach is particularly important for large organisations operating across the GCC, wider Middle East and South Africa, where different countries, business units and regulatory environments may have very different requirements. A tool that appears redundant at group level may still support a critical local process.

For applications selected for retirement, provide a clear replacement, migrate required data, test integrations, communicate early and use a short parallel running period where business criticality warrants it. Measure productivity and user experience after the change, not just licence savings.

Finally, make rationalisation continuous through clear SaaS request standards, named ownership, periodic usage reviews and renewal checkpoints. The objective is not the smallest application estate; it is the simplest estate that still allows the business to move quickly.

Show More

Chris Fernando

Chris N. Fernando is an experienced media professional with over two decades of journalistic experience. He is the Editor of Arabian Reseller magazine, the authoritative guide to the regional IT industry. Follow him on Twitter (@chris508) and Instagram (@chris2508).

Related Articles

Back to top button