Guide
How to audit your company's AI spend
To audit your company's AI spend, pull every AI cost into one view — seat subscriptions, API tokens, and infrastructure — then match each dollar to real usage. Spendassay connects your spend and usage sources read-only, prices the waste as findings, each carrying a proof level, and hands your admins a set of step-by-step instructions to recover it. Expect 10 to 15% recoverable within 30 days.
What is an AI spend audit?
An AI spend audit is an independent, cross-vendor review that matches every AI dollar to actual usage. It spans seat subscriptions, API tokens, and infrastructure across vendors. The output is a CFO-credible AI cost report with dollar-priced findings, each carrying a proof level so finance can trust the numbers.
An audit answers one question your vendor dashboards cannot: what did you buy, and did anyone use it? Each vendor grades its own homework and reports only its own slice. An audit sits on the buyer side and reads across all of them at once.
The result is a single AI cost report view, not a pile of invoices. Every line ties spend to usage and prices the gap in dollars. Finance gets a number it can defend; engineering gets a list it can act on.
Spendassay is buyer-side and cross-vendor by design. It grades no vendor's own product and takes no vendor's word for utilization.
What should an AI spend audit cover?
A complete audit covers three cost layers: seat subscriptions like Copilot, Cursor, and ChatGPT; API tokens from OpenAI and Anthropic; and supporting infrastructure. It should surface unused seats, underused seats, shadow AI, tool overlap, and renewal opportunities. Every finding needs a dollar figure and a stated proof level.
Cover all three cost layers, or the audit misses money. Seat spend, token spend, and infra each hide different waste.
The finding types an audit should produce:
- Unused seats: paid licenses with no activity.
- Underused seats: licenses far below the value threshold you paid for.
- Shadow AI: tools detected from SSO or OAuth grants and corporate-card spend that finance never approved.
- Tool overlap: two products doing the same job for the same teams.
- Renewal opportunities: contracts approaching renewal where usage no longer matches the commitment.
- Quality-trend regressions: usage that is climbing while output quality is not.
Every number carries a proof level so you know how sure to be. Counted beats Compared beats Estimated, and each finding exposes the formula behind it. Reporting stays team-level, never an individual league table.
How do you connect your spend and usage sources?
Connect one spend source and one usage source. For spend, link Ramp or upload a corporate-card CSV. For usage, connect GitHub, Okta, Google Workspace, OpenAI, Anthropic, or Cursor. Every connection is read-only and metadata-only, and a CSV import works with zero live integrations.
Start with spend, because that is where the dollars live. Ramp or a corporate-card export tells the audit what you are paying and to whom. This surfaces shadow AI charges finance may not have catalogued.
Then add usage, so the audit can match dollars to activity. GitHub covers Copilot seats, Okta and Google Workspace reveal SSO and OAuth grants, and the OpenAI and Anthropic connectors read token consumption.
Every connector is read-only and metadata-only. Spendassay never reads your source code, prompts, or message content, and the audit never writes to, routes, or throttles a vendor system. If you cannot connect a live integration yet, a CSV import runs the full audit on exported data.
How do you turn findings into recovered dollars?
Work the findings in dollar order. For each one, Spendassay generates a set of step-by-step instructions your own admins execute — reclaim a seat, consolidate an overlapping tool, or open a renewal negotiation with a prepared package. The audit tracks each recovery and banks it into a Recovered statement finance can verify.
Findings are priced, so you fix the largest number first. The audit sets the recoverable target and shows the formula behind it.
Spendassay finds and prices the waste and produces the step-by-step instructions; your admins take the action. It does not reach into a vendor system to remove a seat or cap usage. It gives your team the exact steps, the affected accounts, and the drafted communications.
For contracts, the audit assembles a renewal negotiation package with your usage evidence and a benchmark. For everything recovered, the Recovered statement records the banked dollars so the CFO can confirm the audit paid off.
How much can an audit recover, and how fast?
For a typical mid-market company, an audit surfaces 10 to 15% of seat and subscription spend as recoverable within 30 days. The best fit is a US mid-market team with 50 to 400 engineers spending at least $150K per year on AI. Results scale with how much of your spend and usage you connect.
The 10 to 15% target holds when spend and usage are both connected across seats and tokens. Idle seats and duplicate tools are the fastest wins, and they show up in the first sync.
The audit serves two buyers at once. The VP of Engineering or CTO gets a team-level activity picture, and the CFO gets a defensible AI cost report with a proof level on every line.
Speed comes from the finding tiers. Measured findings, backed by direct activity data, are ready to act on immediately; modeled findings tell you where to look next. You act on certainty first and investigate the rest.
Step by step
- 1
Connect a spend source
Link Ramp or upload a corporate-card CSV so the audit sees every AI charge, including shadow AI that finance never catalogued. The connection is read-only.
- 2
Connect a usage source
Add GitHub, Okta, Google Workspace, OpenAI, Anthropic, or Cursor so the audit can match each dollar to real activity. Every connector is read-only and metadata-only; it never reads code, prompts, or message content.
- 3
Review the priced findings
Open the findings list, sorted by dollar impact. Check each finding's proof level (counted, compared, or estimated) and its exposed formula to decide how confident to be before acting.
- 4
Act on the step-by-step instructions
For each finding, run the generated step-by-step instructions your own admins execute — reclaim an unused seat, consolidate an overlapping tool, or open a renewal negotiation with the prepared package. The audit never writes to the vendor system itself.
- 5
Bank and track recovery
Confirm each completed action so it lands in the Recovered statement. Finance verifies the banked dollars against the original target, closing the loop on the audit.
Common questions
Is an AI spend audit safe to run on production accounts?
Yes. Every connector is read-only and metadata-only. Spendassay never reads your source code, prompts, or message content, and the audit never writes to, routes, or throttles a vendor system. It reads what you pay and who uses what, nothing more.
Do I need live integrations to start auditing?
No. A CSV import runs the full audit on exported spend and usage data with zero live integrations. You can start with a corporate-card export today and add connectors like GitHub, Okta, OpenAI, and Anthropic when you are ready.
Does the audit remove seats or cut costs automatically?
No. Spendassay finds and prices the waste and generates a set of step-by-step instructions. Your own admins execute the action — reclaiming a seat or consolidating a tool — and the audit tracks each recovery into a Recovered statement. It surfaces and prices; your team acts.
How is each finding's dollar figure justified?
Every finding carries a proof level and exposes its formula. Counted findings rest on direct activity data, Compared findings measure against similar teams, and Estimated findings are modeled from assumptions. You see exactly how sure to be before acting on any number.
Run the audit on your own AI spend
Connect read-only sources and get a CFO-credible AI cost report. Free to start, about 10 minutes to connect.