Copy-and-paste shadow IT policy template
Replace the text in square brackets and adapt the controls to your organization, sector and legal obligations. This example is operational guidance, not legal advice.
1. Purpose
This policy explains how [Organization name] selects, approves and monitors technology used for business purposes. Its purpose is to reduce security, privacy, compliance, operational and financial risks while giving employees a clear and timely route to the tools they need.
2. Scope
This policy applies to all employees, contractors, consultants and third parties who access [Organization name] data or systems. It covers software, SaaS services, AI tools, browser extensions, mobile applications, cloud storage, personal accounts, devices and connected equipment used for work.
3. Approved technology
Business data may be processed only with technology listed in the approved catalog or covered by a documented exception. Users must follow the access, configuration, data handling and retention requirements assigned to each approved service.
4. Restricted and prohibited activity
Users must not install or use unlicensed, cracked or unlawfully copied software. They must not upload confidential, personal, customer-controlled or export-controlled information to an unapproved service. Personal accounts must not be used to store or transfer business data unless explicitly authorized.
5. Requesting a new tool
Requests must be submitted through [request channel] and include the business purpose, intended users, data involved, required integrations and expected duration. [Approving team] will acknowledge requests within [time] and provide a decision or progress update within [time]. Urgent requests will follow [urgent route].
6. Risk assessment and exceptions
Review will be proportionate to risk. It may consider security controls, privacy, data location, contractual terms, license conditions, accessibility, business continuity, supplier viability and integration with existing systems. Exceptions must identify an owner, permitted use, compensating controls, expiry date and review date.
7. Identity, access and offboarding
Approved services must use company-managed identities where available. Multi-factor authentication, least-privilege access and timely removal of leavers are required according to the service’s risk level. Shared accounts are prohibited unless specifically approved and technically necessary.
8. BYOD, remote work and browser extensions
Employee-owned devices may be used only under the organization’s BYOD and remote-work requirements. Browser extensions and locally installed utilities are subject to the same approval rules as other software. Business information must remain within approved accounts and storage locations.
9. Monitoring and privacy
[Organization name] may use proportionate technical and administrative controls to identify unmanaged technology and protect its systems, data and licenses. Monitoring will be documented, limited to legitimate purposes and aligned with applicable employment, privacy and data-protection requirements. Detection is evidence for review, not proof of misconduct.
10. Reporting and remediation
Users should report unapproved technology promptly through [reporting channel] without attempting to conceal or delete evidence. The organization will assess the business need and risk before deciding whether to approve, replace, isolate or remove the technology. Responses will be consistent and proportionate.
11. Ownership and review
The policy owner is [role]. The policy, approved catalog and active exceptions will be reviewed at least [frequency] and following material incidents, regulatory changes or significant changes to the technology environment.
