Marketing Bought Software Without IT, and Now Everyone Pays for It
A marketing manager needed a tool, found one that solved the immediate problem well, and bought it on a company card because the annual cost fell comfortably under the threshold that would have required a formal procurement process. Six months later that tool is storing customer contact data, connected to two other systems through an integration nobody documented anywhere central, and IT is finding out about all of this for the first time because a security review flagged an unfamiliar data flow. Nobody did anything malicious. The tool genuinely helped marketing move faster in the moment it was purchased. It’s just that moving fast in the moment created a set of obligations — security, data governance, integration maintenance — that nobody with the relevant expertise ever got a chance to weigh in on before they existed.
Why This Keeps Happening Even at Well-Run Companies
Modern marketing software is easy to buy without anyone’s approval precisely because a lot of it is priced and packaged to be purchased this way — low enough per-seat cost to avoid formal procurement thresholds, self-service signup, no infrastructure requirement that would naturally route the purchase through IT. This isn’t an accident of the software market; it’s a deliberate go-to-market strategy for a huge share of marketing tools, which specifically target the individual marketer’s budget authority rather than the enterprise procurement process, because the sales cycle for the former is measured in minutes and the latter in months.
Marketing teams, for their part, are usually not trying to bypass IT out of any particular disregard for governance. They’re solving an immediate, real problem, and the formal procurement process, when one exists, is often slow enough relative to the marketing team’s actual pace of work that going around it feels like the only realistic way to get anything done on a reasonable timeline.
What Actually Goes Wrong Later
The risk isn’t really about the software failing to do its job; the tools purchased this way are usually chosen because they genuinely solve the problem at hand. The risk accumulates in the gaps around the tool. Data flowing into an unvetted platform may not meet the company’s actual data handling standards, creating real compliance exposure that nobody assessed because nobody with that expertise knew the tool existed. Integrations built between the new tool and existing systems create dependencies that IT doesn’t know to account for during any later infrastructure change, meaning a routine system update elsewhere can silently break a marketing workflow nobody flagged as depending on it. And when the tool inevitably needs to be evaluated for renewal, replaced, or migrated away from, there’s no institutional knowledge anywhere central about what it actually does, what depends on it, or what data it holds.
A Realistic Picture of the Accumulated Risk
| Risk Category | What Tends to Go Unnoticed |
|---|---|
| Data governance | Customer data stored somewhere outside sanctioned systems |
| Security | Unreviewed access controls, unclear breach exposure |
| Integration dependency | Undocumented connections that break during unrelated changes |
| Vendor risk | No visibility into vendor’s own security or financial stability |
| Institutional knowledge | Nobody outside the original purchaser understands the setup |
Why a Heavy-Handed Fix Doesn’t Work
The obvious response — requiring IT approval for every software purchase regardless of size — tends to fail in practice because it reintroduces the exact friction that caused teams to route around formal process in the first place. A marketing team facing a genuine, time-sensitive need will often find a way around a process that feels disproportionately slow relative to the actual risk of a given tool, and an overly strict policy just pushes the same behavior further underground rather than eliminating it, making the eventual discovery process even harder.
A Lighter-Weight Process That Teams Will Actually Use
A more workable middle ground is a lightweight, fast-turnaround review specifically scaled to the size and risk of the purchase, rather than a single heavyweight process applied uniformly to every tool regardless of cost or data sensitivity. A short intake form that asks a handful of genuinely important questions — what data will this tool touch, will it integrate with anything else, does the vendor have a reasonable security posture — reviewed within a day or two rather than weeks, catches the majority of real risk without meaningfully slowing down a team trying to solve an immediate problem.
Building a Registry Instead of Relying on Formal Approval Alone
Even with a lighter review process in place, some tools will still get adopted informally, and a purely preventive approach will never catch everything. A complementary, lower-friction step is maintaining a simple, actively maintained registry of software currently in use across the marketing function, populated through a periodic, non-punitive check-in rather than an enforcement sweep. This gives IT and security visibility into what actually exists, even for tools that were adopted outside the formal process, without making every disclosure feel like an admission of wrongdoing that teams would rather avoid.
Giving Marketing a Genuine Stake in Getting This Right
The teams that manage this well tend to frame the lightweight review process as protecting marketing’s own interests, not just satisfying an IT requirement imposed from outside. A quick security and data-handling check protects the marketing team from being the one blamed later if the tool turns out to mishandle customer data, and framing it this way — as risk management marketing has a real stake in, not just a compliance hoop — tends to produce genuinely better voluntary participation than framing the same process purely as an IT mandate.
Closing the Gap Without Closing Off Speed
The underlying goal isn’t eliminating marketing’s ability to move quickly on tool decisions, which is a genuine competitive advantage worth preserving. It’s building just enough lightweight visibility and review that the accumulated risk of ungoverned software adoption gets caught early, at low cost, rather than discovered months or years later during a security review, a renewal negotiation, or an incident that could have been avoided with a two-day check nobody thought to require.
By VexioCRM Editorial · Updated September 16, 2026
- software procurement
- IT alignment
- marketing operations