Teardown worksheet / Free with a work email

SBK Consulting Teardown worksheet

The IT Renewal Teardown Worksheet

Decide Every IT Renewal Before the Notice Window Closes

Put the recurring charge, contract terms, actual use, operating evidence, overlap, exit cost, and seller income in one worksheet.

Unlock the full document

This document is free. Leave a work email so we can send corrections and updated versions, and the full sheet unlocks below.

KeepRenegotiateReduceReplaceRetireDefer pending evidence

The recurring charge has no owner

Your predecessor, a board member, a department head, or someone who left in 2022 signed the contract. The charge still hits every month. Nobody can name the users, show what it does, or explain what stops if you cancel.

Count the security tools on your invoices. Put the necessity decision and dated operating evidence beside each charge.

Pull the contract, invoice, admin-console use, setup owner, and control evidence into one row. Controllers, CFOs, Executive Directors, firm administrators, and Solo IT Directors can complete the worksheet in about six hours across three sittings. Write unknown when the record is blank.


Seven facts behind every keep, reduce, replace, or retire decision

A teardown is a per-line examination of a recurring charge against five facts: what the contract actually says, what the product is actually used for, whether it is actually running, what else you own that does the same job, and what it would cost to leave.

Three things this document will never do. It will not tell you that twelve tools is too many; twelve may be right, six may be too many, and eighteen may be defensible in a regulated firm with three offices. It will not give you a target percentage of revenue, because that number does not exist in any form worth quoting, and the reasons are set out in the companion CFO worksheet. And it will not push you toward removal. A product stays when the evidence supports it. Keeping is a finding, and a documented keep is worth as much as a cancellation, because next year you will not have to re-argue it.

The discipline is symmetrical. You need evidence to cut and evidence to keep.


Use three sittings before your first decision date

Sitting one, about two hours: find everything. Do not evaluate anything. You are building a list.

Sitting two, about three hours: fill the contract facts and the use evidence. This is where the real work sits, and where you will find you cannot answer some of it. Good. Write unknown and move on. Sitting three, about one hour: decide. Six states, one owner, one date each.

Do the discovery step first and completely. Every teardown that starts from “the list of tools we know about” produces a clean report on the half of the spend that was already visible.


Part 1: Build the complete renewal calendar

Recurring technology charges hide in more places than an accounting system shows. Work all nine sources below. Each one catches a category the others miss.

#SourceWhat to pullWhat it catchesWhat it misses
1Accounts payable ledger13 months of vendor activity, sorted by recurrenceInvoiced subscriptions, hardware maintenance, support contractsAnything paid by card, anything under a coding threshold
2Corporate card and ACH statements13 months, every line under $500 includedSmall monthly SaaS charges buried in “dues and subscriptions” or “office expense”Charges on cards you do not control
3Expense reimbursements13 months, searched for “subscription”, “annual”, “renewal”, “plan”, “license”Shadow subscriptions on personal cardsTools nobody expenses because they are free tier today
4Identity provider app catalogFull export of connected and assigned applicationsEvery tool someone integrated with single sign-onTools that never used SSO
5Public DNS zone and MX recordsFull zone file including TXT recordsMail provider, mail security vendor, marketing platform, and the domain-verification record left by every SaaS you ever onboardedTools that require no DNS change
6OAuth and third-party app grants in Microsoft 365 or Google WorkspaceList of apps with granted access, with grant dates and grantorsTools staff connected to company data without a purchase orderTools with no cloud data access
7Cloud and app marketplace receiptsAWS, Azure, Google Cloud, Apple, Google Play marketplace line itemsSaaS billed through a cloud bill as a single opaque lineDirect-billed vendors
8Vendor mailAP mailbox and shared mailboxes searched for “renewal”, “auto-renew”, “your invoice”, “receipt”, “subscription”Renewals nobody forwarded to financeAnything sent to a departed employee’s mailbox
9Department heads, asked directly”List every tool your team uses that we pay for, and every tool your team uses that you think is free”The gap between what is paid for and what is usedNothing, if you ask everyone

Use 13 months rather than 12. An annual charge that landed 12.5 months ago falls outside a calendar-year pull and it is the one most likely to auto-renew unnoticed.

Reconcile accounts payable with identity and admin records

Cross the identity provider app list against the AP and card lists. Three cases come out of it.

CaseWhat it means
In SSO, on an invoiceNormal. Proceed to the worksheet.
In SSO, on no invoiceEither genuinely free tier, or somebody else is paying. The second case is the shadow subscription, usually living on a personal card reimbursed as a meal, a conference expense, or a general office line. Ask the grantor named in the OAuth record.
On an invoice, absent from SSO and the app listFrequently a tool nobody has opened in a year. Also frequently a tool holding standing access to your data.

One more search, worth doing once: check whether the account recovery address on each subscription is a mailbox that still exists. A subscription whose password reset goes to a deactivated mailbox cannot be cancelled by you without a vendor support case, and that is an exit cost you want to discover before a renewal rather than during one.


Part 2: Put contract dates and notice terms in Sheet 1

One row per recurring charge. Fill this from the contract and the invoice, never from memory and never from the vendor’s website.

LineVendorProductAnnual costBilling frequencyTerm end dateAuto-renewal (Y/N)Renewal term lengthNotice period (days)Notice methodDecision dateSeats or units billedInternal ownerContract location
1
2
3

Enter the contract owner, term, notice date, and decision date

  • Annual cost. The full annualized figure including any charge billed separately: platform fee, per-seat fee, support tier, overage, and the implementation amortization if you are still paying it.
  • Term end date. From the order form. If the order form references a start date and a term length, calculate it and write the calculated date.
  • Auto-renewal and renewal term length. Auto-renewal is nearly always yes; write it anyway, because writing it forces you to look. A one-year contract that renews into a three-year term is a different instrument from one that renews annually.
  • Notice period. The number of days before term end by which you must give notice to stop the renewal. Common values run from 30 to 90 days. Some contracts require notice before the start of the final quarter of the term.
  • Notice method. Email to a named address, portal ticket, certified mail, or notice to a specific legal address. A cancellation sent the wrong way has not been sent.
  • Internal owner. A named human, never a department. If no name fits, that is a finding, and you record it as one.
  • Contract location. The file path or system where the executed order form actually sits. Most organizations cannot produce the signed document for a third of their subscriptions.

Calculate the last day you can preserve every option

This is the single highest-return step in the whole worksheet, and it is clerical.

  1. Get the order form, never the proposal. The proposal is marketing. The order form is the instrument that was signed.
  2. Follow the incorporation clause. Most order forms are one page and incorporate a master agreement or terms of service by URL. The term, renewal, and notice language lives in that incorporated document under a heading like “Term and Termination”. Some vendors update linked terms, so save a PDF of the terms as they read today with the date you retrieved them.
  3. Compute the decision date, and diary that one. Decision date equals term end date, minus the notice period, minus fourteen days of working room. Put it in a shared calendar with the owner’s name in the title. Organizations miss windows because they diaried the renewal date instead.
  4. If you cannot find the terms, ask the vendor in writing. “Please confirm our current term end date, the renewal term length, the notice period required to prevent renewal, and the notice method.” Keep the reply. That email is now your record.

When you finish, sort the whole sheet by decision date ascending. Anything with a decision date inside 60 days goes to the front of the queue regardless of dollar value, because those are the only lines where delay removes your options.


Part 3: Put actual use and dated evidence in Sheet 2

One row per line, matched to Sheet 1 by line number.

LineControl or business need servedSeats billedAccounts existingAccounts active 90 daysProof of operation (artifact)Proof dateOverlaps with line #Integration costExit cost, knownExit cost, internal hoursExit cost, unknownAdviser compensation
1
2

Write the control served before you evaluate the product

One sentence naming what the product does for the organization, phrased as an obligation or an operating need rather than as a product category.

Weak: “Endpoint security.” Strong: “Detects and isolates malicious activity on 196 laptops and servers, and answers the endpoint detection question on our cyber application and on two client security questionnaires.” Weak: “Compliance platform.” Strong: “Holds the evidence package our auditor requires in November.”

If nobody can write that sentence, the line is already in trouble. Write unknown and continue. You will resolve it in the decision step.

Put purchased seats beside active users

Three numbers, from three different places. Seats billed comes from the invoice, never from the contract (which may state only a minimum) and never from the console (which may show a different figure). Accounts existing comes from the product’s admin console; export the user list. Accounts active in 90 days comes from that same export, filtered on last login or last activity. Ninety days is a fair window. Thirty is too aggressive for seasonal roles and quarterly processes.

Then look for these five specific patterns.

PatternHow it showsWhat to do
Disabled accounts still billedConsole shows suspended or disabled, invoice count unchangedReconcile at renewal; many vendors bill provisioned rather than active
Departed staff never deprovisionedAccounts with last activity before a known departure dateDeprovision now, for security as much as for cost
Shared or generic accounts”frontdesk”, “scanner”, “info”Decide whether the account is required, and who owns it
Seats bought for a project that endedA block of accounts created on one date, never used sinceTrue-down candidate
Real growth the invoice has not caughtActive accounts exceed seats billedFix this before the vendor’s audit clause does

Check the true-down rules before you plan a reduction. Many subscriptions permit a seat decrease only at renewal, with notice. Some prohibit any decrease during a committed term. A few permit reduction only up to a floor stated in the order form. The reduction you can make is a contract question, and it belongs on Sheet 1.

Separate a paid license from an operating control

A license is a permission. A control is a thing that operates. The gap between them is where most of the “are they even working” question lives.

The test is a single question, and it is deliberately hard to fake: can somebody produce an artifact, generated by the product itself, carrying a date inside the last 90 days, showing the product did something?

Product typeArtifact that proves operationArtifact that proves nothing
Endpoint detectionCoverage report showing enrolled devices against total known devices, plus detection or policy-change records with datesA license count
BackupA restore test record: what was restored, when, elapsed time, who verifiedA green backup job dashboard
Email securityBlock or quarantine report for a named period, with volumesThe vendor’s marketing figure for global catch rate
Multi-factor authenticationEnforcement policy export showing scope and every exclusionOne user’s enrollment screenshot
Log management or SIEMIngest volume by source, plus the date a human last opened it and what they didThe fact that logs are being collected
Vulnerability scanningThe most recent scan report, with the date and the remediation status of the findingsA scanner that is licensed and scheduled
Compliance or GRC platformThe evidence package as it currently stands, plus the last login dateThe implementation project plan

Write the artifact name and its date into the sheet. If there is no artifact, write no evidence on record. That is a real finding and it is the most useful thing this worksheet will produce. Two notes on interpretation: a missing artifact does not prove a tool is idle, it proves nobody has checked, and a tool running perfectly while serving no named control is still a candidate for retirement.

Put two tools serving one job in the same comparison row

Overlap is common and it is not automatically waste. Two products can cover the same category at different depths for good reason. Overlap becomes waste when the second product serves no control that the first does not already serve at the level you require.

So the comparison is between the control sentences, never between the product categories.

Common overlap pairThe question that resolves it
Mail platform’s included filtering and a separate mail security gatewayRun both for 30 days and compare what each caught that the other missed. Then decide on the measured difference.
Platform-included endpoint protection and a purchased detection productDoes the purchased one deliver triaged alerts to a human, and does the included one?
Identity provider MFA and a standalone MFA productIs there a system the identity provider cannot cover, and is that system still in use?
SaaS backup included in a vendor plan and a third-party SaaS backupCompare retention period, deletion protection, and restore granularity against your actual obligation
Two remote access or remote support toolsWhich one does the outsourced IT firm use, which one do staff use, and does either need to exist
Password manager and identity provider credential vaultWhich one holds the credentials that matter, including the break-glass accounts
VPN and a newer access product bought to replace itWas the VPN ever turned off

That last row is the most common overlap of all. A replacement gets purchased, the migration stalls at eighty percent, and the organization pays for both indefinitely because the last twenty percent is hard. Look for it specifically.

Record the staff hours and dependencies tied to the product

What it took, or would take, to make this product part of your environment: SSO configuration, directory sync, log forwarding, ticketing integration, agent deployment, and the staff hours already spent. This number matters in both directions. High integration cost argues against replacing a product that works, and it argues against adding a product that duplicates one.


Part 4: Price the exit before you choose it

Exit cost is guessed more often than any other figure on the sheet, and it is wrong in both directions: vendors overstate it during a renewal conversation, and buyers understate it when they are annoyed. Write it in three columns, in the same discipline a board memo uses: known, internal hours, unknown.

ComponentWhere the number comes from
Remaining committed termThe order form. If you are 8 months into a 36-month term, that is contractual, and it is the first thing to check.
Early termination feeThe termination clause. Some contracts have none, and some have a full acceleration of remaining fees.
Data extractionCan you export your data, in what format, and is there a defined window after termination before deletion. Ask in writing and keep the answer.
Retention obligationIf the product holds records you are required to keep for a period, exiting means moving those records somewhere that satisfies the obligation.
Integration teardownSSO, directory sync, log forwarding, ticketing hooks, agent removal from every device.
Parallel runningThe overlap period where you pay for both. Usually 30 to 90 days. Budget it.
Migration labor and retrainingInternal hours and any external help, plus retraining hours per affected person. Be honest about internal hours; they are real and they come out of somebody’s week.
Bundle effectsIf the product is discounted as part of a bundle, removing it may raise the price of what remains. Ask the vendor for the unbundled price of the products you are keeping.
Control gap during migrationWhat covers the control while you switch, and for how long. This one has no dollar figure and it belongs in the unknown column with a description.

An exit cost with a single number and no breakdown is an opinion. An exit cost with three columns is a finding, and it survives challenge in a budget meeting.


Part 5: Record who earns money from the renewal

Every line has a recommender: an IT provider, a broker, a consultant, a reseller, a partner firm, or an internal person with a preference. Record how that party is paid on this line.

Ask in writing, and use plain wording:

“For each product on the attached list, please state whether your firm receives any margin, commission, rebate, market development funds, partner tier credit, referral fee, or other compensation tied to our purchase or renewal of that product, and the approximate amount or percentage.”

Record the answer, the date, and who gave it. Three notes on how to use it.

A compensated recommendation can be entirely correct. This column is not an accusation and it should never be presented as one. What it changes is the burden of proof: a recommendation from a party paid on the purchase needs an independent statement of the requirement before it moves forward, and a recommendation from a party paid the same regardless does not carry that particular question.

Rebates and partner tier credits are usually invisible to the buyer and are frequently the largest component. Ask for them by name, since a question about “commission” alone can be answered truthfully with a no while a tier rebate exists.

A firm with no vendor compensation loses nothing by putting that in writing. A refusal to answer is itself an answer, and you record the refusal in the column.


Part 6: The lifecycle line

Some recurring costs are not subscriptions at all. They are the cost of running something past its support date, and they belong on the worksheet as a separate line with their own decision.

Standard support for Windows 10 ended on October 14, 2025. Microsoft ended technical assistance, software updates, and security fixes on that date. Commercial Extended Security Updates start at US$61 per device for the first year and double in each consecutive year.

That doubling structure is the part that matters for a budget. A device on ESU is a line whose cost is scheduled to rise on a known curve, which makes it directly comparable to the cost of replacing or repurposing the device. Record it this way:

FieldEntry
Device count on Windows 10
Devices enrolled in ESU
ESU cost, year one
ESU cost, year two, at the stated doubling
ESU cost, year three, at the stated doubling
Devices that can be replaced, with cost
Devices that cannot be replaced, why, and the compensating controls around them
Named owner and target date

The same structure works for any end-of-support item: a line-of-business application on an unsupported version, a firewall past its last firmware release, a server operating system in extended support, or a phone system nobody will patch again. Put each one on its own line. These are the items most likely to appear on a cyber insurance application and on a client security questionnaire, so the work is reusable.


Part 7: Put the decision, owner, and date in Sheet 3

Six states. One per line. Every line gets one, including the ones you are keeping.

StateUse it whenWhat the row must contain
KeepThe control sentence is written, the evidence artifact exists and is current, use matches billing, and no alternative you already own serves the same control at the required levelThe evidence artifact name and date. The next review date.
RenegotiateThe product earns its place; the terms do not. Price, term length, seat minimum, auto-renewal, or notice periodThe specific terms you are asking to change, the decision date, and the walk-away position
ReduceThe product earns its place at a smaller quantity or a lower tierTarget quantity, the true-down rule from the contract, and the notice date
ReplaceThe control is still required and this product does not serve it, or something you already own doesThe control that must be preserved, the replacement, the parallel-run period, and the exit cost line
RetireThe control is no longer required, or it is served adequately by something already paid forThe evidence that the control is covered or no longer needed, and who accepted the residual risk
Defer pending evidenceYou cannot decide because the evidence does not exist yetWhat evidence, who produces it, and by what date. Plus the decision date it must beat.

That last row carries the weight of the whole sheet. A defer without a named evidence item, a named owner, and a date is a renewal with extra paperwork. Every deferred line must have a trigger that will actually fire, and the trigger date must sit before the contract decision date. If it cannot, the deferral is not available to you and the line must be decided on the evidence you have.

Record the disposition, owner, conditions, and date

LineVendorDecisionRationale in one sentenceEvidence relied onOwnerAction dateAnnualized effectReviewed by

Part 8: Four illustrative renewal decisions

The organization below is fictional and every number is illustrative. None of it is a benchmark for any real organization. It is a 90-person professional services firm with two offices, one IT person, and an outsourced provider.

Line 12: Endpoint detection and response

FieldEntry
Annual cost$34,200
Term end / notice / decision dateMarch 31, 2027 / 60 days / January 15, 2027
Control servedDetects and isolates malicious activity on 196 laptops and servers. Answers the EDR question on the cyber application and on two client security questionnaires.
Seats billed / accounts existing / active 90 days196 / 196 / 191. Gap: 3 spare laptops in storage, 2 conference room machines
Proof of operationConsole coverage report dated 12 days ago. Three detections in the last 90 days, each with a ticket number and a closure note. Policy last modified six weeks ago.
OverlapPlatform-included antivirus is present. It does not deliver triaged alerts to the outsourced provider; the purchased product does.
Exit costKnown $0 termination. Internal 60 hours. Unknown: detection coverage during a migration.
Adviser compensationOutsourced provider confirmed in writing, June 2026, that it earns a 12% margin on this renewal.

Decision: KEEP. The control sentence is written, the evidence is current and independent of the vendor’s marketing, and the seat count reconciles. The provider’s margin is recorded and does not change the conclusion, because the evidence came from the console rather than from the provider. Next review: December 2026, before the January decision date.

Line 27: Password manager

FieldEntry
Annual cost$8,400 at 140 seats
Term end / notice / decision dateNovember 1, 2026 / 45 days / September 3, 2026
Control servedStores shared credentials for 31 client portals and the break-glass account for the identity provider.
Seats billed / accounts existing / active 90 days140 / 118 / 84
Proof of operationVault access log shows daily use by 6 teams. Break-glass entry accessed and re-sealed in a documented test, May 2026. Contract permits reduction at renewal only, 45 days notice, floor of 50 seats.

Decision: REDUCE to 95 seats. Illustrative saving of about $2,700 annually. The product is doing its job and the evidence is strong. The seat count was set during a 2023 headcount that no longer exists. Notice must be given by September 3 or the 140-seat count renews for a year.

Line 31: Secondary email security gateway

FieldEntry
Annual cost$11,900
Term end / notice / decision dateFebruary 15, 2027 / 30 days / January 2, 2027
Control servedAttachment and URL filtering on inbound mail. Purchased in 2021.
Proof of operationQuarantine report for the last 90 days shows 31 messages held.
OverlapThe firm upgraded its mail platform tier in 2024. That tier includes attachment detonation and URL rewriting, already paid for. A sample review of the 31 held messages found that all 31 were also flagged upstream by the included tier.
Exit costKnown $0. Internal 12 hours to remove mail routing and update MX. Unknown: none material.

Decision: RETIRE at term end, after a documented 30-day parallel comparison to confirm the sample result across a full period. The comparison is the condition, and the controller owns it. Illustrative saving of $11,900 annually. Note what produced this outcome: a tier upgrade bought three years later made an older purchase redundant, and nobody re-examined the older purchase because nothing forced them to.

Line 44: Compliance evidence portal

FieldEntry
Annual cost$19,500
Term end / notice / decision dateDecember 1, 2026 / 60 days / September 18, 2026
Control servedunknown. Purchased in 2024 to prepare for a client-driven audit. The person who owned it left in 2025.
Seats billed / existing / active 90 days, and proof of operation25 / 25 / 0. Last login 14 months ago. Evidence library contains 40 documents, all dated 2024.
Relevant factAn audit is scheduled for November 2026.

Decision: DEFER PENDING EVIDENCE. The evidence required: written confirmation from the auditor whether the evidence package must be delivered through this platform or can be delivered as files. Owner: the controller. Due September 5, 2026, which sits ahead of the September 18 decision date. If the auditor confirms files are acceptable, this line becomes RETIRE on the same day. If the platform is required, it becomes KEEP with a named internal owner assigned before renewal.

Put all four illustrative decisions on one page

LineDecisionAnnualized effect (illustrative)
12, endpoint detectionKeep$0
27, password managerReduce($2,700)
31, mail gatewayRetire($11,900)
44, compliance portalDefer pending evidence, resolves by September 5$0 to ($19,500)

Four lines, four different outcomes, one purchase recommendation between them: none. That is the usual shape of a first teardown. The savings came from a seat count that had drifted and a product made redundant by something already owned, and the largest line on the page was kept because the evidence supported keeping it.


Part 9: Work the nearest decision dates first

Work the decision dates first. Anything inside 60 days gets handled this week regardless of dollar value, because that is the only category where waiting removes an option.

Take the free reductions before anyone proposes a purchase. Seat true-downs, deprovisioning departed staff, and retiring a product superseded by something you already pay for require no capital and no project.

Bring the no evidence on record rows to whoever owns them, and ask for the artifact by a date. Most resolve within two weeks, and the ones that do not are telling you something.

Write the keeps down properly. A documented keep, with its control sentence and its evidence artifact, stops the same conversation from starting over next year. It is also most of the answer to a client security questionnaire and to the controls section of a cyber insurance application.

Set the calendar. Every line gets a decision date in a shared calendar with a named owner. This single habit prevents more waste than any purchasing policy.

One question for whoever recommends your renewals. After you present the teardown, ask which lines they would have flagged, and why they did not. The answer tells you what kind of relationship you have.


Keep each completed row with the renewal approval

This worksheet is general guidance about examining recurring technology costs and contract terms. It is not legal advice, it is not accounting advice, and it does not interpret your contracts. Termination rights, auto-renewal enforceability, and notice requirements vary by contract wording and by state. Have counsel review any termination or non-renewal notice before you send it, particularly where an early termination fee or a multi-year commitment is at issue.

The Windows 10 and Extended Security Updates facts above are sourced to Microsoft through SBK’s source register, line 60. No other external figure appears here, and no percentage-of-revenue benchmark appears anywhere in this document, because none exists that would survive a question about its source, peer set, date, denominator, and limits.

SBK Consulting is a family-run, vendor-neutral IT advisory firm serving the New York, Connecticut, and New Jersey metro area since 2010, with more than 125 years of combined experience and a fully US-based team. Zero vendor partnerships, zero reselling, zero commissions or referral fees, which means we earn nothing on any decision this worksheet produces. We will give a second opinion on one renewal if that is useful to you. If you run the teardown yourself and never call, that is the outcome this document was built for.

(718) 407-4169

The IT Renewal Teardown Worksheet SBK Consulting / sbkconsultants.com / (718) 407-4169