Shadow IT is software a team buys and runs without going through the organization’s official technology approval process. In marketing it usually means a subscription paid on a corporate card, set up in an afternoon, that IT learns about later or never.
Every survey of shadow IT frames it as a security failure. That framing describes the risk accurately and explains almost nothing about why it happens.
A marketer buys an unapproved tool because the approved path and the deadline do not fit together. The campaign ships in 6 weeks. Security review, procurement , and integration work take 3 quarters. Facing that gap, the tool gets bought and the process gets skipped.
Why marketing is the largest source
Marketing runs on software that requires no installation, no server, and no engineering time. A landing page builder, a survey tool, a scheduling app, and an enrichment service can all be live before lunch, each one below the spending threshold that would trigger review. Marketing also carries more discretionary budget than most functions and more deadline pressure than any of them.
The result is a stack where the systems IT knows about are a subset of the systems in use.
What the pattern is telling you
A department with heavy shadow IT is reporting something about its official process. Long queues, unclear ownership of the request, or a review that treats a $200 monthly subscription the same as a data warehouse . It is one of the quieter contributors to martech sprawl that keeps accelerating even after a consolidation push .
Policing the symptom raises the cost of getting caught without changing the math that produced the purchase. Organizations that shrink the problem usually do it by adding a fast lane: a lightweight review for low-risk, low-cost tools, with the full process reserved for systems that touch customer data or core infrastructure.