Decree 341/2025 in effect — software copyright violations fined 10–500 million VND
DZO Digital Solutions
Legal & compliance

Managing SaaS Costs by Department: Showback vs Chargeback

DDzo.softwareSAM & FinOps Team · Dzo.software
·Published 20/07/2026·Updated 20/07/2026·11 min read

In short

SaaS sprawl inflates software spend and compliance risk. How to allocate licences by department using showback/chargeback and control shadow IT under VN law.

Quick answer

Managing SaaS licence costs by department means tying every software/SaaS spend to a specific cost centre, then reporting it back via showback (letting the department SEE the cost it creates) or chargeback (formally billing that cost to the department's budget). It is the most effective way to stop "SaaS sprawl" — the spread of duplicate, ownerless SaaS subscriptions — and to avoid the risk of using more licences than you bought.

Why it matters now: per Flexera 2024 State of the Cloud, 29% of surveyed organizations spend over USD 12 million a year on cloud and 22% spend that much on SaaS; managing cost and security are the top cloud challenges. Big spend that cannot be allocated to a department cannot be optimised or held accountable.

Showback or chargeback? Per the FinOps Foundation, showback is always required in any FinOps practice, while chargeback depends on the organization's accounting policies — it is not always required. Start with showback for transparency, then move to chargeback when the organization needs formal financial allocation to cost centres.

The Vietnam compliance angle: software is protected as a literary work (Điều 22, Luật Sở hữu trí tuệ 50/2005/QH11), and a "licence" is by nature a time-limited, conditional grant of the right to use (Điều 47). Ungoverned "shadow IT" SaaS easily leads to using more rights than purchased — which can be sanctioned administratively under Nghị định 341/2025/NĐ-CP (effective 15 Feb 2026, caps of VND 250 million for individuals / VND 500 million for organizations).

*Disclaimer: This article is for information only and is NOT legal, financial or official licensing advice. Legal document names are kept in Vietnamese (original). Survey figures are taken from official Flexera / FinOps Foundation / Microsoft pages at the time of writing (see sources) — vendor content can change. Check your specific licence terms and consult experts before deciding.*

  • Big spend: 29% of organizations spend over USD 12M/year on cloud, 22% spend that on SaaS (Flexera 2024 State of the Cloud).
  • Tools exist: 57% of large enterprises use multi-cloud FinOps (cost optimization) tools; 61% use multi-cloud security tools (Flexera 2024).
  • FinOps principle: showback is ALWAYS required in any FinOps practice; chargeback DEPENDS on the organization's accounting policy (FinOps Foundation).
  • Detect shadow SaaS: Microsoft Defender for Cloud Apps provides "Shadow IT discovery" and assesses apps against more than 90 risk indicators (CASB).
  • Vietnam fine cap: using software beyond licence scope — up to VND 250 million (individuals) / 500 million (organizations) under Nghị định 341/2025/NĐ-CP (effective 15 Feb 2026).

1. What SaaS sprawl & shadow IT are — and why they burn money

SaaS sprawl is when the number of subscription software (SaaS) accounts in a business grows out of control: departments buy overlapping tools, accounts are bought then abandoned, and nobody holds the full picture. "Shadow IT" is the submerged part of the iceberg — apps employees sign up for on a personal card or work email that IT/procurement never knows about. Flexera itself frames its problem as "taming SaaS sprawl, wasted spend and compliance risks".

Why does it burn money? The spend is already large: per Flexera 2024 State of the Cloud, 29% of surveyed organizations spend over USD 12 million a year on cloud and 22% spend that much on SaaS alone — and "managing cost" plus "security" are the top cloud challenges. When each spend cannot be tied to an accountable department, the business loses the ability to see which accounts are surplus, which tools overlap, and which licences were bought but go unused. Table 1 summarises Flexera's published figures.

The key point: SaaS sprawl is not a "we bought the wrong tool" problem but a governance problem — the lack of a mechanism tying cost to an owner. The fix is not banning employees from buying SaaS, but making every spend visible and owned. That is exactly the role of department-level cost allocation.

Table 1 — Cloud/SaaS spend & governance scale (Flexera 2024 State of the Cloud, checked)
Metric — Flexera 2024 State of the CloudPublished value
Organizations spending over USD 12M/year on cloud29% of respondents
Organizations spending over USD 12M/year on SaaS22% of respondents
Large enterprises using multi-cloud FinOps (cost optimization) tools57%
Large enterprises using multi-cloud security tools61%
Prioritising cost optimization (over sustainability)59% prioritise cost; 29% weigh both equally
Platforms used for significant workloadsAWS 49% · Azure 45% · Google Cloud 21%

2. Showback vs Chargeback: which mechanism for departments?

Showback and chargeback both attribute cost to departments, differing in how "formal" they are. Per the FinOps Foundation, the core difference is "the formality of sending expenses to official accounting budgets": showback reports to a group so it can SEE the cost of the scope it is responsible for (at any granularity), while chargeback creates a formal debit into the organization's financial systems. Table 2 compares the two.

A key FinOps principle: "Showback is always required in any FinOps practice, but chargeback is dependent on organizational accounting policies." Chargeback is not always needed — when technology costs land in one or a few easily allocated cost centres, the cost and burden of building formal chargeback may be unwarranted. Practical advice: start with showback to create transparency and change behaviour; move to chargeback only when the organization genuinely needs to debit department budgets.

Table 2 — Showback vs Chargeback (per FinOps Foundation — Invoicing & Chargeback / Cost Allocation)
CriterionShowbackChargeback
NatureReporting so a department/team SEES the cost of its scopeFORMALLY debiting the cost into the department's budget/accounting system
Requirement (FinOps)Always required in any FinOps practiceDepends on the organization's accounting policy — not always required
When it is enoughAny need for transparency by group, at any granularityWhen formal financial allocation is needed; less needed if cost lands in few easily allocated cost centres
Data requirementsA tagging & cost-centre hierarchy strategyPlus vendor invoice reconciliation + shared-cost handling; demands consistent, timely, accurate data
Organizational roleFinOps/IT led, with budget ownersDirect collaboration with Finance & Accounting (formal journal entries)

3. How to allocate licence/SaaS cost by cost centre

Allocating cost by cost centre starts from a tagging and hierarchy strategy: per the FinOps Foundation, the Cost Allocation capability is about "defining specific tags, labels, naming standards, grouping structures used to identify that a cost is in a particular grouping", while maintaining a strategy for shared cost. In other words: every licence, every SaaS account must carry a "label" showing the owning department/cost centre — otherwise every later showback/chargeback report lacks a foundation.

For SaaS, three minimum data points per subscription: (1) owner — the department/cost centre bearing the cost; (2) seats purchased vs actually used; (3) rights status — is the contract/terms still valid, are there machine/user limits. These three serve both showback (who spends how much) and compliance (is anyone exceeding scope).

On shared cost (one tool used by many departments, e.g. an email or storage platform), the FinOps Foundation is explicit: "define mechanisms to share costs for each shared cost item" and answer "will these costs be held centrally or allocated based on consumption?". Answering this before reporting avoids internal disputes when the money is billed back to each department.

4. The Vietnam compliance angle: department-level management is copyright risk management

Department-level cost allocation is not only a finance problem — it is directly a copyright-compliance one. In Vietnam, software is protected as a literary work (Điều 22, Luật SHTT 50/2005/QH11), and an author's economic rights include reproducing and distributing copies of the work (Điều 20). Every running copy of software, every activated SaaS account is a "copy/right to use" — lawful only within the scope and quantity the licence permits. Table 3 maps each ungoverned-SaaS risk to its legal basis.

Why is shadow IT dangerous for compliance? Because a "licence" under Điều 47 is a time-limited, conditional grant of the right to use — when a department signs up for SaaS out of IT's control, the business loses its ability to prove it is using within permitted scope. To surface this hidden part, CASB tools such as Microsoft Defender for Cloud Apps provide "Shadow IT discovery" — detecting all cloud services in use and assessing them against more than 90 risk indicators, building a complete app inventory to allocate to departments.

The consequence of exceeding scope: per Nghị định 341/2025/NĐ-CP (issued 26 Dec 2025, effective 15 Feb 2026, replacing Nghị định 131/2013/NĐ-CP), the maximum fine in copyright and related rights is VND 250 million for individuals and VND 500 million for organizations. Managing licences by department — knowing exactly who uses what, how many seats — is the first line of defence before a vendor audit or an inspection under this decree.

Table 3 — Ungoverned SaaS/licence risk → Vietnam legal basis (from original legal texts)
Risk when not managed by departmentLegal basis / consequence (Vietnam)
More software copies / accounts running than licences boughtSoftware protected as a literary work (Điều 22); reproducing/distributing copies is the author's economic right (Điều 20) — exceeding scope is infringement
Unclear which department was granted the right, and until when"Licence" = a time-limited, conditional grant of the right to use (Điều 47, Luật SHTT 50/2005/QH11)
Shadow-IT SaaS accounts outside IT's controlMust be discovered to inventory — Microsoft Defender for Cloud Apps: "Shadow IT discovery", assessed against more than 90 risk indicators (CASB)
A vendor audit finds usage beyond purchased rightsAdministrative sanction under Nghị định 341/2025/NĐ-CP — caps VND 250M (individuals) / 500M (organizations), effective 15 Feb 2026

5. A 7-step checklist for managing SaaS licence cost by department

Seven steps to move from "sprawling SaaS" to "every spend has an owner" — in order, each step a question you must answer with data, not guesses:

  • Step 1 — Discover shadow IT. Use a CASB tool (e.g. Microsoft Defender for Cloud Apps, "Shadow IT discovery") to find every SaaS app in use, including what IT does not yet know. Without a complete inventory, you cannot allocate.
  • Step 2 — Tag by cost centre. Define naming/label standards so every licence and SaaS subscription shows its owning department/cost centre (the FinOps tagging & hierarchy strategy).
  • Step 3 — Reconcile seats bought vs used. For each subscription, compare seats purchased with seats actually used to expose surplus accounts and overlapping tools.
  • Step 4 — Handle shared cost. Decide upfront: costs for tools used by many departments held centrally or split by consumption — avoiding disputes when money is billed back.
  • Step 5 — Start with showback. Send each department a report showing the cost it creates (showback is always required in FinOps). Transparency alone often cuts waste.
  • Step 6 — Move to chargeback when needed. Only switch to chargeback (formal debit) when the organization needs to allocate finance into department budgets — with Finance & Accounting.
  • Step 7 — Check compliance periodically. Review each cost centre for usage beyond licensed rights; keep records to defend against a vendor audit or an inspection under Nghị định 341/2025.

Frequently asked questions

1. What is SaaS sprawl? It is when the number of subscription software (SaaS) accounts grows out of control: departments buy overlapping tools, accounts are bought then abandoned, nobody holds the full picture. The "hidden" part — apps employees sign up for without IT knowing — is shadow IT.

2. How does showback differ from chargeback? Per the FinOps Foundation, the difference is formality: showback reports so a department can SEE its cost; chargeback FORMALLY debits the cost into the department's budget/accounting system.

3. Do small businesses need chargeback? Not necessarily. The FinOps Foundation states: showback is always required, while chargeback depends on accounting policy — when cost lands in a few easily allocated cost centres, the burden of formal chargeback may be unwarranted. Start with showback.

4. How big is SaaS/cloud spend? Per Flexera 2024 State of the Cloud: 29% of surveyed organizations spend over USD 12M/year on cloud and 22% spend that on SaaS; managing cost and security are the top cloud challenges. Actual figures vary by size and industry.

5. How do I detect shadow SaaS (shadow IT)? Use a CASB. For example Microsoft Defender for Cloud Apps provides "Shadow IT discovery" — detecting all cloud services in use and assessing them against more than 90 risk indicators, helping build a complete app inventory to allocate by department.

6. What are the Vietnam legal risks of not managing licences by department? Software is protected as a literary work (Điều 22, Luật SHTT); using it beyond licence scope can be sanctioned administratively under Nghị định 341/2025/NĐ-CP — up to VND 250 million (individuals) / 500 million (organizations) — plus the risk of a vendor audit.

*This article is for reference and does not replace legal, financial or licensing advice. Please check your specific licence terms and the original legal texts (ipvietnam.gov.vn, cov.gov.vn) before deciding.*

Conclusion

SaaS sprawl is the natural result of software being easy to buy but slow to govern. The fix is not prohibition but making every spend visible and owned: discover shadow IT, tag by cost centre, report via showback, then move to chargeback when needed. At the same time, managing by department is the copyright defence — knowing who uses what, how many seats, and whether it is still valid — against audit risk and sanctions under Nghị định 341/2025.

You cannot optimise — or comply with — what you cannot see: every dollar spent on SaaS must map to a department and a valid right to use.

Need a software compliance review?

DZO experts provide a free compliance roadmap within 24 hours — e-VAT invoice, local implementation.

Book a free consultation