Chasing Shadows: How To Address Unapproved IT In Travel

By Brett Wheeldon, VP, Solution Advisory – APAC, SAP Concur

Technology now sits at the heart of business travel. Digital transformation, cloud services and the rapid adoption of artificial intelligence across India have made corporate travel more connected, efficient and capable. At the same time, these developments have expanded the technology footprint of organisations, creating more opportunities for unsanctioned tools and channels to enter the travel process. Shadow IT is not a new challenge, but its impact is becoming increasingly difficult to ignore. The use of unapproved applications and platforms can expose organisations to security, financial and regulatory risks. The growing adoption of consumer AI adds another dimension. According to WalkMe, 78% of employees admit to using unapproved AI systems at work. For business leaders, therefore, the question is not simply how to stop this behaviour, but what it reveals about the employee experience.

Employees rarely bypass approved travel tools simply because they want to disregard company policy. More often, they do so because the authorised journey feels slower, less intuitive or less useful than the alternatives available to them. Friction can appear at almost any stage of the travel journey. Hotel content may load slowly, travellers may be unable to save preferred properties or use familiar payment methods, and loyalty benefits may not always be integrated into the booking experience. Some employees may also believe that consumer travel websites offer lower fares or a wider range of options. Every additional point of friction increases the likelihood that a traveller will abandon the approved process in favour of something more convenient.

This is why the objective must go beyond compliance. Organisations need to deliver a seamless experience from search and booking through payment and expense, while keeping policy, control and traveller wellbeing embedded throughout the process. When bookings and expenses move outside approved systems, organisations lose more than transaction visibility. Fragmented travel activity can undermine cost control, operational efficiency, employee support and confidence in enterprise data. Off-channel bookings can make it harder to identify fraudulent receipts, duplicate claims and inflated expenses. Employees may also unknowingly use fraudulent websites or unverified suppliers, increasing the risk of financial losses and chargebacks. Organisations can simultaneously miss out on negotiated rates, preferred suppliers, corporate discounts and other commercial benefits secured through managed travel programmes.

The administrative impact can be equally significant. Manual processing, fragmented information and reconciliation across multiple platforms create additional work for finance and travel teams. What begins as an individual’s attempt to save time can ultimately increase the organisation’s operational burden. There is also a clear duty-of-care implication. In a geographically diverse market such as India, organisations need reliable visibility of traveller itineraries to provide timely assistance during disruptions or emergencies. When bookings take place outside the managed programme, that visibility can be compromised, making it harder to locate and support employees when they need help.

Security and compliance risks further compound the issue. Unapproved tools may process personal, financial and itinerary data without enterprise-level safeguards, creating exposure around privacy, data retention, financial reporting and payment-card obligations. Consumer AI tools have made travel planning faster and more personalised, but convenience can sometimes obscure risk. AI-generated information may be outdated or inaccurate, while recommendations could direct employees towards suppliers that fall outside corporate agreements or approved policies. There is also the risk of sensitive information entering unmanaged AI platforms. Employees may share company information, travel itineraries or personal details without fully understanding how that data is stored or processed.

Receipt scanning provides a practical example. Consumer scanning applications, browser extensions and free optical character recognition tools may upload receipt images to third-party cloud services. Receipts can contain personal information, transaction details and insights into travel patterns. What appears to be a simple productivity shortcut can therefore become a significant data-governance and traveller-safety concern. The challenge is not AI itself, but the use of AI without the governance, security and integration required in a corporate environment.

Organisations will not solve shadow IT through restriction alone. Sustainable change requires IT, HR, finance, legal, operations and travel leaders to work together to create an environment where employees understand expectations while having fewer reasons to work around them. Employees need practical guidance on approved tools, data handling and responsible AI use. Training is more effective when policies are connected to tangible outcomes, including protecting company information, maintaining financial control and ensuring traveller safety.

Organisations should also treat workarounds as experience data. The tools employees choose outside the managed programme can reveal where the approved experience is falling short. These patterns may highlight gaps in content, usability, payment options, speed or personalisation. Rather than simply blocking alternative tools, leaders can use these insights to improve the authorised journey. Ultimately, the strongest control is an approved platform that employees actually want to use. Intuitive, secure and user-friendly experiences reduce the incentive to seek alternatives while giving organisations the visibility and governance required to manage corporate travel effectively.

AI can play a constructive role when embedded within a governed travel and expense environment. Conversational trip planning can allow travellers to express their requirements naturally and build itineraries around their preferences. AI can also enable policy-aligned personalisation by combining individual preferences with corporate rules, ensuring that recommendations remain within the managed programme. Integrating expense context earlier in the journey can further reduce friction. Greater visibility of pricing, travel-class rules and justification requirements can minimise uncertainty when expenses are eventually submitted.

Shadow IT should be viewed as both a risk and a diagnostic signal. It highlights weaknesses in governance, but it also reveals where the employee experience is failing to keep pace with changing expectations. For business leaders in India, the opportunity is to bring these perspectives together. Strengthening governance, educating employees and investing in a travel and expense experience that is secure, intelligent and easy to use can address the underlying causes of shadow IT rather than simply treating its symptoms.

The future of managed business travel will depend on finding the right balance between control and convenience. Organisations that understand why employees seek alternatives and then use technology to remove those pain points will be better positioned to protect their people, data and travel programmes. The ultimate goal is simple: the compliant path should also be the best path. When employees can access the convenience, flexibility and personalisation they expect within a secure and governed environment, organisations can turn technology from a source of risk into a strategic advantage—and maximise the value of every business journey.

Leave a Reply

Discover more from

Subscribe now to keep reading and get access to the full archive.

Continue reading