Software asset management — SAM — is the practice of managing your software licensing obligations while optimising the cost and value of what you have bought. Some of the benefits are the obvious ones. Several are not. Here are eight, and what each means for IT operations.
1. Removing licence compliance risk
Organisations live under the periodic risk of being audited by a publisher at a time of the publisher’s choosing. Even top-tier “unlimited” or all-you-can-eat agreements do not fully protect you from being asked to prove you are correctly licensed for what you have deployed.
These are not chance events. They are calculated. A vendor who funds an audit — and brings in an external partner at their own expense — has a reasonable idea of what the return will be before they start.
Protecting the business from that unplanned, unbudgeted expenditure is the first objective of a SAM programme. Understanding where compliance risk sits is what makes it actionable: under-licensing can be corrected deliberately, in line with a licensing strategy you chose, rather than at a price and on a timetable someone else set.
Above all it means you are in control. The year proceeds as planned, and neither IT nor the business ends up in a public dispute with a publisher.
2. Reducing and avoiding cost
Arguably this should be first, because cost is the point.
Audits are expensive and disruptive, but SAM does more than prevent the mistakes that make them expensive. It stops the overspending happening in the first place.
The waste is easiest to measure in SaaS, where the vendor meters usage for you. 46% of SaaS licences go unused — the average organisation uses 54% of what it holds. That figure is specific to SaaS, not to every licence you own.
The mechanism for recovering it is usage metering. CerteroX SAM meters software use at file level, tracking first-used and last-used dates and reporting a percentage-used figure over a rolling 90-day window. That feeds the optimisation process directly: unused installations can be removed and their licences returned to a pool for reassignment, which reduces what you need to buy. On the SaaS side, CerteroX SaaS Management flags licences with 30 or more days of zero usage and offers reclaim, reassign, downgrade or archive as actions on the finding rather than as a separate project.
The same data tells procurement what is genuinely required, so the next purchase is sized to reality.
3. Preventing security risk
One of the core principles of good ITAM and SAM is that you can see everything you run. Guesswork and manually stitched-together inventory from a handful of tools do not qualify.
CerteroX ITAM covers Windows, macOS, Linux, AIX, HP-UX and Solaris with one agent and one schema, alongside agentless and standalone inventory for locked-down and air-gapped systems, network discovery, Active Directory import and cloud connectors. Ten discovery methods, one data model, nothing to reconcile afterwards.
That raw inventory is then enriched by software recognition. The Software Recognition Database holds more than 3.5 million normalised titles, resolving what was discovered into a real publisher, product, edition and version — and the Software Recognition Service adds release date, end-of-support and extended-support dates on top.
This is what makes the security use case work. When a vulnerability is published against a specific version, you can answer immediately whether you run it and on which machines, rather than commissioning a survey. Remediation becomes targeted, and you can report back with evidence that the exposure has been closed. Lifecycle tracking gets you ahead of the same problem: software past end of support stops receiving fixes, and knowing which of yours is approaching that date is the difference between planning an upgrade and discovering one.
4. Navigating mergers, acquisitions and divestitures
During any MAD activity, every asset needs verifying — software licences included. For a large organisation the total value of software assets runs to many millions, and so does the risk if the entity being traded is not properly licensed.
Changes of ownership can alter licensing provisions, so contracts with publishers need to be read and understood rather than assumed to transfer. And because a merger increases complexity, it is a well-known trigger for a formal audit — precisely when nobody has spare capacity to defend one.
Due diligence therefore has to extend to licence compliance. A tactical effective licence position engagement gives you that clarity quickly, along with the legal and financial impact of transferring the software assets. You may need to confirm that assets held by specific legal entities come across, or correct shortfalls before ownership changes hands. Nobody wants to buy a business and inherit a multi-million-pound licensing exposure the week the audit letter arrives.
5. Standardising and rationalising the application portfolio
We have seen organisations become dependent on a small piece of software that turns out to be unlicensed. That means no guarantee about how a critical part of operations continues to function. The software may be end of life and out of support. It may block an upgrade elsewhere. The publisher may discover the usage and act to stop it.
A licence records what both parties agreed. Understanding what you have and what you use — including non-commercial, tier two and tier three software — is a business continuity control, not just a compliance one.
There is an operational cost to sprawl as well. Overlapping applications increase the burden of supporting end users and the overhead of running and maintaining products that could be consolidated into fewer, cheaper or more strategic options. SAM gives you the visibility, the licensing terms, the lifecycle dates, the costs and the usage, so the decision is informed.
For SaaS this is a first-class capability rather than an analysis exercise. CerteroX SaaS Management maintains a catalogue of more than 35,000 applications and uses it to detect functional overlap, ranking rationalisation candidates by recoverable saving. It also classifies AI tools from application feature tags rather than a fixed list, so the Shadow AI picture keeps up as new tools appear — which matters, because that is where unmanaged applications are arriving fastest.
6. Managing cost in the cloud
Cloud has been both liberation and burden for a lot of organisations, particularly those that made the jump quickly. The ease with which resources are provisioned pulled control away from IT governance, leaving businesses committed to the platform while firefighting the bill.
SAM has a role even inside the financial models set by cloud centres of excellence and FinOps teams, because the principles are the same: see what you have, understand usage against business need, assign accountability for cost, and manage consumption closely enough to forecast, buy commitments sensibly and spot anomalies quickly.
Two of the largest software savings in cloud are SaaS subscription optimisation and bring-your-own-licence. BYOL uses on-premises entitlement inside public cloud, and provider interoperability increasingly supports it — Oracle’s arrangement with Azure is the obvious example. It only works if you have genuine control of licensing on both sides of the boundary, which is exactly the position SAM produces.
The infrastructure spend responds to the same discipline. CerteroX Cloud Management runs 26 named, individually tunable optimisation checks across 12 cloud and data platforms — abandoned instances and load balancers, obsolete snapshots and snapshot chains, instances stopped but not deallocated, volumes long unattached, rightsizing, generation upgrades, reserved instance and savings plan opportunities. Certero’s average cloud cost saving across environments under management is 38%.
And the governance layer stops the waste returning: expense anomaly detection against a rolling daily average, budget policies, tag compliance rules, resource TTL with automatic enforcement, and daily and total expense limits per resource or pool.
SaaS is usually the easiest saving to realise. Identify the unused and underused subscriptions, then remove them with confidence, because the usage evidence is there to support the decision.
7. Improving your negotiating position
Beyond controlling compliance risk — and not walking into a negotiation already owing the vendor money — the detail SAM produces puts you in a materially stronger position at renewal.
Demonstrating that you are compliant weakens the publisher’s hand. It removes the pressure point that turns a renewal into an unfavourable agreement written entirely in their interest. Knowing precisely what you use, and what you will use, lets you buy the shape of agreement you actually need.
Unifying software buying across the organisation compounds the effect. Consolidated volume gets a better deal than several departments negotiating independently, sometimes with the same vendor, occasionally against each other.
8. Unifying asset intelligence
The tactical and strategic benefits above are the well-rehearsed ones. The underrated benefit is what happens when the information stops being fragmented.
It is a strategic mistake to manage hardware, software, remote devices, the data centre, SaaS and cloud in separate tools — or to let the requirements of service management dictate the choice of platform that everything else then has to live with. You end up with several partial truths and a standing argument about which one is right.
SAM is the discipline that forces the issue, because it is the hardest of them. It needs the most capable discovery, it needs the nuance of licensing handled properly, it needs the wide view and the current view, and it needs to work across on-premises infrastructure and cloud without a gap in the middle.
That is the case for a single platform across all five asset classes — IT assets, software, SaaS, cloud and AI — on one data model. Not five products integrated after the fact, but one record that every discipline reads from. When the barriers to information come down, teams communicate better, decisions get made on evidence, and IT can respond at the speed the business is asking for.
To talk through what one record across all five asset classes would change, talk to us.