Skip to content

Do You Have to Accept an Official Software Vendor Audit Report?

A publisher’s audit report is a submission, not a verdict. What an independent audit defence actually does, the questions that separate a SAM partner from a reseller, and why an audit report is still worth challenging after it lands.

Anyone who has been through an official publisher audit knows how daunting it can be. Publishers are adept at timing the letter — often on a three-year cycle, or when a merger or acquisition has raised the odds that you are no longer fully in control.

And if you know you are not in control, if you do not have a firm handle on what software is out there, how it is being used and where you stand on your effective licence position, then you can be fairly confident there is a compliance problem somewhere. Probably alongside unidentified overspending on software the business does not need. The often literally million-dollar question is: by how much?

How to respond to an audit letter

The ideal position is to already be in control, with a capable SAM platform and either an in-house or outsourced team with the licensing skills to run it. That team supplies the evidence of control that satisfies a publisher its software is deployed and accessed in accordance with entitlement. The audit risk is managed before it arrives, and organisations in this position are usually optimising their software spending as a matter of routine rather than as a response to a letter.

For everyone else — the organisations very much on a publisher’s radar — the next best move once that letter lands is a rapid audit defence with a SAM partner who can tell you how to navigate the process and how to respond well.

That is what Certero does: technology and services in the same organisation, either proactively or as a tactical audit defence engagement when one is needed.

Identifying a SAM partner you can trust

What matters here is understanding the roles and relationships in play — the publisher, the publisher’s commercial reseller channel, the officially appointed auditor, and whoever you choose as your SAM partner. Those four have different interests, and only one of them is yours.

When you are under audit, independence and dedicated SAM proficiency are the attributes to look for. Five questions worth asking:

  • Does the partner have a vested interest in selling you the licences you would need to buy to resolve any non-compliance?
  • Is the partner a specialist in licence optimisation, or in identifying licensing requirements for commercial purposes?
  • Do they have technology that goes to the depth required to identify your software accurately, or are they running scripts?
  • Do they have the skills — and the appetite — to interpret data and rules in your interest to the nth degree?
  • Do they offer transparency and sovereignty over your own data? Can you see what is happening?

The uncomfortable truth is that an effective licence position exercise for a single publisher can produce materially different answers depending on who runs it. Licensing rules and scenarios are open to interpretation. Accuracy varies widely between inventory and SAM tools. Assumptions and false positives are common, the underlying data used to calculate the position is often not available for scrutiny, and the audit process itself can be a revenue exercise for the publisher. So: who works for you, and who works for the publisher?

How software audit defence actually works

Here is the part organisations tend to miss. An independent audit defence can be valuable even after the officially appointed auditor has produced their report.

An audit is, at bottom, a request for evidence that you are using the software appropriately. That is all the publisher wants. The complexity of software licensing is what makes that evidence hard to identify, hard to control and hard to report on accurately.

So the process does not have to be adversarial. But with a partner who has both deep knowledge of the publisher’s rules and accurate ITAM and SAM technology behind them, you have stronger means at your disposal than the publisher does to establish your best-case position — and to prove it.

What goes wrong in an auditor’s report

Auditors’ reports contain errors, and the errors fall into recognisable categories. These are the ones worth checking line by line before you accept a finding:

Bad inventory data taken at face value. If the discovery underneath the audit came from a tool that cannot see a platform properly — non-persistent VDI, a partitioned Unix frame, a clustered SQL environment — the installation counts are wrong before any licensing logic runs. Ask what collected the data and how.

Entitlement history that was not fully walked back. Upgrade rights, downgrade rights and second-use entitlements bought years ago frequently do not make it into an auditor’s view. It is entirely possible to be recorded as non-compliant on a product you are actually over-licensed for.

Products counted that are not installed. A file signature that matches a component of a larger product, or a leftover registry entry, can produce an exposure for something nobody ever deployed. This is the single most common category worth challenging, because the correction is total rather than partial.

Licensing rules applied without the environment. Core factors, cluster awareness, virtualisation topology and access-control mechanisms for RDS, Citrix and VDI all change the number materially. A generic reading of the rules against a generic reading of the environment gives a generic — and usually unfavourable — answer.

None of these require an argument with the publisher. They require better evidence than the auditor had.

Certero audit defence at a glance

Technology-led services. The consultancy team runs on the same platform Certero sells. CerteroX ITAM covers six operating system families with one native agent — Windows, macOS, Linux, AIX, HP-UX and Solaris — plus mobile device management for iOS and Android, virtual infrastructure, cloud and SaaS. Ten discovery methods land in a single schema, so there is no reconciliation exercise between sources before the licensing work can start.

Publisher depth where audits actually bite. CerteroX SAM carries dedicated licence engines for Microsoft, Oracle, IBM, SAP, Adobe and Salesforce, with the effective licence position computed continuously — purchased, used, available, required, variance and exposure — rather than reconciled at a point in time. Software recognition resolves against a database of more than 3.5 million titles.

Verified with Oracle. Certero is a verified third-party tool vendor with Oracle License Management Services. Oracle’s audit team can accept data from Certero during an official audit, as an alternative to installing Oracle’s own measurement tools.

In-house SAM team. Dedicated specialists for Microsoft, Oracle, IBM and SAP. Certero does not need to rely on partnerships for the licensing knowledge, so the success of an engagement rests with one accountable organisation.

Independence. Certero has no commercial interest in selling you licences and does not share your information with third parties. It is not part of the business model.

Experts in your corner. Even a large publisher’s appointed auditor can get it wrong, and it is never too late to bring in an independent view — particularly if you are facing a significant exposure.

Longevity. Establishing an effective licence position is a substantial piece of work, so it is worth not throwing away. Because the compliance and optimisation reporting comes out of the platform, you have the option of keeping it: continuing with the product, or moving to a SAM managed service, and turning a one-off defence into sustained visibility and control.

The short answer

No, you do not have to accept an official audit report as final. It is a submission based on the evidence the auditor had, produced by a party whose interests are not yours. If you can produce better evidence, you can change the outcome — and quite often the better evidence is already sitting in your own environment, waiting for something accurate enough to collect it.

To find out more about Certero’s audit defence services, get in touch.


Certero was named the sole Customers’ Choice in the 2024 Gartner® Peer Insights™ Voice of the Customer for Software Asset Management Tools — the only vendor in the category to reach that position.

GARTNER is a registered trademark and service mark, and PEER INSIGHTS is a trademark and service mark, of Gartner, Inc. and/or its affiliates in the U.S. and internationally and are used herein with permission. All rights reserved. Gartner Peer Insights content consists of the opinions of individual end users based on their own experiences and should not be construed as statements of fact, nor do they represent the views of Gartner or its affiliates.

Related reading

Other posts covering the same ground.

  • Device-based licensing and access control

    Locking an application down at user level does not make you compliant with a per-device licence. In a Citrix or RDS environment, one user with access can cost you a licence for every device in the organisation.

    • ITAM
    • SAM
    • Governance
    4 min
  • Gartner Myth Buster – Part 1

    A third-party summary of a vendor can be wrong, and it stays wrong for as long as people read it. The case for checking a vendor's facts at source — and the current, sourced record for Certero.

    • ITAM
    • SAM
    • Governance
    7 min
  • The role of good data in software audits

    An audit is won or lost on the quality of your inventory long before the letter arrives. Six ways data goes wrong, and what it takes to have the answer already in hand.

    • ITAM
    • SAM
    • Governance
    8 min
From reading to evidence

Put the hardest claim here
to a technical person.

Everything argued above is checkable. Name the publisher, the billing account or the platform you would argue with, and the session is built around it — the reasoning attached, not a summary slide.

No gated download at the end of it.