Anyone who has been through an official publisher audit knows how daunting it
can be. Publishers are adept at timing the letter — often on a three-year cycle,
or when a merger or acquisition has raised the odds that you are no longer fully
in control.
And if you know you are not in control, if you do not have a firm handle on what
software is out there, how it is being used and where you stand on your effective
licence position, then you can be fairly confident there is a compliance problem
somewhere. Probably alongside unidentified overspending on software the business
does not need. The often literally million-dollar question is: by how much?
How to respond to an audit letter
The ideal position is to already be in control, with a capable SAM platform and
either an in-house or outsourced team with the licensing skills to run it. That
team supplies the evidence of control that satisfies a publisher its software
is deployed and accessed in accordance with entitlement. The audit risk is
managed before it arrives, and organisations in this position are usually
optimising their software spending as a matter of routine rather than as a
response to a letter.
For everyone else — the organisations very much on a publisher’s radar — the next
best move once that letter lands is a rapid audit defence with a SAM partner who
can tell you how to navigate the process and how to respond well.
That is what Certero does: technology and services in the same organisation,
either proactively or as a tactical audit defence engagement when one is needed.
Identifying a SAM partner you can trust
What matters here is understanding the roles and relationships in play — the
publisher, the publisher’s commercial reseller channel, the officially appointed
auditor, and whoever you choose as your SAM partner. Those four have different
interests, and only one of them is yours.
When you are under audit, independence and dedicated SAM proficiency are the
attributes to look for. Five questions worth asking:
- Does the partner have a vested interest in selling you the licences you would
need to buy to resolve any non-compliance?
- Is the partner a specialist in licence optimisation, or in identifying
licensing requirements for commercial purposes?
- Do they have technology that goes to the depth required to identify your
software accurately, or are they running scripts?
- Do they have the skills — and the appetite — to interpret data and rules in
your interest to the nth degree?
- Do they offer transparency and sovereignty over your own data? Can you see what
is happening?
The uncomfortable truth is that an effective licence position exercise for a
single publisher can produce materially different answers depending on who runs
it. Licensing rules and scenarios are open to interpretation. Accuracy varies
widely between inventory and SAM tools. Assumptions and false positives are
common, the underlying data used to calculate the position is often not available
for scrutiny, and the audit process itself can be a revenue exercise for the
publisher. So: who works for you, and who works for the publisher?
How software audit defence actually works
Here is the part organisations tend to miss. An independent audit defence can be
valuable even after the officially appointed auditor has produced their
report.
An audit is, at bottom, a request for evidence that you are using the software
appropriately. That is all the publisher wants. The complexity of software
licensing is what makes that evidence hard to identify, hard to control and hard
to report on accurately.
So the process does not have to be adversarial. But with a partner who has both
deep knowledge of the publisher’s rules and accurate ITAM and SAM technology
behind them, you have stronger means at your disposal than the publisher does to
establish your best-case position — and to prove it.
What goes wrong in an auditor’s report
Auditors’ reports contain errors, and the errors fall into recognisable
categories. These are the ones worth checking line by line before you accept a
finding:
Bad inventory data taken at face value. If the discovery underneath the audit
came from a tool that cannot see a platform properly — non-persistent VDI, a
partitioned Unix frame, a clustered SQL environment — the installation counts are
wrong before any licensing logic runs. Ask what collected the data and how.
Entitlement history that was not fully walked back. Upgrade rights,
downgrade rights and second-use entitlements bought years ago frequently do not
make it into an auditor’s view. It is entirely possible to be recorded as
non-compliant on a product you are actually over-licensed for.
Products counted that are not installed. A file signature that matches a
component of a larger product, or a leftover registry entry, can produce an
exposure for something nobody ever deployed. This is the single most common
category worth challenging, because the correction is total rather than partial.
Licensing rules applied without the environment. Core factors, cluster
awareness, virtualisation topology and access-control mechanisms for RDS, Citrix
and VDI all change the number materially. A generic reading of the rules against
a generic reading of the environment gives a generic — and usually unfavourable —
answer.
None of these require an argument with the publisher. They require better
evidence than the auditor had.
Certero audit defence at a glance
Technology-led services. The consultancy team runs on the same platform
Certero sells. CerteroX ITAM covers six operating system families with one native
agent — Windows, macOS, Linux, AIX, HP-UX and Solaris — plus mobile device
management for iOS and Android, virtual infrastructure, cloud and SaaS. Ten
discovery methods land in a single schema, so there is no reconciliation exercise
between sources before the licensing work can start.
Publisher depth where audits actually bite. CerteroX SAM carries dedicated
licence engines for Microsoft, Oracle, IBM, SAP, Adobe and Salesforce, with the
effective licence position computed continuously — purchased, used, available,
required, variance and exposure — rather than reconciled at a point in time.
Software recognition resolves against a database of more than 3.5 million titles.
Verified with Oracle. Certero is a verified third-party tool vendor with
Oracle License Management Services. Oracle’s audit team can accept data from
Certero during an official audit, as an alternative to installing Oracle’s own
measurement tools.
In-house SAM team. Dedicated specialists for Microsoft, Oracle, IBM and SAP.
Certero does not need to rely on partnerships for the licensing knowledge, so the
success of an engagement rests with one accountable organisation.
Independence. Certero has no commercial interest in selling you licences and
does not share your information with third parties. It is not part of the
business model.
Experts in your corner. Even a large publisher’s appointed auditor can get it
wrong, and it is never too late to bring in an independent view — particularly if
you are facing a significant exposure.
Longevity. Establishing an effective licence position is a substantial piece
of work, so it is worth not throwing away. Because the compliance and
optimisation reporting comes out of the platform, you have the option of keeping
it: continuing with the product, or moving to a SAM managed service, and turning
a one-off defence into sustained visibility and control.
The short answer
No, you do not have to accept an official audit report as final. It is a
submission based on the evidence the auditor had, produced by a party whose
interests are not yours. If you can produce better evidence, you can change the
outcome — and quite often the better evidence is already sitting in your own
environment, waiting for something accurate enough to collect it.
To find out more about Certero’s audit defence services, get in
touch.
Certero was named the sole Customers’ Choice in the 2024 Gartner® Peer Insights™
Voice of the Customer for Software Asset Management Tools — the only vendor in
the category to reach that position.
GARTNER is a registered trademark and service mark, and PEER INSIGHTS is a
trademark and service mark, of Gartner, Inc. and/or its affiliates in the U.S.
and internationally and are used herein with permission. All rights reserved.
Gartner Peer Insights content consists of the opinions of individual end users
based on their own experiences and should not be construed as statements of fact,
nor do they represent the views of Gartner or its affiliates.