With cloud-enabled subscription models dominating the software landscape, you could be forgiven for assuming that vendor audits are a thing of the past. They are not. And it is worth asking whether it is wise for a CIO to take their eye off software asset management on the strength of that assumption.
In January, the 2025 Survey on Software Audits — based on responses from more than 300 database administrators, IT leaders and executives — reported the opposite of the trend most people expect.
- Frequency is up. 62% of respondents reported being audited by a major software vendor within the past year, against 40% in 2023.
- The bill is up. The share of organisations incurring financial penalties above $1m has tripled, from 10% in 2023 to 32%.
- Nobody was ready. Organisations with more than 5,000 employees saw the sharpest rise — 66% recently audited, against 50% in 2023 — and were still taken by surprise.
So audits are still happening, and on disruption alone they cannot be ignored. Hybrid environments are making the process harder rather than easier, because the evidence a publisher asks for now spans on-premises hosts, virtual infrastructure and cloud accounts that different teams own.
The publishers most inclined to audit, and why
There are long-term strategies being played out here, and several of them produce sharp increases in recurring spend alongside genuinely difficult audit positions.
Microsoft. Microsoft 365, Intune and Autopilot may look as though they have taken care of desktop administration — at a higher total cost of ownership than the traditional Office model, but with less to argue about. The exposure moved to the server room. SQL Server licensing turns on cores, cluster topology and virtualisation rights, and the calculation is contestable often enough that you want to be able to check it independently rather than accept the first number you are shown.
IBM. Failing to deploy and configure ILMT correctly removes your sub-capacity licensing rights immediately, and it removes them retrospectively. The requirement includes an inventory cycle of no more than 30 minutes, which is an operational commitment rather than a one-off installation.
Oracle. Notoriously complex, and now with Java creating audit exposure in organisations that never ran an Oracle database. The risk moved out of the data centre without anyone deciding it should.
VMware. Since the Broadcom acquisition and the forced move to subscription, audit activity has increased.
ServiceNow. Another move towards subscription licensing, and another vendor with a growing focus on customer audits.
The pattern is consistent. Where a vendor changes a licensing model, audit activity follows the change — because the change is what creates the gap between what you bought and what you are entitled to run.
Pick your fires
Let us put the whole thing in perspective. Software audits are a risk. Cloud waste is a certainty.
29% of cloud spend is wasted, and that figure went up for the first time in five years. That is not a probability weighted by whether a letter arrives. It is happening now, every month, in almost every organisation running public cloud at scale.
You can understand, then, why many IT leaders shifted focus and investment towards managing IaaS, PaaS and SaaS ahead of traditional on-premises IT asset management. The maths appeared to favour it.
What followed was less defensible. There has been a tendency to roll ITAM, and software asset management in particular, into adjacent systems — a service desk platform, or a mobile device management tool such as Intune — rather than run a dedicated capability. That strategy is increasingly being exposed as hopeful. It treats software licensing as a records problem when it is a calculation problem, and the calculation is where the audit finding lives.
Be careful about the discovery assumption in particular. Device management requires devices to be enrolled, which means you already have to know they exist. Asset discovery is the opposite proposition: it tells you what is out there. Those are different capabilities and only one of them survives contact with an acquisition, a remote workforce or a Unix platform nobody documented.
The need to see and manage the full scope of hardware and software is not going away, and it is not getting simpler.
Neglecting on-premises ITAM also has direct consequences for cloud management. Automated discovery of unknown SaaS applications depends on device-level visibility — you find shadow IT partly by watching what browsers on managed machines actually connect to. Maintain network discovery of devices and you retain a route to intelligence about SaaS and AI usage. Lose it and you lose both.
ITAM, SAM and FinOps in the Cloud+ era
Cloud+, in a financial operations context, means managing technology spend across a wider scope than public cloud alone: IaaS and PaaS, SaaS, and the on-premises infrastructure that is not going anywhere.
It stands to reason that the financial maturity, stakeholder accountability and continuous optimisation that FinOps brought to cloud spend should be applied back to ITAM and SAM. The disciplines were solving the same problem from opposite ends. FinOps knows what you are renting. ITAM knows what you already own — and therefore what the rental is quietly duplicating.
2025 saw the scope of FinOps widen and ITAM actively aligned into FinOps practice. That direction has held.
What has changed since this piece was first published is that the tooling caught up. The argument used to end with a prediction that the market would take time to adapt. It did adapt.
CerteroX runs ITAM, SAM, SaaS Management, Cloud Management and AI Management on one platform and one data model. CerteroX Cloud Management is a FinOps Certified Platform, and Certero is a FinOps Certified Service Provider — both recorded with the FinOps Foundation. Practically, the combined scope means:
- On-premises and cloud in one cost model. Cost Explorer across owner, pool, service, region, account and day, with native support for FOCUS, the FinOps open cost and usage specification, so the model stays portable rather than locked in a vendor schema.
- Publisher-grade licence engines for Microsoft, Oracle, IBM, SAP, Adobe and Salesforce, computing an effective licence position continuously rather than in the week the audit letter arrives. Oracle’s audit team can accept Certero measurement data during an official audit as an alternative to installing Oracle’s own tools.
- 26 named optimisation checks on the cloud side, every one individually tunable with its own thresholds, pool exclusions and account skips — abandoned instances, obsolete snapshot chains, instances stopped but not deallocated, reserved instance and savings plan opportunities.
- SaaS discovery from three converging signals, including a browser extension, so the applications nobody procured appear on the same register as the ones that were.
Unifying software policy, security, cost allocation and optimisation across every vendor and every environment is not an aspiration any more. Dissolving the barriers between ITAM, SAM and FinOps brings maturity and clarity to both sides, and easier management is where the cost savings actually come from.