In this instalment of the series we spoke to members of Certero’s in-house SAM
services team about something that gets overlooked when software vendor audits
are discussed: what they do to the individuals inside IT who have to answer them,
usually on top of an already demanding job.
Responsible businesses and IT leaders need to be alert to what sustained stress
of this kind does — both to a person’s wellbeing and to the stability of their
role in the team.
Certero’s consultancy team have been on both sides of it. They have been the
target of an official vendor audit, and they have been brought in as independent
auditors to take the pressure and uncertainty off a customer. As our UK and EMEA
Oracle and Salesforce licensing specialist puts it:
It’s no secret that “official” software audits are lengthy and can result in
unexpected financial penalties. Everyone has heard the horror stories of an
audit that ran for months because of a dispute about usage or an impasse about
a small clause in the vendor agreement, which resulted in substantial legal
fees. But what about the human face of audits?
The blame game
Within IT, after cyber security incidents and redundancy programmes, software
vendor audits are about as disruptive and painful as it gets. They have every
ingredient of a bad time: the timing is out of your control, you are legally
obliged to respond, they consume resource you had committed elsewhere and derail
your planned work, and they can land a financial impact the business was not
carrying in any forecast.
Our licensing consultant in APAC has watched this play out repeatedly:
To state the obvious, software audits are not fun. Often, companies “react” or
“fire-fight” when it comes to being audited as they’re not prepared and are
immediately on the back foot. Unfortunately, this also means that it’ll fall
into the lap of an unsuspecting team within the organisation or, even worse and
often seen, a sole individual to deal with. All of a sudden, they need to
become a licensing expert; learn how to get an inventory of everything the
business runs; learn who the relevant stakeholders are; navigate the minefield
of the vendor’s pitfalls and tactics; negotiate an almost certain bill for a
shortfall in licences upon completion — and all this while doing their day job.
All in, a company can expect three months for an audit to complete, and that is
a best-case scenario. Multiply that by the number of vendors whose software
you’re using and it becomes very stressful very quickly, with numerous people
out of action fighting fires.
Nobody wants to be the person who let a catastrophe happen. Someone has to be
accountable, but the real responsibility cannot sit in one individual’s hands.
For everyone involved it is a stressful and potentially damaging thing to be
handed.
Our Oracle specialist elaborates. Do any of these sound familiar?
- You have ultimate responsibility for the audit outcome. Your management team
will look to you for answers if anything goes wrong.
- You have a strong team of technical colleagues and you do trust them, but a lot
of the terms, detail and finesse is technobabble, so you have to take what they
tell you at face value — which means the small, nagging voice in your head will
not shut up about evidence.
- You do not sleep well, worrying about what exactly that audit might find and
what you could do about it.
- You do not have a licensing team. You have a few people who claim to know
enough, and it is a constant concern that “enough” may not be sufficient.
- You know that only a handful of people in your organisation hold all the
detail — the purchasing paperwork, the architectural diagrams — and if one or
more of them leaves, you are in serious trouble.
- You were not expecting that audit letter. In fact nobody in your team has ever
been through the process, so you are not sure what to expect or how to handle
it.
- You do not know where you will find the time to decipher and follow the audit
instructions. Your technical team is already at capacity and you are expecting
them to push back on everything you need from them.
- You came into an ITAM or SAM role with experience of licensing and audits for
common vendors like Microsoft, and the role has quietly expanded until you are
expected to be an expert in the data centre as well — Oracle, IBM, SAP.
These are a small selection of the comments and concerns Certero consultants have
heard from customers over the years. We know audits hurt financially. What is
less discussed is valued, senior employees taking extended leave, driven by the
anxiety and pressure of handling complex audit requirements on top of the job
they were actually hired to do.
It does not stop at audits, either. Maintaining, managing and controlling large
software portfolios adds to the same burden, and plenty of people are feeling the
pressure without an audit letter ever arriving.
The point is that although software and software audits are technology-driven,
there is a human element to the process, and it is usually the last thing
considered.
What actually reduces the load
Sympathy is not a control. If an audit is going to fall on one or two people, the
only thing that changes the outcome is how much of the work is already done
before the letter arrives.
Almost all of the distress described above traces back to the same root: the
organisation does not have a defensible position, so the position has to be
built under time pressure, by people who are learning as they go, against a
counterparty who does this professionally.
That is the part that is now a tooling problem rather than a heroism problem.
- A continuous position rather than a reconstruction. CerteroX SAM computes
the effective licence position continuously — purchased, used, available,
required, variance and exposure — rather than reconciling at a point in time.
The answer you would give an auditor today already exists.
- Publisher-specific engines where the findings actually come from. Generic
recognition tells you that you have four hundred installs of Oracle Database.
It does not tell you which options and packs are enabled, which cores are
licensable under which core factor, or which hosts are covered down by an
Enterprise Edition pool. Dedicated engines for Microsoft, Oracle, IBM, SAP,
Adobe and Salesforce close that gap, which is the gap the audit finding lives
in.
- IBM sub-capacity without the scramble. PVU and Virtual Processor Core
metrics, an ILMT connector with compliance gap analysis, Component Resolution
that matches deployed components to products with scored suggestions, and
enforcement of the thirty-minute inventory cycle that sub-capacity licensing
actually requires.
- SAP without touching production. A non-invasive ABAP connector reads named
users de-duplicated across systems, along with roles, engines and authorisation
definitions, and priority-ordered analysis rules propose the licence type each
user should hold. Current, suggested and optimal positions side by side — not a
project to produce.
- Evidence, held. An audit trail across agreements, transactions and
exclusions, so the answer to “how do you know?” is a record rather than a
recollection from someone who may have left.
- A recognised starting position with Oracle. Certero is a verified
third-party tool vendor with Oracle License Management Services. In Certero’s
published wording, that means Oracle’s audit team can accept data from Certero
during an official audit, as an alternative to installing Oracle License
Management measurement tools.
None of that makes an audit pleasant. It changes what it costs the people who
have to answer it, which is a different and more achievable goal.
Recognising breaking point, and a safe pair of hands
Certero understand this because we have been there, and we are still there every
day. What we bring is a tested way through the problem that gets the best result
available without spending your team to get it. As our Oracle specialist puts it:
We say that we think and do things differently, and yes — we created a way to
remove the technical and data headaches from the process. But we also have
real, live human beings, which means we’re fully equipped to support you
through the licensing challenges that inevitably come up.
As IT and licensing across hybrid environments becomes costlier and more
complex, we develop and maintain the expertise and capability to optimise your
investments so that you don’t have to.
Recognising where breaking point is for your team, and avoiding a catastrophe in
human as well as financial terms, is essential. It is also what secures the
longevity and effectiveness of the team you have spent years building.
So if you have audit questions or concerns you are struggling with, do not suffer
in silence. Talk to us — or, if you would rather start with the
mechanics, CerteroX SAM is where the position gets built.