Skip to content

Broad and Vague Audit Clauses may be Unenforceable

An English High Court ruling on a licence audit clause set out how precisely audit rights have to be drafted to be relied on. The checklist it produced is worth running against your own publisher agreements before the next audit letter arrives.

Do you understand the audit clauses in your software agreements? Do you find them broad and vague? A 2014 English High Court judgment suggests that if you do, the publisher may have a weaker position than the wording implies.

The case was 118 Data Resource Ltd v IDS Data Services Ltd & others [2014] EWHC 3629 (Ch), analysed at the time by the UK law firm Penningtons Manches (now Penningtons Manches Cooper). It concerned an audit clause in a database licence agreement rather than a software licence, but the reasoning applies to any vendor audit clause: broad and vague audit clauses may very well be unenforceable in the way the licensor expects.

The licence gave 118 Data Resource the right to enter IDS’s premises “for the purpose of ascertaining that the provisions of this Agreement are being complied with”. That sounds sweeping. The court read it narrowly. It permitted the licensor to check that the database was being stored and used within the terms of the licence — and no further. It did not entitle the licensor to commercially sensitive material such as the identity of the licensee’s customers or the prices at which the data had been sub-licensed.

The judgment reiterated the requirement for licensors to set out audit terms clearly. Vague terms may not be enforceable to the extent the licensor assumes, and a licensor who wants a specific right needs to have written that specific right down.

What should your software audit clauses state?

According to the Penningtons Manches analysis, to be effective — to protect the vendor’s right to check that the licensee is not in breach, while protecting the licensee’s own rights — an audit clause needs to be drafted with sufficient particularity to the circumstances of the agreement in question.

In particular, the clause should state:

  • The purpose for which the audit may be carried out
  • What information may be inspected
  • What information may not be inspected. Access should not be allowed to commercially sensitive information or to legally privileged information
  • What consequences follow if a breach is discovered by the audit
  • Whether data should be delivered up if a breach is discovered
  • What use can be made of information obtained as a result of the audit
  • Who may carry out the audit — the other party, or an independent third party
  • Where the audit may be carried out
  • The frequency with which audits may be carried out
  • The timing of audits, so as to minimise disruption to the business
  • Who bears the cost of the audit

Why this is worth an afternoon of your time

All of which means it may be well worth dusting off your licence agreements and examining the audit clauses carefully to see how they have been phrased. Not every clause is drafted to that standard, and the only way to know where yours sits is to read it. Note which of the eleven points above your agreement actually addresses, and which it leaves open. The gaps are as informative as the text.

Two practical cautions. First, this is a question for your legal team, not your SAM team — the point here is that the contract is a live document worth reviewing, not that you should argue contract law with a publisher unaided. Second, a weak audit clause is a reason to be better informed, not a reason to be less prepared. A publisher who cannot rely on the clause it drafted has other routes to the same conversation, and a commercial relationship to lean on.

The better position is not needing to argue

Contract wording is one line of defence. Evidence is the other, and it is the one you control.

An audit is, at bottom, a request for proof that you are using the software in accordance with your entitlement. If you can produce that proof on demand, the scope of the audit clause matters far less, because there is nothing contentious for it to reach.

That is what CerteroX SAM is built to give you. Dedicated licence engines for Microsoft, Oracle, IBM, SAP, Adobe and Salesforce compute the effective licence position continuously — purchased, used, available, required, variance and exposure — rather than reconciling it in the fortnight after a letter arrives. Entitlement, transactions, agreements and maintenance are held in the same place as the deployment data, with an audit trail across agreements, transactions and exclusions. Software recognition resolves against the Software Recognition Database, which holds more than 3.5 million titles.

Certero is also a verified third-party tool vendor with Oracle License Management Services, which means Oracle’s audit team can accept data from Certero during an official audit as an alternative to installing Oracle’s own measurement tools.

So: check your licence agreements now, before the next audit letter lands on your desk. Then make sure that when it does, the answer is already sitting in front of you.

Looking for support ahead of your next software audit? Certero provides SAM services including vendor audit defence — get in touch.

Related reading

Other posts covering the same ground.

  • Oracle ULA – What are the dangers and how do you avoid them?

    An Oracle Unlimited Licence Agreement is only unlimited within its clauses. What certification actually asks of you, where toxic consumption creeps in, and why the measurement work has to start at the beginning of the term rather than the last six months.

    • SAM
    • Governance
    6 min
  • Microsoft Licensing Update – August 2025

    Microsoft's August 2025 Product Terms changes: Extended Term standardised across programmes, Exchange and Skype for Business Server Subscription Editions, the Exchange and Windows 10 ESU programmes, and the Dynamics 365 F&O enforcement dates.

    • SAM
    • Governance
    4 min
  • Oracle ULA: know your options. Exit with confidence.

    Renew, rescope or exit — an Oracle ULA gives you three routes and a narrow window to choose between them. The questions to settle first, and a six-point health check to see how ready you actually are.

    • SAM
    • Governance
    6 min
From reading to evidence

Put the hardest claim here
to a technical person.

Everything argued above is checkable. Name the publisher, the billing account or the platform you would argue with, and the session is built around it — the reasoning attached, not a summary slide.

No gated download at the end of it.