Do you understand the audit clauses in your software agreements? Do you find them
broad and vague? A 2014 English High Court judgment suggests that if you do, the
publisher may have a weaker position than the wording implies.
The case was 118 Data Resource Ltd v IDS Data Services Ltd & others [2014] EWHC
3629 (Ch), analysed at the time by the UK law firm Penningtons Manches (now
Penningtons Manches Cooper). It concerned an audit clause in a database licence
agreement rather than a software licence, but the reasoning applies to any
vendor audit clause: broad and vague audit clauses may very well be
unenforceable in the way the licensor expects.
The licence gave 118 Data Resource the right to enter IDS’s premises “for the
purpose of ascertaining that the provisions of this Agreement are being complied
with”. That sounds sweeping. The court read it narrowly. It permitted the
licensor to check that the database was being stored and used within the terms
of the licence — and no further. It did not entitle the licensor to commercially
sensitive material such as the identity of the licensee’s customers or the
prices at which the data had been sub-licensed.
The judgment reiterated the requirement for licensors to set out audit terms
clearly. Vague terms may not be enforceable to the extent the licensor assumes,
and a licensor who wants a specific right needs to have written that specific
right down.
What should your software audit clauses state?
According to the Penningtons Manches analysis, to be effective — to protect the
vendor’s right to check that the licensee is not in breach, while protecting the
licensee’s own rights — an audit clause needs to be drafted with sufficient
particularity to the circumstances of the agreement in question.
In particular, the clause should state:
- The purpose for which the audit may be carried out
- What information may be inspected
- What information may not be inspected. Access should not be allowed to
commercially sensitive information or to legally privileged information
- What consequences follow if a breach is discovered by the audit
- Whether data should be delivered up if a breach is discovered
- What use can be made of information obtained as a result of the audit
- Who may carry out the audit — the other party, or an independent third party
- Where the audit may be carried out
- The frequency with which audits may be carried out
- The timing of audits, so as to minimise disruption to the business
- Who bears the cost of the audit
Why this is worth an afternoon of your time
All of which means it may be well worth dusting off your licence agreements and
examining the audit clauses carefully to see how they have been phrased. Not
every clause is drafted to that standard, and the only way to know where yours
sits is to read it. Note which of the eleven points above your agreement
actually addresses, and which it leaves open. The gaps are as informative as the
text.
Two practical cautions. First, this is a question for your legal team, not your
SAM team — the point here is that the contract is a live document worth
reviewing, not that you should argue contract law with a publisher unaided.
Second, a weak audit clause is a reason to be better informed, not a reason to
be less prepared. A publisher who cannot rely on the clause it drafted has other
routes to the same conversation, and a commercial relationship to lean on.
The better position is not needing to argue
Contract wording is one line of defence. Evidence is the other, and it is the one
you control.
An audit is, at bottom, a request for proof that you are using the software in
accordance with your entitlement. If you can produce that proof on demand, the
scope of the audit clause matters far less, because there is nothing contentious
for it to reach.
That is what CerteroX SAM is built to give you. Dedicated licence engines for
Microsoft, Oracle, IBM, SAP, Adobe and Salesforce compute the effective licence
position continuously — purchased, used, available, required, variance and
exposure — rather than reconciling it in the fortnight after a letter arrives.
Entitlement, transactions, agreements and maintenance are held in the same place
as the deployment data, with an audit trail across agreements, transactions and
exclusions. Software recognition resolves against the Software Recognition
Database, which holds more than 3.5 million titles.
Certero is also a verified third-party tool vendor with Oracle License Management
Services, which means Oracle’s audit team can accept data from Certero during an
official audit as an alternative to installing Oracle’s own measurement tools.
So: check your licence agreements now, before the next audit letter lands on your
desk. Then make sure that when it does, the answer is already sitting in front of
you.
Looking for support ahead of your next software audit? Certero provides SAM
services including vendor audit defence — get in touch.