Skip to content

Building a Business Case for Software Asset Management

Compliance, efficiency and agility is a better frame for a SAM business case than governance and risk. The hard part is costing the benefit — which is now something the tooling can do for you.

Most software asset management programmes do not fail on execution. They fail before they start, because nobody ever built a case that senior management could act on.

The obstacles are usually mundane. There are higher priorities. The opportunity is not understood, because it has never been quantified. Somebody senior believes the problem is already handled by procurement, or by the service desk, or by whoever renews the Microsoft agreement.

The only way through is a business case that sets out the cost of doing the work against the cost of not doing it. And in practice one criterion decides it: what this does to the bottom line.

A better framework than GRC

There are several ways to structure the argument. The instinct is to reach for governance, risk and compliance, because SAM sits naturally inside it and because the language is familiar to an audit committee.

It is the wrong choice for this audience. GRC frames the whole programme as cost avoidance, and cost avoidance always loses to a project with a revenue number attached.

The ITAM Review’s framing is better: build the case around compliance, efficiency and agility. All three matter to IT, and all three translate into language a board already uses.

Compliance

This is the strongest leg, and the easiest to attach real numbers to.

Software vendor audits are frequent, disruptive and expensive, and the cost is not only the settlement. It is the weeks of engineering and procurement time spent assembling evidence under a deadline set by somebody else.

Frame it as a comparison: here is our current position, here is what an audit would cost us today, and here is what these actions do to that exposure. If your organisation has been audited before, you already have the number. If a peer in your sector has, that will do.

The trap is claiming compliance is a one-off fix. It is not. A licence position is only true on the day it is calculated, which is why the case should be for a continuous position rather than a remediation project.

Efficiency

If an audit is not a live concern, the case has to be built here instead.

Visibility of what is installed, and of what is actually being used, lets you identify software nobody has opened in months and stop paying for it. It also gives you the evidence to assess your current architecture and propose cheaper or better alternatives — which is a different and larger saving than harvesting unused licences.

The scale of the opportunity is worth putting in front of a sceptical reader:

  • The average organisation uses only 54% of the SaaS licences it pays for — 46% go unused.
  • 29% of cloud spend is wasted, a figure that rose in 2026 for the first time in five years.

Neither figure is your figure. That is the point of the exercise: the case should establish what the equivalent number is in your organisation, and the first phase of the programme is often justified on nothing more than finding out.

Agility

The last leg is the ability to cope with what comes next: a migration you have been told to complete by a date, a security exposure that requires you to know within hours which machines run an affected version, a new application to roll out across an organisation you cannot currently describe.

Every one of those is faster and cheaper with an accurate inventory, and every one of them is a scramble without one. Agility is the hardest leg to cost, but it is the one that resonates most with executives who have recently lived through one of those events.

Costing the benefit

The original difficulty with this framework was that the middle step — putting a number on the expected benefit — was largely guesswork. The standard advice was to involve stakeholders early, get them to help cost the savings, and devise metrics you could measure the change against. Sound advice, and slow.

That step is now largely mechanical, because the platform computes the figures the business case needs:

Licence exposure, as a number. CerteroX SAM produces an effective licence position with purchased, used, available, required, variance and exposure held separately, alongside overspend and additional-licences-required calculations. That is the compliance leg of your case, computed rather than estimated.

Utilisation, with evidence behind it. AppsMonitor meters software use at file level with first-used and last-used tracking, and a % Used metric over a rolling 90-day window. Before you propose reclaiming a licence from somebody, that is the evidence you need — and in the business case, it is the difference between “we think some of this is unused” and a defensible count.

Realised saving, tracked after the fact. CerteroX SaaS Management records realised savings, realised avoidance and ROI by fiscal quarter, along with an Optimization Score across utilisation, response and adherence. That matters more than it sounds: the hardest part of a SAM business case is not the first one, it is the second one, and the second one is easy if you can show what the first one actually delivered.

The same discipline applied to cloud. CerteroX Cloud Management runs twenty-six named recommendation checks — abandoned instances, obsolete snapshot chains, instances stopped but not deallocated, reserved instance purchase opportunities — each individually tunable. Named checks produce itemised savings rather than a single unattributable total, which is exactly what a finance reviewer will ask you to break down.

If you want to sketch the numbers before you write anything, the ROI calculator will get you to a defensible order of magnitude.

Where cases fall over

Three things sink an otherwise good SAM business case.

Claiming a saving you cannot evidence. One challenged number costs you the whole document. Use figures you can show the working for, and mark estimates as estimates.

Presenting it as a tooling purchase. The case is for an outcome — a continuous, defensible licence position and a lower software bill. The tool is a line in the cost side, not the subject.

No measurement plan. If you cannot say how the benefit will be measured after the fact, you are asking for trust rather than making a case. Decide the metrics before you present, not after you are funded.

If you can’t measure it, you can’t manage it — and you certainly can’t fund it.

If you want a second pair of eyes on the case before it goes to the board, get in touch.

Related reading

Other posts covering the same ground.

From reading to evidence

Put the hardest claim here
to a technical person.

Everything argued above is checkable. Name the publisher, the billing account or the platform you would argue with, and the session is built around it — the reasoning attached, not a summary slide.

No gated download at the end of it.