Most software asset management programmes do not fail on execution. They fail
before they start, because nobody ever built a case that senior management could
act on.
The obstacles are usually mundane. There are higher priorities. The opportunity
is not understood, because it has never been quantified. Somebody senior
believes the problem is already handled by procurement, or by the service desk,
or by whoever renews the Microsoft agreement.
The only way through is a business case that sets out the cost of doing the work
against the cost of not doing it. And in practice one criterion decides it:
what this does to the bottom line.
A better framework than GRC
There are several ways to structure the argument. The instinct is to reach for
governance, risk and compliance, because SAM sits naturally inside it and
because the language is familiar to an audit committee.
It is the wrong choice for this audience. GRC frames the whole programme as cost
avoidance, and cost avoidance always loses to a project with a revenue number
attached.
The ITAM Review’s framing is better: build the case around compliance,
efficiency and agility. All three matter to IT, and all three translate into
language a board already uses.
Compliance
This is the strongest leg, and the easiest to attach real numbers to.
Software vendor audits are frequent, disruptive and expensive, and the cost is
not only the settlement. It is the weeks of engineering and procurement time
spent assembling evidence under a deadline set by somebody else.
Frame it as a comparison: here is our current position, here is what an audit
would cost us today, and here is what these actions do to that exposure. If your
organisation has been audited before, you already have the number. If a peer in
your sector has, that will do.
The trap is claiming compliance is a one-off fix. It is not. A licence position
is only true on the day it is calculated, which is why the case should be for a
continuous position rather than a remediation project.
Efficiency
If an audit is not a live concern, the case has to be built here instead.
Visibility of what is installed, and of what is actually being used, lets you
identify software nobody has opened in months and stop paying for it. It also
gives you the evidence to assess your current architecture and propose cheaper
or better alternatives — which is a different and larger saving than harvesting
unused licences.
The scale of the opportunity is worth putting in front of a sceptical reader:
- The average organisation uses only 54% of the SaaS licences it pays for — 46%
go unused.
- 29% of cloud spend is wasted, a figure that rose in 2026 for the first time in
five years.
Neither figure is your figure. That is the point of the exercise: the case
should establish what the equivalent number is in your organisation, and the
first phase of the programme is often justified on nothing more than finding
out.
Agility
The last leg is the ability to cope with what comes next: a migration you have
been told to complete by a date, a security exposure that requires you to know
within hours which machines run an affected version, a new application to roll
out across an organisation you cannot currently describe.
Every one of those is faster and cheaper with an accurate inventory, and every
one of them is a scramble without one. Agility is the hardest leg to cost, but
it is the one that resonates most with executives who have recently lived
through one of those events.
Costing the benefit
The original difficulty with this framework was that the middle step — putting a
number on the expected benefit — was largely guesswork. The standard advice was
to involve stakeholders early, get them to help cost the savings, and devise
metrics you could measure the change against. Sound advice, and slow.
That step is now largely mechanical, because the platform computes the figures
the business case needs:
Licence exposure, as a number. CerteroX SAM produces an effective licence
position with purchased, used, available, required, variance and exposure held
separately, alongside overspend and additional-licences-required calculations.
That is the compliance leg of your case, computed rather than estimated.
Utilisation, with evidence behind it. AppsMonitor meters software use at
file level with first-used and last-used tracking, and a % Used metric over a
rolling 90-day window. Before you propose reclaiming a licence from somebody,
that is the evidence you need — and in the business case, it is the difference
between “we think some of this is unused” and a defensible count.
Realised saving, tracked after the fact. CerteroX SaaS Management records
realised savings, realised avoidance and ROI by fiscal quarter, along with an
Optimization Score across utilisation, response and adherence. That matters more
than it sounds: the hardest part of a SAM business case is not the first one,
it is the second one, and the second one is easy if you can show what the first
one actually delivered.
The same discipline applied to cloud. CerteroX Cloud Management runs
twenty-six named recommendation checks — abandoned instances, obsolete snapshot
chains, instances stopped but not deallocated, reserved instance purchase
opportunities — each individually tunable. Named checks produce itemised savings
rather than a single unattributable total, which is exactly what a finance
reviewer will ask you to break down.
If you want to sketch the numbers before you write anything, the
ROI calculator will get you to a defensible order of
magnitude.
Where cases fall over
Three things sink an otherwise good SAM business case.
Claiming a saving you cannot evidence. One challenged number costs you the
whole document. Use figures you can show the working for, and mark estimates as
estimates.
Presenting it as a tooling purchase. The case is for an outcome — a
continuous, defensible licence position and a lower software bill. The tool is a
line in the cost side, not the subject.
No measurement plan. If you cannot say how the benefit will be measured
after the fact, you are asking for trust rather than making a case. Decide the
metrics before you present, not after you are funded.
If you can’t measure it, you can’t manage it — and you certainly can’t fund it.
If you want a second pair of eyes on the case before it goes
to the board, get in touch.