A software licence optimisation programme costs money to run. So does not running one — usually more. The difference is that one cost is a budget line somebody has to defend, and the other arrives unannounced as a true-up, a settlement or a renewal you had no bargaining position in.
That asymmetry is the whole problem with getting a programme approved. Nobody is comparing the two numbers, because only one of them has ever been written down.
So the job of the business case is not really to sell a tool. It is to make the cost of doing nothing visible, and then show that the programme reduces it by more than it costs. Four questions get you most of the way there. Each one converts an invisible loss into a figure you can put in front of a budget holder.
1. Are you buying more licences than you actually need?
The answer is almost certainly yes, unless you already run a formal, continuous reclamation process. Not because anyone is careless, but because purchasing is a decision and reclamation is a chore, so one happens and the other does not.
What you need to establish is whether each product’s real usage matches what you assumed when you bought it. Deployed is not used. Assigned is not used. Used last quarter is not used.
What the number looks like. For on-premises software, this is the gap between installs and actual execution. For SaaS it is much larger: 46% of SaaS licences go unused, with the average organisation using 54% of what it pays for. In money, that is an average of $19.8M wasted each year on unused SaaS licences alone, against an average annual SaaS spend of $55.7M.
You do not need those figures to be true of you. You need them to justify finding out what is true of you, which is a much easier thing to get funded.
What answers it. AppsMonitor meters file-based usage with first-used and last-used tracking and a % Used figure over a rolling 90-day window, so a harvesting decision is evidenced rather than argued. On the SaaS side, unused licence detection fires at 30 or more days of zero usage, with reclaim, reassign, downgrade tier, archive, remind and dismiss available as actions rather than as a report somebody has to work through by hand.
2. What do vendor audits actually cost you?
Take the last one. Add up the settlement, the unbudgeted purchases made under time pressure, and the maintenance you then carried on those purchases.
Then add the part nobody puts on the invoice: the people. An audit response consumes senior technical time for weeks — the same people who were meant to be delivering something else. That opportunity cost is real, it is large, and it is almost never counted, which is precisely why the business case should count it.
Now ask the harder question. Could that cost have been avoided by fixing the under-licensing before the publisher found it? Buying a shortfall on your own timetable, in a negotiation you chose the timing of, is a fundamentally different transaction to buying it during an audit.
What answers it. A continuously computed Effective Licence Position — purchased, used, available, required, variance and exposure — rather than a point-in-time reconciliation performed when the letter arrives. Publisher-grade engines for Microsoft, Oracle, IBM, SAP, Adobe and Salesforce, so the position holds up on the products that actually generate findings. And for Oracle specifically, CerteroX is a verified third-party toolset: Oracle’s audit team can accept data from Certero during an official audit, as an alternative to installing Oracle’s own measurement tools.
One published example of what this is worth, from NHS South West London ICB, where £100k of Microsoft compliance risk was mitigated and the organisation’s SAM maturity was accelerated by three to four years:
Certero’s SAM managed service allowed us to significantly mature our license posture at a fast pace, something that would have taken 3-4 years without their involvement.
— Reece Emson, ITAM Asset/PSL Manager, NHS South West London ICB
3. Do you know the full extent of your software liabilities?
This question is about the metrics nobody is tracking, which are always the expensive ones.
Work through it in four parts:
- Identify the metrics that apply to you and that nobody currently measures. Processor and core counts, PVUs, named users, concurrent access, external connectors. If nobody owns a metric, nobody is measuring it, and it is almost certainly wrong.
- Understand what those metrics cost. A metric you are not tracking is not a small risk if it is priced per core.
- Test whether the relevant staff understand the rules. Virtualisation causes the majority of licensing surprises precisely because the people making infrastructure decisions are not the people who read the product terms. Adding a host to a cluster is a capacity decision to one team and a licensing event to another.
- Establish who carries the liability where operations are outsourced. Find out whether your managed service provider or you are responsible for compliance. The worst arrangement — and it is more common than it should be — is one where the provider can deploy software across your environment while you retain full liability for any resulting shortfall.
What answers it. Direct connection to the virtualisation layer — VMware, Hyper-V, Citrix XenServer, IBM HMC, Oracle VM, Red Hat oVirt and Nutanix — so host, cluster and guest relationships are inventoried rather than described. Oracle processor types and core factors, licence pools with hosting rights and geographic rules, and cover-down logic for Enterprise Edition. IBM PVU and Virtual Processor Core sub-capacity with an ILMT connector and enforcement of the 30-minute inventory cycle. Microsoft server core and processor licensing with cluster and virtualisation awareness. Access Control rules for RDS, Citrix and VDI. These are the places liability hides.
4. How much software do you buy reactively?
Add up what you purchase through one-off, transactional negotiations rather than under a framework. Every one of those is a purchase made without volume, without timing and usually without an alternative.
Then estimate what strategic sourcing would have saved — consolidated demand, framework agreements, renewal dates you control. The gap between the two is a recurring annual saving, which makes it the most persuasive line in the business case, because it does not stop after year one.
What answers it. Upcoming renewals with days-to-renewal and utilisation rate alongside each one, so you enter a negotiation knowing what proportion of what you are renewing is actually used. Application rationalisation ranked by recoverable saving, which finds the four tools doing one job before you renew all four. And a full agreement, transaction, maintenance and supplier record, so consolidation opportunities are visible rather than remembered.
The two cost centres this question originally missed
When this article was first written, a licence optimisation business case meant on-premises software. That is no longer where most of the recoverable money is.
SaaS. The average enterprise portfolio now runs 305 applications. Very little of it was procured centrally, which means very little of it appears in the systems your business case is currently built from. CerteroX SaaS Management discovers it through three converging signals — identity provider sync from Entra ID and Okta, connector sync pulling authoritative user and licence lists from the vendor across 47 connectors shipping today, and a browser extension detecting SaaS domains with per-user attribution — with a catalogue of 35,000+ applications behind the classification.
Cloud. 29% of cloud spend is wasted, and that figure went up for the first time in five years. CerteroX Cloud Management applies 26 named, individually tunable recommendation checks across twelve cloud and data platforms — abandoned instances and load balancers, obsolete snapshot chains, instances stopped but not deallocated, rightsizing, generation upgrades, reserved instance and savings plan opportunities. Certero’s average cloud cost saving across environments under management is 38%.
Both belong in the business case for the same reason the original four questions do: the spend is already happening, nobody currently owns the number, and the recovery is measurable.
Putting it together
A business case that works has three parts, in this order:
- The cost of doing nothing, built from the four questions above and stated as an annual figure with the audit exposure separated out from the recurring overspend.
- The recovery, evidenced rather than projected — usage data you can show, renewals you can name, and a compliance position you can hand to a publisher.
- The cost of the programme, which is the only one of the three anybody was ever going to scrutinise.
The reason the first is usually missing is not that it is unknowable. It is that gathering it needs discovery, inventory, metering and entitlement data in one place — and if that data existed, the programme would already be running.
That is the circularity to break in the pitch. You are not asking for budget to buy a tool. You are asking for the visibility that tells you what the tool is worth, and that visibility is worth having whichever way the decision goes.
To see where numbers like these come from — metered usage, entitlement records, a licence position that recomputes — book a demo.