Skip to content

Why, as a CFO, is software asset management important?

Software is now one of the largest and least controlled lines in the budget. Software asset management is the discipline that makes it forecastable — and it reduces risk at the same time.

How does software asset management benefit a CFO?

In many organisations the IT function ultimately reports to the CFO. That does not mean the CFO is expected to know the detail of what IT does. Making sure expenditure lands on budget, and that IT is broadly supporting the business strategy, is usually where the involvement ends.

That is understandable. With a hundred more pressing things on the desk, the technical minutiae of IT are not a priority and will glaze the eyes over before they cure the insomnia.

One area is worth the time anyway: software asset management. No technical understanding is required, because what it produces is financial — cost savings and reduced risk, both of which are squarely the CFO’s responsibility.

A line of spend that grew up

Traditionally the people responsible for SAM were tucked away in a back room counting licences, and were regarded by some as a brake on the business. That reading is out of date. The organisations that have adopted SAM properly treat it as a financial control, and it behaves like one.

Software asset management is, at heart, a process for making software acquisition and disposal decisions: identifying and eliminating unused or infrequently used software, consolidating licences, and moving to licensing models that fit how the organisation actually works.

It manages an item of expenditure that has grown in both size and importance, whether your future lies in the cloud or not. In the past, the bulk of IT spend went on hardware — tangible metal, plastic and glass you could see on a desk. Software was incidental, a fraction of the cost. Now even the smallest organisation is dependent on technology, and the software line has grown accordingly.

Where the money actually goes now

The original version of this post argued that the spend had migrated into the datacentre, and that the big-ticket software — the ERP system the business runs on, the large database platforms holding customer data — was where the savings were.

That was true when it was written. It is no longer the whole picture, and if you are a CFO reading this now, the shape of the problem has moved.

Three things have changed:

Software buys itself. A SaaS application does not need a procurement cycle, a server or an install. The average enterprise portfolio now runs to 305 SaaS applications. Very little of that arrived through a single controlled route.

A large share of it is not used. Some 46% of SaaS licences go unused — the average organisation uses 54% of what it pays for — and the average organisation wastes $19.8M a year on unused SaaS licences alone, against an average annual SaaS spend of $55.7M per organisation. That is not a licensing subtlety. It is a budget line with a hole in it.

Cloud sits alongside it, with the same problem. 29% of cloud spend is wasted, and that figure rose for the first time in five years.

The datacentre licensing exposure has not gone away — Oracle, IBM and SAP still generate the largest single audit findings, and they are still the hardest to compute. But it is now one of three places the money leaks, and a CFO who only watches the on-premises licence position is watching a shrinking share of the total.

Across cloud environments under management, Certero’s own figure for the average saving achieved is 38%.

The perils of a software audit

Cost savings are not the only financial benefit. Unbudgeted costs are the bane of any business, and organisations that do not practise SAM are particularly exposed to them.

The publisher’s main instrument here is the software audit. It is written into the licence agreement; there is no opting out of it. Audits are disruptive and expensive to defend. For an organisation with no SAM programme, the usual end result is a true-up bill for software it turns out to be using without entitlement, and sometimes a penalty on top.

Two costs, not one. There is the settlement, which is unbudgeted by definition. And there is the opportunity cost of your people spending weeks assembling evidence instead of doing their jobs.

Some organisations treat this as business as usual and provision for it. That is a decision, but it is an odd one: it is the only line in the budget where the answer to “why is this here?” is “because we do not know what we own.”

Prevention is cheaper than cure. Plan for the audit — or have a provider plan it with you — so that your licensing is in good order before the letter arrives rather than after. That is the difference between negotiating from a position you can evidence and negotiating from one you cannot.

It is also achievable. NHS South West London ICB mitigated £100,000 of Microsoft compliance risk and accelerated three to four years of SAM maturity, with Reece Emson, its ITAM Asset/PSL Manager, describing the work this way:

Certero’s SAM managed service allowed us to significantly mature our license posture at a fast pace, something that would have taken 3-4 years without their involvement.

Reducing security risk

The other area that reaches the CFO’s desk is risk.

Your systems and the information in them are of standing interest to criminals. Security is therefore paramount, and with the diverse, geographically spread technology most organisations now run, keeping it airtight is not easy. Anything that materially helps is worth having.

The useful part is that a good SAM programme produces the security information as a by-product. A detailed, current inventory of every piece of software in use lets your security people identify and deal with what is unsupported, out of date, unauthorised — a frequent source of malware — redundant or simply legacy.

CerteroX SAM tracks end-of-life and end-of-support dates against recognised titles, so “unsupported” is a report rather than an investigation. Governance policies enforce rules as code, and application blacklisting stops prohibited software rather than merely noting it. On the SaaS side, OAuth grants consented to by employees are discovered and risk-scored on data sensitivity, scope, how consent was given and how long the grant has been dormant — the exposure that most often outlives the person who created it.

Two reasons, not one

Software asset management saves money and reduces risk. For a CFO those are not adjacent benefits; they are the two things the role is measured on.

The question worth asking is not whether the organisation does SAM. It is whether anyone can tell you, today and without a project, what the organisation owns, what it is using, and what it would owe if a publisher asked tomorrow.

If the answer takes more than a fortnight to assemble, that is the finding.

Related reading

Other posts covering the same ground.

From reading to evidence

Put the hardest claim here
to a technical person.

Everything argued above is checkable. Name the publisher, the billing account or the platform you would argue with, and the session is built around it — the reasoning attached, not a summary slide.

No gated download at the end of it.