Software audits arrive without warning and rarely at a convenient moment. If you have avoided one so far, that is luck rather than strategy. The question worth answering in advance is what you do in the first week.
Don’t panic
You will almost always have time to plan your response. Audit clauses give the publisher the right to ask; they do not give them the right to an answer by Friday. The initial letter is the start of a negotiation about scope, method and timetable, and how you handle that opening exchange has more effect on the final number than anything you do later.
So the first response is not to start counting installs. It is to stand up a project.
Based on our experience helping organisations defend audits, a five-stage approach works.
1. Governance and control
Establish your team early and assign the roles explicitly: who owns the response, who owns the data, who owns the commercial relationship, who signs anything off.
If you are using a third party to help, appoint a single point of contact for them. Audit responses fail more often on coordination than on licensing. Agree the key tasks, the timescales, and how often and by what method you will review progress. Write it down.
The reason this comes first is simple. Everything in the stages below produces evidence, and evidence that arrives through four different people in three different formats is evidence you cannot defend.
2. Communication
Understand how, when and who will be communicating with the publisher.
Then handle the internal half, which is the part people forget. A message needs to go out across the organisation that a communication lock-down is in force between you and the publisher until further notice, and that any and all contact goes through the engagement team. A well-meaning administrator answering a direct question from an account manager can concede a scope point that costs more than the rest of the audit.
3. Asset discovery and inventory
To produce an inventory the publisher will accept, you need automated discovery. Manual declarations and one-off scripts do not survive scrutiny, because the auditor’s first question is how you know the list is complete.
This is where the shape of your tooling matters more than its feature list. CerteroX ITAM collects through ten discovery methods — a native agent across Windows, macOS, Linux, AIX, HP-UX and Solaris, agentless and command-line collection for locked-down machines, standalone inventory for air-gapped systems, network discovery, Active Directory import, third-party ITAM import and cloud connectors — all landing in one schema. There is no reconciliation project afterwards, because there is nothing to reconcile. Network discovery sweeps a class-C subnet in under five seconds, which is how you find the machines nobody told you about before the auditor does.
Raw inventory is then resolved against the Software Recognition Database, more than 3.5 million normalised publisher, product and version titles. That is the step that turns a list of executables into a list of licensable products, and it is the step that generic discovery tools skip.
Where gaps remain — and on a first audit there will be some — close them with supplementary collection and documented manual declarations, and be explicit in the submission about which is which.
On the publishers that bite hardest, the depth of the measurement is the defence:
- Oracle. Certero is a verified third-party tool vendor under Oracle License Management Services. Oracle’s audit team can accept data from Certero during an official audit, as an alternative to installing Oracle’s own measurement tools. Options and packs are captured with evidence and override, alongside processor types, core factors, licence pools with hosting rights, and cover-down logic for Enterprise Edition.
- IBM. PVU and Virtual Processor Core metrics, an ILMT connector with compliance gap analysis, and enforcement of the 30-minute inventory cycle that sub-capacity licensing actually requires.
- SAP. A non-invasive ABAP connector reads named users de-duplicated across systems, along with roles, engines and authorisation definitions, without touching production.
- Microsoft. Device and user CALs, named user and external connectors, and SQL Server and Windows Server core and processor licensing with cluster and virtualisation awareness.
4. Entitlement discovery
Entitlement work can begin at any stage, and it should begin immediately, because it is almost always the critical path.
This is the process of collecting every proof of entitlement for the publisher’s products. Do not underestimate it, particularly if your records are patchy. Purchases made through resellers who no longer exist, entitlement acquired with a company you bought, agreements held by a department rather than by IT — all of it has to be found.
Then comes contract interpretation: reviewing the terms and conditions to establish a baseline entitlement that is actually relevant to your organisation. Two customers with identical install counts can have entirely different exposure because one has downgrade rights and the other does not.
Hold the results in one place — licences, transactions, agreements, maintenance, suppliers and publishers, with Microsoft Licence Statement import where it applies, and an audit trail across all of it. In an audit, an install you cannot produce a purchase for is an install you did not buy, whatever actually happened.
5. Effective licence position
The final stage reconciles deployment and usage data against entitlement data to produce an Effective Licence Position: purchased, used, available, required, variance and exposure. This is the basis of the negotiation.
One thing has changed fundamentally since this advice was first written, and it changes the economics of the whole exercise. An ELP used to be a spreadsheet and a report — something you built under time pressure, circulated, and watched go stale. CerteroX SAM computes the position continuously rather than as a point-in-time reconciliation, with usage metered at file level and a percentage-used figure over a rolling ninety-day window.
That difference is not cosmetic. When the position is live, stages three, four and five are already done before the letter arrives. The audit stops being a discovery exercise about your own organisation and becomes what it should have been all along: a disagreement about interpretation, which you are equipped to have.
Be ready rather than responsive
The best defence is not a fast response. It is having nothing to find out.
If you know what you own, what is running, what you are entitled to and where the variance sits — and you know it on an ordinary Tuesday rather than only in audit season — then the letter is an administrative task rather than a crisis. The organisations that come out of audits badly are almost never the ones that were non-compliant by a wide margin. They are the ones that could not prove otherwise in time.
To see a continuous licence position rather than a reconstructed one, book a demo.