Software audits have not gone away, and vendors under revenue pressure tend to run more of them. Microsoft, Oracle, SAP and IBM remain the most likely auditors.
The work that decides how an audit goes happens long before the letter arrives, and most of it is data work. This piece looks at what “good data” actually means: discovery and inventory that miss nothing, and asset data enriched enough to automate the parts of licence reconciliation that otherwise consume a SAM manager’s year.
Start with the ways data goes wrong.
Risk 1: Data silos
If you still need more than one tool to see hardware and software across the organisation, you do not have a single source of truth — you have several sources and an argument.
Collating them by hand is slow, error-prone and out of date by the time anyone reads the result. That makes licence reconciliation flawed before it begins, because the data manipulation is happening in a spreadsheet rather than inside a licensing engine that understands entitlement.
Risk 2: Inaccurate discovery and inventory
If you cannot measure it, you cannot manage it. If you do not have a current picture of hardware and software, you cannot know what you have installed or what needs licensing.
Gaps usually come from one of five places.
Legacy tools doing a job they were not built for. Hardware inventory and service desk tools were designed to capture configuration items, not the depth of software detail SAM needs. Microsoft SCCM is a capable deployment platform; it was never a licensing engine.
Tools that cannot actively discover. Some SAM products only report on what they have already been told exists. That leaves blind spots wherever the environment changes, and you do not know what you do not know. Bear in mind that in an audit the vendor understands the limits of your tooling and will use thorough discovery of their own.
Policy decisions. Plenty of organisations will not permit inventory agents on servers — which is precisely where the most expensive and most audit-sensitive software lives. Agentless collection has to be an option, and the strongest coverage combines both.
Remote devices. Corporately owned machines that rarely touch the corporate network still need to be seen, secured and inventoried, wherever they are.
Split ownership. Traditional IT structures put different teams in charge of Microsoft, Oracle, IBM and SAP. The technical problems are genuinely different; the governance problem — controlling spend and strategy with a major publisher — is the same in every case, and it should sit under one SAM function. Desktop and data centre can now be managed in one place, and separating them mostly serves the vendor.
CerteroX ITAM is built around that last point. Ten discovery methods land in a single schema: native agent, command-line inventory for locked-down hosts, agentless, standalone inventory for air-gapped systems, network discovery, Active Directory import, third-party ITAM import, cloud and SaaS connectors, browser monitoring and file metering. The same native agent covers Windows, macOS, Linux, IBM AIX, HP-UX and Oracle Solaris — the Unix platforms are not an integration project, they are just another operating system. Network Discovery sweeps a class-C subnet in under five seconds using NetBIOS, SNMP and ICMP.
There is no reconciliation project between those methods, because there is nothing to reconcile.
Risk 3: No control over software downloads
Most volume licensing agreements now let anyone download a publisher’s entire catalogue. It takes very little time to lose track of what is installed where.
Worse, some software installs with options or management packs enabled that nobody asked for. Oracle is the standard example. Use them — deliberately or by accident — and they are chargeable. The audit is usually where that becomes apparent, and the true-up invoice follows shortly after.
CerteroX SAM handles Oracle options and packs explicitly, with the evidence for each detection and an override where you can demonstrate it was not in use, alongside processor types and core factors, licence pools with hosting rights and geographic rules, and cover-down logic for Enterprise Edition. That level of detail is what an Oracle engagement actually turns on. A tool that tells you there are 400 installs of Oracle Database has not told you anything an auditor cares about.
Risk 4: Active Directory alone is not the answer
Many SAM tools take a feed from Active Directory and treat it as the definitive list of devices to deploy an agent to.
Active Directory is not comprehensive. It will not show you Linux and Unix hosts, DMZ machines, Macs, or anything sitting in a workgroup or another domain. Whatever it misses never gets an agent, so the software on those machines is never inventoried, so it never appears in your licence position — right up until an auditor finds it.
Keeping AD current is also a permanent job in any organisation with regular joiners and leavers. Across many thousands of objects spread regionally or globally, the odds of it being both complete and accurate at any given moment are not good.
An incomplete device list produces an incomplete software inventory. The fix is not to abandon AD — it is a useful source — but to cross-reference it against independent discovery of the network rather than trusting it on its own.
Risk 5: SaaS and cloud
You pay for these as you go, so there is no real risk of being found under-licensed. The risk of overspending, though, is substantial, and controlling it now sits squarely inside SAM governance.
Treat visibility of SaaS and cloud consumption as being as fundamental as device inventory. It needs to be in the same place as everything else, with the analysis available whenever it is needed to right-size spend.
Both ship as part of the platform. CerteroX SaaS Management discovers applications through a browser extension, identity provider sync and 47 vendor connectors, detects licences unused for 30 days or more, and closes the offboarding gap with a per-user checklist showing revocation status for every seat. CerteroX Cloud Management applies twenty-six named, individually tunable optimization checks across twelve cloud and data platforms, with tag compliance, resource TTL and expense anomaly detection to stop the waste returning next month.
Risk 6: The vendor has to accept your evidence
The general rule in an audit is that you must produce evidence supporting your stated licence position, and there are no pre-approved outputs. The data centre has some exceptions.
Oracle is the notable one. Oracle is thorough, and it normally deploys its own LMS (License Management Services) or GLAS (Global Licensing and Advisory Services) scripts to find traces of Oracle software. The output goes directly to Oracle, who come back with their interpretation of it.
CerteroX SAM is verified by Oracle License Management Services. In Certero’s words: “Being a verified 3rd party toolset means that Oracle’s audit team can accept data from Certero for Oracle during an official audit, as an alternative to installing Oracle License Management measurement tools.”
Read that carefully, because the distinction matters. It does not mean Oracle waives the audit. It means Oracle’s audit team can accept your data instead of requiring their scripts to be run — which avoids the disruption of a separate script deployment and, more importantly, puts the findings in your hands first.
That changes the negotiating position. Your SAM team, or a licensing consultant working with you, sees the data before the vendor’s interpretation of it arrives, and can question anything that does not match the contract. The combination of detailed measurement and someone who knows how the agreement reads is worth a great deal in that conversation.
Overcoming the challenges
So how do you get an accurate and current inventory of everything?
The answer is layered: use sources like Active Directory, cross-reference them against independent scans of the network, and use multiple inventory methods and connectors to reach the places a single method cannot. It has to update automatically as things change, because a point-in-time picture is wrong by the following week.
That sounds complex because it is, and historically most of a SAM manager’s time went on unpicking it.
The practical first step is to be honest about legacy tooling and whether it is still fit for purpose. Bending an old ITAM product into a SAM shape is far more work than moving to a single platform that does both, and the quality, integrity and availability of the underlying data improve at the same time.
A single platform removes the disparate-source problem by construction. One data source, one interface, one version of the truth.
Once the data is consolidated, it can be enriched automatically — and this is where the time actually comes back. Software recognition resolves discovered files against a normalised library of publishers, products and versions: the Software Recognition Database holds more than 3.5 million titles, with release date, end-of-support and extended-support dates attached, plus SWID tags and UNSPSC classification.
That removes the human error in deciding what a discovered binary is, whether it needs licensing, and under which metric. Reconciliation then becomes dynamic: licensing rules run continuously against your entitlement, rather than being reconstructed by hand each quarter.
The result is a live view of compliance and exposure in financial terms, updating as things change. It is a long way from a static point-in-time report assembled with a spreadsheet and a lot of coffee.
The value of that central record goes well beyond audit defence — it improves everything IT has to measure and report on. But in an audit specifically, it means the information is already there. When the vendor calls, you already know where you stand and what needs fixing.
Which is the whole point. The best time to prepare for an audit is well before anyone tells you there is going to be one.