First published in November 2017, revised in December 2019, and revised again on
migration.
Always expect an Oracle audit
Oracle licensing rules are notoriously complex, and through its License
Management Services division Oracle rigorously enforces compliance.
Like every software vendor, Oracle needs to protect its intellectual property.
Inside your Oracle Master Agreement you will find a specific clause covering its
right to audit, and that clause normally requires written notice — 45 days is the
standard forewarning that Oracle intends to audit you. Read your own agreement;
the notice period is one of the few terms in Oracle licensing that is actually
easy to check.
What is the difference between a licence review and an audit?
In practice there is very little difference between an Oracle Licence Review and
an Oracle audit. The distinction is mostly one of terminology, and of how the
engagement is described internally. The process is effectively the same.
Oracle’s Licence Management Review department will talk about a licence review
rather than an audit. That reflects the fact that initiating one requires
collaboration from the customer, and “review” sounds friendlier and less
intrusive than “audit”. But a licence review still includes an assessment and
analysis of your usage in order to verify compliance. An audit of usage is being
performed either way.
Do not let the vocabulary lower your guard. The output of a review carries the
same commercial consequences as the output of an audit.
What takes place during an Oracle audit?
The official start is the notification letter, which is often addressed to the
CIO and the CFO. The letter names the LMS consultant or partner conducting the
engagement, so the organisation knows exactly who it is dealing with. It also
identifies which legal entities are in scope, and which Oracle programs are being
examined.
The Oracle Master Agreement gives Oracle access to information, and traditionally
that has meant running Oracle’s own licence compliance scripts across your
systems to establish how the software is actually being used.
That is no longer the only route. Certero is a verified third-party tool vendor:
Oracle’s audit team can accept data from Certero during an official audit, as an
alternative to installing Oracle’s own measurement tools. If you already run
continuous measurement, you are not obliged to start from a standing start with
someone else’s scripts on your production systems.
If unauthorised or unlicensed software is found, that may constitute a breach of
contract, a violation of intellectual property rights, or both. Non-compliance
can lead to financial penalties and a requirement to purchase additional
licences to remedy the position — typically without the discount that applied to
the original purchase. That last detail is the one people underestimate. The
commercial damage is rarely the licence count. It is the loss of the discount on
the licences you now have to buy under time pressure.
Where the findings actually come from
A generic SAM tool will tell you that you have 400 installs of Oracle Database.
That is not the question Oracle is asking. The question is which options and
management packs are enabled, which processor types and core factors apply to the
hosts running them, whether virtualisation gives Oracle grounds to count the
whole cluster, and which hosts are covered down by an Enterprise Edition pool.
Every one of those is a place where an install count and a compliance position
diverge, and every one of them is where an audit finding lives. If your reporting
stops at “installed yes/no”, you do not have an Oracle position. You have an
inventory.
How to prepare
You will not necessarily be audited in any given year, and being audited
recently is no reason to relax. Nor should you feel relief at having escaped the
last round of activity — it is usually only a matter of time before that letter
arrives.
Preparation means being able to answer the questions above continuously, not in
the 45 days after the notification lands. In practice that means:
- Know what is installed, and what is switched on. Options and packs need
evidence, and the ability to override a detection where you can demonstrate the
feature was never used.
- Know your hardware properly. Processor types and core factors change the
answer. So does the virtualisation layer beneath.
- Hold the paperwork in one place. Ordering documents, licence agreements,
terms and conditions, amendments. The contract is what determines your rights,
and reconstructing it from an email archive under time pressure is how
organisations concede positions they did not need to concede.
- Understand your pools. Hosting rights, geographic restrictions and
cover-down logic for Enterprise Edition all change what a given deployment
costs you.
- Watch unlimited agreements. A ULA looks like safety until it is time to
certify.
CerteroX SAM models all of this in its Oracle licence engine: options and packs
with evidence and override, processor types and core factors, licence pools with
hosting rights and geographic rules, cover-down logic for Enterprise Edition,
uncapped quantity for unlimited agreements, and E-Business Suite
responsibilities. Discovery and usage monitoring run continuously across the
environment, and ordering documents, agreements and terms sit alongside the
measurement rather than in a separate archive.
The point is not that a tool makes an audit painless. The point is that the
position is computed before the letter arrives, so the 45 days is spent
reviewing an answer rather than assembling one.
Now is the time to get control of your Oracle licensing, before it is too late.
The same measurement that defends the audit also shows you where you are holding
entitlement nobody is using, which is the more useful half of the exercise for
most of the year.
Book a demo to see the Oracle licence engine work a populated
deployment, options, partitioning and all.