Skip to content

Oracle Audit – A Beginner's Guide to Licensing Audits

What an Oracle licence review actually is, how the audit process runs from the notification letter onwards, and what to have in place before it arrives.

First published in November 2017, revised in December 2019, and revised again on migration.

Always expect an Oracle audit

Oracle licensing rules are notoriously complex, and through its License Management Services division Oracle rigorously enforces compliance.

Like every software vendor, Oracle needs to protect its intellectual property. Inside your Oracle Master Agreement you will find a specific clause covering its right to audit, and that clause normally requires written notice — 45 days is the standard forewarning that Oracle intends to audit you. Read your own agreement; the notice period is one of the few terms in Oracle licensing that is actually easy to check.

What is the difference between a licence review and an audit?

In practice there is very little difference between an Oracle Licence Review and an Oracle audit. The distinction is mostly one of terminology, and of how the engagement is described internally. The process is effectively the same.

Oracle’s Licence Management Review department will talk about a licence review rather than an audit. That reflects the fact that initiating one requires collaboration from the customer, and “review” sounds friendlier and less intrusive than “audit”. But a licence review still includes an assessment and analysis of your usage in order to verify compliance. An audit of usage is being performed either way.

Do not let the vocabulary lower your guard. The output of a review carries the same commercial consequences as the output of an audit.

What takes place during an Oracle audit?

The official start is the notification letter, which is often addressed to the CIO and the CFO. The letter names the LMS consultant or partner conducting the engagement, so the organisation knows exactly who it is dealing with. It also identifies which legal entities are in scope, and which Oracle programs are being examined.

The Oracle Master Agreement gives Oracle access to information, and traditionally that has meant running Oracle’s own licence compliance scripts across your systems to establish how the software is actually being used.

That is no longer the only route. Certero is a verified third-party tool vendor: Oracle’s audit team can accept data from Certero during an official audit, as an alternative to installing Oracle’s own measurement tools. If you already run continuous measurement, you are not obliged to start from a standing start with someone else’s scripts on your production systems.

If unauthorised or unlicensed software is found, that may constitute a breach of contract, a violation of intellectual property rights, or both. Non-compliance can lead to financial penalties and a requirement to purchase additional licences to remedy the position — typically without the discount that applied to the original purchase. That last detail is the one people underestimate. The commercial damage is rarely the licence count. It is the loss of the discount on the licences you now have to buy under time pressure.

Where the findings actually come from

A generic SAM tool will tell you that you have 400 installs of Oracle Database. That is not the question Oracle is asking. The question is which options and management packs are enabled, which processor types and core factors apply to the hosts running them, whether virtualisation gives Oracle grounds to count the whole cluster, and which hosts are covered down by an Enterprise Edition pool.

Every one of those is a place where an install count and a compliance position diverge, and every one of them is where an audit finding lives. If your reporting stops at “installed yes/no”, you do not have an Oracle position. You have an inventory.

How to prepare

You will not necessarily be audited in any given year, and being audited recently is no reason to relax. Nor should you feel relief at having escaped the last round of activity — it is usually only a matter of time before that letter arrives.

Preparation means being able to answer the questions above continuously, not in the 45 days after the notification lands. In practice that means:

  • Know what is installed, and what is switched on. Options and packs need evidence, and the ability to override a detection where you can demonstrate the feature was never used.
  • Know your hardware properly. Processor types and core factors change the answer. So does the virtualisation layer beneath.
  • Hold the paperwork in one place. Ordering documents, licence agreements, terms and conditions, amendments. The contract is what determines your rights, and reconstructing it from an email archive under time pressure is how organisations concede positions they did not need to concede.
  • Understand your pools. Hosting rights, geographic restrictions and cover-down logic for Enterprise Edition all change what a given deployment costs you.
  • Watch unlimited agreements. A ULA looks like safety until it is time to certify.

CerteroX SAM models all of this in its Oracle licence engine: options and packs with evidence and override, processor types and core factors, licence pools with hosting rights and geographic rules, cover-down logic for Enterprise Edition, uncapped quantity for unlimited agreements, and E-Business Suite responsibilities. Discovery and usage monitoring run continuously across the environment, and ordering documents, agreements and terms sit alongside the measurement rather than in a separate archive.

The point is not that a tool makes an audit painless. The point is that the position is computed before the letter arrives, so the 45 days is spent reviewing an answer rather than assembling one.

Now is the time to get control of your Oracle licensing, before it is too late. The same measurement that defends the audit also shows you where you are holding entitlement nobody is using, which is the more useful half of the exercise for most of the year.

Book a demo to see the Oracle licence engine work a populated deployment, options, partitioning and all.

Related reading

Other posts covering the same ground.

  • Device-based licensing and access control

    Locking an application down at user level does not make you compliant with a per-device licence. In a Citrix or RDS environment, one user with access can cost you a licence for every device in the organisation.

    • ITAM
    • SAM
    • Governance
    4 min
  • Gartner Myth Buster – Part 1

    A third-party summary of a vendor can be wrong, and it stays wrong for as long as people read it. The case for checking a vendor's facts at source — and the current, sourced record for Certero.

    • ITAM
    • SAM
    • Governance
    7 min
  • The role of good data in software audits

    An audit is won or lost on the quality of your inventory long before the letter arrives. Six ways data goes wrong, and what it takes to have the answer already in hand.

    • ITAM
    • SAM
    • Governance
    8 min
From reading to evidence

Put the hardest claim here
to a technical person.

Everything argued above is checkable. Name the publisher, the billing account or the platform you would argue with, and the session is built around it — the reasoning attached, not a summary slide.

No gated download at the end of it.