Audits rarely go wrong for exciting reasons. They go wrong because a question gets asked that nobody can answer with evidence, and the burden of proof sits with you.
Two of those questions come up almost every time.
Proving licence entitlement
Knowing which licences you own and what you are entitled to use sounds simple. In a complex organisation where procurement was never centralised, it is anything but.
Evidence of a purchase might be an email in somebody’s inbox. It might be an electronic record held on a reseller’s website. It might be a paper certificate in a drawer. Internal records are usually patchy, and usually missing the things that matter: part number, description, quantity purchased, agreement information, maintenance start and end dates.
In our experience you should reconcile from several sources rather than trusting one. The reliable ones are:
- vendor consumption reports
- reseller sales order history reports
- internal procurement data
Once you know what you own, that has to be turned into what you are entitled to use. Upgrades and cross-grades have to be applied. Product release dates and maintenance coverage have to be understood, because entitlement to a version is a function of when it shipped and whether you were in support at the time. Only then do you have a single source of entitlement.
Many organisations have no central entitlement repository at all, or a fragmented one. Combine that with no Definitive Media Library, and you cannot prove your right to use software when it is challenged. The auditor is not obliged to assume good faith, and an unprovable licence is, for their purposes, an unowned one.
The good news is that this is an internal problem with an internal fix. Collecting and collating entitlement into one repository, backed by a DML so you can also prove which media you deployed, tells you where your shortfalls are before someone else finds them.
Doing it in a tool rather than a spreadsheet is what makes it hold. CerteroX SAM stores licences, transactions, agreements, maintenance, suppliers and publishers in one place, with purchase order and invoice capture attached to the financial record. Volume licence, retail, OEM and FPP transactions are all first-class. Microsoft Licence Statement import brings the publisher’s own view of your position in directly. Downgrade rights and second-use entitlement are handled by the engine rather than reasoned about by hand, which is the step organisations most often get wrong. Assignment types cover per device, per processor and per core, and subscription entitlements carry expiry flags so a lapse shows up as a date rather than a surprise.
Every change to an agreement, a transaction or an exclusion is recorded. That audit trail is frequently what turns a disputed finding into a closed one.
Where Oracle is involved there is a further point worth knowing. Certero is verified by Oracle License Management Services: Oracle’s audit team can accept data from Certero during an official audit, as an alternative to installing Oracle’s own measurement tools. That is a meaningful difference to how an Oracle engagement runs.
The cloud and software asset management
Plenty of vendors will sell you a cloud migration partly on the basis that it reduces management overhead and removes the threat of non-compliance. There is truth in it — a user cannot access software they have not been assigned a licence for. It does not remove the problem of managing licences.
Here is why. To make certain employees are never blocked from software they need to do their job, organisations over-license. That makes you popular with the publisher. It is not a good use of a budget.
And it does not net off. If an audit finds that you over-licensed one title while under-licensing another, no accommodation is made for the overspend. You will still be presented with the full bill for the under-licensed title. You pay twice: once for the seats nobody opened, and again for the ones you were short of.
So you need visibility of both directions at once. CerteroX SaaS Management detects unused licences at thirty days of zero usage, tracks cost per licensed user against cost per active user, and ranks application overlap by recoverable saving — with 47 SaaS connectors pulling authoritative user and licence lists from the vendors themselves rather than inferring them. CerteroX Cloud Management does the equivalent for infrastructure spend across twelve cloud and data platforms.
One final thing about the cloud: not all of your software is in it. There is on-premises software still to identify, manage and license correctly, and there always will be. So the platform has to cover both, with all licensing information managed in one place and reported accurately publisher by publisher.
That is the case for one data model rather than three tools. CerteroX resolves software recognition against a Software Recognition Database of more than 3.5 million titles, and the SaaS catalogue behind application discovery carries more than 35,000 applications. On-premises installs, SaaS subscriptions and cloud-hosted workloads land in the same schema, so the Effective Licence Position — purchased, used, available, required, variance and exposure — is computed continuously rather than assembled the week the audit letter arrives.
Which is the whole point. An audit defence is not a project you start when you are notified. It is a position you are already holding.
Name the publisher you would least like to hear from and book a demo — the session gets built around that one.