1. What is a software vendor audit?
A software vendor audit is how publishers such as Microsoft, Oracle, IBM, Adobe and SAP protect themselves against software being used beyond what was paid for — deliberately or otherwise. Periodically they ask a customer to demonstrate that they are adequately licensed for everything they have deployed.
You agreed to this when you installed the software. The right to audit sits in the licence terms, and it is legally binding.
2. What types of audit are there?
There is more than one dynamic at play. An audit can be internal — a best-practice SAM exercise you run on yourself — or external. External ones are either a formal procedure instigated by the publisher, or they emerge from a conversation with a vendor or reseller, dressed as a “SAM review” or a discussion about what you might need to buy.
Internal audits. Reasons to run one on yourself:
- Verify your licence compliance and identify risk before someone else does
- Track and report on software and its actual usage
- Quality-assure what is deployed — a health check on the software in use
- Find cost-reducing optimisation opportunities
- Meet industry, corporate or legal requirements
External audits. A formal audit usually arrives as a letter in the post. If the approach comes by email or telephone, it is more likely a software review — variously called a SAM engagement, self-audit or software compliance review.
The distinction matters. A review is voluntary. An audit is a contractual obligation. Declining a review, however, can and does lead to a formal audit.
The golden rule: any time you submit information to a vendor, or agree to the scrutiny of a formal audit, you are disclosing confidential information that can lead to unplanned expenditure — if you are not fully in control of your licensing.
So ask cui bono — who benefits?
Formal vendor audits are funded by the vendor, who will bring in a partner at their own expense. Nobody spends that money without confidence in the return.
Resellers exist to sell you volume licences. Paying a reseller to audit you and then buying what they recommend is a conflict of interest with a friendly face on it, and it is worth being clear-eyed about how confidentiality works in that arrangement.
The alternative is to work out your licensing position independently — in-house, or with a SAM partner who has no commercial interest in selling you anything except their expertise.
3. Why are software audits a risk?
Because software licensing is genuinely complex, and complexity at scale produces errors.
Remember that you do not own software. You buy the right to use it under agreed terms. Publishers therefore reserve the right to check that everything deployed is paid for — and at the same time it is remarkably easy to make expensive mistakes in both directions, over-deploying what you are licensed for while over-buying things nobody opens.
The waste side of that is measurable. 46% of SaaS licences go unused — the average organisation uses 54% of what it holds. That figure is specific to SaaS rather than to all software, and it is worth quoting precisely rather than generalising it into a claim about every licence you own.
Unbudgeted expenditure is only part of the cost. An audit is also long, disruptive and stressful, and it consumes the time of exactly the people you need for other work.
Make no mistake about the legal position. Deploying software generally means entering an agreement with the vendor, as set out in the end user licence agreement. That agreement gives them the right to audit, and where you are found to be under-licensed, it typically requires you to put it right within a fixed number of days.
If you disagree with the findings, the burden is on you to evidence the challenge. In extreme cases that ends in court, which is expensive, public and rarely a good outcome for anyone’s reputation.
4. What is an independent software audit?
To protect the business from the cost and disruption of a vendor audit, you have two options.
Run the SAM programme in-house — with the people, processes and technology to stay in control of licensing.
Augment or outsource to an independent SAM partner who performs the internal audit for you, tells you exactly where the risk is, and optimises the licensing to reduce cost.
Either way you are informed and in control, and you can prove it to a vendor if asked. Often that is enough to avoid the audit in the first place, because auditors are drawn to organisations that look unprepared.
There is a security dividend too. SAM identifies all your software, which means when a vulnerability is published you can see immediately whether you run the affected version and where. Knowing precisely what is deployed, and where company data sits, is a security control as much as a licensing one.
The audit process is really about establishing an Effective Licence Position — an evidenced, agreed statement of how correctly you are licensed at a point in time. An independent partner can produce that as an emergency audit defence engagement, as a tactical ELP and optimisation exercise, or sustain it through an ongoing SAM managed service.
5. Which vendors are most likely to audit?
The ones you spend the most with, and whose licensing metrics are hardest to get right. Those two things travel together.
Oracle is the obvious example: options and packs enabled by default, processor core factors, cover-down rights for Enterprise Edition, and hosting and geographic rules in the licence pool. IBM sub-capacity requires an inventory cycle of no more than 30 minutes before you are entitled to sub-capacity rates at all. SAP licensing turns on named user classification across systems and roles, and on engine measurement. Microsoft server licensing turns on cores, clusters and virtualisation, not on desktops. Adobe and Salesforce are subscription models where the exposure is on the seat count.
Those six — Microsoft, Oracle, IBM, SAP, Adobe and Salesforce — are the publishers CerteroX SAM ships dedicated licence engines for, for exactly this reason. A generic tool tells you that you have 400 installations of Oracle Database. It does not tell you which options are enabled, which cores are licensable under which core factor, or which hosts are covered by an existing pool. That gap is where the audit finding lives.
6. What triggers an audit?
Vendors know your spending cycles and roughly what your consumption should look like. Triggers are more predictable than they feel:
Renewals and routine events. These usually attract the soft-touch “let us see what you are using” approach, but any event where you disclose information carries risk. The more complex the agreement, the higher that risk.
Change. Mergers, acquisitions and divestitures change the scope of the agreement and the shape of the organisation. Complexity increases, control weakens, and auditors notice.
The three-year cycle. After an audit you spend to get compliant. The question is what you do next. If you treat it as finished rather than investing in control, you have roughly three years to drift back out of position — which is about how long it takes for the same letter to arrive again.
Hard times. When a vendor’s sales teams are short of their numbers, audit activity generates revenue. Approaching their year end, that pressure is real and it is not within your control.
Leaving. Reducing your spend with a publisher gets noticed, and vendors and resellers talk to each other. If you are migrating away, be certain of your licensing position first — otherwise you can end up with a bill you can only mitigate by buying more of the thing you were trying to leave.
Whistleblowers. Unlicensed use can be reported to bodies such as BSA | The Software Alliance or the Federation Against Software Theft. A disgruntled employee is a real risk vector; managing licensing properly is the only durable answer.
Casual disclosure. Vendors are always listening. A conversation between your engineers and vendor support about an upcoming project, or a questionnaire filled in by a database administrator who unknowingly declares an exposure, is enough. Once the declaration exists, disputing it means an audit.
Downloads. Where a publisher lets you download software freely from their site, they generally know who downloaded what. Pulling down something you are not entitled to run is a visible signal of non-compliance.
7. What is software audit defence?
Audit defence is what it sounds like: an emergency engagement, run by an independent SAM partner, starting the moment the letter arrives.
A good one earns its keep several times over. Your partner should help control the scope and scale of the audit, establish a commercially favourable Effective Licence Position by limiting under-licensing exposure, and make use of value already sitting unused in your existing agreements.
They also handle the communications. At that point this is contract law, and having experienced consultants managing the correspondence removes a great deal of the stress and most of the guesswork — from timescales and scope through to what you should actually buy, from someone with no interest in selling it to you.
Underneath the engagement, the work is evidential. What you need is the entitlement record in one place, the deployment record reconciled against it, exclusions handled properly — MSDN, development, training and second-use devices taken out of scope with a documented reason — and an audit trail across agreements, transactions and exclusions that shows how the position was reached. CerteroX SAM computes that position continuously rather than reconstructing it under time pressure, which is the difference between producing evidence and producing a story.
8. Can you challenge an audit?
Yes — and it is possible to challenge the results even after a formal audit has completed. The mechanism is evidence. If you can demonstrate that the sponsored report is inaccurate, in a way that stands up, the finding changes.
That requires two things: measurement data you can defend, and someone who knows the publisher’s licensing rules well enough to argue them. Neither is available at short notice if you have not been measuring.
It is also why the work does not have to be done in-house. NHS South West London ICB used Certero’s SAM managed service to mitigate £100,000 of Microsoft compliance risk. Their ITAM Asset/PSL Manager, Reece Emson, describes the effect: “Certero’s SAM managed service allowed us to significantly mature our license posture at a fast pace, something that would have taken 3-4 years without their involvement.”
The pattern is consistent. Organisations that can evidence their position negotiate. Organisations that cannot, pay.