Why SaaS is not the end of SAM
SaaS removes the under-licensing risk, not the discipline. The question stops being "am I compliant?" and becomes "am I using what I pay for, and does the leaver still have access?"
- SAM
- SaaS
- Governance
Audits rarely arrive at random. Ten patterns that reliably attract a vendor's attention — from a drop in support spend to a reseller who thinks there is a deal in it — and what to have in place before any of them apply to you.
Software audits have a habit of arriving at the worst possible moment. That is less coincidence than it looks. Vendors watch for patterns, and most audit requests follow something the customer did — or stopped doing — that the vendor noticed.
Knowing the triggers will not stop an audit. It will tell you when one is likely, which is enough time to get your licence position in order first. Here are the ones that come up most often.
Vendors want predictable, growing revenue. Anything that signals you are moving away is a flag:
None of these is improper. All of them attract attention. Before you make a significant reduction in software spend, establish your compliance position for that vendor. If an audit request follows, you already know the answer and the conversation is short.
M&A activity is chaotic, and licensing compliance across the legal entities involved is one of the first things to fall off the list. Vendors know this, and transitions are a well-worn moment to ask.
Compliance ought to be part of due diligence rather than a discovery made afterwards. That can be a tactical effective licence position exercise or work your own team does, if you have licensing specialists for the publishers that matter. What it cannot be is an assumption that entitlements travel cleanly with the entity — for most publishers, they do not.
It sounds obvious, but the first question that surfaces when contract negotiations open is: are you correctly licensed? Framed as an assessment review or a friendly look at where you are, it is a softer approach than a formal audit. It has the same consequence. Any information you hand over is information you are then liable for.
The way to control this is procedural: hold to your information security guidelines on sharing company confidential information, and route everything through one channel.
Being found under-licensed at the start of a negotiation destroys your position before you have opened it. Go in knowing your numbers, or plan to spend more.
For perpetual, on-premises licensing, renegotiations and major investments tend to run on three-year cycles. That is the rhythm at which the vendor expects to be paid. If you have not renewed or heard from your account manager for a while, that silence has a shelf life.
New infrastructure can move your licence requirement enormously and immediately. Standing up backup servers for disaster recovery is the classic example, as is any change to hosts inside a virtualised environment. For products licensed per processor core — with core factors applied — the attributes of the physical host can multiply your requirement the moment a workload moves onto it.
A publisher’s direct visibility of these changes is limited. Their account teams’ visibility is not: hardware purchases get discussed, and people in the industry talk.
The fix is to bring licensing into the change process. A mature SAM function advises on cost and risk at the planning stage, not after the cluster is built.
Growth is a good problem. It is also a licensing event. As headcount rises, new people are provisioned with technology, and that consumption usually needs additional licences behind it. Increase your numbers proactively or expect the question.
Using software without adequate licences is a reputational issue as well as a financial one, and it lands on employees too. Someone who has raised it internally and watched nothing happen may decide to raise it with the vendor or the reseller instead.
The defence is cultural rather than technical. Senior leaders have to treat SAM as a governance obligation, so that people who notice a problem have somewhere internal to take it.
Asking a vendor for a statement of your historic proof of entitlement has been known to generate exactly the interest you were trying to avoid. It is an uncomfortable irony, because gathering entitlement data is a necessary step towards control.
It also points at the answer. Keep an accurate, central entitlement record that the relevant people can actually reach, and you rarely need to ask the vendor for it. A SAM platform with a single repository for licences, transactions, agreements, maintenance and suppliers makes this a lookup rather than a project.
Sometimes it has nothing to do with you. Publishers get acquired by investors or merge with larger players. New owners want returns, and audit revenue is one of the faster levers available to them. Expect audit activity to rise for a period after a publisher changes hands.
The patterns above are enough to trigger one audit. Once one has happened, another becomes more likely — poor control is rarely confined to a single publisher, and vendor sales teams talk to a large channel of partners and resellers.
Be discreet while you are navigating an audit, and use the time to prepare for the next one rather than treating the closed audit as the end of the matter.
It is worth remembering who profits. Resellers transact licence purchases and earn on them. Their relationship with the publisher is their primary commercial relationship, not their relationship with you, and information moves between the two at several levels.
This post was originally written about perpetual, on-premises licensing. Two newer surfaces now generate as much exposure.
Subscription true-ups. SaaS publishers do not need to send an audit letter, because they can already see your tenant. Salesforce, Microsoft 365, Adobe and the rest reconcile at renewal, and the conversation opens with their numbers rather than yours. The counter is to arrive with a defensible view of who is assigned a licence and who has actually opened it. CerteroX SaaS Management pulls authoritative user and licence lists directly from 47 vendor connectors, reconciles them against identity-provider sync from Entra ID and Okta, and flags licences with 30 days or more of zero usage — so the seats you are about to renew are the seats somebody uses.
Bring-your-own-licence in the cloud. Moving a licensed workload to a cloud provider does not move the licensing problem with it; it usually makes it worse, because instances multiply, move between hosts and change size without anyone raising a change request. Publishers know this and ask about it. Reconciling cloud resource inventory against entitlement is the same discipline as the data centre, applied to a faster-moving target.
The best way to avoid the financial and reputational damage an audit can do is to already be in control of your licensing. That looks different depending on what you have in-house.
A unified view of hardware and software. If you have a capable SAM team already, what they usually lack is one trustworthy record. CerteroX ITAM and CerteroX SAM discover and reconcile devices and installed software across Windows, macOS, Linux, AIX, HP-UX and Solaris into a single schema, with publisher-grade licence engines for Microsoft, Oracle, IBM, SAP, Adobe and Salesforce computing an effective licence position continuously rather than the week the letter arrives.
Audit defence. If you are already in the process and need to limit exposure, audit management is a discrete engagement that can be run before, during or after an audit.
Licensing expertise on demand. Certero has subject matter experts across the major publishers who can supplement your team rather than replace it.
A managed service. If SAM is not something you want to staff, the SAM managed service runs it end to end, on the same platform. Reece Emson, ITAM Asset/PSL Manager at NHS South West London ICB, describes what that compresses: “Certero’s SAM managed service allowed us to significantly mature our license posture at a fast pace, something that would have taken 3-4 years without their involvement.”
Organisations that keep accurate licensing records and can demonstrate they know their position reduce their audit exposure and negotiate from a stronger place when an audit does land. The triggers above are largely outside your control. Being ready for them is not.
Talk to us about where your position is weakest.
Other posts covering the same ground.
SaaS removes the under-licensing risk, not the discipline. The question stops being "am I compliant?" and becomes "am I using what I pay for, and does the leaver still have access?"
Acquisition is the first step in software asset management, which makes it the one where mistakes compound. Buying outside the agreement, buying through the wrong reseller, and deploying the wrong version to the wrong device all start here.
Software is an asset with unusual properties — it can be acquired by anyone in seconds, it leaves no physical trace, and the paperwork proving you are entitled to it is easy to lose. Each of those is a distinct commercial risk.
Everything argued above is checkable. Name the publisher, the billing account or the platform you would argue with, and the session is built around it — the reasoning attached, not a summary slide.
No gated download at the end of it.