LICENSEWARE

Software license audit

This article is about contractual verification of software license use by a licensor. For internal reconciliation, see Effective license position. It is not legal advice; the executed agreement governs any audit.

On This Page

A software license audit is a verification, carried out by or on behalf of a software licensor, of whether a customer’s deployment and use of licensed software is within the rights the customer has acquired. The right to audit is contractual: it comes from an audit or verification clause in the license agreement, which typically sets the notice period, the customer’s duty to cooperate and keep records, confidentiality of the results, and what the customer must do if unlicensed use is found. Vendors use different names for the process, including audit, license review, verification and system measurement.

An audit compares the licensor’s reading of the customer’s entitlements with deployment and usage data, which amounts to an effective license position computed by the licensor. Findings are settled commercially, usually by the purchase of additional licenses, and less often litigated.

History

Audit clauses are a long-standing feature of enterprise software agreements, and public documentation of how they operate has grown with vendor publication of standard agreements online. Public-sector reviews have tied audit exposure to weak license management. In 2014 the U.S. Government Accountability Office found that only 2 of 24 major federal agencies had comprehensive software license management policies and that agencies lacked inventories to show the extent to which licenses were over- or under-purchased.[12] Court judgments on disputed findings are rare; one widely reported example is SAP UK Ltd v Diageo Great Britain Ltd (2017), discussed below.[9]

Scope and definitions

The audit clause

The following table summarizes the audit or verification terms in standard agreements published by five vendors. Each is a specific published version; executed agreements may differ.

Vendor and document Notice Customer duties Outcome if non-compliant 
Oracle Master Agreement, Schedule P (v062223)[1] 45 days written notice Cooperate, give reasonable assistance and access to information, including running Oracle data measurement tools and providing the output Remedy within 30 days of written notification, which may include paying for additional licenses; otherwise Oracle may end support, licenses or the agreement. Customer bears its own costs of cooperating 
Microsoft Customer Agreement, General Terms (US sample, March 2023)[2] 30 days Keep records; provide information, documents and visual access to systems running the products. Microsoft may use an independent auditor under nondisclosure, at Microsoft’s expense Order licenses for the period of unlicensed use within 30 days. If unlicensed use is 5% or more of total use, reimburse verification costs and buy licenses at 125% of the then-current price, or the legal maximum if lower 
IBM Client Relationship Agreement, section 7.1 (08-2023)[3] Reasonable notice; annual deployment report on 30 days’ request Create, retain and provide deployment data; allow verification by IBM and independent auditors at all sites and environments Order and pay at current rates for excess deployments, plus subscription and support for the excess for the lesser of its duration or two years, plus related charges 
SAP Software Use Rights, section 4 (v.4-2026)[4] In general once a year, under SAP standard procedures Customer may run the measurement itself with unaltered SAP tools and self-declaration forms and transmit results to SAP Not stated in that section 
Adobe VIP Terms, section 5.2[5] No more than once a year, on 30 days written notice Keep deployment records for two years after termination; provide an unedited report and purchase documentation within 30 days Buy the necessary licenses within 30 days; on-site audit possible after 10 business days’ notice if concerns remain 

Who audits

  • Vendor license teams. Oracle’s Global Licensing Advisory Services (GLAS) describes itself as offering guidance on aligning use of Oracle software with business goals, and publishes the tools it uses to collect deployment information.[8][6]
  • Independent auditors. Microsoft’s and IBM’s published terms allow the verification to be performed by independent auditors bound by confidentiality.[2][3]
  • The customer. Several agreements provide for self-measurement or self-reporting: SAP’s self-declaration and measurement tools, IBM’s annual deployment report, and the Microsoft Enterprise Agreement’s annual true-up, which Microsoft describes as including an annual self-assessment of licenses and services in use.[4][3][10]

Practice

Audit procedures are set by each contract, but most follow the same stages.

  1. Notice. The licensor sends written notice under the audit clause. The notice period runs from this date: 30 days under the Microsoft and Adobe terms above, 45 under the Oracle terms.[2][5][1] The customer usually confirms scope (entities, products, period), contacts and confidentiality at this point.
  2. Data collection. The customer provides entitlement records and deployment data. Collection may use vendor scripts or tools, or tools the vendor has verified. Oracle lists the Oracle Collection Tool, a set of programs run in the customer’s estate to collect product usage information, and the Global Deployment Matrix, an online form for cataloging programs in use. It also names third-party SAM tools that GLAS has verified for particular Oracle products, and notes that the verification covers only the tool’s usage data for those products.[6] SAP requires unaltered SAP measurement tools.[4]
  3. Analysis. The auditor maps deployments to entitlements under the vendor’s metric definitions, floors and use rights.
  4. Findings. The auditor issues a report of apparent shortfalls. Under the Oracle and Microsoft terms, reports and non-public data from the audit are confidential.[1][2] The customer reviews the findings, corrects factual errors and raises contractual points such as use rights that were not applied.
  5. Settlement. The customer remedies within the contractual period, usually by ordering licenses and, where the terms say so, back support or subscription. The IBM terms, for example, add subscription and support for excess deployments for up to two years.[3]

Self-assessment and alternatives

Organizations run internal reviews to know their position before a licensor asks. ISO/IEC 19770-1 states that it can be used by internal and external parties to assess an organization’s ability to meet its own IT asset management requirements.[11] Some vendors also offer programs that sit alongside the audit process. Oracle’s Verified SAM (VSAM) program, delivered by verified partners, lists eligibility for a one-year audit reprieve among its customer benefits, subject to Oracle’s approval.[7]

Standards and frameworks

The ISO/IEC 19770 family does not regulate vendor audits, but it standardizes the records that both sides rely on: an IT asset management system (Part 1), software identification tags (Part 2), entitlement records (Part 3) and resource utilization measurement (Part 4). See ISO/IEC 19770 and Effective license position.[11]

Disputes and case law

Where the parties disagree about what the license covers, the dispute turns on the wording of the agreement. In SAP UK Ltd v Diageo Great Britain Ltd (2017), SAP claimed additional license and maintenance fees because two Salesforce-based systems interacted with mySAP ERP. The High Court held that only Named Users were authorized to use or access the ERP software directly or indirectly under that agreement, that the users of the two systems were not authorized, and that SAP was entitled to additional fees to be assessed by reference to usage and SAP’s price list.[9] The judgment is specific to that agreement and its definitions.

Relationship to other disciplines

Audits are the external test of license compliance. Preparation depends on software asset management practices: an up-to-date effective license position, complete entitlement records and reliable deployment data. In agreements with periodic self-reporting, such as true-up orders, much of the same work is done on a regular cycle rather than on audit notice.

Criticism and challenges

Audits consume customer time and data-collection effort; under the Oracle terms quoted above the customer bears its own costs of cooperating.[1] Findings depend on how metrics and policies are interpreted, and some vendor policy documents that shape findings are stated to be educational rather than contractual. GAO’s work suggests that gaps in the customer’s own inventory make it harder to check an auditor’s figures.[12]

Out of scope

This article does not cover financial statement audits, security audits, or open source license enforcement by copyright holders, which is discussed under License compliance. It does not give negotiation advice.

References

  1. Oracle Master Agreement (online, Switzerland), v062223Schedule P section 8 Audit; Schedule H section 8 AuditRetrieved 2026-09-26.
  2. Microsoft Customer Agreement Sample (United States), March 2023General Terms, Verifying compliance; linked from the Microsoft Customer Agreement samples pageRetrieved 2026-09-26.
  3. IBM Client Relationship Agreement (Z126-6548_WOS_11_US_08-2023)Section 7.1 Licensing VerificationRetrieved 2026-09-26.
  4. SAP Software Use Rights (enGLOBAL.v.4-2026)Section 4 VerificationRetrieved 2026-09-26.
  5. Adobe Value Incentive Plan Terms and ConditionsSection 5.2 auditRetrieved 2026-09-26.
  6. GLAS Tooling (Oracle Global Licensing Advisory Services)Oracle Collection Tool; Global Deployment Matrix; verified third-party tool vendorsRetrieved 2026-09-26.
  7. GLAS VSAM Program (Oracle)Verified SAM partners; audit reprieve subject to Oracle approvalRetrieved 2026-09-26.
  8. Global Licensing Advisory Services (Oracle)Retrieved 2026-09-26.
  9. SAP UK Ltd v Diageo Great Britain Ltd [2017] EWHC 189 (TCC)High Court of England and Wales (TCC), judgment of 16 February 2017Effective 2017-02-16. Retrieved 2026-09-26.
  10. Enterprise Agreement Program Guide (Microsoft)Updated March 2025; annual self-assessmentRetrieved 2026-09-26.
  11. ISO/IEC 19770-1:2017 Information technology — IT asset management — Part 1: IT asset management systems — RequirementsEdition 3, 2017-12; confirmed 2024Retrieved 2026-09-26.
  12. GAO-14-413 Federal Software Licenses: Better Management Needed to Achieve Significant Savings Government-WideU.S. Government Accountability Office, 22 May 2014Effective 2014-05-22. Retrieved 2026-09-26.

See also

Esc