A software license audit is a verification, carried out by or on behalf of a software licensor, of whether a customer’s deployment and use of licensed software is within the rights the customer has acquired. The right to audit is contractual: it comes from an audit or verification clause in the license agreement, which typically sets the notice period, the customer’s duty to cooperate and keep records, confidentiality of the results, and what the customer must do if unlicensed use is found. Vendors use different names for the process, including audit, license review, verification and system measurement.
An audit compares the licensor’s reading of the customer’s entitlements with deployment and usage data, which amounts to an effective license position computed by the licensor. Findings are settled commercially, usually by the purchase of additional licenses, and less often litigated.
History
Audit clauses are a long-standing feature of enterprise software agreements, and public documentation of how they operate has grown with vendor publication of standard agreements online. Public-sector reviews have tied audit exposure to weak license management. In 2014 the U.S. Government Accountability Office found that only 2 of 24 major federal agencies had comprehensive software license management policies and that agencies lacked inventories to show the extent to which licenses were over- or under-purchased.[12] Court judgments on disputed findings are rare; one widely reported example is SAP UK Ltd v Diageo Great Britain Ltd (2017), discussed below.[9]
Scope and definitions
The audit clause
The following table summarizes the audit or verification terms in standard agreements published by five vendors. Each is a specific published version; executed agreements may differ.
| Vendor and document | Notice | Customer duties | Outcome if non-compliant |
|---|---|---|---|
| Oracle Master Agreement, Schedule P (v062223)[1] | 45 days written notice | Cooperate, give reasonable assistance and access to information, including running Oracle data measurement tools and providing the output | Remedy within 30 days of written notification, which may include paying for additional licenses; otherwise Oracle may end support, licenses or the agreement. Customer bears its own costs of cooperating |
| Microsoft Customer Agreement, General Terms (US sample, March 2023)[2] | 30 days | Keep records; provide information, documents and visual access to systems running the products. Microsoft may use an independent auditor under nondisclosure, at Microsoft’s expense | Order licenses for the period of unlicensed use within 30 days. If unlicensed use is 5% or more of total use, reimburse verification costs and buy licenses at 125% of the then-current price, or the legal maximum if lower |
| IBM Client Relationship Agreement, section 7.1 (08-2023)[3] | Reasonable notice; annual deployment report on 30 days’ request | Create, retain and provide deployment data; allow verification by IBM and independent auditors at all sites and environments | Order and pay at current rates for excess deployments, plus subscription and support for the excess for the lesser of its duration or two years, plus related charges |
| SAP Software Use Rights, section 4 (v.4-2026)[4] | In general once a year, under SAP standard procedures | Customer may run the measurement itself with unaltered SAP tools and self-declaration forms and transmit results to SAP | Not stated in that section |
| Adobe VIP Terms, section 5.2[5] | No more than once a year, on 30 days written notice | Keep deployment records for two years after termination; provide an unedited report and purchase documentation within 30 days | Buy the necessary licenses within 30 days; on-site audit possible after 10 business days’ notice if concerns remain |
Who audits
- Vendor license teams. Oracle’s Global Licensing Advisory Services (GLAS) describes itself as offering guidance on aligning use of Oracle software with business goals, and publishes the tools it uses to collect deployment information.[8][6]
- Independent auditors. Microsoft’s and IBM’s published terms allow the verification to be performed by independent auditors bound by confidentiality.[2][3]
- The customer. Several agreements provide for self-measurement or self-reporting: SAP’s self-declaration and measurement tools, IBM’s annual deployment report, and the Microsoft Enterprise Agreement’s annual true-up, which Microsoft describes as including an annual self-assessment of licenses and services in use.[4][3][10]
Practice
Audit procedures are set by each contract, but most follow the same stages.
- Notice. The licensor sends written notice under the audit clause. The notice period runs from this date: 30 days under the Microsoft and Adobe terms above, 45 under the Oracle terms.[2][5][1] The customer usually confirms scope (entities, products, period), contacts and confidentiality at this point.
- Data collection. The customer provides entitlement records and deployment data. Collection may use vendor scripts or tools, or tools the vendor has verified. Oracle lists the Oracle Collection Tool, a set of programs run in the customer’s estate to collect product usage information, and the Global Deployment Matrix, an online form for cataloging programs in use. It also names third-party SAM tools that GLAS has verified for particular Oracle products, and notes that the verification covers only the tool’s usage data for those products.[6] SAP requires unaltered SAP measurement tools.[4]
- Analysis. The auditor maps deployments to entitlements under the vendor’s metric definitions, floors and use rights.
- Findings. The auditor issues a report of apparent shortfalls. Under the Oracle and Microsoft terms, reports and non-public data from the audit are confidential.[1][2] The customer reviews the findings, corrects factual errors and raises contractual points such as use rights that were not applied.
- Settlement. The customer remedies within the contractual period, usually by ordering licenses and, where the terms say so, back support or subscription. The IBM terms, for example, add subscription and support for excess deployments for up to two years.[3]
Self-assessment and alternatives
Organizations run internal reviews to know their position before a licensor asks. ISO/IEC 19770-1 states that it can be used by internal and external parties to assess an organization’s ability to meet its own IT asset management requirements.[11] Some vendors also offer programs that sit alongside the audit process. Oracle’s Verified SAM (VSAM) program, delivered by verified partners, lists eligibility for a one-year audit reprieve among its customer benefits, subject to Oracle’s approval.[7]
Standards and frameworks
The ISO/IEC 19770 family does not regulate vendor audits, but it standardizes the records that both sides rely on: an IT asset management system (Part 1), software identification tags (Part 2), entitlement records (Part 3) and resource utilization measurement (Part 4). See ISO/IEC 19770 and Effective license position.[11]
Disputes and case law
Where the parties disagree about what the license covers, the dispute turns on the wording of the agreement. In SAP UK Ltd v Diageo Great Britain Ltd (2017), SAP claimed additional license and maintenance fees because two Salesforce-based systems interacted with mySAP ERP. The High Court held that only Named Users were authorized to use or access the ERP software directly or indirectly under that agreement, that the users of the two systems were not authorized, and that SAP was entitled to additional fees to be assessed by reference to usage and SAP’s price list.[9] The judgment is specific to that agreement and its definitions.
Relationship to other disciplines
Audits are the external test of license compliance. Preparation depends on software asset management practices: an up-to-date effective license position, complete entitlement records and reliable deployment data. In agreements with periodic self-reporting, such as true-up orders, much of the same work is done on a regular cycle rather than on audit notice.
Criticism and challenges
Audits consume customer time and data-collection effort; under the Oracle terms quoted above the customer bears its own costs of cooperating.[1] Findings depend on how metrics and policies are interpreted, and some vendor policy documents that shape findings are stated to be educational rather than contractual. GAO’s work suggests that gaps in the customer’s own inventory make it harder to check an auditor’s figures.[12]
Out of scope
This article does not cover financial statement audits, security audits, or open source license enforcement by copyright holders, which is discussed under License compliance. It does not give negotiation advice.