An Oracle license audit is not a harder version of a Microsoft one. It is a different exercise, and the differences are structural rather than cultural.
Most general audit advice still applies. What follows is the part that does not transfer.
The soft audit
Oracle frequently opens without invoking the audit clause at all. What arrives instead is an offer: a “license review”, a health check, an advisory conversation, sometimes free, usually framed as helpful.
Because no clause was invoked, no contractual deadline applies and no formal scope exists. That sounds like an advantage and works as the opposite. A formal audit is bounded by what your agreement permits. An informal review is bounded by whatever you agree to hand over, and people hand over far more when nobody has said the word audit.
Treat a review request with exactly the seriousness of a formal notification. Same single point of contact, same scope discipline, same review of anything before it leaves.
Virtualisation is the main event
The single largest source of Oracle claims, and the one where the gap between vendor position and contract text is widest.
The dispute is about what counts as the machine your software runs on. Oracle’s stated position on soft partitioning means a database on a small number of virtual machines can be treated as licensable across a much larger pool of physical hosts it could theoretically move to. The multiplier this produces is how a modest deployment becomes a very large claim.
The critical detail: Oracle’s partitioning policy is a published document, not a contract term, and it is generally not incorporated into the agreements customers sign. That distinction is the entire basis of most successful defences, and it is why the argument is worth having rather than conceding.
None of which helps if your environment is genuinely wide open. Cluster design decisions made years ago by people with no licensing context are the usual root cause, and they are expensive to unwind under time pressure.
Java is now a licensing problem
The change that caught the most organisations out. Oracle moved Java SE onto an employee-based metric, so the price is driven by total headcount rather than by installs or by the people who use it.
Read that again if you run Java anywhere. A handful of installations at a company of several thousand people prices against several thousand people. Organisations that considered Java a free runtime discovered they were buying a company-wide subscription.
Java also spreads without anyone deciding to deploy it. It arrives bundled inside other vendors’ products, on developer laptops, inside container images. An inventory built from procurement records will miss almost all of it.
Back-support is the sting
Where an Oracle settlement diverges hardest from other vendors.
A finding is rarely just the licence you should have bought. It is that licence, plus support fees backdated across the period you were non-compliant, at list. On a multi-year gap the backdated support can exceed the licence cost, and it is the line most people have not budgeted for when they estimate exposure.
What to do differently
- Never run the scripts and send raw output. True everywhere, load-bearing here, because Oracle’s tooling reports on an estate far wider than your deployment and the interpretation gap is enormous.
- Establish what your contract actually incorporates. Specifically whether policy documents form part of it. This one question determines the size of the virtualisation argument.
- Inventory Java separately, and everywhere. Not via procurement. Scan endpoints, images and third-party products.
- Get the architecture diagram right before anyone asks. Which hosts, which clusters, what can move where. The defence is almost always technical, and assembling it under a deadline is how concessions happen.
- Price back-support into any exposure estimate. Otherwise your number is wrong by more than the licence itself.
The wider point
Oracle’s Java move is the cleanest example of something we write about constantly. Nobody’s deployment changed. The metric changed, and thousands of organisations became non-compliant overnight without touching anything.
You cannot defend against that with an internal inventory, because your inventory is accurate. What went stale is the rule it was measured against. Tracking those changes as they happen is what CopperFeed is for, and it is the same mechanism behind legacy plan sunsets.
General mechanics are in Software License Audits, and the selection patterns in What Triggers a Software Audit.
General guidance, not legal or licensing advice. Oracle’s policies and metrics change, and your own agreement governs rather than any summary of it. Verify current terms and take advice before responding to a review or audit request.