Category: Licensing & Audits

Vendor audits, licence metrics, and the entitlement changes that make a correct inventory wrong.

  • Oracle License Audits: What Makes Them Different

    An Oracle license audit is not a harder version of a Microsoft one. It is a different exercise, and the differences are structural rather than cultural.

    Most general audit advice still applies. What follows is the part that does not transfer.

    The soft audit

    Oracle frequently opens without invoking the audit clause at all. What arrives instead is an offer: a “license review”, a health check, an advisory conversation, sometimes free, usually framed as helpful.

    Because no clause was invoked, no contractual deadline applies and no formal scope exists. That sounds like an advantage and works as the opposite. A formal audit is bounded by what your agreement permits. An informal review is bounded by whatever you agree to hand over, and people hand over far more when nobody has said the word audit.

    Treat a review request with exactly the seriousness of a formal notification. Same single point of contact, same scope discipline, same review of anything before it leaves.

    Virtualisation is the main event

    The single largest source of Oracle claims, and the one where the gap between vendor position and contract text is widest.

    The dispute is about what counts as the machine your software runs on. Oracle’s stated position on soft partitioning means a database on a small number of virtual machines can be treated as licensable across a much larger pool of physical hosts it could theoretically move to. The multiplier this produces is how a modest deployment becomes a very large claim.

    The critical detail: Oracle’s partitioning policy is a published document, not a contract term, and it is generally not incorporated into the agreements customers sign. That distinction is the entire basis of most successful defences, and it is why the argument is worth having rather than conceding.

    None of which helps if your environment is genuinely wide open. Cluster design decisions made years ago by people with no licensing context are the usual root cause, and they are expensive to unwind under time pressure.

    Java is now a licensing problem

    The change that caught the most organisations out. Oracle moved Java SE onto an employee-based metric, so the price is driven by total headcount rather than by installs or by the people who use it.

    Read that again if you run Java anywhere. A handful of installations at a company of several thousand people prices against several thousand people. Organisations that considered Java a free runtime discovered they were buying a company-wide subscription.

    Java also spreads without anyone deciding to deploy it. It arrives bundled inside other vendors’ products, on developer laptops, inside container images. An inventory built from procurement records will miss almost all of it.

    Back-support is the sting

    Where an Oracle settlement diverges hardest from other vendors.

    A finding is rarely just the licence you should have bought. It is that licence, plus support fees backdated across the period you were non-compliant, at list. On a multi-year gap the backdated support can exceed the licence cost, and it is the line most people have not budgeted for when they estimate exposure.

    What to do differently

    1. Never run the scripts and send raw output. True everywhere, load-bearing here, because Oracle’s tooling reports on an estate far wider than your deployment and the interpretation gap is enormous.
    2. Establish what your contract actually incorporates. Specifically whether policy documents form part of it. This one question determines the size of the virtualisation argument.
    3. Inventory Java separately, and everywhere. Not via procurement. Scan endpoints, images and third-party products.
    4. Get the architecture diagram right before anyone asks. Which hosts, which clusters, what can move where. The defence is almost always technical, and assembling it under a deadline is how concessions happen.
    5. Price back-support into any exposure estimate. Otherwise your number is wrong by more than the licence itself.

    The wider point

    Oracle’s Java move is the cleanest example of something we write about constantly. Nobody’s deployment changed. The metric changed, and thousands of organisations became non-compliant overnight without touching anything.

    You cannot defend against that with an internal inventory, because your inventory is accurate. What went stale is the rule it was measured against. Tracking those changes as they happen is what CopperFeed is for, and it is the same mechanism behind legacy plan sunsets.

    General mechanics are in Software License Audits, and the selection patterns in What Triggers a Software Audit.

    General guidance, not legal or licensing advice. Oracle’s policies and metrics change, and your own agreement governs rather than any summary of it. Verify current terms and take advice before responding to a review or audit request.

  • What Triggers a Software Audit

    Audits look random from the inside. They are not. Vendors run audit programmes as revenue operations, and the accounts they select share a small number of characteristics.

    Knowing the software audit triggers will not make you immune. It will tell you which quarter to be ready for, which is most of the benefit.

    The pattern behind selection

    An audit costs the vendor money and burns goodwill with a customer. They run it when the expected recovery justifies both, which means they are looking for accounts where a shortfall is likely and where the commercial relationship is already going the wrong way.

    Put another way: audits are aimed at customers who are spending less than they used to, or are about to.

    The triggers most often reported

    Your spend went down

    The clearest one. You cut seats at renewal, dropped a module, or let a product lapse. Revenue that was forecast has gone missing, and an audit is the fastest way to look for it somewhere else in your estate.

    This catches people out because the cut was legitimate. You genuinely stopped using the thing. The audit is not a punishment for that, it is an attempt to recover the number.

    You declined a migration

    Particularly to cloud. If the vendor’s strategy is moving customers onto a hosted product and you said no, you have become an account that needs a different route to the same revenue. Refusing a migration is one of the most consistently reported triggers there is.

    Your agreement is expiring

    Timing here is not coincidental. An audit finding that lands during a renewal negotiation is worth far more to the vendor than the same finding six months later, because the shortfall can be folded into a bigger forward commitment instead of settled in cash.

    If you receive a notification within a couple of quarters of a major renewal, assume the two are related and plan the negotiation as one conversation rather than two.

    You merged, acquired, or divested

    M&A creates genuine licensing complexity, and vendors know it. Most agreements restrict transferring licences to a new legal entity, and most integrations move software around long before anyone reads that clause. Divestitures are worse, because entitlements rarely split cleanly.

    You told them something

    The underrated one. Headcount announcements, a press release about a new data centre, a case study naming your architecture, a conference talk by one of your engineers, a job posting listing the exact versions you run. All of it is public, and all of it is read.

    Two things that raise your exposure quietly

    Virtualisation. The gap between the hardware a product runs on and the hardware it could theoretically run on is where a great many claims live. Policies here are frequently not contractual, which is a fight worth having but a fight nonetheless.

    Vendor-side changes you did not notice. Licensing metrics change. Products get repackaged, editions get merged, a metric moves from installs to employees. Your deployment did not move, but the ruler did.

    That last one is the reason we track vendor changes at CopperFeed. A pricing or packaging change you missed is an entitlement change you cannot see in your own inventory, and it will surface at the worst possible moment. Related: Legacy Plan Sunsets.

    What to do with this

    Not paranoia. Timing.

    1. Assume the quarter after any significant cut is your risky one. Do the internal reconciliation then, while nobody is asking for it.
    2. Reconcile before a renewal, not during. Knowing your own position ahead of the conversation is the whole game, and it is much cheaper before there is a claim on the table.
    3. Treat M&A as a licensing project. It will not be on anyone’s integration checklist, and it should be.
    4. Keep a file of what changed. Dated notes on metric changes, repackaging and tier retirements for your major vendors. When an auditor asserts your entitlement means something different from what you understood, that file is the argument.

    If a notification has already arrived, the mechanics are in Software License Audits: Why You Got Picked and What Happens Next. Oracle works differently enough to warrant its own page: Oracle License Audits.

    Triggers here are drawn from published practitioner and consultancy accounts rather than from vendor disclosure, since no vendor publishes its selection criteria. Treat them as informed pattern-matching. General guidance, not legal advice.

  • Software License Audits: Why You Got Picked and What Happens Next

    A software license audit is a vendor exercising a clause you already agreed to. Not an investigation, not an accusation, and not optional. Somewhere in the agreement your company signed is a right for the vendor to verify your deployment against what you bought, and one day they use it.

    The letter arrives from procurement or legal, rarely from your account manager, and it is polite. It asks for a call to discuss a “license review”. What happens over the following weeks is largely determined in the first fortnight, mostly by people who have never done this before.

    Read the numbers you are about to be shown with suspicion

    Search this topic and you will find large settlement averages: figures in the millions for Oracle and SAP, high six figures for Microsoft, usually presented without methodology.

    Check who publishes them. Almost every page ranking for audit terms is written by a firm that sells audit defence, and the number at the top is doing marketing work. That does not make the figures invented. It does mean they are drawn from the population that hired a defence firm, which is the subset with the worst exposure, and it means nobody publishing them has an incentive to say your situation is probably fine.

    The same applies to the case studies, where an eight-figure claim reduced to almost nothing is presented as typical. Selection bias is doing the heavy lifting. Firms publish the wins.

    What is reliably true is duller: most audits end in a purchase rather than a penalty, the purchase is usually smaller than the opening claim, and the size of the gap depends mostly on preparation.

    What actually happens

    The shape is consistent across vendors.

    Notification. A letter citing the audit clause, naming an audit firm, and proposing a kick-off. The clock in your contract starts here, and the deadlines are usually shorter than the work requires.

    Data collection. You are asked to run vendor-supplied scripts or complete deployment questionnaires. This is the stage that decides the outcome, and the one companies rush.

    Findings. The auditor produces a report showing a shortfall, priced at list. Not your negotiated rate. List.

    Settlement. The claim converts into a purchase, usually alongside a renewal, frequently with the shortfall discounted in exchange for a larger forward commitment. This is where the vendor gets what it actually wanted.

    That last point is worth sitting with. An audit is rarely about the penalty. It is a mechanism for opening a commercial conversation you were not planning to have, at a moment when your negotiating position is weak.

    The one thing that matters most

    Look at the script output before it leaves your building.

    Vendor discovery scripts produce raw data that requires interpretation, and the interpretation is not neutral. The same output can support very different conclusions depending on how deployment, entitlement and environment are read. Hand it over unreviewed and the vendor’s reading becomes the starting position, and every subsequent conversation is you arguing backwards from their number.

    Run the scripts. Read the output. Understand what it says about your estate before anyone else sees it. If it shows a genuine gap, you want to know that privately first, because it changes your strategy entirely.

    Consultancies in this space claim companies that verify first concede substantially less. Treat the multiple as marketing, but the direction is right and the reasoning is obvious.

    Things that make it worse

    • Answering quickly to seem cooperative. Speed is not a virtue here. The deadline in your contract is negotiable more often than people assume, and asking for time is normal.
    • Letting scope drift. The audit covers what the clause says it covers. Requests routinely extend beyond that, and nobody will stop them on your behalf.
    • Engineers talking directly to auditors. Not because anyone is dishonest, but because a helpful technical answer given without context becomes a finding. Route everything through one person.
    • Treating it as a technical exercise. It is a commercial negotiation that happens to involve inventory data.

    The connection to everything else

    Audits do not arrive at random, and the triggers correlate with exactly the contract events we write about elsewhere: spend declining, a plan being retired, a migration you declined, a renewal approaching. We cover that in What Triggers a Software Audit.

    There is also a quieter link. When a vendor retires the tier you were on, your entitlements change under you, and the version of the truth you have been tracking internally goes stale. A lot of audit exposure is not deliberate over-deployment. It is an inventory that stopped matching a product catalogue that moved. That is the subject of Legacy Plan Sunsets, and the reason CopperFeed records what changed and when.

    Oracle deserves separate treatment, because its audit practice differs from the rest in ways that matter: Oracle License Audits: What Makes Them Different.

    General guidance, not legal or licensing advice. Audit rights, deadlines and remedies are defined by your own agreements, which vary considerably. Read yours, and get advice before responding to a notification.