A software license audit is a vendor exercising a clause you already agreed to. Not an investigation, not an accusation, and not optional. Somewhere in the agreement your company signed is a right for the vendor to verify your deployment against what you bought, and one day they use it.
The letter arrives from procurement or legal, rarely from your account manager, and it is polite. It asks for a call to discuss a “license review”. What happens over the following weeks is largely determined in the first fortnight, mostly by people who have never done this before.
Read the numbers you are about to be shown with suspicion
Search this topic and you will find large settlement averages: figures in the millions for Oracle and SAP, high six figures for Microsoft, usually presented without methodology.
Check who publishes them. Almost every page ranking for audit terms is written by a firm that sells audit defence, and the number at the top is doing marketing work. That does not make the figures invented. It does mean they are drawn from the population that hired a defence firm, which is the subset with the worst exposure, and it means nobody publishing them has an incentive to say your situation is probably fine.
The same applies to the case studies, where an eight-figure claim reduced to almost nothing is presented as typical. Selection bias is doing the heavy lifting. Firms publish the wins.
What is reliably true is duller: most audits end in a purchase rather than a penalty, the purchase is usually smaller than the opening claim, and the size of the gap depends mostly on preparation.
What actually happens
The shape is consistent across vendors.
Notification. A letter citing the audit clause, naming an audit firm, and proposing a kick-off. The clock in your contract starts here, and the deadlines are usually shorter than the work requires.
Data collection. You are asked to run vendor-supplied scripts or complete deployment questionnaires. This is the stage that decides the outcome, and the one companies rush.
Findings. The auditor produces a report showing a shortfall, priced at list. Not your negotiated rate. List.
Settlement. The claim converts into a purchase, usually alongside a renewal, frequently with the shortfall discounted in exchange for a larger forward commitment. This is where the vendor gets what it actually wanted.
That last point is worth sitting with. An audit is rarely about the penalty. It is a mechanism for opening a commercial conversation you were not planning to have, at a moment when your negotiating position is weak.
The one thing that matters most
Look at the script output before it leaves your building.
Vendor discovery scripts produce raw data that requires interpretation, and the interpretation is not neutral. The same output can support very different conclusions depending on how deployment, entitlement and environment are read. Hand it over unreviewed and the vendor’s reading becomes the starting position, and every subsequent conversation is you arguing backwards from their number.
Run the scripts. Read the output. Understand what it says about your estate before anyone else sees it. If it shows a genuine gap, you want to know that privately first, because it changes your strategy entirely.
Consultancies in this space claim companies that verify first concede substantially less. Treat the multiple as marketing, but the direction is right and the reasoning is obvious.
Things that make it worse
- Answering quickly to seem cooperative. Speed is not a virtue here. The deadline in your contract is negotiable more often than people assume, and asking for time is normal.
- Letting scope drift. The audit covers what the clause says it covers. Requests routinely extend beyond that, and nobody will stop them on your behalf.
- Engineers talking directly to auditors. Not because anyone is dishonest, but because a helpful technical answer given without context becomes a finding. Route everything through one person.
- Treating it as a technical exercise. It is a commercial negotiation that happens to involve inventory data.
The connection to everything else
Audits do not arrive at random, and the triggers correlate with exactly the contract events we write about elsewhere: spend declining, a plan being retired, a migration you declined, a renewal approaching. We cover that in What Triggers a Software Audit.
There is also a quieter link. When a vendor retires the tier you were on, your entitlements change under you, and the version of the truth you have been tracking internally goes stale. A lot of audit exposure is not deliberate over-deployment. It is an inventory that stopped matching a product catalogue that moved. That is the subject of Legacy Plan Sunsets, and the reason CopperFeed records what changed and when.
Oracle deserves separate treatment, because its audit practice differs from the rest in ways that matter: Oracle License Audits: What Makes Them Different.
General guidance, not legal or licensing advice. Audit rights, deadlines and remedies are defined by your own agreements, which vary considerably. Read yours, and get advice before responding to a notification.