HomeOracle HubAudit Frequency Report
Advisory  |  Audit Frequency and Cost Market Report 2026

The audit is a revenue motion, and the settlement tracks preparation

A software audit is a revenue motion, not a neutral compliance check: the teams that scope, analyze, and settle it report into the organization that owns the renewal. Across the audits we defended, the settlement tracked the buyer's preparation far more closely than the size of the gap, so the defense begins long before the letter arrives.

Prepared by Redress Compliance · Updated September 2, 2026 · Cross vendor advisory. Based on 90 to 120 software audits defended 2024 to 2025 across Oracle, IBM, Microsoft, SAP, Broadcom VMware, Salesforce, and ServiceNow.

Executive summary

Expect a formal audit every 3 to 5 years from at least one major vendor, and one somewhere in the estate almost every year. Most large enterprises face a formal audit or license review every 3 to 5 years from each of the vendors that audit hardest.

Across a full Oracle, IBM, Microsoft, and SAP portfolio, the practical answer is an audit somewhere in the estate every year.

The vendor ranking is stable, and four names drive it. In a three year window, Oracle audited 55 to 70 percent of large enterprises in our file, IBM 45 to 55, Microsoft 40 to 50, and SAP 30 to 40.

Broadcom VMware rose to 20 to 30 percent after the 2025 letter campaigns, Salesforce sat at 15 to 25, and the hyperscalers almost never ran a formal license audit.

Opening claims ran 2 to 4 times the settlement, and the gap is the negotiation. Once each line was validated against an independent baseline, opening claims commonly ran 2 to 4 times the figure the engagement settled at.

The gap came from environment classification, contested metric interpretations, dormant deployments priced as live, and list price applied where net price was contractual.

Posture, not gap, decided the outcome. Buyers who controlled the data and paced the response settled at roughly 30 to 50 percent of the opening claim. Buyers who cooperated fully and fast settled far higher on identical facts, because everything they volunteered was priced before anyone tested it.

The defense begins before the letter, and the highest return move is early help. The pre letter posture is three files maintained continuously: the entitlement record, the deployment data owned internally, and a written position on the contested metrics. Engaging independent audit defense before the first response, not after the first finding, was the highest return move across the file.

3 to 5 yrs
The typical gap between formal audits from any one major vendor at a large enterprise.
2 to 4x
Opening claims against the defended settlement, once lines were validated independently.
30 to 50%
Of the opening claim settled by buyers who controlled the data and paced the response.
55 to 70%
Of large enterprises formally audited by Oracle inside a three year window, the most active vendor.
1.

How often are enterprises audited, and by whom?

A large enterprise running the four major vendors should plan for a formal audit somewhere in the estate every year, and for each of Oracle, IBM, Microsoft, and SAP to arrive roughly once every 3 to 5 years. The frequency is not evenly spread.

It clusters around the vendors with the most complex metrics and the most to gain, because complexity is where unlicensed use hides and where a claim is easiest to build.

The ranking below comes from the audits we defended between 2024 and 2025, cross checked against the audit histories of the wider client base. The bands are planning ranges rather than survey precision. The order of the vendors has not changed in years, and that stability is the more useful fact.

VendorShare formally audited in 3 yearsTypical form of the reviewWhat drives the claim
Oracle55 to 70 percentFormal GLAS audit under the 45 day contract clause; Java reviews opened by emailDatabase options and packs, Java SE, virtualization counting, Named User Plus minimums
IBM45 to 55 percentFormal audit run by an accounting firm on IBM's behalfSub capacity eligibility, ILMT report gaps, PVU counting on virtual clusters
Microsoft40 to 50 percentPartner led SAM engagement; formal verification under the Customer Agreement is rarerSQL Server cores, Windows Server in virtual estates, SPLA, Microsoft 365 assignment gaps
SAP30 to 40 percentAnnual system measurement plus enhanced reviews framed as advisoryNamed user classification, indirect and digital access, engine metrics
Broadcom VMware20 to 30 percent, risingCease and desist letters, then formal audits from mid 2025Perpetual licenses with lapsed support, core counts under the subscription bundles
Salesforce and ServiceNow15 to 25 percentContractual usage reviews and true ups rather than classic auditsOverage on seats and consumption meters, minimums at renewal
AWS, Google Cloud, Microsoft AzureRare formal auditsContinuous consumption and commitment reviewsCommitment shortfalls, marketplace attribution, egress and support tier drift

How the bands were built

The percentages describe large enterprises, meaning estates with more than roughly 5,000 employees and at least three of the major vendors under contract. Smaller estates are audited less often by Oracle and IBM and more often, in proportion, by Microsoft through its partner channel.

The bands would move down for a mid market company and up for a bank or a telecom.

A formal audit means a written notice under the audit clause, or a review that produced a priced compliance claim. Advisory framed reviews that ended without a claim are excluded from the formal count, even though we treat them as audits in practice. Counting them would push every band up by 10 to 20 points.

Region matters less than sector. Financial services, telecom, and public sector estates sat at the top of every vendor's band because they run the largest database and middleware footprints and have the most complex entity structures. Manufacturing and retail sat in the middle.

Professional services sat at the bottom, with Java as the exception that reaches everyone.

Why the ranking is stable

Audit frequency follows metric complexity, not customer behavior. Oracle's database is licensed per processor with a core factor table, with separately licensed options that a single command can enable. IBM's middleware is licensed per processor value unit with a sub capacity rule that depends on a reporting tool.

Both create findings without anyone deciding to break a rule.

Microsoft and SAP have equally complex metrics but a different commercial channel. Microsoft prefers partner led asset management engagements that convert into Enterprise Agreement true ups and Azure commitments. SAP prefers the annual measurement and the renewal conversation, with the audit clause held in reserve.

The formal audit count is lower, but the commercial outcome is the same.

What changed in 2025 and 2026

Three vendors moved up the frequency table. Oracle's Java team shifted from download log outreach to formal notices under the master agreement, which we cover in the Java GLAS formal notice guide. Broadcom moved from letters to audits on lapsed VMware perpetual estates.

IBM tied audit timing to the ELA renewal calendar more visibly than before, which the IBM audit timing analysis examines.

The lens that explains the behavior: ask what commercial outcome each mechanism serves.

The teams that run the audit report into the organization that owns the renewal. The finding converts into a purchase, a cloud commitment, a bigger agreement, or a subscription. The ranking is stable across years because the vendors with the most complex metrics have the most claims to build.

Read every frequency band, cost band, and trigger through that question and the behavior predicts itself.

2.

What triggers a software audit?

Audits are triggered by commercial events, and the single most reliable trigger across every vendor is a renewal or support decision going the vendor's way less than expected. The compliance rationale is real, but it is the justification rather than the cause. When we reconstruct the six months before a letter, one of the events below is almost always present.

What does not trigger an audit

Three beliefs about triggers cost buyers money because they lead to the wrong precautions. The first is that a clean prior audit buys a quiet period. It does not.

Oracle and IBM have both returned inside three years to estates that settled cleanly, because the account plan changed rather than the compliance picture.

The second is that buying more at renewal prevents the audit. A larger commitment changes the vendor's incentive for a year, and then the next renewal cycle starts and the audit becomes the tool for growing it again. The third is that staying quiet keeps the estate off the list.

Silence reads as an account with no active opportunity, which is exactly the profile a compliance team is asked to work.

The practical conclusion is that the trigger is largely outside the buyer's control, and the preparation is entirely inside it. Time spent trying to avoid the letter is better spent on the three files described in section 7, which decide what the letter costs.

The soft audit front door

Every vendor now runs a voluntary review that gathers audit grade data without audit constraints. Microsoft calls it a SAM engagement. SAP calls it a license optimization or advisory review.

Oracle's Java team calls it a licensing conversation, and Broadcom calls it a support entitlement check. The data requested is identical to a formal audit, and the contract protections of the formal audit clause do not apply.

Treat every advisory framed review as discovery. Answer it under the same scope discipline, with the same independent baseline, and with the same paced schedule as a formal notice. The Java volunteer audit analysis and the Microsoft SAM preparation guide cover the two most common versions.

How Oracle selects targets

Oracle's selection combines the account plan, the support history, and the contract calendar rather than random sampling. A ULA approaching certification, a support reduction, a large virtualized estate, or a Java download record each raises the probability. We analyze the selection model in how Oracle selects audit targets and list the standing triggers in the Oracle audit triggers guide.

3.

What does each vendor's audit actually look like?

Each major vendor runs its audit through a different contractual mechanism, and the mechanism determines both the timeline and the leverage. The contract clause sets the notice period, the tools, and the remedy. The commercial organization behind the clause decides how the finding is priced.

Knowing both before the letter arrives is the difference between a paced response and a scramble.

Oracle: the GLAS audit and the Java review

Oracle's standard master agreement gives Oracle the right to audit on 45 days written notice, requires payment of any fees for excess use within 30 days of written notification, and states that Oracle is not responsible for any of the customer's costs in cooperating. The wording is public in Oracle's transactional master agreement.

The clause also says the audit shall not unreasonably interfere with normal business operations, which is the buyer's main contractual handle.

The audit is run by Global Licensing and Advisory Services, formerly License Management Services. Oracle's own description of the service sets out four phases: kickoff, assessment, reporting, and close. The assessment phase is where Oracle's collection scripts run, and the report is where the claim appears.

We walk each phase in the Oracle audit guide and the GLAS script analysis.

Three technical positions decide most Oracle claims. First, Oracle's partitioning policy states that it is for educational purposes only, yet Oracle prices VMware estates as if every core the virtual machine could reach must be licensed. Second, the processor core factor table decides how many licenses a physical core requires.

Third, database options and management packs that a single parameter enables are priced as deployed whether or not anyone used them.

Java changed the shape of Oracle audits from 2023. The Java SE Universal Subscription is priced per employee, and Oracle's published price list defines Employee as all full time, part time, and temporary employees plus the employees of agents, contractors, outsourcers, and consultants supporting internal operations.

The tiers run from $15.00 per employee per month below 1,000 employees to $5.25 at 40,000 to 49,999. The price list's own example prices 28,000 employees at $6.75 per month, or $2,268,000 per year.

The commercial consequence is that a Java finding for a few hundred installations converts into a subscription for the entire workforce. That conversion is the audit's purpose, and the Java audit defense guide and the 45 day timeline guide cover how to hold the installation count separate from the employee count for as long as the facts allow.

Two further Oracle mechanics deserve their own note. Named User Plus licensing carries a minimum of 25 users per processor for Database Enterprise Edition, so a lightly used database on a large host is often cheaper to license per processor than per user, and the audit counts whichever produces the larger figure.

The Named User Plus minimums guide covers the arithmetic.

The Unlimited License Agreement is the other. At the end of the ULA term the customer certifies its deployment counts, and those counts become the perpetual entitlement. Oracle reviews the certification closely, and the review is an audit in everything but name.

Estates that certified without an independent count have handed Oracle both the number and the evidence to dispute it later.

IBM: sub capacity, ILMT, and the accounting firm

IBM's audit is a reporting audit before it is a deployment audit. Under the Passport Advantage sub capacity licensing terms, a customer may license virtual capacity rather than the full physical server only if the IBM License Metric Tool or an approved alternative is installed, reports are generated at least quarterly, and reports are retained for two years.

The tool must be in place within 90 days of the first eligible deployment.

Miss any of those conditions and IBM's position is that the deployment reverts to full capacity licensing, which means every core in the physical server or the cluster. That is how a modest middleware estate produces a nine figure opening claim.

The audit itself is usually performed by an accounting firm engaged by IBM, working from ILMT output, discovery scans, and interviews with the infrastructure team.

The defense is a reconciliation exercise. ILMT data is corrected, cluster boundaries are documented, and the shortfall in reporting is separated from the shortfall in licenses. The ILMT exposure report quantifies the gap, the IBM audit defense playbook sequences the response, and the IBM audit clause redlines show which contract terms to fix before the next ELA.

The processor value unit itself is the second layer. Most current x86 cores carry 70 PVUs, so a two socket server with 32 cores represents 2,240 PVUs at full capacity.

If that server is one of eight in a cluster where virtual machines can move freely, IBM's full capacity position counts all eight, or 17,920 PVUs, for a product that may run on two virtual cores.

The auditor's method is predictable and worth knowing in advance. The firm requests ILMT reports, runs its own discovery scripts, and interviews the virtualization team about cluster boundaries and migration rules. Discrepancies between what ILMT reported and what discovery found become the working paper, and the working paper becomes the claim.

The buyer who has reconciled ILMT against discovery before the auditor arrives has already written most of the defense.

Microsoft: the Customer Agreement and the SAM engagement

Microsoft's formal audit right sits in the verifying compliance clause of the Microsoft Customer Agreement. Microsoft may verify compliance on 30 days notice, using an independent auditor under nondisclosure or a self audit. If unlicensed use is found, the customer must order sufficient licenses within 30 days.

If unlicensed use reaches 5 percent or more of total use, the customer also reimburses Microsoft's verification costs and buys the shortfall at 125 percent of the then current price.

In practice the formal clause is the exception. Most Microsoft reviews arrive as a SAM engagement delivered by a partner, funded by Microsoft, and positioned as a service to the customer. The data gathered is the same as a formal audit.

The output is a deployment summary that feeds the next Enterprise Agreement true up or an Azure commitment, which is why the engagement is offered so freely.

SQL Server core counts in virtual estates, Windows Server datacenter versus standard edition on hosts, and SPLA reporting at service providers generate most of the value. The common Microsoft audit findings guide lists the recurring findings and the fixes, and the SPLA audit process guide covers the hosting case.

Microsoft 365 has quietly become a second audit surface. The question is no longer whether the licenses were bought but whether they were assigned, whether the assigned plan matches the features in use, and whether external users and shared mailboxes were licensed correctly.

The data is in the tenant, the partner can pull it in an afternoon, and the finding feeds the next Enterprise Agreement true up.

Service providers under SPLA face the strictest regime, because the reporting is monthly and the audit right is exercised through the reseller. A provider that under reported for three years faces a claim for the full period at the current price. The SPLA audit defense guide covers the provider case in detail.

SAP: the annual measurement and indirect access

SAP's audit is continuous rather than episodic. The license agreement obliges the customer to run the system measurement every year, using the USMM transaction on each system and the License Administration Workbench to consolidate. Every year, the customer tells SAP what it deployed and how users are classified.

The formal audit clause exists, but SAP rarely needs it because the measurement already reports the estate.

The claim that matters is indirect access. In SAP UK Ltd v Diageo Great Britain Ltd, decided in February 2017, the High Court found that Diageo's customers and sales staff using Salesforce based applications connected to SAP through SAP PI were accessing the SAP system indirectly, and so required Named User licenses.

SAP had claimed roughly £54.5 million in additional fees. The court decided liability in SAP's favor and left the quantum open.

The backlash produced SAP's April 2018 digital access model, which prices indirect use on nine document types rather than named users, as reported at the time by The Register. That did not remove the exposure. It moved it to document counts that most customers cannot measure without SAP's own tools.

The SAP indirect access liability report sizes the exposure, and the SAP audit defense framework sets out the five pillars of the response.

User classification is the quieter SAP exposure. Every named user must carry a type, from Professional through Limited Professional to Employee, and each type has a different price. Users left unclassified in the measurement default to the most expensive type.

Engines such as payroll, sales orders, and HANA memory carry their own metrics, and the measurement reports them whether or not the buyer has checked them.

SAP's 2019 Digital Access Adoption Program offered conversions at a steep discount for customers who adopted the document model before a deadline. Customers who declined kept the named user model and kept the Diageo exposure.

Both positions are defensible, but only if the estate has measured its own document counts and user types before SAP does, which the digital access audit defense guide explains.

Broadcom VMware: letters first, audits second

Broadcom rebuilt VMware's commercial model within weeks of closing the acquisition in November 2023. VMware's own end of availability notice confirmed that perpetual licenses and support renewals were no longer for sale and that the portfolio moved to subscription only, packaged as VMware Cloud Foundation and VMware vSphere Foundation. Customers with active support kept it until expiry.

Nobody could renew it.

The audit motion followed the expiry curve. In spring 2025, customers with lapsed support received cease and desist letters demanding removal of any update installed after the support end date and warning that VMware could exercise its audit right. By June 2025, formal audit notices followed, with an accounting firm named and short reply windows, as Computer Weekly reported.

The commercial purpose is to convert lapsed perpetual estates into subscriptions.

Broadcom's audit is unusual because the finding is rarely about license quantity. It is about the right to run patched software without support, and the settlement offered is a subscription at the new bundle price. The Broadcom VMware audit defense guide covers the response, and the VMware licensing risk analysis covers the exposure created by the bundle structure itself.

The subscription model carries its own compliance mechanics. VMware Cloud Foundation and vSphere Foundation are licensed per core with a minimum of 16 cores per physical processor, and in 2025 Broadcom raised the minimum purchase to 72 cores per order. A host with two 8 core processors is licensed as 32 cores, and a small site is licensed as 72.

Core counts, not virtual machine counts, are what the audit checks.

The buyer's leverage in a Broadcom audit is unusual. The finding is that the estate is running without support, and the remedy the vendor wants is a subscription. A buyer with a credible migration plan to another hypervisor can price the subscription against the migration and negotiate a shorter term.

A buyer without one takes the bundle at the offered price.

Salesforce, ServiceNow, and the hyperscalers

Salesforce and ServiceNow rarely run a classic audit because their contracts do the work. Usage above the subscribed quantity is an overage or a true up under the order form, and the vendor sees usage in its own platform.

The event to plan for is the renewal, where minimums, overage rates, and consumption meters get reset, as the Salesforce true ups playbook and the ServiceNow license audit guide explain.

The hyperscalers almost never audit. AWS, Google Cloud, and Azure meter every unit of consumption and invoice it, so there is nothing to discover. The recurring event is the commitment review, where a shortfall against an Enterprise Discount Program or a Microsoft Azure Consumption Commitment becomes a true up invoice or a forced renewal.

The AWS overcommit risk assessment treats that as the audit equivalent it is.

Consumption meters are the SaaS version of the option pack. Salesforce data storage, API call volumes, and Agentforce conversations, and ServiceNow transaction and integration units, each carry an allowance and an overage rate.

The allowance is rarely monitored by the buyer, the overage is invoiced by the vendor, and the renewal conversation opens with the overage as the baseline for the new commitment.

4.

What does a software audit actually cost?

The settlement is the largest line but rarely the only one, and a defended audit at a large enterprise consumes six categories of cost that finance should budget together. The bands below come from the audits we defended between 2024 and 2025 and are planning ranges.

The pattern matters more than any single number: the cheapest audit is the one where the preparation was paid for before the letter.

Cost categoryTypical range at a large enterpriseWhat moves it
Settlement or true up30 to 50 percent of the opening claim when defended; 70 to 100 percent when concededData control, scope discipline, contested metric positions
Back support and maintenanceOften 22 percent of net license per year for Oracle, backdated; similar mechanics at IBM and SAPHow far back the vendor dates the shortfall
Forward commitmentFrequently larger than the settlement itselfWhether the settlement is folded into a ULA, ELA, cloud commitment, or subscription
Internal time600 to 2,500 hours across IT, procurement, legal, and financeDuration of the audit and how many data requests were answered
External advisors and counselA small fraction of the settlement varianceWhen they were engaged; before or after the first response
Operational disruptionDelayed projects, frozen environments, deferred migrationsWhether the buyer or the vendor set the schedule

How the vendor builds the claim

The opening claim is built at list price, at full capacity, and over the longest defensible period. Oracle prices at the global price list before any discount and adds backdated support. IBM prices the full physical capacity of every server where a sub capacity condition failed.

Microsoft applies the 125 percent uplift where the 5 percent threshold is met. SAP counts every indirectly connected user or every document over the term.

None of those choices is an accounting fact. Each is a negotiating position, and the audit report that presents them as findings is the vendor's opening offer. The audit defense cost report breaks the claim build down further, and the Oracle audit cost guide covers the Oracle specific arithmetic.

A worked example: an Oracle database claim

Take an eight host VMware cluster, each host with two 16 core processors, where Oracle Database Enterprise Edition runs on two of the hosts. Oracle's opening position counts all eight hosts, or 256 cores. At the core factor of 0.5 for that processor family, that is 128 processor licenses.

At Oracle's published list price of $47,500 per processor for Enterprise Edition, the license claim alone is $6,080,000.

Add three years of backdated support at 22 percent of net license per year and the claim passes $10 million before a single option is counted. If Diagnostics Pack and Tuning Pack were enabled by default on those databases, a further $12,500 per processor list is added across all 128 processors, or $1,600,000, plus support.

The buyer's position counts the two hosts where the software ran, with evidence that affinity rules or a separate cluster kept it there. That is 64 cores, or 32 processors, or $1,520,000 at list before the contract's net discount.

With the packs disabled and shown unused, and support running from the evidenced first use rather than the earliest install date, the defended position lands between a quarter and a third of the opening claim. The gap is entirely a matter of which facts are established first.

The forward commitment is the real price

The most expensive audits in our file were not the ones with the largest settlement. They were the ones where the settlement was folded into a forward agreement, because the vendor's goal was never the back payment. An Oracle finding becomes a ULA.

An IBM finding becomes an ELA extension. A Microsoft SAM finding becomes an Azure commitment, and a Java finding becomes an employee wide subscription.

Finance should therefore price the audit as the settlement plus the net present value of the commitment it triggers, minus what the enterprise would have bought anyway. On that measure, a settlement discounted to 40 percent of the claim but tied to a five year commitment can cost more than a settlement at 80 percent paid once.

5.

Why do opening claims run 2 to 4 times the settlement?

Opening claims run 2 to 4 times the settlement because the claim is built from assumptions that favor the vendor at every step, and each assumption falls when tested against an independent baseline. The inflation is not fraud and it is not error. It is the predictable result of a process designed by the party that benefits from the answer.

Six mechanisms produce most of the gap.

  1. Environment classification. Development, test, disaster recovery, and decommissioned environments are counted as production. Oracle's rules on failover and standby, and IBM's rules on cold backup, are applied at their narrowest.
  2. Virtualization boundaries. Every host a virtual machine could migrate to is counted as licensable. The cluster, or the whole vCenter, replaces the server. The vMotion and DRS argument is the most common Oracle example.
  3. Dormant deployments priced as live. An option enabled by default, a Java runtime installed with a third party application, or a WebSphere instance nobody used for two years all count as deployed.
  4. Contested metric interpretations. Indirect access counted per human user rather than per document, Named User Plus minimums applied per processor, and PVU counts at full capacity where the reporting condition arguably held.
  5. List price and backdating. The shortfall is priced at list rather than the contract's net price, and support is backdated to the earliest plausible install date rather than the first evidenced use.
  6. Scope creep. The audit letter names three products and the data request covers thirty. Everything discovered in the extra twenty seven is added to the claim.

The defense addresses each mechanism with evidence rather than argument. Change records prove the environment classification. Hypervisor configurations and affinity rules prove the boundary.

Usage logs prove dormancy. The contract proves the metric and the net price. The Oracle audit mechanics guide catalogs the evidence line by line.

Two habits made the evidence usable when it was needed. The first was keeping change records and hypervisor configurations for the full period the vendor could claim, which for Oracle and IBM means the life of the deployment and for Microsoft means the term of the agreement.

Evidence that existed but could not be produced within the audit schedule was worth nothing.

The second was writing the contested positions down before the audit rather than assembling them during it. A position paper written under deadline reads as a rationalization. The same paper written a year earlier, with the evidence attached, reads as the enterprise's standing interpretation of its contract, and auditors treat it differently.

The raw discovered gap was the least predictive number in the file.

Across 90 to 120 defended audits, the correlation between the size of the technical gap and the size of the settlement was weak. The correlation between the buyer's posture at the first response and the settlement was strong. That is the whole report in two sentences.

6.

Which response posture halves the claim?

The posture that halved the claim in our file had five components, and buyers who held all five settled at roughly 30 to 50 percent of the opening figure. Buyers who held none settled near the opening figure on comparable facts. The components are not technical.

They are decisions about who controls the data, who sets the schedule, and when independent help enters.

Where the common advice on cooperating with the auditor is wrong

The standard advice is to cooperate fully, respond promptly, and treat the auditor as a neutral professional. We disagree, and the file supports the disagreement. The auditor may be professional and may be independent of the sales team on paper, but the report lands with the organization that owns the renewal, and that organization prices it. Prompt, full cooperation hands over untested data on the vendor's timeline, and every mechanism in section 5 then operates on that data before the buyer has a baseline. Cooperation within the contract is an obligation. Cooperation beyond the contract, on the vendor's schedule, with unreviewed data, is a concession, and it was the single most expensive decision in the audits we defended. The right posture is courteous, contractual, and paced.

The audit report is the vendor's opening offer. The buyer who treats it as a finding pays for the mistake twice: once in the settlement and again in the commitment that follows.
Free white paper

The Oracle audit response playbook

The most active vendor's sequence end to end: the scope letter, the validation pass, and the settlement mechanics that generalize to IBM, Microsoft, and SAP.

Get the white paper →
7.

How do you build the defense before the letter arrives?

The defense before the letter is three files maintained continuously and a contract that limits what the audit can do. The files take months to build and hours to maintain. The contract terms take one renewal to fix.

Enterprises that had both in place settled fastest and lowest, and most had built them after an earlier audit they wished they had prepared for.

The three files

  1. The entitlement record. Every order form, master agreement, amendment, certificate, and support renewal, reconstructed and current, with the metric and the net price for every product. Most enterprises cannot produce this in a week, and the vendor knows it.
  2. The deployment data. Owned internally and refreshed at least quarterly, rather than discovered by the vendor's scripts first. For IBM this is ILMT. For Oracle it is the option and pack usage views, the hypervisor inventory, and the Java installation inventory covered in the defensible Java inventory guide.
  3. The position paper on contested metrics. Where the estate stands on virtualization counting, sub capacity conditions, indirect access, and environment classification, written down with the contract clauses and evidence that support each position, before anyone asks.

The annual internal audit

Run the vendor's audit on yourself once a year, using the vendor's own scripts and metrics, and reconcile the result against the entitlement record. The exercise finds the accidentally enabled option, the orphaned Java runtime, and the ILMT agent that stopped reporting while the fix costs nothing.

The internal Oracle audit guide and the Microsoft usage review template give the procedure.

The contract terms that limit the audit

The audit clause is negotiable at every major vendor, and the renewal is the only time the vendor will discuss it. The clauses below returned the most value in the audits we defended. Each one is invisible until the letter arrives and decisive afterward.

ClauseVendor defaultBuyer position to negotiate
Notice period30 days at Microsoft, 45 days at Oracle, often silent at IBM60 to 90 days, with the audit start date agreed rather than imposed
FrequencyAt any timeOnce in any 24 or 36 month period, and not within 12 months of a prior audit
ScopeUse of the Programs, undefinedNamed products, named entities, named regions; anything else requires a new notice
Tools and dataVendor scripts, raw output sharedBuyer runs collection; output reviewed before release; no agents installed without approval
AuditorVendor staff or a firm of the vendor's choosingIndependent firm, nondisclosure signed, no contingent fee, no sales team access to working papers
Remedy and pricingList price, backdated support, 125 percent uplift at MicrosoftShortfall priced at the contract's net discount, support from evidenced first use, no penalty uplift
Cure period30 days to pay90 days to remediate by removal, reassignment, or purchase, at the buyer's choice
ConfidentialityAudit results shared within the vendorResults confidential to the audit team; not usable in renewal negotiation

The vendor specific redlines are in the Oracle audit clause redlines, the IBM audit clause redlines, and the SAP audit protection clauses. None of them is exotic. Each is refused at first and accepted at the third ask, usually in exchange for nothing the buyer valued.

Try Vera AI · free 30 day trial
Vera builds your defensible position paper from the contract record.
  • Percentile standing for your exact deal size and industry, from real closed transactions
  • Scenario simulation before the call: test alternative terms and see the financial impact of each
  • A negotiation playbook, talking points, and a two page executive brief on day one
Start the free Vera AI trial →30 days free · no credit card · cancel anytime
8.

What should happen in the first 45 days after the letter?

The first 45 days decide the audit, because the scope, the data flow, and the schedule are all set in that window and none of them is reclaimed later. Oracle's notice period is 45 days by contract, Microsoft's is 30, and Broadcom's 2025 letters asked for a reply within days.

Whatever the vendor's number, the buyer's plan runs on the same sequence.

Days 1 to 5: contain and convene

Acknowledge receipt in writing without conceding scope, dates, or tools. Route every vendor contact through one named owner and instruct the wider organization that nobody else answers vendor questions. Convene legal, procurement, the platform owners, and independent defense in the first week.

The first 48 hours checklist is the short version.

Days 5 to 20: baseline before anything is shared

Reconstruct the entitlement record and run the internal collection against the letter's stated scope, using the vendor's metrics so that the numbers will be comparable. Identify every contested position in the estate and write it down with its evidence. Nothing is shared with the vendor in this window except the agreed scope and a proposed schedule.

Days 20 to 45: agree scope, schedule, and data handling

Negotiate the scope letter down to the products and entities named in the notice, agree the collection method, and agree that raw output is reviewed before release. Propose a schedule that fits the business calendar and cite the contract's interference language. Then, and only then, begin the collection.

The multi vendor audit response playbook carries the full sequence, and the Oracle audit letter guide covers the most common version.

Days 45 to 120: validate, contest, and settle

Once collection is complete, every line in the vendor's draft findings is compared to the buyer's baseline and sorted into three groups: agreed, contested on the facts, and contested on the contract. The agreed group is small and is conceded promptly, which buys credibility for the rest. The factual disputes are resolved with evidence.

The contractual disputes are the negotiation.

Settlement mechanics vary by vendor, but the structure is the same. The vendor prefers a purchase at the current price list wrapped in a forward agreement. The buyer prefers remediation by removal or reassignment, and where a purchase is unavoidable, a purchase at the contract's net discount with no forward commitment attached.

Where the two meet depends on the renewal calendar and on how much the buyer conceded in the first 45 days.

One rule held in every settled engagement: nothing is signed until the release language is read. A settlement that releases the claim for the audited products and period is worth having. A settlement that leaves the same period open for a later audit of adjacent products, or that resets the support baseline, is a down payment on the next claim.

9.

What we saw across audit defenses, 2024 to 2025

Across roughly 90 to 120 software audits that Fredrik Filipsson and the Redress audit defense team defended for enterprise clients between 2024 and 2025, the final settlement tracked the buyer's preparation far more closely than the size of the discovered gap. Oracle and IBM engagements made up the largest share, with Microsoft, SAP, Broadcom VMware, and Java reviews behind them.

The numbers below describe that file.

2 to 4x
The claim inflation

Opening claims against eventual settlements, once each line met an independent baseline.

4 vendors
The formal audit engine

Oracle, IBM, Microsoft, and SAP driving the large majority, hyperscalers almost none.

Patterns the file repeated

What did not work

Three responses failed often enough to name. Arguing the vendor's business model was one: the audit is a revenue motion, but saying so to the auditor changes nothing, and the time is better spent on evidence. Escalating to the account executive was another, because the account executive's interest in a large finding is stronger than the auditor's.

The third was refusing the audit outright. The contract grants the right, and a refusal converts a licensing dispute into a breach dispute, which moves it from procurement to litigation and raises every cost. The engagements that settled lowest were courteous, contractual, evidenced, and slow, in that order.

The bands are planning ranges rather than quotes, and the pattern over the decimal is the report's whole point. Posture beats gap, the defense predates the letter, and the first response sets the trajectory everything after follows. The audit trends review tracks how the pattern moved over the period.

10.

How should finance budget for audits?

Finance should budget the audit as a recurring operating event, not a tail risk, because at least one major vendor arrives every 3 to 5 years and the portfolio produces one almost every year. A recurring event gets a line, an owner, and a reserve. A tail risk gets a footnote and a scramble.

The table below is a planning frame rather than a forecast.

Planning inputUnprepared estatePrepared estate
Audits per year across the portfolio1 to 21 to 2; frequency does not change
Settlement as share of opening claim70 to 100 percent30 to 50 percent
Forward commitment attachedUsually, at the vendor's termsOnly where the enterprise wanted it anyway
Internal hours per audit1,500 to 2,500600 to 1,200
Duration9 to 18 months4 to 9 months
Annual preparation costNone budgetedA fraction of one avoided settlement

The arithmetic favors preparation by a wide margin. The annual cost of maintaining the three files and running the internal audit is small against the settlement variance between a prepared and an unprepared response to a single claim. The audit defense readiness checklist scores the estate in minutes, and the audit defense practice runs the program with you.

The owner, the reserve, and the calendar

Three things turn the planning frame into a program. The first is a named owner for audit readiness, usually in software asset management or procurement, with authority to hold the three files and to run the annual internal audit.

Estates without an owner rebuilt the entitlement record from scratch in every audit, which is where most of the internal hours went.

The second is a reserve, sized from the planning table and released only against a defended settlement. A reserve that exists changes the negotiation, because the buyer can walk toward litigation credibly and the vendor knows it.

The third is a calendar that maps every renewal and support expiry against the audit window that precedes it, so that the preparation is finished before the trigger fires rather than after.

11.

What to do next

  1. Budget the audit as a recurring event, every 3 to 5 years per major vendor and yearly somewhere in the portfolio, with a named owner and a reserve.
  2. Build and maintain the three files: the entitlement record, the deployment data, and the position paper on contested metrics.
  3. Run the vendor's audit on yourself annually, with the vendor's own scripts and metrics, and fix what it finds while the fix is free.
  4. Fix the audit clause at the next renewal: notice, frequency, scope, tools, auditor independence, remedy pricing, and confidentiality.
  5. Treat every advisory framed review as discovery, because the soft front door gathers audit grade data without audit constraints.
  6. Control the data and pace the response when the letter arrives, the posture that settled at 30 to 50 percent of claims.
  7. Engage independent defense before the first response, the highest return move on the cycle. The audit defense practice runs the defense with you from the letter to the settlement.
12.

Frequently asked questions

How often do software vendors audit enterprises?

Most large enterprises face a formal audit or license review every 3 to 5 years from at least one major vendor, and across a full Oracle, IBM, Microsoft, and SAP portfolio, almost every year somewhere in the estate.

Oracle led the ranking at 55 to 70 percent of large enterprises audited in a three year window, with IBM at 45 to 55, Microsoft at 40 to 50, and SAP at 30 to 40.

Which vendors audit the most?

Oracle and IBM by a clear margin, driven by database options, Java, virtualization counting, and sub capacity data quality, with Microsoft and SAP following through partner led asset management engagements and annual measurements rather than blunt demands.

Broadcom VMware moved up sharply in 2025 with letters and formal audits on lapsed perpetual estates. Salesforce rarely runs a classic audit, and the hyperscalers almost never do, leaning on constant consumption and commitment reviews instead.

What triggers a software license audit?

Commercial events trigger audits: an approaching renewal or ULA certification, lapsed support, a merger or divestiture, an announced migration away from the vendor, download and telemetry signals, and missing compliance reports such as ILMT or the SAP annual measurement.

Sales territory pressure is the trigger nobody writes down. An account that has bought little in two or three years, in a region behind quota, is a candidate regardless of its compliance.

How accurate are audit claims?

Opening claims commonly ran 2 to 4 times the figure engagements eventually settled at, once each line was validated against an independent baseline. The gap between claim and settlement is a negotiation, not an accounting fact.

It is built from environment classifications, contested metric interpretations, dormant deployments priced as live, list pricing, backdated support, and scope creep. The raw discovered gap was the least predictive number in the file.

How much can audit settlements be reduced?

Buyers who controlled the data and paced the response settled at roughly 30 to 50 percent of the opening claim, while buyers who cooperated fully and fast settled far higher on identical facts.

The settlement reflects posture more than gap, which is why the preparation, the independent baseline, the owned deployment data, and the paced schedule price directly into the outcome.

What does an Oracle audit clause actually allow?

Oracle's standard master agreement allows an audit on 45 days written notice, requires the customer to cooperate and to pay any fees for excess use within 30 days of written notification, and states that Oracle is not responsible for the customer's costs of cooperating.

The same clause says the audit shall not unreasonably interfere with normal business operations, which is the buyer's handle on schedule and scope. The notice period, frequency, scope, and remedy pricing are all negotiable at renewal.

Why are software audits really run?

As revenue motions: the teams that scope, analyze, and settle the audit report into the same organization that owns the renewal, and findings convert into license purchases, cloud commitments, larger agreements, or subscriptions.

Asking what commercial outcome each mechanism serves explains audit behavior more reliably than any compliance rationale, and the report holds that lens throughout.

When should you engage audit defense help?

Before responding to the letter, not after the first finding lands: it was the highest return move across 90 to 120 defended audits, because the first response frames the scope, the data flow, and the trajectory of everything after.

Help engaged early means everything shared is shared inside a strategy. Help engaged late inherits whatever the early cooperation already conceded.

© 2026 Redress Compliance · Independent, buyer sideredresscompliance.com
Industry Recognized
500+ Enterprise Clients
$2B+ Under Advisory
11 Vendor Practices
100% Buyer Side Independent
Advisory White Paper

The full Oracle audit response playbook from the audit defense practice.

The most active vendor's sequence end to end: the scope letter, the validation pass, and the settlement mechanics that generalize.

Gated with a work email on the download page. No sales follow up you did not ask for.

Get the White Paper →
Independent, buyer side. We never share your details with vendors.
Run the audit defense readiness checklist against your estate in under five minutes.
Open the Tool → Cost Optimization →
Editorial boardroom interior

The advisor your vendors do not want.

500+ enterprise clients. 11 vendor practices. Industry recognized. One conversation can change what you pay for the next three years.

Stay ahead of Advisory pricing and contract moves.

One buyer side briefing a week. Renewal signals, discount bands, and the levers that work. No vendor spin.