The enterprise software licence compliance checklist.
Most organisations invest in licence compliance after an audit notification arrives, not before — and the outcome is worse for it. This note reorganises 60+ controls into a self-audit you run by domain: entitlement records, deployment tracking, virtualisation, users, cloud & BYOL, and SaaS. Work each table, close the highest-risk gaps first, and run an internal true-up before a vendor does.
An audit notification triggers the work that should have been routine. Continuous compliance is cheaper than the scramble — and four domains generate the largest settlements: Oracle virtualisation, SAP indirect & Digital Access, IBM ILMT, and the completeness of your asset inventory. Fix those first, then run a quarterly self-audit so gaps surface on your terms.
01 Key findings
Posture beats position. Posture is structural — the controls, processes and governance that create compliance as an ongoing state. Position is point-in-time. Organisations that focus on position only when an audit arrives discover that posture gaps made their position far worse than it needed to be.
Four domains carry most of the risk. Oracle Database virtualisation, SAP indirect access and Digital Access, IBM ILMT deployment and scan frequency, and software-asset-inventory completeness produce the largest audit settlements in the market — and are the most frequently undermanaged.
Entitlement records and deployment discovery are the foundation. A current licence register and continuous discovery underpin every other control. Without them, vendor-specific controls cannot be operated reliably.
Renewals are the most common audit trigger. Any organisation with material Oracle, SAP or IBM spend that cannot confirm its high-risk controls should close them before the next renewal cycle, not after the notification.
Run the true-up yourself. A quarterly self-assessment by IT, procurement and legal turns audit findings into managed exposure — detected and remediated before a vendor measures you.
02 Entitlement records
Every downstream control depends on knowing exactly what you are entitled to. Build one register and one contract repository, and reconcile them against what is actually deployed.
| Control | What good looks like |
|---|---|
| Central licence register | Every entitlement documented with vendor, product, licence metric, quantity, agreement number, expiry and renewal date — no deployed product without a register line. |
| Executed-agreement repository | All agreements, order forms and amendments stored under version control; legal, procurement and IT work from one current version, never a stale contract. |
| Oracle ULA schedule | Active ULA term dates confirmed and all ULA-covered products correctly identified in the schedule; deployments documented precisely because the certification count locks perpetual entitlement at term end. |
| ULA certification timing | Deployment growth monitored against the ULA term — certify early if growth has stabilised, later if it is ongoing; products outside the ULA schedule are never deployed without separate entitlement. |
| Oracle Java SE entitlement | Java SE 17+ covered by Employee-metric subscriptions or Named User Plus licences at the correct organisational count; container deployments licensed per container, not per physical host. |
| IBM Passport Advantage records | Entitlement records current and licence part numbers reconciled to ILMT Product IDs, so the paper trail matches the measured estate. |
03 Deployment tracking
You cannot defend a position you cannot see. Continuous discovery across every environment — production, development, test and DR — is the second foundation control.
| Control | What good looks like |
|---|---|
| Oracle Database inventory | Current inventory of every installation with version, edition and licensed processor count across all environments; Standard Edition 2 hosts within the 2-socket-per-licence maximum. |
| Oracle Options & Packs | Options and Packs actively disabled where not licensed — particularly Diagnostics Pack and Tuning Pack — so default installs never silently consume entitlement. |
| Oracle WebLogic options | WebLogic deployments audited for options licensing, including Coherence, SOA Suite and OEM inclusions; only licensed options in use. |
| Java SE discovery | Complete inventory of Java SE across endpoints, servers and containers via automated tooling; Java 8 update 202 and below treated as free legacy, update 211 and above as subscription-required; free builds (OpenJDK, Eclipse Temurin, Amazon Corretto) documented as Java SE-free. |
| SAP system measurement | USMM / SLAW measurement run at least quarterly with outputs retained as evidence. |
| ILMT software catalogue | Catalogue kept current so every deployed IBM product is correctly identified and Product ID mapping reflects the real estate. |
04 Virtualisation & partitioning
Virtualisation is where the largest, most technically demanding exposure sits. Oracle and IBM both price against how you partition and measure — misconfiguration here converts sub-capacity entitlement into full-capacity liability.
| Control | What good looks like |
|---|---|
| Oracle partitioning | VMware hard partitioning or approved Oracle partitioning technology correctly configured for every Oracle Database deployment on virtual infrastructure, so only approved technology limits licensable cores. |
| Oracle Processor Core Factor | The factor (0.5 for Intel/AMD, 1.0 for SPARC/Power) documented per licensed server and matched against Oracle's current Processor Core Factor Table. |
| Containerised Java | Java SE licensed per container instance, not per physical host, reflecting how Oracle counts most subscription models. |
| Windows Server edition | Standard vs Datacenter edition matched to VM density — Datacenter where unlimited VMs per licensed host are required. |
| SQL Server core licensing | Core-based licensing covers all cores on each licensed server, including virtual cores where soft partitioning is used. |
| IBM sub-capacity & ILMT | ILMT deployed before any sub-capacity entitlement is used, scanning the catalogue at least every 30 days, with audit snapshots retained for 2 years; any IBM software outside scan scope (isolated networks, cloud, containers) identified and assessed. |
Oracle virtualisation and IBM ILMT are the two controls that most often turn into eight-figure findings. Oracle applies its partitioning policy aggressively, and an organisation entitled to sub-capacity pricing but running ILMT incorrectly is exposed to full-capacity pricing on Oracle-equivalent scale. If you cannot evidence either today, treat it as the priority ahead of every other item on this page.
05 Users & access
For SAP and Microsoft, the exposure is less about deployment method and more about who is assigned what. Ghost accounts and mis-classified users are the most common findings in both estates.
| Control | What good looks like |
|---|---|
| SAP named-user classification | Classification reviewed at least quarterly so Professional, Limited Professional, Employee and other user types reflect actual system usage. |
| Inactive SAP users | Users with no login in 90+ days deactivated or reclassified — inactive users still consume entitlement in SAP's measurement. |
| Microsoft 365 reconciliation | Active M365 assignments reconciled against HR headcount at least monthly; departed employees and ghost accounts removed before they show up as findings. |
| Microsoft 365 tier fit | E5 assignments validated against actual E5 feature use, downgrading to E3 where E5 features are unused. |
| Microsoft 365 add-ons | Teams Premium, Copilot for Microsoft 365 and other add-ons assigned only to active users holding the prerequisite base licence. |
06 Cloud commitments & BYOL
Cloud risk is mostly commercial: over-commitment, under-utilisation, and BYOL licences carried into the cloud without the entitlement to support them. Track commitment pace as closely as technical compliance.
| Control | What good looks like |
|---|---|
| Oracle in the cloud | Oracle on AWS, Azure or GCP licensed correctly — BYOL at the appropriate count or cloud-native Oracle licences matching deployed instances. |
| Azure Hybrid Benefit | AHB elections documented and supported by current Software Assurance for every on-premises licence claimed; SQL Server on Azure licensed PAYG or BYOL with valid SA, with instance size matching the licence metric. |
| AWS committed spend | EDP commitment pace reviewed monthly against shortfall penalties, with Reserved Instance and Savings Plan utilisation audited so committed budget is not wasted. |
| Google Cloud CUDs | Committed Use Discount coverage aligned to sustained workloads, avoiding stranded commitment on volatile ones. |
| Cloud marketplace BYOL | Marketplace purchases reviewed for separate BYOL licence obligations distinct from cloud consumption. |
07 SaaS & subscriptions
SaaS and subscription models introduce indirect access and renewal-window exposure. SAP Digital Access and Microsoft NCE terms are the two that most often surprise buyers.
| Control | What good looks like |
|---|---|
| SAP indirect-access map | Every third-party system that reads from or writes to SAP via API, interface or integration middleware mapped — including indirect users who access SAP data through CRM, CPQ or portal applications. |
| SAP Digital Access | Document-generating integrations (sales orders, purchase orders, production orders, deliveries) identified and their document volumes quantified; the Digital Access Adoption Programme (DAAP) reviewed to convert exposure to named document licences at preferential pricing. |
| RISE with SAP terms | RISE contracts confirmed to include Digital Access terms that match your real integration footprint. |
| Microsoft NCE terms | New Commerce Experience auto-renewal dates and cancellation windows tracked to avoid unwanted renewals at full price. |
08 Running an internal true-up
The checklist is designed for quarterly self-assessment by IT, procurement and legal. It will not tell you whether you are compliant — that requires measurement against your specific agreements — but it will tell you whether your governance is structured to detect and manage issues before they become findings, and whether your documentation is sufficient to defend your position when an audit arrives.
Run it as an internal true-up: work each domain table, measure the high-risk controls against your entitlements, and produce a documented compliance-position report for every major vendor at least annually. Treat critical controls as the minimum viable posture and advanced controls as the full standard for areas of significant exposure.
Concentrate the first true-up on the four domains that generate the largest audit settlements: Oracle Database virtualisation, SAP indirect access and Digital Access exposure, IBM ILMT deployment and scan frequency, and software-asset-inventory completeness. Any organisation with material Oracle, SAP or IBM spend that cannot confirm these controls should engage advisory support before its next renewal cycle — renewals are the most common audit trigger.
09 Compliance framework
Vendor-specific controls only work on top of organisational infrastructure. These four structural controls turn point-in-time fixes into sustained posture.
Named ownership
Designate a Software Asset Manager or team with clear accountability for licence compliance. Compliance without ownership is compliance in name only, and every other control degrades without it.
Single source of truth
A centralised licence register plus a versioned contract repository, accessible to legal, procurement and IT. Many compliance failures trace back to teams operating on the wrong version of an agreement.
Change-management gate
A mandatory licence impact assessment for any change affecting licensed deployment — virtualisation changes, server migrations, M&A integrations — with a software-licence due-diligence workstream on every acquisition.
Audit-response readiness
A documented protocol for when a notification arrives: designated contacts, legal-counsel engagement, communication governance, and a procurement team briefed on the triggers that renewals and M&A can create.
10 Prioritise & act
Not all controls carry equal risk. Sequence remediation by exposure, not by convenience.
Oracle Database virtualisation compliance, SAP indirect access and Digital Access exposure, IBM ILMT deployment and scan frequency, and software-asset-inventory completeness — the four areas behind the largest settlements and the most undermanaged.
Microsoft 365 user reconciliation and true-up preparation, cloud committed-spend tracking, contract-repository completeness, and change-management licence gates — achievable in-house but reliant on consistent process discipline.
Governance documentation, the audit-response protocol, M&A licence due diligence, and annual formal reconciliations — the structural controls that make point-in-time fixes into sustained posture.
Is your licence position audit-ready?
Our audit defence practice runs an independent compliance assessment across Oracle, SAP, Microsoft and IBM — finding exposure before vendors do and building the governance that keeps you protected year-round.
The Licensing Edge
Weekly vendor and licensing intelligence for enterprise IT leaders. 3,000+ subscribers.