Research Note · Compliance · Audit

The enterprise software licence compliance checklist.

Most organisations invest in licence compliance after an audit notification arrives, not before — and the outcome is worse for it. This note reorganises 60+ controls into a self-audit you run by domain: entitlement records, deployment tracking, virtualisation, users, cloud & BYOL, and SaaS. Work each table, close the highest-risk gaps first, and run an internal true-up before a vendor does.

By James Hill-WoodUpdated Mar 20269 min readAudit Defence cluster
Bottom line

An audit notification triggers the work that should have been routine. Continuous compliance is cheaper than the scramble — and four domains generate the largest settlements: Oracle virtualisation, SAP indirect & Digital Access, IBM ILMT, and the completeness of your asset inventory. Fix those first, then run a quarterly self-audit so gaps surface on your terms.

01 Key findings

  1. Posture beats position. Posture is structural — the controls, processes and governance that create compliance as an ongoing state. Position is point-in-time. Organisations that focus on position only when an audit arrives discover that posture gaps made their position far worse than it needed to be.

  2. Four domains carry most of the risk. Oracle Database virtualisation, SAP indirect access and Digital Access, IBM ILMT deployment and scan frequency, and software-asset-inventory completeness produce the largest audit settlements in the market — and are the most frequently undermanaged.

  3. Entitlement records and deployment discovery are the foundation. A current licence register and continuous discovery underpin every other control. Without them, vendor-specific controls cannot be operated reliably.

  4. Renewals are the most common audit trigger. Any organisation with material Oracle, SAP or IBM spend that cannot confirm its high-risk controls should close them before the next renewal cycle, not after the notification.

  5. Run the true-up yourself. A quarterly self-assessment by IT, procurement and legal turns audit findings into managed exposure — detected and remediated before a vendor measures you.

02 Entitlement records

Every downstream control depends on knowing exactly what you are entitled to. Build one register and one contract repository, and reconcile them against what is actually deployed.

ControlWhat good looks like
Central licence registerEvery entitlement documented with vendor, product, licence metric, quantity, agreement number, expiry and renewal date — no deployed product without a register line.
Executed-agreement repositoryAll agreements, order forms and amendments stored under version control; legal, procurement and IT work from one current version, never a stale contract.
Oracle ULA scheduleActive ULA term dates confirmed and all ULA-covered products correctly identified in the schedule; deployments documented precisely because the certification count locks perpetual entitlement at term end.
ULA certification timingDeployment growth monitored against the ULA term — certify early if growth has stabilised, later if it is ongoing; products outside the ULA schedule are never deployed without separate entitlement.
Oracle Java SE entitlementJava SE 17+ covered by Employee-metric subscriptions or Named User Plus licences at the correct organisational count; container deployments licensed per container, not per physical host.
IBM Passport Advantage recordsEntitlement records current and licence part numbers reconciled to ILMT Product IDs, so the paper trail matches the measured estate.

03 Deployment tracking

You cannot defend a position you cannot see. Continuous discovery across every environment — production, development, test and DR — is the second foundation control.

ControlWhat good looks like
Oracle Database inventoryCurrent inventory of every installation with version, edition and licensed processor count across all environments; Standard Edition 2 hosts within the 2-socket-per-licence maximum.
Oracle Options & PacksOptions and Packs actively disabled where not licensed — particularly Diagnostics Pack and Tuning Pack — so default installs never silently consume entitlement.
Oracle WebLogic optionsWebLogic deployments audited for options licensing, including Coherence, SOA Suite and OEM inclusions; only licensed options in use.
Java SE discoveryComplete inventory of Java SE across endpoints, servers and containers via automated tooling; Java 8 update 202 and below treated as free legacy, update 211 and above as subscription-required; free builds (OpenJDK, Eclipse Temurin, Amazon Corretto) documented as Java SE-free.
SAP system measurementUSMM / SLAW measurement run at least quarterly with outputs retained as evidence.
ILMT software catalogueCatalogue kept current so every deployed IBM product is correctly identified and Product ID mapping reflects the real estate.

04 Virtualisation & partitioning

Virtualisation is where the largest, most technically demanding exposure sits. Oracle and IBM both price against how you partition and measure — misconfiguration here converts sub-capacity entitlement into full-capacity liability.

ControlWhat good looks like
Oracle partitioningVMware hard partitioning or approved Oracle partitioning technology correctly configured for every Oracle Database deployment on virtual infrastructure, so only approved technology limits licensable cores.
Oracle Processor Core FactorThe factor (0.5 for Intel/AMD, 1.0 for SPARC/Power) documented per licensed server and matched against Oracle's current Processor Core Factor Table.
Containerised JavaJava SE licensed per container instance, not per physical host, reflecting how Oracle counts most subscription models.
Windows Server editionStandard vs Datacenter edition matched to VM density — Datacenter where unlimited VMs per licensed host are required.
SQL Server core licensingCore-based licensing covers all cores on each licensed server, including virtual cores where soft partitioning is used.
IBM sub-capacity & ILMTILMT deployed before any sub-capacity entitlement is used, scanning the catalogue at least every 30 days, with audit snapshots retained for 2 years; any IBM software outside scan scope (isolated networks, cloud, containers) identified and assessed.
Highest-risk gaps

Oracle virtualisation and IBM ILMT are the two controls that most often turn into eight-figure findings. Oracle applies its partitioning policy aggressively, and an organisation entitled to sub-capacity pricing but running ILMT incorrectly is exposed to full-capacity pricing on Oracle-equivalent scale. If you cannot evidence either today, treat it as the priority ahead of every other item on this page.

05 Users & access

For SAP and Microsoft, the exposure is less about deployment method and more about who is assigned what. Ghost accounts and mis-classified users are the most common findings in both estates.

ControlWhat good looks like
SAP named-user classificationClassification reviewed at least quarterly so Professional, Limited Professional, Employee and other user types reflect actual system usage.
Inactive SAP usersUsers with no login in 90+ days deactivated or reclassified — inactive users still consume entitlement in SAP's measurement.
Microsoft 365 reconciliationActive M365 assignments reconciled against HR headcount at least monthly; departed employees and ghost accounts removed before they show up as findings.
Microsoft 365 tier fitE5 assignments validated against actual E5 feature use, downgrading to E3 where E5 features are unused.
Microsoft 365 add-onsTeams Premium, Copilot for Microsoft 365 and other add-ons assigned only to active users holding the prerequisite base licence.

06 Cloud commitments & BYOL

Cloud risk is mostly commercial: over-commitment, under-utilisation, and BYOL licences carried into the cloud without the entitlement to support them. Track commitment pace as closely as technical compliance.

ControlWhat good looks like
Oracle in the cloudOracle on AWS, Azure or GCP licensed correctly — BYOL at the appropriate count or cloud-native Oracle licences matching deployed instances.
Azure Hybrid BenefitAHB elections documented and supported by current Software Assurance for every on-premises licence claimed; SQL Server on Azure licensed PAYG or BYOL with valid SA, with instance size matching the licence metric.
AWS committed spendEDP commitment pace reviewed monthly against shortfall penalties, with Reserved Instance and Savings Plan utilisation audited so committed budget is not wasted.
Google Cloud CUDsCommitted Use Discount coverage aligned to sustained workloads, avoiding stranded commitment on volatile ones.
Cloud marketplace BYOLMarketplace purchases reviewed for separate BYOL licence obligations distinct from cloud consumption.

07 SaaS & subscriptions

SaaS and subscription models introduce indirect access and renewal-window exposure. SAP Digital Access and Microsoft NCE terms are the two that most often surprise buyers.

ControlWhat good looks like
SAP indirect-access mapEvery third-party system that reads from or writes to SAP via API, interface or integration middleware mapped — including indirect users who access SAP data through CRM, CPQ or portal applications.
SAP Digital AccessDocument-generating integrations (sales orders, purchase orders, production orders, deliveries) identified and their document volumes quantified; the Digital Access Adoption Programme (DAAP) reviewed to convert exposure to named document licences at preferential pricing.
RISE with SAP termsRISE contracts confirmed to include Digital Access terms that match your real integration footprint.
Microsoft NCE termsNew Commerce Experience auto-renewal dates and cancellation windows tracked to avoid unwanted renewals at full price.

08 Running an internal true-up

The checklist is designed for quarterly self-assessment by IT, procurement and legal. It will not tell you whether you are compliant — that requires measurement against your specific agreements — but it will tell you whether your governance is structured to detect and manage issues before they become findings, and whether your documentation is sufficient to defend your position when an audit arrives.

Run it as an internal true-up: work each domain table, measure the high-risk controls against your entitlements, and produce a documented compliance-position report for every major vendor at least annually. Treat critical controls as the minimum viable posture and advanced controls as the full standard for areas of significant exposure.

Where the settlements come from

Concentrate the first true-up on the four domains that generate the largest audit settlements: Oracle Database virtualisation, SAP indirect access and Digital Access exposure, IBM ILMT deployment and scan frequency, and software-asset-inventory completeness. Any organisation with material Oracle, SAP or IBM spend that cannot confirm these controls should engage advisory support before its next renewal cycle — renewals are the most common audit trigger.

09 Compliance framework

Vendor-specific controls only work on top of organisational infrastructure. These four structural controls turn point-in-time fixes into sustained posture.

Control 01

Named ownership

Designate a Software Asset Manager or team with clear accountability for licence compliance. Compliance without ownership is compliance in name only, and every other control degrades without it.

Control 02

Single source of truth

A centralised licence register plus a versioned contract repository, accessible to legal, procurement and IT. Many compliance failures trace back to teams operating on the wrong version of an agreement.

Control 03

Change-management gate

A mandatory licence impact assessment for any change affecting licensed deployment — virtualisation changes, server migrations, M&A integrations — with a software-licence due-diligence workstream on every acquisition.

Control 04

Audit-response readiness

A documented protocol for when a notification arrives: designated contacts, legal-counsel engagement, communication governance, and a procurement team briefed on the triggers that renewals and M&A can create.

10 Prioritise & act

Not all controls carry equal risk. Sequence remediation by exposure, not by convenience.

Address now
Highest priority

Oracle Database virtualisation compliance, SAP indirect access and Digital Access exposure, IBM ILMT deployment and scan frequency, and software-asset-inventory completeness — the four areas behind the largest settlements and the most undermanaged.

This quarter
Medium priority

Microsoft 365 user reconciliation and true-up preparation, cloud committed-spend tracking, contract-repository completeness, and change-management licence gates — achievable in-house but reliant on consistent process discipline.

Ongoing
Maintenance

Governance documentation, the audit-response protocol, M&A licence due diligence, and annual formal reconciliations — the structural controls that make point-in-time fixes into sustained posture.

Is your licence position audit-ready?

Our audit defence practice runs an independent compliance assessment across Oracle, SAP, Microsoft and IBM — finding exposure before vendors do and building the governance that keeps you protected year-round.

Request an assessment →

The Licensing Edge

Weekly vendor and licensing intelligence for enterprise IT leaders. 3,000+ subscribers.