Secure technology facility with controlled access entrance
IBM

US Defense Supplier. IBM audit closed 90 percent down.

The classified enclaves could not run ILMT, so the auditor priced them at theoretical maximum. A negotiated evidence protocol repriced everything.

Contact Us IBM Advisory
500+Enterprise clients
$2B+Under advisory
Industry Recognized
500+ Enterprise Clients
$2B+ Under Advisory
11 Vendor Practices
100% Buyer Side Independent

A northeastern US defense supplier faced an IBM audit where classified, air gapped networks could not run standard ILMT reporting. A negotiated alternative evidence path closed the claim 90 percent below the opening number.

Key takeaways

  • The estate: IBM Db2, WebSphere, and MQ split across corporate networks and air gapped classified enclaves.
  • The trigger: no ILMT telemetry from the enclaves, so the auditor defaulted them to full capacity.
  • The constraint: security rules barred standard scanning tools and external data flows from classified segments.
  • The defense: negotiate an alternative evidence protocol the security office could approve.
  • The outcome: the claim closed 90 percent below the opening position.
  • The lesson: restricted environments need a documented licensing evidence protocol agreed before audits, not during them.

Why did IBM audit the US defense supplier?

IBM audited the supplier because a visible share of its estate produced no compliance telemetry at all. The corporate network ran ILMT acceptably, but the classified enclaves running Db2, WebSphere, and MQ were dark by design.

From the publisher's side, dark segments read as risk. The opening claim defaulted every enclave to full capacity PVU and assumed deployment the auditor could not see.

  • Audit trigger: material estate segments with no ILMT reporting, by security design.
  • Publisher position: full capacity defaults plus assumed enclave deployment.
  • Customer reality: enclave deployment was modest, controlled, and internally documented.

Why could the supplier not just run ILMT everywhere?

Because security accreditation barred it. The enclaves prohibited unapproved agents, external connections, and data exports, which ruled out both standard ILMT operation and handing raw scan output to an external auditor.

Standard audit expectations versus enclave reality

ExpectationStandard estateAir gapped enclave
ILMT agents deployedRoutineRequires accreditation review
Telemetry exportAutomaticProhibited without sanitization
Auditor scan accessNegotiableBarred by security policy
Evidence formatTool generated reportsSanitized, attested inventories

What does IBM's sub capacity framework say about such environments?

The sub capacity terms are built around ILMT, with narrow exceptions, and restricted environments sit awkwardly inside them. That ambiguity is exactly why the evidence protocol had to be negotiated explicitly rather than assumed.

How was the claim defended without standard telemetry?

The defense negotiated an alternative evidence protocol: internally generated, security sanitized inventories of enclave deployment, attested by named officers, reconciled against the consolidated Passport Advantage entitlement baseline.

  1. Agree the evidence protocol in writing with IBM before producing any enclave data.
  2. Generate internal deployment inventories inside the enclaves under security supervision.
  3. Sanitize and attest the inventories through the security office for external release.
  4. Reconcile attested deployment against the consolidated entitlement baseline.
  5. Settle on the attested position, with the protocol documented for future audits.

Did IBM accept attested inventories instead of ILMT output?

Yes, after negotiation. Attested, methodologically documented inventories carried the claim because the alternative was an unresolvable standoff between audit demands and federal security law, which served neither side.

What was the commercial outcome for the supplier?

The audit closed 90 percent below the opening claim. The attested inventories collapsed the assumed enclave deployment, sub capacity evidence repriced the corporate estate, and the agreed protocol now governs every future audit cycle.

  • Claim reduction: 90 percent off the opening position at close.
  • Protocol secured: the alternative evidence path is now documented and reusable.
  • Forward posture: enclave inventories refresh on a standing schedule with attestation.

What should other cleared contractors take from this?

Negotiate the evidence protocol before the audit, not during it. A pre agreed path for restricted segments removes the full capacity default that otherwise prices the dark estate at its theoretical maximum.

Where the common advice on audits in classified environments is wrong

The standard advice to cleared contractors is to keep auditors entirely away from classified programs and simply absorb whatever licensing defaults result, treating the overpayment as a cost of security. We disagree. In roughly 25 to 35 IBM engagements Morten Andersen advised in 2024 to 2025, that posture left the largest preventable overpayments we recorded, because full capacity defaults priced dark segments at their theoretical maximum year after year. Security and evidence are not opposites. The buyer side move is a sanitized, attested inventory protocol agreed with the publisher in writing; it satisfies the security office, collapses the defaults, and in this case took 90 percent off the claim.

Secure corporate facility exterior with restricted access signage
Air gapped segments produce no telemetry by design, and undefended, that silence prices the estate at its theoretical maximum.

What the engagement data shows

Three cuts of our advisory engagement file frame the size of the opportunity.

90%
Below the opening claim at close
70 to 95%
Restricted segment claim cuts via evidence protocols
25 to 35
IBM engagements advised 2024 to 2025

Source: Redress Compliance advisory engagement file, 2024 to 2025.

What to do next

Five moves turn this analysis into a lower invoice on the next renewal.

A sequence you can run this quarter

  1. Inventory which estate segments cannot run standard compliance telemetry and why.
  2. Draft the alternative evidence protocol with your security office now.
  3. Propose the protocol to IBM in writing before any audit letter arrives.
  4. Consolidate Passport Advantage entitlements across all business units.
  5. Run attested enclave inventories on a standing schedule, not on demand.
  6. If a notice arrives, agree the evidence protocol before producing any data.
Cover of the IBM Audit Defense Guide white paper from Redress Compliance

White Paper · IBM

IBM Audit Defense Guide

The buyer side framework we use with Fortune 500 clients defending IBM software audits. Read it free.

Read the white paper
Need help? Try our AI agents. Ask the IBM licensing AI agent → Scoped to one vendor and one problem. Runs in your browser.

Frequently asked questions

What triggered the IBM audit at the US defense supplier?

Material estate segments produced no ILMT telemetry because security accreditation barred the tooling, and the auditor defaulted those dark segments to full capacity PVU claims.

How much was the IBM audit claim reduced?

The claim closed 90 percent below the opening position after attested enclave inventories replaced the full capacity assumptions and sub capacity evidence repriced the corporate estate.

Can ILMT run in air gapped classified networks?

Generally not in standard form. Unapproved agents, external connections, and data exports are barred, so restricted environments need a negotiated alternative evidence path instead.

Will IBM accept evidence other than ILMT reports?

Yes, by negotiation. Sanitized, attested deployment inventories with documented methodology carried this audit, and the agreed protocol now governs future cycles.

What should cleared contractors do before their next IBM audit?

Agree the alternative evidence protocol with IBM in writing before any audit, run attested inventories on a schedule, and consolidate entitlements so the baseline is ready.

Free Download

The full IBM Audit Defense Guide framework from the IBM Advisory.

The PVU and ILMT moves that close IBM audits at a fraction of the opening claim.

Used across more than five hundred enterprise engagements. Independent. Buyer side. Built for procurement leaders running the next renewal cycle.

Get the white paper →
Opens the white paper landing page. We only email you about this download.
Run a software spend health check against your IBM estate in under five minutes.
Open the Tool →
90%
Below the opening claim at close
70 to 95%
Restricted segment claim cuts via evidence protocols
25 to 35
IBM engagements advised 2024 to 2025

An estate that cannot be scanned will be priced at its theoretical maximum unless you hand the auditor a better evidence path. Build that path first.

Morten Andersen
Co Founder. Ex IBM, ex Oracle.
Deep Library

More on this topic.

IBM Advisory →
Government conference room
IBM
California Government IBM Audit
A records driven public sector defense, 85 percent cut.
7 min read
License compliance dashboard on a laptop screen
IBM
IBM ILMT and Sub Capacity Guide
The eligibility rules and the reporting discipline.
8 min read
Audit defense planning documents on a desk
IBM
IBM Audit Defense and Resolution
The notice to settlement playbook for IBM audits.
9 min read
Editorial boardroom interior

The advisor your vendors do not want.

500+ enterprise clients. 11 vendor practices. Industry recognized. One conversation can change what you pay for the next three years.

Stay ahead of IBM licensing changes.

One buyer side briefing a week. Pricing moves, audit signals, and the levers that work. No vendor spin.