The audit is a revenue motion, and the settlement tracks preparation
A software audit is a revenue motion, not a neutral compliance check: the teams that scope, analyze, and settle it report into the same organization that owns the renewal, and the finding is the opening move in a sale. Across the audits we defended, the final settlement tracked the buyer's preparation far more closely than the size of the discovered gap, which reframes the whole discipline as something that begins long before the letter arrives.
Prepared by Redress Compliance · August 8, 2026 · Cross vendor advisory. Based on 90 to 120 software audits defended 2024 to 2025.
Executive summary
Expect a formal audit every 3 to 5 years from at least one major, and yearly somewhere in the estate.
Most large enterprises face a formal audit or license review every 3 to 5 years from at least one major vendor, and across a full Oracle, IBM, Microsoft.
And SAP portfolio the practical answer is almost every year somewhere in the estate: the frequency clusters around the vendors with the most complex metrics and the most to gain, because complexity is where unlicensed use hides and where a claim is easiest to build.
The vendor ranking is stable, and four names drive it.
In a three year window, Oracle audited 55 to 70 percent of large enterprises, IBM 45 to 55, Microsoft 40 to 50, and SAP 30 to 40, with Broadcom VMware at 20 to 30, Salesforce at 15 to 25, and the hyperscalers almost never running a formal license audit.
Leaning on consumption and commitment reviews instead.
Oracle and IBM lead on database options, Java, virtualization counting, and sub capacity data quality; Microsoft and SAP usually arrive framed as advisory or asset management reviews rather than blunt legal demands.
Opening claims ran 2 to 4 times the settlement, and the gap is the negotiation. Opening claims commonly ran 2 to 4 times the figure the engagement eventually settled at once each line was validated against an independent baseline.
And the split was posture shaped: buyers who controlled the data and paced the response settled at roughly 30 to 50 percent of the opening claim, while buyers who cooperated fully and fast settled far higher.
The gap between claim and settlement is a negotiation, never an accounting fact, and the raw discovered gap is the least predictive number in the file.
The defense begins before the letter, and the highest return move is early help.
The pre letter posture is entitlement records maintained, deployment data owned, and a clear position on the contested metrics, virtualization boundaries, sub capacity rules, and indirect access, established before anyone asks: engaging independent audit defense before responding.
Not after the first finding lands, was the highest return move across the file, because everything shared after that point is shared inside a strategy rather than volunteered into a claim.
The frequency ranking, over a three year window
| Vendor | Share formally audited in 3 years | What drives it |
|---|---|---|
| Oracle | 55 to 70 percent | Database options, Java, and virtualization counting |
| IBM | 45 to 55 percent | Sub capacity rules and metric tool data quality |
| Microsoft | 40 to 50 percent | Usually framed as a SAM engagement, not a demand |
| SAP | 30 to 40 percent | Advisory framed reviews, indirect access underneath |
| Broadcom VMware and Salesforce | 20 to 30 and 15 to 25 percent | Rising post acquisition, and rare respectively |
| The hyperscalers | Rare formal audits | Constant consumption and commitment reviews instead |
The lens that explains the behavior: ask what commercial outcome each mechanism serves.
The teams that run the audit report into the organization that owns the renewal, the finding converts into a purchase, a cloud commitment, a bigger agreement, or a subscription, and the ranking is stable across years because the vendors with the most complex metrics have the most claims to build.
Read every frequency band, cost band, and trigger through that question and the behavior predicts itself.
The posture that halves the claim
- Control the data: the buyer runs the collection against agreed scope and validates every line against an independent baseline before anything is conceded.
- Pace the response: the schedule is the buyer's to propose, and the audits that ran on the vendor's clock settled closest to the opening claim.
- Never cooperate fully and fast: the file's clearest anti pattern, full speed cooperation settling far above the paced engagements on identical facts.
- Hold the contested metric positions: virtualization boundaries, sub capacity conditions, and indirect access definitions decided most of the 2 to 4 times inflation.
- Engage defense before responding: the highest return move on the cycle, because the first response frames everything that follows.
The Oracle audit response playbook
The most active vendor's sequence end to end: the scope letter, the validation pass, and the settlement mechanics that generalize.
Get the white paper →The defense that begins before the letter
The pre letter baseline is three files maintained continuously: the entitlement record, contracts, certificates, and support history reconstructed and current; the deployment data, owned internally rather than discovered by the vendor's scripts first.
And the position paper on the contested metrics, where the estate stands on virtualization counting, sub capacity conditions, and indirect access before anyone asks.
The vendor by vendor mechanics run through the practice, the Oracle sequence in the audit mechanics guide and the Oracle audit guide, the IBM reconciliation in the ILMT exposure report, the SAP five pillar framework in the SAP audit defense framework, and the soft audit front doors.
The reviews framed as advisory, in each vendor's file, because the voluntary review that gathers audit grade data without audit constraints is the pattern that repeats everywhere.
- Percentile standing for your exact deal size and industry, from real closed transactions
- Scenario simulation before the call: test alternative terms and see the financial impact of each
- A negotiation playbook, talking points, and a two page executive brief on day one
What we saw across audit defenses, 2024 to 2025
Across roughly 90 to 120 software audits we defended for enterprise clients between 2024 and 2025, the final settlement tracked the buyer's preparation far more closely than the size of the discovered gap:
Opening claims against eventual settlements, once each line met an independent baseline.
Oracle, IBM, Microsoft, and SAP driving the large majority, hyperscalers almost none.
The budgeting translation for finance: the audit is a recurring operating event, not a tail risk, arriving from at least one major vendor every 3 to 5 years and from somewhere in the portfolio annually, and the settlement variance.
30 to 50 percent of the claim for the prepared against far higher for the cooperative, prices the preparation directly.
The bands are planning ranges rather than quotes, and the pattern over the decimal is the report's whole point: posture beats gap, the defense predates the letter, and the first response, framed by independent help or volunteered in good faith, sets the trajectory everything after follows.
Your first five moves
- Budget the audit as a recurring event, every 3 to 5 years per major vendor and yearly somewhere in the portfolio.
- Maintain the three files continuously: entitlements, deployment data, and the contested metric positions.
- Control the data and pace the response, the posture that settled at 30 to 50 percent of claims.
- Treat advisory framed reviews as discovery, since the soft front door gathers audit grade data without audit constraints.
- Engage independent defense before the first response, the highest return move on the cycle. The cost optimization practice runs the defense with you.
Frequently asked questions
How often do software vendors audit enterprises?
Most large enterprises face a formal audit or license review every 3 to 5 years from at least one major vendor, and across a full Oracle, IBM, Microsoft, and SAP portfolio, almost every year somewhere in the estate.
Oracle led the ranking at 55 to 70 percent of large enterprises audited in a three year window, with IBM at 45 to 55, Microsoft at 40 to 50, and SAP at 30 to 40.
Which vendors audit the most?
Oracle and IBM by a clear margin, driven by database options, Java, virtualization counting, and sub capacity data quality, with Microsoft and SAP following through partner led asset management engagements rather than blunt demands.
Salesforce rarely runs a classic audit, and the hyperscalers almost never do, leaning on constant consumption and commitment reviews instead.
How accurate are audit claims?
Opening claims commonly ran 2 to 4 times the figure engagements eventually settled at, once each line was validated against an independent baseline: the gap between claim and settlement is a negotiation, not an accounting fact, built from environment classifications, contested metric interpretations.
And dormant deployments priced as live.
The raw discovered gap was the least predictive number in the file.
How much can audit settlements be reduced?
Buyers who controlled the data and paced the response settled at roughly 30 to 50 percent of the opening claim, while buyers who cooperated fully and fast settled far higher on identical facts.
The settlement reflects posture more than gap, which is why the preparation, the independent baseline, the owned deployment data, and the paced schedule, prices directly into the outcome.
Why are software audits really run?
As revenue motions: the teams that scope, analyze, and settle the audit report into the same organization that owns the renewal, and findings convert into license purchases, cloud commitments, larger agreements, or subscriptions.
Asking what commercial outcome each mechanism serves explains audit behavior more reliably than any compliance rationale, and the report holds that lens throughout.
When should you engage audit defense help?
Before responding to the letter, not after the first finding lands: it was the highest return move across 90 to 120 defended audits, because the first response frames the scope, the data flow, and the trajectory of everything after.
Help engaged early means everything shared is shared inside a strategy; help engaged late inherits whatever the early cooperation already conceded.