Licenses bought by acquired companies never migrated into the main entitlement site, so deployments the buyer had already paid for were counted as unlicensed
The estate works fine operationally. Its records are what fail the audit, and records are the cheapest thing in the whole matter to fix.
Prepared by Redress Compliance · August 19, 2026 · IBM audit matters. 25 to 35 matters worked, 2024 to 2025.
Executive summary
Acquisition entitlements lost: licenses bought by acquired companies never migrated into the main site, so deployments looked unlicensed to an auditor who could not see them.
Reporting coverage partial: agents reached the data centre but missed depot and warehouse edge servers, which triggered full capacity counts on every one of them.
Middleware sprawl: integration stacks grew node by node for years with nobody reconciling deployments against entitlements.
Every move in the defense generalizes. Consolidate entitlements before the auditor counts, restore reporting coverage with historical evidence, and remove dead installs with change records.
Why was the opening number so high?
Three compounding effects, and none of them was a finding about genuine overuse. The auditor priced what it could see, and it could not see most of the entitlement.
Three things that inflated it
- Full capacity counting: edge servers without reporting agents were assessed at full physical capacity.
- Invisible entitlements: acquired company licenses sat in unlinked sites the auditor never saw.
- List price math: every gap was priced at list with back maintenance added on top.
The estate had grown through acquisition
License records were scattered across three legacy entitlement sites nobody had consolidated. The sub capacity terms that govern the counting are published at the sub capacity terms.
What did the defense sequence look like?
Four moves in order, each one narrowing the number the next move worked against. The sequence is what produced the result, not any single argument.
| Stage | Exposure position | What moved it | What it required |
|---|---|---|---|
| Auditor opening | 100 percent baseline | Full capacity counts plus list pricing | Nothing from the buyer |
| After entitlement consolidation | Roughly 40 percent | Acquired site licenses surfaced | Linking three legacy sites |
| After reporting remediation | Roughly 15 percent | Sub capacity restored on edge servers | Historical hypervisor data |
| After deployment cleanup | Roughly 10 percent | Dead installs removed with evidence | Change records as proof |
| Settled | 7 percent | Forward purchase, back maintenance waived | A commercial close |
Consolidation moved the most, and cost nothing
Linking the three legacy sites surfaced entitlements covering most flagged deployments. The licenses had been bought and paid for years earlier; they were simply not visible from where the auditor was looking. The site structure is described on the programme pages.
The remediation was retroactive, not prospective
Agents reached the warehouse edge and historical hypervisor data supported a retroactive sub capacity argument, per the requirements in the metric tool documentation.
The IBM audit defense checklist
The consolidation sequence, the reporting evidence, and the buyer side moves from notice to settlement.
Get the brief →What 25 to 35 IBM audit matters showed
Across roughly 25 to 35 IBM audit matters Fredrik Filipsson worked between 2024 and 2025, logistics and transport estates shared a distinct risk profile: lean teams, acquisition history and heavy middleware. Three patterns recur.
- Acquisition entitlements lost: licenses bought by acquired companies never migrated into the main site, so deployments looked unlicensed.
- Reporting coverage partial: agents reached the data centre but missed depot and warehouse edge servers, triggering full capacity counts.
- Middleware sprawl: integration stacks grew node by node for years with nobody reconciling deployments against entitlements.
The estate works fine operationally. Its records are what fail the audit, and records are the cheapest thing in the matter to fix.
- Your agreements decoded into plain English before the auditor interprets them for you
- Entitlements, caps and protections verified across your whole contract portfolio
- A defensible position paper generated in minutes rather than weeks
Why are acquisitive estates exposed?
Because acquisition moves the deployment faster than it moves the paperwork. The servers arrive on day one and the entitlement records arrive whenever somebody gets to them, which is often never.
Three conditions that compound
- Lean teams with no dedicated entitlement owner.
- An acquisition history that scattered records across separate sites.
- Middleware that grew node by node over a decade.
The cross vendor version of the same response sequence sits in the software audit defense playbook.
The edge is where the reporting stops
Depot and warehouse servers sit outside the data centre and outside the tooling that covers it. That gap is invisible until an auditor prices every uncovered core at full capacity.
Watch the briefing · 5:44The Audit Is the Sales CallWhy the timing of an audit is commercial rather than compliance driven, and what reporting hygiene decides before anybody argues.
What did the settlement structure look like?
A small forward purchase at a negotiated discount, back maintenance waived in writing, and a remediation commitment with dates attached.
Both sides got what they actually needed
The vendor books new business; the buyer pays for go forward value instead of penalties. That trade is available in most matters and it is rarely the shape the opening letter proposes.
Waived in writing, not implied
Back maintenance waived verbally is back maintenance that reappears. The framework governing the agreement sits in the published programme licence agreement, and the settlement language belongs against it. The negotiation sequence sits in the settlement strategy guide.
Where the common advice on audit exposure is wrong
The common advice is to treat a large opening claim as a measurement of real exposure and budget against it. We disagree.
The opening number measures visibility, not usage
Entitlement consolidation alone took the position from 100 percent to roughly 40 percent, and nothing about the deployment changed. The licenses had been bought years earlier and were simply invisible from where the auditor stood.
The buyer side move is to consolidate entitlement sites before the auditor counts, restore reporting coverage with historical evidence, remove dead installs with change records, and close commercially rather than punitively. The full method sits in the audit defense playbook.
What the matter measured, opening to settlement
Two cuts of the exposure walk, and neither depended on disputing a single technical finding.
Achieved through entitlement consolidation, reporting remediation and deployment cleanup, in that order.
Left behind by acquisitions and never linked, which is what made paid for licenses invisible to the auditor.
The largest single move was administrative. That is the finding that transfers to any estate with an acquisition history.
Your first five moves
- Consolidate every legacy entitlement site before an auditor counts, because that move alone took this matter from 100 percent to roughly 40.
- Extend reporting coverage to depot and edge servers, since agents that stop at the data centre leave every uncovered core priced at full capacity.
- Keep historical hypervisor data, which is what supports a retroactive sub capacity argument rather than a prospective one.
- Remove decommissioned and duplicate installs with change records as proof, because an install removed without evidence is worse than one left in place.
- Close commercially, with back maintenance waived in writing. The audit defense practice runs the consolidation before the letter arrives, which is the only sequence that helps.
Frequently asked questions
Why do acquisitive estates fail audits?
Because acquisition moves the deployment faster than the paperwork. The servers arrive on day one and the entitlement records often never migrate at all.
What does the opening number actually measure?
Visibility rather than usage. Entitlement consolidation alone took this matter from 100 percent to roughly 40, with no change to the deployment.
How much did consolidation recover?
Roughly 60 percentage points of the opening position. The licenses had been bought years earlier and were invisible from where the auditor was looking.
Why were the edge servers so expensive?
Because reporting agents reached the data centre and stopped. Every uncovered core was then assessed at full physical capacity rather than at sub capacity.
Can sub capacity be argued retroactively?
With historical hypervisor data, yes. That evidence is what supports a retroactive argument rather than a prospective commitment.
What is middleware sprawl?
Integration stacks that grew node by node over a decade with nobody reconciling deployments against entitlements. It works operationally and fails on paper.
How were dead installs removed?
With change records as proof. An install removed without evidence is worse than one left in place, because it looks like concealment.
What did the settlement look like?
A small forward purchase at a negotiated discount, back maintenance waived in writing, and a remediation commitment with dates attached.
Why does that shape work for both sides?
The vendor books new business and the buyer pays for go forward value instead of penalties. It is rarely the shape the opening letter proposes.
Does any of this transfer to other estates?
All of it. Consolidate entitlements before the count, restore reporting coverage with historical evidence, remove dead installs with records, and close commercially.