Triggers, the third party auditors, the scope letter, and the first five moves that decide the outcome. Three knowledge checks along the way, and 4 clips from a senior licensing analyst.
This is a taught session, not a talking head. The instructor works through analyst grade slides, and three times the video stops on a question with four options on screen. Pause, commit to an answer, and the next slide explains which option is right and why each of the others is wrong. 4 times in the session the frame splits and a senior licensing analyst gives the view from inside real IBM negotiations, and the instructor picks the clip apart when the slides return.
The full narration of this session, section by section, for reading and reference. Guest analyst clips are marked.
Welcome to session eighteen. The letter has arrived. Everything in the previous seventeen sessions was about the years before this moment, and today is the moment itself. I want to start with the finding that reorganised how I think about audits, and it comes from roughly thirty to forty IBM audits defended between 2024 and 2026. The penalty was driven by data control rather than by genuine overuse. Not by how much software the organisation ran, but by whose numbers defined the conversation. That is a strange and quite hopeful thing to learn, because data control is something you can take. Three knowledge checks. Let's begin.
Five objectives. First, read the signals before the letter, because selection is signal driven, and commercial contraction, estate turbulence and legacy density are also your warning clock. Second, handle the first seventy two hours, which is acknowledge without admitting, escalate internally, engage counsel and an adviser, and only then write the letter that defines the perimeter. Third, answer the scope letter properly, because some requests you meet in full, some you narrow, and two you refuse in writing. Fourth, build the three artifacts, meaning a cleaned deployment inventory, a consolidated entitlement register, and the reporting evidence pack reconciled host by host. And fifth, settle into a forward deal priced independently of the claim, with release language that closes the period, because the finding should be the concession rather than the anchor.
Four numbers. Thirty five to sixty percent of the opening claim, where the buyer ran it as a negotiation, against eighty to one hundred percent for those who treated it as a compliance finding. Two to four times, the reporting collapse in practice, where missing or stale reports forced full capacity pricing across the defended period. Six to twelve, the months from notice to settlement, which tells you this is a negotiation with a long clock rather than an inspection with a deadline. And roughly twenty percent per year of licence value, the backdated support layer, which frequently exceeds the licence shortfall itself. Then the note, and it is the mechanism behind all four numbers. IBM's tooling, run on IBM's schedule, produces IBM's interpretation, and every ambiguity in raw output resolves toward the finding.
Guest analyst clip. The finding that the penalty tracks data control rather than overuse took me a while to accept, because it is not what anybody expects. You would assume the organisation running the most unlicensed software pays the most. And broadly, across a big enough sample, that is not what we see. What we see is that the organisation whose numbers arrive second pays the most. Here is the mechanism, and it is not sinister, it is just how ambiguity works. Any raw discovery output is full of things that could be read two ways. Is that installation active or is it a decommissioned binary nobody deleted. Is that host production or a test rig. Did this deployment start in 2019 or in 2022. Every one of those questions has a defensible answer in both directions, and whoever is holding the pen when the question gets asked chooses the direction. If your data arrives first, cleaned and reconciled, those ambiguities are already resolved and you are explaining a position. If their data arrives first, you are contesting one, and contesting is a great deal harder than explaining. So the practical instruction is unglamorous. Whatever else happens in the first month, your numbers should reach the table before theirs do.
Whoever is holding the pen when the ambiguity gets resolved chooses the direction. So your numbers should reach the table before theirs do. Now, how you end up on the list at all.
Three signals, on top of one routine. Commercial contraction, meaning renewals shrinking, support dropped on legacy lines, a conversion that stalled, and it selects you because an audit protects revenue that a seller no longer can. Estate turbulence, meaning acquisitions and divestitures in the last couple of years, which selects you because entitlements scramble across entities faster than anyone consolidates the paperwork, and IBM knows that. Legacy density, meaning estates heavy in WebSphere, Db2 and Tivoli lineage products, which selects you because that is exactly where the sub capacity obligations and the reporting findings live. And underneath all three, the cadence, because reviews run on a Passport Advantage cycle executed largely by third party audit firms, with selection layered on top of a routine that runs regardless. Read that table twice. Every signal on it is visible to you before it is acted on, which makes it a warning clock rather than a surprise.
Knowledge check one. You dropped support on several legacy products last year and an acquisition is still being integrated. What does that mean? A, nothing, both were sound commercial decisions. B, you have two of the three selection signals showing, so the warning clock is running. C, an audit is contractually barred while integration is in progress. D, only the acquisition matters, support decisions are invisible to IBM. Pause here. Both decisions were correct. What do they look like from the other side of the table?
The answer is B, two of the three signals. Commercial contraction and estate turbulence are both named, and both are entirely visible to IBM, because one of them is recorded in their own billing system. Answer A is right about the decisions and wrong about the consequence, and I want to be careful here, because I am not telling you to keep paying support you do not need in order to look less interesting. That would be an expensive superstition. What the signals tell you is that your probability has changed, and the correct response to a changed probability is to get the evidence pack in order, which costs you an afternoon rather than a support line.
So, the first seventy two hours, four moves in order. Hours zero to four, acknowledge: a short written acknowledgement, no admission of usage, no commitment to a specific response, routed through procurement or external counsel rather than sent by whoever happened to open the email. Hours four to twenty four, escalate internally: brief the CIO, the CFO if it is material, General Counsel and vendor management, and do not brief the IBM account team, and do not brief partners on the IBM payroll. Hours twenty four to forty eight, engage externally: external counsel and a buyer side adviser, with both engagements papered before any further communication with IBM. Hours forty eight to seventy two, the first letter and triage: a written letter requesting a defined data perimeter, with emergency reporting remediation running in parallel rather than afterwards. And freeze communication to one channel, because a helpful engineer answering a direct question is how perimeters expand for free.
Now the scope letter, and what you do with each request. Reporting for the last twenty four months, provide it, because where you are licensed sub capacity this is the exhibit that helps you and withholding it would be arguing against your own defence. A full estate scan, narrow it, providing the IBM product inventory only, because non IBM products are outside the entitlement and refusing them is both correct and expected. Cluster topology, limited, meaning enough to establish the boundary for the products in scope rather than a complete map of infrastructure that has nothing to do with IBM. Running IBM's discovery script, refuse in writing, because the scripts collect data well beyond contractual entitlement and once collected it cannot be uncollected. And direct system access, refuse in writing, because the contract does not grant it. Both refusals are written and reasoned rather than evasive, and that is precisely what makes them hold.
Guest analyst clip. Once collected, it cannot be uncollected. That is the sentence I would tattoo on the inside of a procurement team's eyelids if they let me. Because the pressure in the first fortnight is all in one direction, and it is a decent, cooperative pressure. Everybody wants to be reasonable. Nobody wants to look like they have something to hide, and refusing a request feels adversarial when the relationship has been perfectly friendly for a decade. So the script gets run, because running it seems like the fastest way to demonstrate that there is nothing to worry about. And what actually happens is that a tool built by the other party, to answer questions defined by the other party, produces a dataset covering considerably more than the contract entitles them to see, and that dataset is now the basis of the discussion permanently. There is no mechanism to withdraw it. What I say to clients is that a written, reasoned refusal is not an adversarial act, it is a normal contractual position, and it is what a competent counterparty expects. The auditors are not offended. They have received that letter many times. The only party who is ever surprised by it is the customer who did not know they could send it.
A written, reasoned refusal is a normal contractual position rather than an adversarial act. The only party surprised by it is the customer who did not know they could send it.
Knowledge check two. The auditor sends a questionnaire and a discovery script, with a two week deadline. What do you do? A, run both promptly to demonstrate good faith and speed the process up. B, refuse the script in writing, agree the perimeter first, and build your own inventory before any data leaves. C, run the script but delay the questionnaire. D, ignore both until IBM escalates. Pause here, and ask whose dataset will define the scope.
The answer is B. The scripts collect well beyond contractual entitlement and the questionnaire expands the perimeter for free, so running either first hands over the definition of scope. Answer A is the instinct of every organisation that simply wants this over with, and speed is exactly what costs the money here, because the timeline is six to twelve months and nothing you do in week one shortens it except in your own mind. Answer D is the opposite error and it is worth naming, because refusal has to be written, reasoned and prompt. Silence forfeits the argument rather than making it.
So, the three artifacts, assembled before the response deadline. A cleaned deployment inventory, with development and test separated, retired hosts documented and duplicates resolved, because raw output is exactly where deployment inflation lives. A consolidated entitlement register built from the actual contracts rather than from a portal export, which is session five done properly and then kept current. And the reporting evidence pack with coverage reconciled host by host, which is what bounds the full capacity window to the periods you genuinely cannot evidence. Present those before their tooling defines the scope, because buyers who presented reconciled data first cut findings materially against those who handed over raw output and argued afterwards. And run the same discipline annually, because the identical exercise done without a letter in the room is what makes an audit a correspondence rather than a crisis.
Guest analyst clip. I want to point at something that should be slightly annoying, in a useful way. Look at the three artifacts we just described. A cleaned deployment inventory. A consolidated entitlement register. A reporting evidence pack with coverage reconciled. Now compare that to the operating model from session ten, the quarterly close, the five numbers, the annual drill. They are the same thing. Not similar, the same. The audit response is simply the ordinary discipline, performed under time pressure, by people who are frightened, with a counterparty watching. And that observation has a genuinely useful consequence, which is that you already know exactly what an audit will ask you for, in detail, right now, today, with no letter in the building. There is no secret list. So the choice available to any organisation is not whether to do this work, because you will do it either way. It is whether to do it on a Tuesday in your own time, at your own pace, with the ability to fix what you find, or to do it in eight weeks with an auditor's deadline and every gap you discover being simultaneously discovered by somebody who will price it. Same work. Wildly different circumstances. I have never met anybody who did it the first way and regretted it.
Same work, wildly different circumstances. You already know exactly what an audit will ask for, which means the only real question is when you choose to answer it.
Now how a finding is actually built, because people imagine something more punitive than the reality. There is no separate fine. The finding is the deployed minus entitled gap, priced at list under the agreement terms, and nothing punitive is added on top. It is priced at list rather than at your discount, because the terms permit that and your discount is treated as a commercial concession that returns only in settlement, which is a deliberate asymmetry. Then support is added, backdated to first use, at roughly twenty percent of licence value per year, and that backdated layer frequently exceeds the licence shortfall itself, which surprises everybody the first time they see the arithmetic. First use dates are evidence rather than assumptions, which makes them worth contesting, because every year removed from a first use date removes a year of the backdated layer. And the reporting record bounds the window, because a demonstrably repaired control bounds the exposure period, which is why the repair happens in week one.
And then settlement, where the structure is worth more than the discount. A one time payment settles at seventy to one hundred percent of the opening claim with nothing forward to show for it, which makes it the worst available structure and it should be declined. A multi year subscription settles at thirty five to sixty percent, and it is the standard buyer side recommendation because it converts a backwards looking penalty into forward capability you were probably going to buy anyway. A trade for new business settles at twenty to forty percent, which is the best outcome available and only genuinely available where you are expanding the footprint rather than pretending to. Price the forward deal independently first, on its own merits, before the claim enters the conversation, and then let the finding be the concession that closes it. And get release language, paper that closes the audited period cleanly, because a settlement that leaves the period open has bought you considerably less than you paid for.
Knowledge check three. IBM offers to reduce a finding by sixty percent if you sign a three year commitment sized to the claim. What is the risk? A, none, a sixty percent reduction is a strong outcome. B, you are signing a forward commitment sized by the claim rather than by your telemetry, which is the classic settlement trap. C, only that three years is a long term. D, the reduction cannot be applied to backdated support. Pause here, and ask what sized the forward deal, your usage or their finding.
The answer is B. Signing a forward commitment sized by fear rather than by telemetry is the first of the three named settlement traps, and a discount on the wrong quantity is the mistake this course has been returning to since session five. Answer A is exactly how the offer is designed to feel, and there is a very simple test that cuts through it. Would you have bought this shape, at this size, if no letter had ever arrived? If the answer is no, then what you are buying is relief rather than software, and relief priced at three years of commitment is expensive relief.
Guest analyst clip. The settlement conversation is where I see otherwise excellent negotiators lose their footing, and I think the reason is emotional rather than analytical. By the time you reach settlement you have had six or nine months of this. People are tired. There is a number on the table that makes the problem disappear, and there is enormous organisational appetite to simply be finished. So a commitment gets signed that nobody would have entertained eighteen months earlier, and it gets signed by people who are individually very good at their jobs. What I try to do at that point is separate the two transactions on paper, physically, in two columns. On the left, what do we owe for the past, and what is the defensible number. On the right, what do we want to buy for the future, and what would we pay for it if no audit existed. Two columns, priced independently. And then, only then, negotiate the relationship between them. Almost always the forward column is smaller than what is being proposed, and almost always the backward column is smaller than the opening claim, and the deal that closes is better on both sides of the page. The mistake is never doing arithmetic wrong. It is letting one number do the work of two.
So, the whole defence in five moves. Control the timeline from the first letter, acknowledging through a single channel, agreeing scope in writing, and never running vendor supplied tooling before your own inventory exists. Build the three artifacts, the cleaned deployment inventory, the consolidated entitlement register, and the reporting evidence pack reconciled host by host. Dismantle the finding layer by layer, taking deployment inflation out, evidencing first use dates, and bounding the full capacity window with the coverage record. Fix the reporting immediately and document the date, because a demonstrably repaired control bounds the exposure period and trades far better than a broken one. And settle into a forward deal you priced yourself, with release language that closes the period, remembering that six to twelve months is the right calendar and compressing it only ever helps the other side.
Three sentences. Selection is signal driven on top of a routine review cycle, so commercial contraction, estate turbulence and legacy density are your warning clock, and every one of those signals is visible to you before anybody acts on it. Across roughly thirty to forty audits defended, the penalty was driven by data control rather than genuine overuse, because whoever's dataset defines the scope owns the negotiation, which is why the discovery script and the direct access request are refused in writing while your own three artifacts get built first. And a finding is the deployed minus entitled gap priced at list plus support backdated to first use at roughly twenty percent a year, settling at seventy to one hundred percent as a one time payment, thirty five to sixty as a multi year subscription, or twenty to forty traded against genuine new business, which makes the structure worth more than the discount.
Homework, about an hour, and it is a readiness check rather than an analysis. Score yourself on the three signals, contraction, turbulence and legacy density, because two out of three showing is not a prediction and it is a very good reason to spend the next hour well. Find out who would acknowledge the letter, so if a notice arrived tomorrow addressed to your CIO, who replies, and do they know not to answer anything substantive. Check the single channel exists, asking whether anybody outside a named group has a relationship with an IBM auditor or with a partner on the IBM payroll. Time the three artifacts, so deployment inventory, entitlement register and evidence pack, and how many days would each take today, honestly. And read your audit clause, asking what the agreement actually permits in terms of access, tooling and notice, because that clause is the basis of both of the written refusals.
Five guides. The audit defence playbook carries the hour by hour opening, the four phase choreography from perimeter to settlement, the data perimeter table and the five named pitfalls, and it is the one to have open when a letter actually arrives. The audit penalties guide explains what triggers a review, why findings price at list rather than at your discount, and the backdated support layer that exceeds the shortfall. And the ILMT comprehensive pillar covers the evidence pack an auditor asks for first, and why a repaired control bounds the exposure period.
The eighty two million dollar case study shows what sixty days spent on evidence rather than on negotiation actually achieves against cluster wide counting, and it is the clearest illustration of data control I can point you at. And the IBM licensing guide gives the estate view behind every finding. Next time, defending and settling a finding in detail: the ILMT gap, back maintenance, and dismantling a claim layer by layer. See you there.