Dismantling a claim layer by layer, the reporting gap, back maintenance, and the paper that closes the period. Three knowledge checks along the way, and 4 clips from a senior licensing analyst.
This is a taught session, not a talking head. The instructor works through analyst grade slides, and three times the video stops on a question with four options on screen. Pause, commit to an answer, and the next slide explains which option is right and why each of the others is wrong. 4 times in the session the frame splits and a senior licensing analyst gives the view from inside real IBM negotiations, and the instructor picks the clip apart when the slides return.
The full narration of this session, section by section, for reading and reference. Guest analyst clips are marked.
Welcome to session nineteen. Last time the letter arrived and we controlled the opening. Today the number arrives, and I want to reframe it before we do anything else. An opening claim is not a fact. It is a model, built from assumptions about periods the auditor could not see, and models lose to better evidence rather than to better arguments. That distinction sounds academic and it is worth several million dollars in the file behind this session. Negotiating a discount validates the model. Contesting the base replaces it. Three knowledge checks. Let's begin.
Five objectives. First, treat the claim as a model, built on assumptions about what the auditor could not see. Second, take the inflation out first, meaning non production, decommissioned installs, duplicates and misidentified discoveries, before anybody discusses a rate or a structure. Third, bound the full capacity window with the coverage record, because the exposure is only the periods you genuinely cannot evidence rather than the whole term. Fourth, price back maintenance separately, because support backdated to first use at roughly twenty percent of licence value a year frequently exceeds the shortfall it sits on top of. And fifth, close the period on paper, with release language that ends the audited period cleanly, because a settlement that leaves it open has bought you less than you paid for.
Four numbers from the defended file. Eighty five to ninety six percent, how far opening claims compressed where the sub capacity evidence trail could be rebuilt for the disputed quarters. Eight of ten, the cases where full capacity claims collapsed once reporting was reconstructed for the periods in dispute. Sixty days, the first two months of one defence, spent on evidence rather than on negotiation, before any number was discussed at all. And roughly twenty percent per year of licence value, the backdated support layer, which frequently exceeds the licence shortfall itself. And then the note, which is the sentence to carry into any settlement conversation. Negotiating a discount validates the model. Contesting the base replaces it. Those are two different pieces of work, and only one of them changes the size of the claim.
Guest analyst clip. I want to describe what an opening claim actually is, because the psychology of receiving one gets in the way of understanding it. It arrives as a document, with a number, from a professional firm, and it looks like a finding. It reads like an accountant telling you what you owe. And that framing is doing an enormous amount of work, because what you have actually received is a first position, constructed under uncertainty, by people who had to make a decision every time the data was ambiguous. And every one of those decisions went in one direction. Not dishonestly, I want to be clear about that. If you cannot tell whether an installation was active, you count it. If you cannot tell when it started, you assume the earliest plausible date. If you cannot see coverage for a quarter, you price it at full capacity. Each of those is a defensible choice in isolation. Stacked, they produce a number that is much larger than the defensible one, and the only thing that reverses them is evidence. So when I open one of these documents, I do not read it as an accusation. I read it as a list of the assumptions somebody had to make, and my job is to replace as many of them as I can with facts.
A list of the assumptions somebody had to make, and the job is replacing them with facts. So here are the four places those assumptions live.
A claim is four numbers stacked, and each is contestable. The deployment layer assumes everything discovered is a live licensable deployment, and what removes it is a cleaned inventory covering non production, decommissioned software and duplicates. The boundary layer assumes the whole host or cluster is in scope, and what removes it is topology and mobility history showing what the workload could actually reach. The period layer assumes full capacity applies across the entire term, and what removes it is the coverage record, bounding the exposure to the unevidenced quarters only. And the arrears layer assumes support is owed from first use at list, and what removes it is evidenced first use dates plus a separate negotiation on the layer itself. Then the note, which is why the order matters. Work them in that sequence, because every layer you remove shrinks the layers below it, since arrears are calculated on a licence gap you have already made smaller.
Knowledge check one. You could argue the claim is unfair, or produce evidence that removes hosts from it. Which is worth more? A, the fairness argument, because it addresses the relationship. B, the evidence, because negotiating a discount validates the model while contesting the base replaces it. C, they are equivalent if the final number is the same. D, neither, settlements are decided by spend history. Pause here, and ask which one changes the size of the claim rather than the price of it.
The answer is B, the evidence. The claim is a model and models lose to better evidence. Answer C is the one worth examining properly, because in a single negotiation the final numbers might genuinely look similar, and they are still not equivalent. A discount is a concession, granted this time, and concessions can be withdrawn at the next conversation. A corrected base is a fact. It stays corrected, it shapes every subsequent discussion you have with that vendor, and nobody has to grant it to you again. You are choosing between borrowing a number and owning one.
So, layer one, deployment inflation and where it hides. Non production counted as production, because development, test and sandbox environments carry their own terms, and treating them as production is the single most common inflation in a raw discovery set. Decommissioned software still installed, meaning binaries left on a host after an application retired, and installed counts, which is why removal is a defence as well as a saving. Duplicates and misidentified discoveries, the same instance seen twice or a component identified as a full product, which is the catalog problem from session eight arriving as a claim instead of as an invoice. Bundled components counted standalone, a program entitled inside a bundle priced as though it were bought separately, which is session five's double purchase in reverse. So clean the inventory before it leaves the building, because every one of these is defensible with records you already hold, and every one of them is permanent once it is in the agreed dataset.
Now layers two and three, the boundary and the period it applies to. The boundary is evidenced rather than asserted, because topology exports and mobility history show which hosts a workload could actually reach, and that is what took one claim from eighty two million dollars to six hundred thousand. Partial data is still data, because incomplete coverage discarded rather than supplemented is a defence thrown away, and partial records combined with other evidence still bound a period. The window is only the unproven quarters, so three good quarters are three quarters you do not pay for, which means you assemble every period you can evidence rather than conceding the term. A repaired control bounds it forward, so fixing the reporting immediately and documenting the date stops the exposure period growing while the audit runs. And reconstruct where you can, from archived backups, exports somebody saved, database history, because in eight of ten cases the claim collapsed once the trail was rebuilt.
Guest analyst clip. I want to talk about the instinct to withhold partial evidence, because it is one of the few genuinely counterproductive instincts I see from otherwise sensible teams. The reasoning goes like this. We only have five of the eight quarters. If we hand over five, we are effectively admitting we do not have the other three, and it will look like we were not in control. Better to say nothing and negotiate. I understand the logic and it is wrong on both counts. It is wrong tactically, because the auditor already knows you cannot produce those three quarters, that is precisely why the claim prices all eight. You are not concealing anything. And it is wrong economically, because each of those five quarters is a separate argument that removes a separate period from the model. Withholding them does not protect the three, it donates the five. In one defence we looked at, partial coverage had been discarded rather than supplemented, and the evidence that would have bounded a very large claim was simply never put on the table because somebody judged it too incomplete to be useful. Incomplete is not the same as worthless. In this exercise, incomplete is most of what anybody ever has.
Withholding the five does not protect the three, it donates the five. Incomplete is not worthless, and incomplete is most of what anybody has.
Knowledge check two. You hold reporting for five of the eight disputed quarters. The claim prices all eight at full capacity. What do you do? A, withhold the five, since producing partial evidence looks weak. B, produce all five, because each evidenced quarter comes off the claim and the exposure bounds to the remaining three. C, wait until all eight can be reconstructed. D, concede the period and negotiate the rate. Pause here, and ask whether this is one argument or eight separate ones.
The answer is B, produce all five. This is eight separate arguments rather than one, and each evidenced quarter removes a period from the model. Answer A is a real instinct and it is exactly backwards, for the reason you just heard. And answer C is worth a word too, because waiting to reconstruct all eight sounds diligent and it usually means missing a response deadline, at which point the perimeter and the timeline both slip out of your control. Produce what you have, keep reconstructing in parallel, and add periods to the pile as they come.
Layer four, back maintenance, which is the layer people forget to model. It is support, backdated to first use, at roughly twenty percent of licence value per year, accumulating for every year the deployment is assumed to have existed. It frequently exceeds the shortfall, which surprises everybody the first time, because all the attention goes to the licence number while the annuity underneath it is quietly larger. First use dates are evidence rather than assumptions, so every year removed from a first use date removes a year of arrears, and change records, project documents and purchase histories often carry that date. It shrinks as the layers above shrink, because arrears are calculated on the licence gap, so removing deployment inflation removes arrears on those same instances automatically. And it is negotiable on its own, because the backdated layer is worth more as leverage than as cash, and it moves furthest against a forward transaction the vendor can actually book.
Guest analyst clip. The backdated support layer is the part of a finding that I most often see mismodelled internally, and the mistake has a specific shape. Somebody receives the claim, extracts the licence shortfall, and briefs that number upward. The board hears a licence number. And then the actual settlement conversation involves a figure substantially larger, because sitting underneath the licence gap is support, backdated to first use, at around twenty percent a year, compounding across however many years the deployment is assumed to have run. On a six year assumed history that layer alone can exceed the licence figure that everyone has been discussing. Now the useful consequence of understanding this is that it changes what you attack. If arrears are calculated per year from an assumed first use date, then the first use date is worth as much as the deployment count, and it is often far easier to evidence. A change ticket. A project closure document. A purchase order with a date on it. Any of those can remove two or three years from the assumption, and each year removed takes a fifth of the licence value off the claim. That is a very high return on an afternoon in a records system.
The first use date is worth as much as the deployment count, and it is usually easier to evidence. A change ticket can remove years.
So what actually moved the numbers, five from the file. Mobility history on a cluster claim, where an opening position of eighty two million dollars settled at six hundred thousand, because migration logs proved the software had never run on most of the priced hosts. A rebuilt evidence trail on a reporting gap, where an opening claim near one hundred and ninety nine million dollars settled at twelve point four million across sixteen weeks once the sub capacity trail was reconstructed. Coverage remediation on a consolidation, where a thirty two million dollar claim settled at one point three million after reporting had been incomplete during a virtualisation programme. Deployment cleaning at scale, where a twenty two million dollar exposure reached three million in fourteen weeks before anybody entered a commercial negotiation. And a smaller one for proportion, where an opening of four point seven million on a reporting gap closed at one point one million, with sub capacity rights secured for the following three years.
And then the paper, which has five jobs. Close the audited period, with release language that ends it cleanly, because without that you have paid to settle a period that remains open to revisiting. Price the forward deal separately, on its own merits, sized by your telemetry rather than by the claim, and then let the finding be the concession that closes it. Avoid list based arrears, because accepting list pricing on the backdated layer to protect a discount that was never actually at risk is one of the three named settlement traps. Secure the rights going forward, since one settlement closed at one point one million and locked sub capacity rights for three years, which is worth more than the difference on the cheque. And align it with a renewal where you can, because settlements aligned with a renewal or a platform transition closed thirty to sixty percent cheaper than standalone settlements.
Knowledge check three. The finding is agreed and IBM sends settlement paper with no release clause. What is the risk? A, none, payment ends the matter in practice. B, you have paid to settle a period that remains open, so the same period can be revisited. C, only that future audits may start sooner. D, the discount could be withdrawn. Pause here, and ask what exactly the payment bought.
The answer is B. Letting the settlement paper skip the release language is one of the three named settlement traps, and it is the one nobody notices, because by that point the money has moved and the file feels closed. Answer A describes how it feels rather than what was purchased. You bought a number. Without the release, you did not buy the finality, and finality was the entire reason for paying it. I would go further: if a settlement contains only one clause you personally read, make it that one, because everything else in the document is about price and that clause is about whether the price ends the matter.
Guest analyst clip. There is a moment near the end of every settlement where the organisational energy collapses, and I have learned to watch for it. The number has been agreed. Everyone is relieved. The paper arrives, and it goes to whoever handles paper, and it gets signed, because the hard part is over. Except the hard part is not entirely over, because the document is where you find out what you actually bought. And the specific thing I would have you check, before anybody signs, is whether the audited period is released. Not whether the amount is right, which everybody checks, but whether paying it closes the period. I have seen settlements where it did not, and the consequence is genuinely strange to explain to a board: we paid the money, and the period remains open. What makes this preventable is that it is one clause. You do not need to be a lawyer to look for it, though you should absolutely have one read the document. You need to know that it should be there and to ask the question out loud in a room where everybody wants to go home. That is a small act of stubbornness at exactly the moment when nobody has any stubbornness left, which is why I flag it now, months before you will need it.
So, the defence in the order that works, five steps. Fix the reporting on day one, before anything else, because a repaired control bounds the exposure forward while a broken one keeps the window growing underneath you. Clean the deployment set, taking non production out, decommissioned out, duplicates resolved and bundled components identified, which is layer one and it shrinks everything below it. Evidence the boundary and the periods, with topology, mobility history and every quarter you can produce, because each one removes a period from the model. Then attack the arrears, with first use dates evidenced, the layer priced separately, and never accepted at list to protect a discount that was not at risk. And settle forward with release language, into a deal you priced yourself, aligned with a renewal where possible, on paper that closes the period.
Three sentences. An opening claim is a model built on four stacked assumptions, deployment, boundary, period and arrears, and each layer is contestable with records you already hold, which is why negotiating a discount validates the model while contesting the base replaces it. Claims compressed eighty five to ninety six percent where the evidence trail could be rebuilt and collapsed in eight of ten cases once reporting was reconstructed for the disputed quarters, and partial evidence is worth producing because each evidenced quarter removes a period from the claim. And back maintenance at roughly twenty percent of licence value a year frequently exceeds the shortfall it sits on, it shrinks automatically as the layers above it shrink, and the settlement needs release language that closes the period or you have paid for a finality you did not receive.
Homework, about an hour, and all of it is preparation for something you hope never happens. Separate your non production estate, asking whether you can produce today a list of which hosts are development, test and sandbox, because that list is layer one of a defence you may never need. Find one decommissioned install, an application retired in the last two years whose software is still sitting on a host, because removing it is both a saving and a defence. Check what first use dates you could evidence, from change records, project documents and purchase dates, because every year you can prove is a year of arrears you do not pay. Count your evidenced quarters, out of the last eight, because that count is your exposure boundary and you can measure it in ten minutes. And read a settlement clause, so if you have settled anything with any vendor recently, check whether the paper actually released the period, because many do not.
Five guides. The audit defence playbook carries the settlement structures, the five pitfalls, and a worked defence from notice through to release. The audit penalties guide explains how the finding is built, why it prices at list, and the backdated support layer that exceeds the shortfall. And the eighty two million dollar case study shows cluster wide counting dismantled by mobility history, with the first sixty days spent on evidence rather than argument.
The New York financial institution case study covers a rebuilt sub capacity trail across sixteen weeks, and what aligning a settlement with a renewal turned out to be worth. And the Pennsylvania manufacturer case study covers incomplete reporting during a consolidation, and how the coverage record bounded the window. Next time is the capstone: negotiating with IBM, and one estate taken end to end through everything this course has covered. See you there.