A formal letter and a pair of reading glasses on a desk
IBM Audit Penalties

IBM audit penalties: how the number is built. And which parts of it you can contest.

How IBM prices an audit finding, why missing ILMT evidence multiplies it, and how to cut each layer before you settle, with a worked example.

Contact Us IBM Advisory
500+Enterprise clients
$2B+Under advisory
PublishedOctober 27, 2025UpdatedSeptember 24, 2026
ContentsKey takeawaysHow the penalty is calculatedA worked exampleThe ILMT multiplierWhat triggers an auditWhat we have seenResponding to the letterHow findings settleWhat to do nextFAQ

IBM does not fine you after an audit. The finding is your deployment gap priced at list, plus up to two years of backdated Subscription and Support, and it grows fastest when ILMT evidence fails. Each layer can be contested with better data.

Key takeaways
  • No separate fine. An IBM finding is a commercial calculation built from your deployment data and the auditor's assumptions.
  • List price first. Shortfalls are priced before your negotiated discount, which comes back only at settlement.
  • Back support has a limit. The standard Passport Advantage agreement charges Subscription and Support on excess use for its duration or two years, whichever is shorter.
  • ILMT is the biggest multiplier. Missing or stale reports reprice sub capacity hosts at full capacity, 2 to 4 times real use in the audits we defended.
  • Your data should arrive first. Customers who submitted reconciled data before IBM's tooling set the scope cut their findings materially.
  • Settle on a deal you priced alone. Let the finding close a forward deal priced on its own merits, with a release covering the audited period.

IBM does not issue fines after a software audit. What arrives is a finding: the gap between what you deployed and what you are entitled to, priced at list, plus Subscription and Support charged back for the period the gap existed. Every part of that number rests on data and assumptions, and every part can be contested.

I worked at IBM and Oracle before moving to the customer side. This page takes an IBM finding apart line by line, runs a worked example, and sets out what to do in the first two weeks after the letter, when most of the final number is decided.

How does IBM calculate an audit penalty?

IBM builds the finding from four layers: the license shortfall, backdated Subscription and Support, full capacity repricing of any host without valid ILMT evidence, and list pricing across all of it. The table sets out IBM's position on each layer and the counterargument that usually holds.

The four layers of an IBM audit finding
LayerIBM's positionThe counterargument
License shortfallDeployed minus entitled, priced at list under the IPLA and Passport Advantage termsThe deployment count is usually inflated. Dev and test instances, decommissioned hosts and double counted clusters fall away under a clean inventory.
Backdated Subscription and SupportRoughly 20 percent of license value per year, reaching back to first use, up to the two year limit in the agreementFirst use dates are assumptions drawn from discovery output. Operational records that date a deployment later, or a retirement earlier, cut this layer directly.
Full capacity repricingHosts without valid ILMT coverage priced at every physical coreCoverage evidence, restored reports and the remediation record limit the repricing to the window you cannot prove.
List pricingFindings priced before any discountDiscounts come back in settlement, and they come back furthest when the finding is folded into a forward transaction IBM can book.

What the Passport Advantage agreement says about back charges

The verification clause in plain terms
  • Notice and auditors. IBM may verify compliance upon reasonable notice, at all sites and for all environments, and may use an independent auditor bound by a written confidentiality agreement.
  • Records. You must create, keep and provide records and system tool output that prove your deployments, and keep sub capacity reports for at least two years.
  • Charges. For excess use, IBM invoices the licenses, plus Subscription and Support for the lesser of the duration of the excess use or two years, plus any additional charges the verification identifies.
  • Reports on request. Version 11 of the agreement, which applied to existing Passport Advantage customers from May 1, 2023, asks for your deployment report within 30 days of IBM's request.

Check every back charge against that limit. At roughly 20 percent a year, the back charge on perpetual licenses tops out near 40 percent of the license shortfall. A letter that reaches further back, or adds charges it cannot tie to a clause, is the first thing to challenge.

First use dates still count inside that limit. If your change records show the extra deployment went live 9 months ago, the back charge covers 9 months, whatever date the discovery output implies.

Why is the finding priced at list and not at your discount?

The agreement allows IBM to specify the charges in its invoice, and IBM prices compliance gaps at list. Your negotiated discount returns only in settlement, so the opening number is large by design. That gap stops working against you once you price any forward purchase on its own merits, before the claim enters the conversation.

The costliest mistake we see is treating the letter as a bill and asking for a discount on it. A finding is a calculation from data and assumptions, so correct the inputs first and discuss price last.

Watch the briefingResearch briefing · 5:44

The IBM Audit Is the Sales Call: Timing and ILMT Hygiene Decide It

What does an IBM audit finding look like in numbers?

Take a hypothetical company that owns 1,400 PVUs of a middleware product. It runs the product in virtual machines with 24 virtual cores in total, on a 3 host VMware cluster where each host has 2 Intel Xeon sockets of 12 cores. IBM rates that processor at 70 PVUs per core.

For round arithmetic, assume a list price of $50 per PVU and annual Subscription and Support at 20 percent of that, or $10 per PVU. The excess use has run for more than two years, so the full two year back charge applies.

Hypothetical finding, with and without valid ILMT evidence
LineSub capacity, ILMT evidence intactFull capacity, ILMT evidence missing
Deployed PVUs24 cores x 70 = 1,68072 cores x 70 = 5,040
Entitled PVUs1,4001,400
Shortfall280 PVUs3,640 PVUs
Licenses at $50 list$14,000$182,000
Back charge, two years at $10 per PVU$5,600$72,800
Opening finding$19,600$254,800

The deployment count triples when ILMT evidence fails. The finding grows 13 times, because the entitlement that covered most of the real use now covers a small share of the full capacity count.

Now apply the counterarguments. If change records show the extra 280 PVUs went live 9 months ago, the back charge in the first column falls from $5,600 to $2,100. If repaired ILMT evidence covers every quarter but the last two, the full capacity back charge shrinks to that window.

Free white paper

IBM Audit Defense Guide

The response timeline, the ILMT evidence pack and the settlement terms, in one download for the letter and the renewal.

Get the white paper →

Why does a missing ILMT report multiply an IBM audit penalty?

Sub capacity licensing is conditional. You may license the virtual cores a program uses, instead of every physical core in the host, only while the IBM License Metric Tool is deployed, scanning, and reporting at least quarterly, with reports kept for two years. New sub capacity customers must have ILMT running within 90 days of their first eligible deployment.

When any of those conditions fails, the affected hosts are priced at full capacity. Across our defended audits that repricing ran 2 to 4 times real consumption, and the ILMT failure drove more penalty value than every genuine shortfall combined. The eligibility rules in detail are in our sub capacity and ILMT guide.

Rack mounted server hardware with green and blue status lights
Without valid ILMT data, auditors typically count every activated core on each host a virtual machine could run on, so one unscanned cluster can outweigh the rest of a finding.

Why auditors ask about ILMT first

It is the highest yield question available to them. A failed ILMT requirement needs no proof of over deployment, turns a compliant looking environment into a full capacity assessment, and reaches across the whole period the evidence cannot cover.

The partial failures cost the most, because they surface only when the audit asks for the evidence pack. Typical cases are agents missing from a third of the hosts, a vCenter connection that stopped reporting, and reports that were generated but never kept.

How to check your ILMT evidence before IBM does

  • Audit snapshots. In ILMT, open Reports, then All Metrics, and use Audit Snapshot. Generate one for the past two years and check that no quarter is missing, since a server rebuild or a lapsed data import leaves gaps an auditor will price.
  • Agent coverage. Compare the hosts and virtual machines ILMT sees with your CMDB and vCenter inventory. Every gap can be priced at full capacity.
  • VM manager connections. A broken connection means ILMT loses the host capacity data it needs for sub capacity counts.
  • Software classification. Unassigned or wrongly bundled components inflate the count, so check each one maps to the right product.

Smaller companies lost their ILMT exception in 2023

Companies with fewer than 1,000 employees and contractors and less than 1,000 PVUs of total physical capacity could once ask IBM for an exception and report manually. IBM stopped accepting exceptions on May 1, 2023, and manual reporting under earlier exceptions ended on January 1, 2024.

That leaves smaller customers exposed if they never deployed the tool. Large groups fail differently: ILMT is installed, but coverage develops gaps after acquisitions, cloud migrations and new clusters.

What triggers an IBM software audit?

IBM reviews run on a Passport Advantage cycle, are carried out largely by third party audit firms on IBM's schedule, and pick accounts that show certain signals. The same signals work as your warning clock. The letter is rarely a surprise to IBM, and it should not be one to you.

  • Shrinking spend. Renewals that shrink, support dropped on legacy product lines and Cloud Pak conversions that stalled mark an account where an audit protects revenue a seller cannot.
  • Corporate change. Acquisitions and divestitures scatter entitlements across legal entities faster than anyone consolidates the paperwork, and IBM knows it. See our note on the merger and divestiture clause.
  • Legacy PVU products. Environments heavy in WebSphere, Db2 and Tivoli lineage products carry the sub capacity obligations where the ILMT finding lives.
  • Partial support renewals. Under version 11, renewing Subscription and Support for fewer licenses than before requires system generated evidence of current use at least 30 days before the renewal date, which puts your deployment data in front of IBM.

What happens after the letter, stage by stage, is covered in our guide to the IBM license audit process.

What have we seen in the IBM audits we defended?

Across roughly 30 to 40 IBM audits we defended between 2024 and 2026, the size of the penalty was driven by who controlled the data, far more than by real overuse. Whoever's dataset defines the scope controls the negotiation.

IBM's tooling, run on IBM's schedule, produces IBM's interpretation of your environment, and every ambiguity in raw output resolves toward a larger finding. Customers who presented their own reconciled deployment and entitlement data before IBM's tooling defined the scope cut their findings materially. Those who handed over raw output ended up negotiating against IBM's reading of it.

Every dollar in an IBM audit letter was built from data and assumptions, so every dollar can be reopened with better data.

The three records to have before the response deadline

  1. A cleaned deployment inventory. Dev and test separated from production, since some IBM programs have separate non production part numbers at a lower price, and retired hosts documented with decommission dates.
  2. An entitlement register. Consolidated from the actual contracts and Passport Advantage records across every legal entity and site, including licenses that came with acquisitions.
  3. The ILMT evidence pack. Audit snapshots by quarter, with coverage reconciled host by host and every gap explained.

Why we advise against running the auditor's scripts first to show good faith

The usual advice is to cooperate fast and run whatever discovery scripts the auditor supplies, on the theory that goodwill lowers the finding. We disagree. In the audits we defended, speed on IBM's terms produced raw output that set the scope before the customer understood its own position.

Cooperate fully, on a timeline agreed in writing, and only after your own inventory exists.

How should you respond to an IBM audit letter?

Respond through one channel, agree the scope in writing, and build your own data before anyone runs IBM supplied tooling. Data control and timeline control are won or lost in the first two weeks, before any number is discussed. The notice and scope terms you can negotiate in advance are in our note on the IBM audit clause.

IBM audit response timeline
WhenWhat to do
Days 1 to 3Acknowledge the letter through one named contact. Ask for the programs, sites, entities and review period in writing.
Week 1Export ILMT data as it stands, pull every audit snapshot and start the entitlement register.
Week 2Agree the data collection plan and dates. Hold auditor scripts until your inventory is complete.
Before submissionReconcile deployment against entitlement host by host. Fix ILMT gaps and record the date of each repair.
Draft findingChallenge each layer: inflated counts, first use dates, the full capacity window, the back charge period.
SettlementPrice any forward deal separately, then agree the release.

What the auditor will say, and what to say back

  • "Send the ILMT audit snapshots for the last two years within 30 days." Agree, for the programs and sites confirmed in writing. Ask for that scope before any data leaves your hands.
  • "Hosts without ILMT coverage count at full capacity for the whole period." Only for the window your records cannot cover. Provide the agent deployment history and the date coverage was restored.
  • "The deployment dates come from our discovery run." Offer your change and installation records instead, and point to the agreement's two year limit on back support.
  • "A Cloud Pak commitment would make this go away." Say you will price the Cloud Pak on ILMT telemetry as a separate proposal, and that any settlement needs release language for the audited period.

How do IBM audit findings usually settle?

Most IBM findings settle against a forward transaction IBM can book: a Cloud Pak commitment, a renewal expansion or an ELA style consolidation. The backdated layer is worth more to IBM as a bargaining chip in that deal than as cash, and it gives way furthest when a forward purchase is on the table.

Price any forward deal on its own merits first, independently of the claim. Then let the finding be the concession that closes the deal, never the opening number that sizes it. The Cloud Pak licensing guide covers the conversion mechanics that usually carry the forward side.

Three settlement traps

  • Buying to make the claim disappear. A forward commitment sized by worry about the finding, and never checked against ILMT telemetry, leaves you paying for shelfware for years.
  • Paying list priced arrears to protect a discount. Customers accept list based back charges to protect a renewal discount that was never at risk.
  • Settling without a release. Settlement paper that skips release language leaves the audited period open to a second claim.

Each trap is avoidable when the finding has been taken apart layer by layer before anyone discusses a deal.

Wording to ask for in the settlement agreement

  • Release. A release of claims for the programs, entities and period audited, so the same years cannot be reopened.
  • Agreed baseline. The final reconciled PVU counts attached as a schedule for the next audit to start from.
  • ILMT status. Written acknowledgment that sub capacity reporting is compliant from the remediation date onward.
  • Audit interval. A commitment that IBM will not audit the same programs again for an agreed period.
  • Price protection. A price hold on the forward deal, so the discount you won does not erode at the next renewal.

What to do next

  1. When the letter arrives. Acknowledge through one channel, agree scope in writing, and run no IBM supplied tooling until your own inventory exists.
  2. Within two weeks. Build the three records: a cleaned deployment inventory, a consolidated entitlement register, and the ILMT evidence pack reconciled host by host.
  3. Before you submit data. Fix ILMT at once and document the repair date. A repaired control bounds the exposure period and trades far better than a broken one.
  4. When the draft finding lands. Take it apart layer by layer: inflated deployment out, first use dates evidenced, the full capacity window bounded, back support held to two years.
  5. At settlement. Price any forward deal independently, then close with release language that covers the audited period. Our IBM practice runs this sequence with you.
  6. After the audit. Repeat the reconciliation every year. Vendor Shield keeps the three records current between audits.

Frequently asked questions

What penalties does an IBM software audit impose?

There is no fine. IBM invoices the licenses you are short at list price, Subscription and Support on that shortfall for up to two years, and any additional charges the verification identifies. Every input, from deployment counts to first use dates, rests on data you can check and contest.

Why are IBM audit findings priced at list instead of our discount?

The agreement allows IBM to specify the charges, and IBM prices compliance gaps at list, treating your contract discount as something to be earned back in settlement. Leave the discount question until the counts themselves are corrected, because each correction removes value at the full list rate.

What happens if ILMT is missing during an IBM audit?

The hosts that lack evidence lose sub capacity eligibility, and IBM counts every activated physical core on them for the period you cannot prove. Restore ILMT at once and record the date, since that date limits the full capacity window in the negotiation.

What triggers an IBM license audit?

The Passport Advantage review cycle combined with account signals: shrinking renewals, dropped support, stalled Cloud Pak conversions, acquisitions or divestitures, and heavy use of PVU licensed products. Third party audit firms run most reviews. Treat any of those signals as a prompt to reconcile your data early.

Should we hand over our raw ILMT and discovery output?

Not until your own reconciliation exists. Raw output counts dev and test copies, retired hosts and duplicate cluster entries against you. Submit reconciled data with a short note explaining each adjustment, so the auditor starts from your version of the environment.

How do IBM audit findings usually settle?

Usually inside a forward purchase IBM can book, such as a Cloud Pak commitment or a renewal expansion, far more often than as a cash payment. Settle only after the finding is corrected, with the forward deal priced separately and a written release for the audited programs and period.

Can IBM charge more than two years of back support after an audit?

Not under the standard International Passport Advantage Agreement, which charges Subscription and Support on excess use for the lesser of the excess use period or two years. Negotiated contracts such as an ELA can differ, so check your own terms before accepting any older charges.

Newsletter
Licensing news that changes what you pay

One email a week on vendor price moves, audit activity and what worked in recent renewals.

Subscribe
Vendor Shield
An advisor on call for every vendor conversation

Always on advisory for renewals, audits and contract questions across your software vendors.

Explore Vendor Shield
Advisory White Paper

Get the IBM audit defense guide.

The first two weeks, the data control method, the ILMT evidence pack, the counterarguments to each layer of a finding, and the settlement structures that close it.

Gated with a work email on the download page. No sales follow up you did not ask for.

Get the White Paper →
We never share your details with vendors.

IBM licensing news, once a week.

Price changes, audit activity and what worked in recent renewals. No vendor spin.