Formal letter and reading glasses on a desk
IBM Audit Process

How an IBM software license audit works. Your ILMT evidence sets the finding.

The audit clause, the notice and kickoff, ILMT sub capacity proof, the data request and the draft finding, with the checks and contract terms that lower exposure.

Contact Us IBM Advisory
500+Enterprise clients
$2B+Under advisory
PublishedApril 23, 2026UpdatedSeptember 24, 2026
ContentsKey takeawaysHow the audit runsWhy ILMT decides itChecking your ILMT positionControlling the data requestWhat we have seenAnswering the auditorCutting the exposureWhat to do nextFAQ

An IBM software license audit is decided by your ILMT evidence. With current sub capacity reports you pay for the virtual cores you use. Without them, IBM counts every physical core on the host.

Key takeaways
  • Contractual basis. IBM audits run under the verification clause of the Passport Advantage agreement, usually through an appointed third party firm.
  • ILMT is the evidence. Current ILMT reports are what allow sub capacity licensing, and IBM requires the tool within 90 days, quarterly reports and two years of retention.
  • Gaps become full capacity. Without compliant reports IBM measures full physical capacity, which can multiply the licensed core count many times over.
  • Scope is negotiable. The audit opens with a notice and a data request, and the scope of that request is worth agreeing in writing at the kickoff.
  • Most exposure is missing proof. The bulk of the exposure we find traces to missing ILMT coverage on virtualized hosts, and far less to real over deployment.
  • Readiness changes the tone. With current ILMT and clean records, an audit becomes a reconciliation instead of a settlement negotiation.

How does an IBM software license audit actually run?

An IBM software license audit is a contractual check under the verification clause of your Passport Advantage agreement. IBM, usually through an appointed third party firm, sends a notice, requests deployment data, measures your usage against entitlement and presents a finding.

Under that clause IBM may verify compliance at all of your sites on reasonable notice. It may use an independent auditor, provided IBM has a written confidentiality agreement with that firm. By default the process is procedural, and how it ends depends almost entirely on the quality of your sub capacity evidence.

The notice and the kickoff

The audit opens with a formal letter that cites the agreement clause and names the products in scope. A kickoff call follows, where the auditor proposes the scope, the timeline and the data request. Treat that call as a scoping negotiation, because what you accept there sets how much of your infrastructure the auditor will see.

  • Notice. Confirms the legal basis and the products in scope. Check both against your own agreement before you reply.
  • Kickoff. Sets the data request and the timeline. Both are negotiable, so put your own version in writing.
  • Data collection. You provide ILMT reports and deployment records for the servers in scope.

Measurement, the draft finding and the invoice

The auditor compares measured deployment with your entitlement and issues a draft finding. This is the point to challenge the method and correct measurement errors, before the number is final and passes to IBM for billing.

The agreement also sets what the bill can contain. You pay the charges IBM specifies in its invoice for the excess use, plus Software Subscription and Support on that excess for the lesser of the period of excess use or two years. Check the start dates the auditor assigns to each shortfall, because they drive the back support charge.

IBM audit stages and where you have influence
StageWhat happensWhat you controlRisk if you stay passive
NoticeLegal basis cited, products namedConfirm the products in scopeLow
KickoffData request and timeline setNegotiate scope and timelineScope creep
Data collectionYou submit ILMT reportsSubmit clean sub capacity proofFull capacity default
Draft findingAuditor presents the exposureChallenge method and inputsInflated settlement
Final report and invoiceIBM bills excess use and back supportCredit entitlement, dispute datesPaying for errors you never contested
Watch the briefingResearch briefing · 5:44

The IBM Audit Is the Sales Call: Timing and ILMT Hygiene Decide It

Why does the IBM License Metric Tool decide the outcome?

ILMT decides the outcome because its reports are the evidence IBM requires before it accepts sub capacity counting. Sub capacity licensing means you license only the virtual cores assigned to an IBM product, instead of every core in the host or cluster. The right depends on running the IBM License Metric Tool and keeping its reports.

The Passport Advantage sub capacity rules set four conditions, and an auditor tests each one.

  • Installation. ILMT must be installed within 90 days of your first sub capacity deployment.
  • Reporting. Reports must be produced at least once per quarter.
  • Retention. Those reports must be kept for two years.
  • No exceptions. IBM stopped accepting exceptions to the ILMT requirement on May 1, 2023, including the one for companies with fewer than 1,000 employees. Customers that already qualified could report manually only until January 1, 2024.

What happens without compliant ILMT?

  • Full capacity default. IBM counts every physical core on the host, whatever the virtual machine was assigned.
  • Multiplier effect. A small product on a large host can be charged at many times its real footprint.
  • No retroactive fix. Installing ILMT after the audit notice does not restore sub capacity for the period before it.

A worked example on a VMware cluster

Say you run IBM MQ in one virtual machine with 8 vCPUs. The machine sits in a six host VMware cluster, and each host is a two socket Intel Xeon server with 16 cores per socket. IBM's PVU table rates those cores at 70 PVUs each, as our PVU licensing guide explains.

Hypothetical PVU count for one MQ virtual machine
Counting basisCores countedPVUsMultiple of sub capacity
Sub capacity, ILMT current8 virtual cores5601x
Full capacity, one host32 physical cores2,2404x
Full capacity, whole cluster192 physical cores13,44024x

The software and the workload are identical in all three rows. What changes is whether ILMT evidence exists for the period. If the auditor argues the machine could have run on any host in the cluster, the last row becomes the opening position, and back support is charged on top of it.

Keeping ILMT audit ready

Coverage is half of audit readiness. The other half is knowing what each product entitles you to deploy. The License Information documents in the IBM Terms catalog define which bundled components a parent program covers, which matters when the auditor starts counting components.

Free white paper

IBM audit defense checklist

The steps from notice to settlement, including ILMT checks and scope control.

Get the white paper →

How do you check your own ILMT position before IBM does?

Run the checks the auditor will run, once a year before your support anniversary and again on the day a notice arrives. Each one uses screens and files ILMT already produces.

  • VM Managers panel. Confirm every vCenter or other hypervisor manager shows a working connection. Without it ILMT cannot see host capacity, and the affected virtual machines drift toward full capacity counting.
  • Scan status. Sort computers by last scan date and look for machines that stopped reporting. Those are the servers an auditor will price at full capacity.
  • Software Classification panel. Confirm each discovered component is assigned to the product you actually licensed. Unconfirmed bundling is a common source of phantom products in a finding.
  • All Metrics report. Read the peak PVU or VPC value per product for the period. Sub capacity is billed at the peak, so the current value understates your position.
  • Audit snapshot. Generate one and open the data condition file inside it. It records the reporting period and the health of the data, which an auditor checks before trusting the numbers.
  • Entitlement records. Pull your Passport Advantage entitlement and compare it, product by product, with the All Metrics peaks.

The contract now assumes you can do this on demand. The version 11 Passport Advantage terms, which apply to existing customers' orders and renewals from May 1, 2023, let IBM ask for deployment reports in its own format and expect them within 30 days.

Which mistakes turn into audit findings?

  • Leaving servers out of ILMT. A cluster gets excluded during a migration and never added back. Every IBM product on it is then counted at full capacity for the whole gap.
  • Running an old ILMT version. The terms expect you to upgrade promptly when IBM releases a new version. An outdated software catalog also misidentifies products, and those errors land in the finding.
  • Collecting data but never generating reports. ILMT gathers data automatically, but the quarterly reports must be produced and kept. A quarter without reports is a quarter without proof.
  • Accepting the auditor's spreadsheet as the record. Reconcile every line against your own ILMT data before you comment on any total.

How do you control the audit data request?

You control it by agreeing its limits in writing at the kickoff. The data request defines how much of your infrastructure the audit touches. A broad request invites scope creep and surfaces unrelated exposure, while a scoped request keeps the audit to the products actually in question.

  • Products in scope. Confirm the audit covers only the products named in the notice.
  • Environment boundary. Limit data to the servers and clusters where those products run.
  • Format and channel. Agree the report format and route every file through one named contact, so you control what is shared and keep a log of it.

Why fast, open ended cooperation works against you

The usual advice is to cooperate fully and quickly with the auditor, to show good faith and close the audit fast. We disagree. In more than half the IBM audits we defended in 2024 and 2025, fast and broad cooperation surfaced 20 to 30 percent more environment than the audit needed, and the finding grew with it.

The better course is to cooperate professionally but scope tightly. Submit only clean sub capacity proof for the products in question, answer on the agreed timeline, and challenge the method on the draft finding. A quick close helps the auditor meet a schedule. An accurate close is what lowers your invoice.

Aisle of server racks in a data center
Each vCenter needs its own VM manager connection in ILMT. A cluster added after the tool was set up is easy to miss, and every IBM product on it then drifts toward full capacity.

What have we seen in recent IBM audit defenses?

Most of the exposure we find comes from broken sub capacity proof, not from customers running more software than they bought. Between 2024 and 2025 I worked roughly 30 to 40 IBM audit defense engagements, and our engagement file puts the firm's count of IBM audits defended in that period at 36. Three patterns came up again and again.

  • ILMT gaps. Hosts missing from ILMT accounted for 40 to 60 percent of the initial exposure, because each one forced a full capacity count. The median share was 52 percent.
  • Stale reports. Customers that had ILMT installed but not reporting for 90 days lost sub capacity rights on those servers.
  • Scope creep. Unmanaged data requests pulled in 20 to 30 percent more environment than the audit required.

Fixing the evidence, correcting measurement and scoping the request reduced the findings we worked on by 27 percent on average.

The number IBM opens an audit with is almost never the number you owe. Clean sub capacity proof closes that gap, and speed does not.

What will IBM and its auditor say, and how should you answer?

Expect a small set of standard positions. Each has a factual reply, and giving it in writing keeps the discussion on evidence.

  • "We need a hardware inventory of all your servers." The notice names specific products. Offer ILMT data and host details for the servers where those products are installed, and ask for a written reason before providing anything wider.
  • "Your ILMT data has gaps, so full capacity applies." Full capacity can apply only to the servers and dates without reports. Ask the auditor to list them, then offer hypervisor allocation history for those dates as supporting evidence. IBM does not always accept it, but it narrows the dispute.
  • "These components are separate chargeable products." Check the License Information document for the parent product. Many IBM programs include supporting programs licensed only for use with the parent, and the Software Classification panel shows how ILMT bundled them.
  • "This can all be resolved inside a new agreement." Get the reconciled finding in writing first. Then judge the commercial offer on its own merits, because a settlement folded into a new purchase hides what you actually owed.

How do you cut IBM audit exposure?

You cut it with evidence and scope control. Bring current ILMT reports, a host inventory and your entitlement records, because IBM settles against documented data and gives little weight to assertions. Our guide to negotiating IBM audit settlements covers the commercial stage.

  • Confirm ILMT coverage. Check the VM manager connections and scan dates for the in scope servers before you submit anything.
  • Hold the scope. Keep the audit to the named products and the agreed environment.
  • Challenge the draft. Correct measurement errors, wrong dates and misclassified components.
  • Reconcile entitlement. Credit unused and shelved entitlement against the exposure on the same product.
  • Check the invoice lines. Confirm the back support period never exceeds the excess use period or two years, whichever is shorter.

Contract terms to ask for at your next renewal

IBM rarely changes its standard audit clause for small accounts, but side terms become negotiable when a sizable renewal or new purchase is on the table. Our note on IBM audit clause redlines has sample wording.

  • A minimum notice period. A fixed number of days before kickoff gives your team time to assemble data without rushing.
  • A frequency limit. No more than one audit in any 12 month period stops back to back reviews.
  • A scope limit. The audit covers named products and the environments where they are deployed.
  • A cure period for ILMT gaps. Time to repair reporting before full capacity is applied protects you from one broken connector.
  • Shortfall pricing at your contracted discount. Without it, the invoice price for excess use is whatever IBM specifies.
  • Limits on auditor data use. The auditor shares results only with IBM and deletes your data when the audit closes.

How to prepare before a notice arrives

The evidence you keep for audits also serves at renewal. If you renew only part of your Subscription and Support, IBM now expects system generated proof of current use 30 days before the renewal date. ILMT reports reconciled against entitlement each quarter give you that proof, and they make the next audit notice routine.

What to do next

  1. This month. Confirm the IBM License Metric Tool is installed and reporting on every host running IBM software, with every VM manager connection live.
  2. This quarter. Verify ILMT discovers all instances, confirm the software classification, and check that your reports cover the last two years.
  3. When a notice arrives. Confirm the legal basis and the exact products in scope before you reply, and name one contact for all auditor requests.
  4. At the kickoff. Negotiate the scope and timeline of the data request, and confirm what you agreed in writing.
  5. During data collection. Submit only clean sub capacity proof for the products in scope.
  6. On the draft finding. Challenge the method and correct measurement errors, dates and misclassified components.
  7. Before you settle. Credit unused entitlement against the exposure and check the back support periods. Our IBM audit defense white paper walks through each stage, and our IBM audit defense service can run the response with you.

Frequently asked questions

How does an IBM software license audit work in 2026?

It follows the verification clause in your Passport Advantage terms. An appointed auditor collects deployment data for the named products, compares it with your entitlement and issues a draft finding you can contest before IBM invoices. Most of the outcome is settled at two points: the scope you agree at kickoff and your response to the draft.

Why is the IBM License Metric Tool so important in an audit?

Sub capacity is a right that depends on evidence. Without ILMT reports for a server and period, IBM has no obligation to accept that you used fewer cores than the host has, so the count reverts to physical capacity. VPC products running in containers follow the same logic, with IBM License Service producing the reports instead of ILMT.

What happens if I do not have ILMT installed?

IBM counts every physical core on each host where the product runs, and where virtual machines can move between hosts, the auditor may argue for the whole cluster. Installing ILMT after the notice only helps from that day forward, so start collecting data at once and use hypervisor records to argue the earlier period.

Can I negotiate the scope of an IBM audit?

Yes. After the kickoff, send your own written scope: the named products, the named environments, the data format and a single contact for all requests. Anything outside that scope should then need a written request from the auditor that explains which licensed product it relates to.

Should I cooperate fully and quickly with an IBM auditor?

Cooperate on time and in good faith, but within the scope you agreed. Volunteering data on products outside the notice gives the auditor new material to price. Keep a log of every file you send, so each line of the draft finding can be traced back to your own data.

How much IBM audit exposure comes from real over deployment?

Less than most customers expect. In our 2024 to 2025 defenses, 40 to 60 percent of initial exposure traced to ILMT gaps and stale reports. Repairing the sub capacity proof removed most of it without any license purchase. Real over deployment does occur, usually where a product spread to new servers without an entitlement check.

How long must I keep ILMT reports?

At least two years, with reports generated at least once per quarter. Quarterly is the ceiling, so many teams produce them monthly to leave fewer gaps. Store the audit snapshots somewhere other than the ILMT server, so a rebuild or failed upgrade cannot destroy your evidence.

How do I prepare for an IBM audit before the notice arrives?

Run the auditor's checks on yourself once a year: VM manager connections, scan freshness, software classification, peak usage and entitlement. Fix gaps while no audit clock is running, and keep a reconciled report set ready to send within the 30 days the current Passport Advantage terms allow.

Newsletter
Licensing news that changes what you pay

One email a week on vendor price moves, audit activity and what worked in recent renewals.

Subscribe
Vendor Shield
An advisor on call for every vendor conversation

Always on advisory for renewals, audits and contract questions across your software vendors.

Explore Vendor Shield
Advisory White Paper

Get the IBM audit defense checklist from our IBM practice.

The notice, sub capacity proof, scope control and draft finding steps, set out as a checklist your team can work through.

Gated with a work email on the download page. No sales follow up you did not ask for.

Get the White Paper →
We never share your details with vendors.

IBM licensing news, once a week.

Price changes, audit activity and what worked in recent renewals. No vendor spin.