Formal letter and reading glasses on a desk
IBM Audit Settlements

IBM audit settlement negotiation for CIOs. Correct the claim before you discuss price.

How IBM builds an audit claim from full capacity, back support and list price, and how to rebuild evidence, contest each layer and close the settlement.

Contact Us Negotiation Advisory
500+Enterprise clients
$2B+Under advisory
PublishedDecember 12, 2024UpdatedSeptember 24, 2026
ContentsKey takeawaysInside the claimWorked exampleNegotiation sequenceWhat we have seenIBM lines and repliesCommercial settlementCostly mistakesWhat to do nextFAQ

IBM's opening audit claim stacks full capacity counts, back maintenance and list prices. Rebuild your sub capacity evidence first, contest each layer in writing, then settle the residual as forward spend with a full release.

Key takeaways
  • Three layers, all contestable. An IBM claim combines a full capacity license count, back support on the shortfall and list pricing, and each one can be challenged.
  • Full capacity drives the size. Where ILMT evidence is missing or disputed, full capacity pricing inflates claims 5x to 10x.
  • Defended cases settle low. Matters we defended in 2024 to 2025 settled at 5 to 15 percent of the opening claim.
  • Evidence first, money second. Use the first 60 days to rebuild sub capacity evidence from ILMT and hypervisor records before any commercial talk.
  • Settle with forward spend. Close the residual exposure as a commitment IBM can book, such as a renewal or Cloud Pak purchase, instead of a cash penalty.
  • Close the period for good. Require release language that covers the audited period completely, then run ILMT properly so the next audit starts from accepted data.

What is actually inside an IBM audit settlement claim?

An IBM audit claim is three numbers stacked on top of each other: a license shortfall priced at full capacity, back maintenance on that shortfall, and list pricing with no discount. Each layer can be contested, and because they multiply, correcting the base number reduces every layer above it.

The full capacity layer is usually the largest. Without accepted ILMT records, IBM's auditors price every core the software could run on, following the sub capacity rules that sit under the IBM Passport Advantage terms. The opening claim then prices the shortfall at current Passport Advantage list rates, with none of the discount you normally receive.

The three layers to contest

  • The metric base. Full capacity versus sub capacity, as defined on the IBM sub capacity licensing page. It is the layer where rebuilt evidence changes the number most.
  • The time base. Back maintenance assumes the shortfall existed for years. Deployment records often show a much shorter window.
  • The price base. List price with zero discount is IBM's opening position. It is never the number a defended matter settles on.

Why ILMT decides most of the outcome

Sub capacity pricing depends on IBM License Metric Tool reports. The Passport Advantage terms require ILMT within 90 days of first deploying an eligible product, with reports produced at least quarterly and kept for two years.

IBM's sub capacity letter states the penalty for missing this requirement. The product is charged at full capacity for every physical core activated on the server.

What if your ILMT records have gaps?

A gap in ILMT data does not settle the case in IBM's favor. Reconstructed evidence from virtualization platforms is regularly accepted in settlement, but your team has to build it, host by host and quarter by quarter. Stating that the VMs were small carries no weight without the export behind it.

How much does contesting each layer change the number?

Contesting all three layers in turn can take a seven figure claim down to a few percent of its opening value. The example below is hypothetical, with round prices chosen for the arithmetic, but the mechanics follow the Passport Advantage rules.

Say the auditor finds an unlicensed IBM middleware product on a VMware cluster. The assumptions are:

  • Hardware. 8 hosts, each with 2 Intel Xeon sockets of 16 cores, so 256 physical cores rated at 70 PVUs per core on the IBM PVU table.
  • Actual use. The virtual machines that run the product have 32 vCPUs in total.
  • Prices. A list price of $60 per PVU and annual support at $12 per PVU.
Hypothetical claim, corrected one layer at a time
StepPVUs countedLicenseBack supportTotal
Opening claim: full capacity, two years back support, list price17,920$1,075,200$430,080$1,505,280
Metric base corrected to sub capacity (32 vCPUs)2,240$134,400$53,760$188,160
Time base corrected: first install 9 months before the audit2,240$134,400$20,160$154,560
Price base corrected: 40 percent off list, back support waived2,240$80,640$0$80,640

The final figure is about 5 percent of the opening claim. The metric correction alone removed almost 88 percent of it, which is why the evidence work comes before any commercial talk. Contractually, back support runs only as long as the excess use did, up to two years, so install dates are worth real money.

How to check your own position before IBM does

  • ILMT audit snapshot. The audit snapshot export shows peak PVU consumption per product across the reporting period. Check it for gaps, stale scanners and unbundled components.
  • Hypervisor inventories. vCenter exports, Hyper-V host records and PowerVM HMC data show which virtual machines ran on which hosts, and with how many cores.
  • Install and change records. Change tickets, software distribution logs and build records date the first install of each product.
  • Entitlement records. Your Passport Advantage site data and proof of entitlement documents, reconciled by part number before the auditor presents their version.
  • Server lists. Compare the auditor's host list with your records for servers retired before the audit period and hosts counted twice under different names.
Free white paper

IBM Audit Defense Guide

Evidence sequence, claim layer counters and settlement terms from our IBM practice.

Get the white paper →

How does the IBM settlement negotiation sequence work?

The order that works is to control the data room, rebuild the evidence, contest the claim layers in writing, and only then take the corrected number into a commercial agreement. Teams that open commercial talks against the opening claim end up negotiating against the wrong number.

  1. Scope control. Hold the audit to the contractual scope, meaning the programs and entities named in the notice. Refuse requests for data on unrelated parts of your environment.
  2. Evidence rebuild. Assemble ILMT exports, hypervisor inventories and deployment timelines into a counter position that an auditor can check line by line.
  3. Written contest. Challenge the metric base, the time base and the price base with documentation, one layer at a time.
  4. Commercial agreement. Convert the residual exposure into forward spend that IBM can book as revenue.
IBM audit claim layers and the counter for each
Claim layerIBM opening positionYour counter
Metric baseFull capacity on all coresRebuilt sub capacity evidence
Time baseShortfall assumed for 2 plus yearsDeployment records that shorten the window
Price baseList price, no discountSettlement at negotiated commercial rates
Back maintenanceFull back support on the shortfallWaived or folded into the forward agreement
Settlement vehicleCash penaltyForward commitment IBM books as a sale

What a realistic timeline looks like

Plan for six to twelve months from the audit letter to a signed settlement. The phases overlap, but the order should hold.

  • First two weeks. Acknowledge the letter, confirm scope in writing, name one point of contact and freeze changes to the in scope servers.
  • By day 60. Finish the evidence rebuild and your own compliance position before the auditor issues a draft report.
  • After the draft report. Send a written response contesting each layer, with the supporting exports attached.
  • Final phase. Agree the corrected number with the auditor, then negotiate the commercial agreement and release with IBM.

Why we do not start by negotiating a discount on the finding

The usual advice is to accept the audit finding as broadly correct and bargain hard on the discount. We think that is the wrong starting point. In roughly 18 of the 15 to 25 IBM matters I worked in 2024 to 2025, the finding itself was wrong by multiples, almost always on the full capacity layer.

Spend the first 60 days attacking the metric base with rebuilt evidence, and discuss money only after that. A 50 percent discount on a claim inflated 10x still leaves you paying 5x what you owe.

Finance papers and a calculator on a desk
Most IBM settlements turn on whose deployment evidence the room believes, which is why the evidence rebuild comes before every commercial conversation.

What have we seen in recent IBM audit settlements?

Across roughly 15 to 25 IBM audit defenses that I ran or reviewed between 2024 and 2025, the opening claim and the final settlement were rarely within an order of magnitude of each other. Defended cases with rebuilt evidence and a commercial agreement settled at 5 to 15 percent of the opening claim. Three patterns came up repeatedly.

  • Opening claims built on full capacity. Where ILMT evidence was missing or contested, IBM priced the entire physical environment. That inflated claims by 5x to 10x over the sub capacity position.
  • Back maintenance as a multiplier. Two years of back support charges on top of license fees often doubled the headline number.
  • Settlements at a small fraction of the claim. The defended cases closed far below the opening figure, and every one of them closed better as restructured forward spend than as cash.
IBM audits settle on evidence and forward revenue. Bring the first, structure the second, and the opening claim soon stops being the reference point.

What will IBM and its auditors say, and how should you reply?

Expect the same handful of lines in most IBM audits. Each one has a factual reply, and giving it in writing keeps the discussion on evidence.

Common lines and precise replies

  • "Your ILMT data is incomplete, so full capacity applies." Ask which servers and which quarters are missing, in writing. Then supply hypervisor records for exactly those gaps, so the full capacity charge is argued server by server rather than applied to the whole environment.
  • "These findings are final and we need a purchase order this quarter." A draft report is open until you have responded to it. Ask for the auditor's working files and calculations, and note that IBM's quarter end is not a contractual deadline.
  • "Back support is contractual." It is, within a limit. The agreement caps it at two years or the length of the excess use, whichever is less, so show the install dates and ask for a recalculation.
  • "Sign a larger agreement and this goes away." Agree in principle, but only after the corrected number is settled, and only with the release written into the same document.

How do you structure the commercial settlement?

The settlement that closes is one IBM's account team can book as forward business: an enterprise license agreement, a Cloud Pak commitment, or a renewal restructure that absorbs the residual exposure. Cash penalties are the worst outcome for both sides and the easiest to negotiate away.

  • Fold the exposure into planned spend. Residual exposure goes into a commitment you were going to make anyway, such as a Cloud Pak purchase or your next renewal.
  • Trade for compliance hygiene. ILMT deployment, an accepted baseline and a clean compliance statement all go into the deal.
  • Close the period. The release must cover the audited period completely, with no room to reopen claims.

Why a cash penalty is the worst settlement shape

Cash produces no forward value for you and books poorly for the IBM account team. It also tells IBM your organization pays on demand, which shapes how the next audit cycle is run.

Contract wording to ask for in the settlement

Settlement terms worth insisting on
  • Full release. IBM releases all claims for the audited programs through a stated date, so the period cannot be reopened.
  • Accepted baseline. The agreement lists your entitlements and deployments as of the settlement date, which becomes the starting point for any future audit.
  • ILMT remediation window. A defined period to bring ILMT into line, with sub capacity accepted going forward during that period.
  • No admission. The settlement records a commercial resolution, without any statement that you breached the agreement.
  • Audit interval. A stated period before IBM starts another verification of the same programs.

What the CIO signs off before final talks

The negotiating mandate needs three figures agreed before final talks begin: the maximum cash you will pay, the acceptable forward commitment, and the compliance position you will run afterward. Settlements drift when those are improvised in the room.

Which mistakes make an IBM audit settlement more expensive?

Most avoidable cost in an IBM settlement comes from a small number of early errors. Each one is easy to prevent if the team knows about it in the first week.

  • Uninstalling software after the letter arrives. Removing products or migrating workloads mid audit looks like evidence tampering and weakens every other argument you make.
  • Handing over more data than the scope requires. Full environment exports invite findings on programs the notice never named.
  • Accepting the auditor's server list as given. Retired hosts and duplicate names inflate the core count, and the metric correction starts from that list.
  • Opening commercial talks early. Discussing money against the opening claim sets the reference point for the rest of the negotiation.
  • Signing without release language. A settlement that does not close the period can be followed by a second claim for the same years.

Our IBM audit defense checklist and the guide to IBM audit penalties cover the evidence list and the charge types in more detail.

What to do next

  1. Answer the letter. Acknowledge the audit letter formally and confirm the contractual scope in writing.
  2. Freeze the in scope servers. Make no uninstalls or migrations that could look like evidence tampering.
  3. Rebuild the evidence. Reconstruct sub capacity data from ILMT and hypervisor records for every quarter in scope.
  4. Contest in writing. Challenge the metric, time and price layers with documentation attached.
  5. Model the commercial agreement. Size it against IBM spend you had already planned.
  6. Close the period. Negotiate release language that ends the audited period for good.
  7. Run ILMT properly. Deploy and maintain ILMT so the next audit starts from accepted data. Our IBM practice runs audit defense end to end, and our PVU table guide for 2026 covers the metric mechanics behind most claims.

Frequently asked questions

How much of an IBM audit claim is typically negotiable?

Most of it. The license count, the back support window and the price are all open to challenge, and the count usually changes most. Final numbers in our defended matters were a small fraction of the opening figure, provided the evidence was rebuilt before commercial talks began.

What happens if we never deployed ILMT?

You lose the automatic right to sub capacity pricing, but you do not lose the case. Hypervisor inventories and deployment records can be assembled into a reconstruction that IBM regularly accepts in settlement. Expect to agree an ILMT deployment deadline as part of the deal.

Should we just negotiate a discount on the audit finding?

No. A discount applied to a finding that is wrong by multiples still leaves you overpaying. Correct the metric base with evidence first, and the discount conversation then happens on a far smaller number that you can defend internally.

What does a good IBM settlement look like?

The residual exposure is folded into forward spend you planned anyway, back maintenance is waived, the audited period is fully released, and IBM accepts a compliance baseline so the next audit starts clean.

How long does an IBM audit settlement take?

Plan for six to twelve months. The first 60 days of evidence work set the direction, and rushing into commercial talks against the opening number is the most expensive mistake available.

Who runs an IBM software audit?

IBM usually appoints an outside audit firm to collect data and prepare the findings, while the IBM account team handles the commercial settlement. Agree the facts with the auditor and the price with IBM, and keep the two conversations separate.

Can IBM charge back support for more than two years?

Not under the standard Passport Advantage terms. Support on excess use is charged for the shorter of the period of excess use or two years, so records that date the first install can cut this line sharply.

Newsletter
Licensing news that changes what you pay

One email a week on vendor price moves, audit activity and what worked in recent renewals.

Subscribe
Vendor Shield
An advisor on call for every vendor conversation

Always on advisory for renewals, audits and contract questions across your software vendors.

Explore Vendor Shield
Advisory White Paper

Get the IBM audit defense guide.

The 60 day evidence sequence, counters for each claim layer, commercial settlement models and release language that closes the period.

Gated with a work email on the download page. No sales follow up you did not ask for.

Get the White Paper →
We never share your details with vendors.

enterprise software licensing news, once a week.

Price changes, audit activity and what worked in recent renewals. No vendor spin.