City financial district skyline at dusk
Oracle Database audits

Oracle Database audit defense for banks. Where the finding comes from and how to cut it.

How Oracle builds a database audit finding against a bank, insurer or payment firm, and how option packs, VMware scope, DR standbys and regulatory evidence change the result.

Contact Us Oracle Advisory
500+Enterprise clients
$2B+Under advisory
PublishedMay 11, 2026UpdatedSeptember 25, 2026
ContentsKey takeawaysWhy Oracle targets banksWhat we saw in 2024 and 2025Where findings come fromA worked exampleOutsourcing rules and DORACore banking and payment platformsDR obligations and licensingChecking your own positionChallenging the LMS findingWhat Oracle says and repliesContract terms to ask forTiming and staffing the responseWhat to do nextFAQ

An Oracle Database audit in a bank rarely turns on the core license. It turns on option packs, cluster scope and disaster recovery, and on how well your answers to Oracle match what you have told your supervisor.

Key takeaways
  • Why banks. Oracle audits banks more often than most sectors because their deployments are large, heavily virtualized and visibly able to pay.
  • Packs drive the bill. Diagnostics and Tuning Pack accounted for 35 to 55 percent of first findings in the banking audits we defended, usually because Enterprise Edition enables them by default.
  • DR is licensable. Oracle's failover allowance covers almost none of the disaster recovery a banking supervisor requires, and most banks discover the gap in the finding.
  • Control the evidence. Raw LMS output carries hostnames, usernames and topology a bank cannot freely export, and redaction, aggregation and on site review are all negotiable.
  • One story, two audiences. Your DORA register of information and your audit response describe the same systems, and Oracle and your supervisor will both notice if they disagree.
  • Use your paper trail. Change control and separation of duties records are cleaner audit evidence than any other sector can produce, so put them to work early.
  • Challenge the draft. An LMS finding is an opening claim built from scripts you can validate line by line, and most first findings shrink materially once scope is corrected.

Banks sit near the top of the target list for Oracle's audit arm. It now carries the GLAS name after years as License Management Services (LMS), and bankers still use both. The deployments are large, the virtualization is dense, and every answer you give Oracle is also read against what you have told your supervisor.

This page covers what is specific to banks, insurers and payment firms. The general audit sequence, the reply to the opening letter and the settlement mechanics are in the Oracle audit response playbook, the audit letter guide and the broader Oracle license audit guide, so we do not repeat them here.

Why does Oracle audit banks more aggressively than other sectors?

Oracle audits banks often because that is where the money sits. Three structural features make financial services a recurring target, and none of them has anything to do with suspected wrongdoing.

Large, concentrated Oracle deployments

Core banking, payments, risk and regulatory reporting often run on Oracle Database Enterprise Edition. The rules for what each edition and option includes are in Oracle's Database 19c licensing information guide. A large bank can hold thousands of processor licenses, so even a small compliance gap in percentage terms becomes a large number in dollars.

Virtualization density

Banks consolidated onto VMware years ago, and resilience requirements then stretched those clusters across data centers. Oracle's published partitioning policy treats VMware as soft partitioning, and on that basis Oracle claims every host in the cluster.

That claim rests on a policy document rather than your contract. The current version, dated February 14, 2022, says itself that it is for educational purposes only and may not be incorporated into any contract. The largest disputes in bank audits live here. The counting rules are covered in the Oracle virtualization licensing guide.

Regulatory data gravity

Sensitive customer data drives heavy use of security and management options. Transparent Data Encryption and Data Redaction sit inside Advanced Security, and many banks add Oracle Database Vault to meet privileged access rules. Each is licensed separately and easy to enable without a purchase order. Regulators want the controls, and Oracle wants the license fee for them.

Watch the briefingResearch briefing · 4:17

How to Negotiate Your Oracle SaaS Renewal: The Five Moves at the Table

What have we seen in banking Oracle audits in 2024 and 2025?

The same three exposures drove most of the bill. Across roughly 18 to 24 Oracle Database audits I defended for banks, insurers and payment firms in 2024 and 2025, these patterns came up again and again:

  • Diagnostics Pack and Tuning Pack. Usage of the two packs made up 35 to 55 percent of Oracle's first finding. They were almost always switched on by default and never scoped when the database was bought.
  • VMware cluster scope. Oracle's cluster boundary claims put a 2 to 4 times multiplier on the core count it proposed, before any argument about soft partitioning had started. We reversed that inflation wherever the cluster records supported it.
  • Active Data Guard standby nodes. In roughly three out of five of the environments we reviewed, standby nodes were under licensed because the team assumed a passive standby needed no license.

One more pattern matters for regulated firms. In those same audits, Oracle accepted redacted and aggregated evidence once the bank had stated its regulatory basis in writing. The refusals that went badly were the ones raised verbally, with no written basis.

Free white paper

Oracle Audit Response Guide

What the LMS scripts collect, how to challenge each line of the finding, and how to answer Oracle from a prepared position.

Get the white paper →

Where do the real findings come from in a bank audit?

From everything bolted onto the core database license. The license on the servers you already know about is rarely the problem, so read the finding one component at a time.

Typical banking audit finding by component
ComponentWhy it appearsHow to contest it
Diagnostics and Tuning PackEnabled by default, used by DBAsDisable, prove each database did not use them, dispute the usage history
VMware cluster scopeOracle's soft partitioning policy claimPin hosts, isolate clusters, read the contract terms
Data Guard standby nodesSecond site nodes assumed to be freeVerify the configuration, license what actually runs
Advanced Security optionEncryption for regulated dataScope to the databases and columns actually using it
Named User Plus minimumsPer processor minimum user countsRecount real users against the minimums

Option packs are the first place to look

Diagnostics Pack and Tuning Pack ship inside Enterprise Edition, and DBAs use them without realizing they are licensed. Oracle's technology price list dated September 15, 2026 shows each carries its own per processor fee on top of the database: $7,500 for Diagnostics and $5,000 for Tuning, against $47,500 for Enterprise Edition itself.

Advanced Security lists at $15,000 per processor and Active Data Guard at $11,500. Support adds 22 percent of the license fee every year. Edition and discount detail is in our Oracle Database pricing guide, and our Oracle Database options and management packs white paper lists every separately charged option.

Feature usage tracking is the evidence base

Oracle reads feature usage from the data dictionary view DBA_FEATURE_USAGE_STATISTICS, where one accidental click on an Enterprise Manager performance page can record a pack as used. Each row carries first and last usage dates and a usage count. You can examine and contest that history entry by entry against your change records.

Most of that usage traces back to a default. The parameter CONTROL_MANAGEMENT_PACK_ACCESS is DIAGNOSTIC+TUNING on Enterprise Edition out of the box, and to NONE on the other editions. Setting it to NONE where the packs are unlicensed stops new usage being recorded. Our guide to suppressing Diagnostics and Tuning Pack access covers the side effects.

What does a first finding look like, and how much of it survives?

A first finding is usually several times what survives a scope review. The example below is hypothetical and priced at list, and the cluster and pack lines are the ones that move.

  • Licensed position. A bank holds 48 Enterprise Edition processor licenses for Oracle VMs on two hosts, with no packs. Each host has two sockets of 24 Intel Xeon cores, so 48 cores times Oracle's 0.5 core factor gives 24 licenses per host.
  • Standby. A physical standby, mounted and applying redo but closed to reads, runs at the second data center on one host of the same size.
  • What the scripts show. The vCenter export lists the two Oracle hosts under the same vCenter as four general purpose hosts, and the feature usage view shows both packs in use.
Hypothetical first finding against the corrected position, license fees at list
LineOracle's first findingAfter scope correction
Enterprise Edition, VMware scopeOracle counts all 6 hosts: 144 processors, shortfall of 96 x $47,500 = $4,560,000Cluster configuration and vMotion history show the Oracle VMs never left their dedicated 2 host cluster: shortfall $0
Diagnostics Pack144 x $7,500 = $1,080,000Real use confirmed on the 48 licensed processors only: 48 x $7,500 = $360,000
Tuning Pack144 x $5,000 = $720,00048 x $5,000 = $240,000
Standby at the second site24 x ($47,500 + $7,500 + $5,000) = $1,440,000Runs Oracle and must match production options: $1,440,000
Total license fees$7,800,000$2,040,000
Annual support at 22 percent$1,716,000$448,800

The corrected position is $5,760,000 lower, a cut of about 74 percent, and every line still rests on evidence Oracle can check. The standby line does not move, because that standby runs Oracle and needs the license. The example is weighted toward the cluster claim. Where a bank already licenses whole clusters, the packs usually become the largest line.

How do outsourcing rules and DORA change an Oracle audit?

They add a second audience to every answer. The description of your Oracle deployment that you hand Oracle has to match the registers, contracts and resilience plans you show your supervisor, because both describe the same systems.

The register of information is now a licensing document

Under DORA, Regulation (EU) 2022/2554, applicable to EU financial entities since January 2025, banks keep registers of information on every ICT third party arrangement. Those registers record where services run and which functions depend on them. The EBA outsourcing guidelines required the same discipline years earlier.

That register is a ready made deployment inventory. It helps you assemble the audit response quickly, and it hurts you if the response contradicts it. Reconcile the two before anything goes to Oracle.

Outsourced operations blur who answers the audit

Many banks run Oracle through outsourcers and cloud providers, but the audit clause binds the bank. The provider holds the configuration data, controls the hypervisor and never signed Oracle's paper.

Your outsourcing contract has to bridge that gap with three commitments: cooperation with vendor audits, data delivery timelines, and access for independent measurement. US supervisors expect equivalent control under the interagency guidance on third party relationships, issued as OCC Bulletin 2023-17.

Keep every public statement consistent

Oracle reads public filings, resilience disclosures and your own cloud announcements before it opens a review. An audit answer that understates what your register documents creates a credibility problem you will not recover from partway through the audit.

What about the Oracle inside core banking and payment platforms?

Much of it is not yours to license freely, and the audit tests exactly that. Core banking suites commonly ship with Oracle under embedded or application specific full use (ASFU) terms sold through the platform vendor, and Oracle checks whether your use stayed inside those restrictions.

Embedded and ASFU terms under the core platform

An embedded or ASFU license covers the named application and nothing else. The purchase trail usually sits with the platform vendor rather than in your own contract files. Recover it before Oracle asks, because an instance without paperwork is priced as full use.

The classic finding is indirect use. A warehouse feed, a reconciliation job or a reporting layer reading the core schema directly gives Oracle the argument that the restricted license no longer applies. The whole underlying database is then recounted at list.

Platform delivered Oracle: what each license type survives
License typeWhat it permitsWhat breaks it in an audit
EmbeddedRuns invisibly inside the vendor productAny direct database access at all
ASFUThe named application, sold through the vendorFeeds and tools outside that application
Full useAny workload on the licensed metricCounting errors in the license metric

Interbank processing and payment switches

Payment switches, clearing gateways and settlement middleware often run Oracle Database with WebLogic underneath, licensed at full use. These systems are shared plumbing, so entitlement questions cross legal entities: the processing subsidiary, the group parent, and sometimes an interbank utility that none of your Oracle contracts name.

Establish which entity holds each license before Oracle's auditors draw that map themselves. Where the WebLogic tier itself is the exposure, the exit economics are laid out in the middleware migration business case.

Change freezes collide with the audit clock

Oracle's audit clause typically gives 45 days written notice before fieldwork begins, and a bank's change calendar can swallow most of that window. Year end freezes, regulatory reporting cycles and payment scheme deadlines all block the cleanup a bank would want to run first.

Put the freeze calendar into your first scoping letter and agree the evidence timeline around it in writing. Better still, do the hygiene work in peacetime: disable packs and pin hosts under normal change control long before any letter arrives.

What do regulator DR obligations do to Oracle licensing?

They create licensable infrastructure faster than Oracle's failover allowance can absorb it. A bank that builds exactly what its supervisor requires has usually built something Oracle expects to be fully licensed.

What regulators require

Resilience rules push banks toward a second site, defined recovery objectives and failover tests that actually run. DORA requires ICT response and recovery plans with regular testing, and national supervisory handbooks demanded the same for years before it.

What Oracle's data recovery policy allows

It allows far less than a bank typically builds. Oracle's data recovery policy, dated July 28, 2020, sets these limits:

  • Failover. An unlicensed failover node is allowed only inside the same cluster, sharing one disk array in a single data center, for up to ten separate 24 hour periods per calendar year. Test days and maintenance downtime count against the ten.
  • One node. Only one failover node per cluster is free, however many are configured.
  • Backup testing. A separate, narrow allowance covers restore testing of backups: up to four times a year, no more than 2 days each time. It does not extend to any setup where the Oracle binaries are copied or kept in sync at the second site.

A Data Guard standby at a second site runs the Oracle software and must be fully licensed, on the same metric and with the same options as production. Opening it for reads while redo applies also requires Active Data Guard, licensed on the primary as well as the standby. Our Active Data Guard guide covers the edge cases.

Regulatory DR patterns against Oracle's licensing treatment
DR patternLicense treatmentWhat to do
Cold failover node, same cluster, shared storageMay qualify for the ten day allowanceLog every failover and every test day
Warm standby at a second site via Data GuardFull license, same metric and optionsBudget for it or redesign the pattern
Reporting standby open for readsFull license plus Active Data GuardClose read access or license the option
Storage replication with Oracle installed at DRTypically licensable once installed and runningKeep binaries off the DR tier until invoked
Backups to tape or object storageNo license for the copies themselvesKeep restore tests within the allowance

Count DR tests as license events

Every failover test either uses up allowance or evidences use. Keep a dated log of tests, their duration and which nodes ran the software. Oracle's own example counts two hours on a Tuesday and three hours on a Friday as two separate periods, so short tests add up quickly.

Your supervisor wants more testing, and Oracle's policy charges for it. Raise that conflict openly in the negotiation. Oracle's account team has seen it before and has room to give on it.

How can a bank check its own Oracle position before the auditors do?

Run the same queries Oracle will run, then add the VMware and contract evidence its scripts do not collect. Everything below exists in a standard Oracle and VMware setup and can be run under normal change control.

  • Pack and option usage. Query DBA_FEATURE_USAGE_STATISTICS on every database, including test and standby, and record DETECTED_USAGES, FIRST_USAGE_DATE, LAST_USAGE_DATE and CURRENTLY_USED for each feature. Our note on running the feature usage report first explains how to read it.
  • Pack access setting. Check CONTROL_MANAGEMENT_PACK_ACCESS in each instance. Any Enterprise Edition database still on the default can record pack use at any time.
  • Standby role and open mode. In V$DATABASE, DATABASE_ROLE shows PHYSICAL STANDBY and OPEN_MODE shows READ ONLY WITH APPLY when a standby is in real time query mode. That combination means Active Data Guard is in use.
  • Cluster boundaries. Export host and cluster membership from vCenter and the vMotion event history for every Oracle VM. That history is what proves a VM never ran outside its cluster.
  • User counts. Enterprise Edition requires at least 25 Named User Plus per processor or the actual number of users, whichever is greater. A 4 processor server with 30 real users still needs 100 NUP licenses.
  • Platform paperwork. Collect the ASFU and embedded license records from each platform vendor, together with a list of every system that reads the core database directly.

How do you challenge an Oracle LMS finding in a regulated bank?

Treat the output as a draft. It is generated by scripts run against your databases, and you have every right to understand and validate each line before you accept a number.

Validate the scripts and their assumptions

The collection scripts read usage tables that can show false positives from old clicks, evaluation use or patched bugs, and Oracle's own support notes acknowledge feature usage anomalies. Document each one against your change records. Our analysis of the LMS audit scripts shows what each one collects.

What a bank cannot hand over, and what to do instead

Raw script output carries hostnames, IP addresses, usernames and network topology that banking secrecy statutes, data protection law and your own security policy restrict. Handing it over unreviewed is a control failure, whatever it looks like to Oracle.

Negotiate the handling before collection starts. Ask for a specific NDA, redacted usernames, aggregated counts instead of row level exports, review on bank premises or in a controlled virtual room, and residency terms for any transfer.

Use your regulatory controls as evidence

Banks run strict separation of duties and change control. That paper trail proves which environments were production, which were passive and who could enable an option. Few other sectors can produce evidence this clean on demand.

Why we advise against settling a bank audit quickly

Resellers and many internal teams advise settling fast, buying the shortfall and protecting the relationship. We think that is the wrong call for a bank. In the banking audits we defended, the first finding was inflated by option scope and virtualization claims that did not survive a reading of the contract.

Settling early locks those errors in for good. Validate every script line, correct the scope, and present your own measurement before any commercial conversation begins. Once you accept a draft figure, it becomes the starting point for every later discussion with Oracle.

Two people comparing documents across a meeting table
Change tickets, access approvals and DR test logs already exist for a bank's supervisors. Putting them in front of Oracle costs little and settles most arguments about which systems were live.
An Oracle audit finding in a bank is an opening offer dressed as a measurement. Read it line by line and most of the fear goes away.

What will Oracle's audit and account teams say, and how should a bank answer?

Expect a small set of standard lines. Each has a precise answer, and giving it in writing keeps the record clean for your supervisor as well as for Oracle.

Typical Oracle lines in a bank audit and replies that hold up
What Oracle saysWhat to say back
"Our policy requires every host in the vCenter cluster to be licensed."The partitioning policy states that it is not part of any contract. Show us the clause in our agreement, and here is the cluster record showing where the Oracle VMs actually ran.
"The feature usage data shows Diagnostics Pack in use."List the databases, features, first and last usage dates and usage counts. We will match each row to our change records and accept the ones that reflect real use.
"We need the full, unredacted script output."Our regulatory obligations restrict that data. We will provide aggregated counts under NDA, with on site review of the underlying rows if you need to verify them.
"The standby is passive, but it still needs Active Data Guard."Only where it is open for reads while redo applies. Here is the V$DATABASE output for each standby showing its open mode.
"A cloud commitment would make this finding go away."We will resolve the compliance question on its own terms first. Any purchase will be a separate decision, on its own business case.

Which contract terms should a bank ask Oracle for?

Ask for terms that fix the problems this audit exposed, in the settlement or the next ordering document. Oracle will not agree to all of them, but each one you win narrows the next audit.

  • An audit data handling annex. Written terms for redaction, aggregation, on premises review and data residency, so the regulatory argument is settled once for every future audit.
  • A named cluster definition. A list of the hosts or clusters that run Oracle, attached to the order. That puts the agreed scope in the contract itself, where a policy document cannot widen it.
  • A limit on audit frequency and scope. For example, no more than one audit in any 12 month period, confined to the programs on the order. See our audit clause redlines.
  • A full release in the settlement. Written confirmation that past use of the audited programs is settled up to the signature date, so the same finding cannot return next year.
  • Change freeze recognition. Agreement that fieldwork and deadlines move around year end and regulatory reporting freezes.

How should a bank time and staff its audit response?

Start before the letter arrives and finish the measurement before any commercial conversation. The order of work is in the numbered steps at the end of this page.

Time the response to your renewal calendar

Oracle often opens an audit ahead of a renewal or a cloud push. Knowing the calendar helps you keep the compliance question apart from the commercial one and avoid a bundled deal you did not need.

Banks have a second calendar: regulator driven change programs. A publicly announced resilience remediation or core banking migration tells Oracle when you are least able to push back, so plan your audit stance around those dates too.

How it changes with the size of the bank

A regional bank with a few dozen processors usually has one DBA team and one vCenter. The self check takes weeks, and the packs tend to be the largest exposure.

A global group with thousands of processors has several outsourcers, many clusters and platform delivered Oracle in each country. Entity mapping and cluster evidence take longer than the measurement itself. More detail is in our Oracle licensing guide for financial services.

Common mistakes that raise the bill

  • Disabling packs without recording when. Without a dated change ticket you cannot show when use stopped, and Oracle will price it as continuing.
  • Allowing the outsourcer to answer Oracle directly. The provider's inventory often covers shared clusters that the bank never used for Oracle.
  • Assuming storage replication is free. Once binaries are installed and running at the DR site, the node is licensable.
  • Sending raw script output under deadline pressure. It exposes regulated data and gives Oracle more topology than the finding needs.

What to do next

  1. Measure first. Commission an independent Oracle Database measurement across production, test and disaster recovery, so you negotiate from your own numbers before Oracle produces its own.
  2. Disable unused options. Tie every Enterprise Edition option and pack to a real workload, and turn off Diagnostics, Tuning and the rest wherever they are not needed, with the date recorded.
  3. Pin virtualization. Record the cluster topology and keep Oracle workloads on defined hosts or dedicated clusters, capturing the configuration.
  4. Verify each standby. Check every standby node against the failover conditions, and license Active Data Guard only where the standby is open for reads while redo applies.
  5. Recount users. Test Named User Plus populations against the contract minimums, using the real, current user population instead of a historical peak.
  6. Reconcile the register. Compare the draft audit response with the outsourcing register before anything is submitted.
  7. Build the evidence file. Assemble change control and separation of duties records into one audit file, and use the audit response white paper as the checklist.
  8. Price and get help. Run the position through the Oracle calculator, benchmark it, and bring in independent Oracle audit defense before any reply to the finding leaves the bank. The Oracle knowledge hub holds the rest of our Oracle library.

Frequently asked questions

Why is my bank a frequent Oracle audit target?

Mostly size and visibility. A bank's Oracle footprint is large, regulated and heavily virtualized, which raises both the potential finding and the odds of a gap in packs or cluster scope. Selection reflects commercial value, not any suspicion of wrongdoing.

What drives most of the finding in a banking Oracle audit?

Separately licensed options and packs, far more than the core database. Diagnostics Pack, Tuning Pack, Advanced Security and the Enterprise Manager management packs are priced per processor, so small amounts of use across hundreds of databases add up. Cluster scope claims then multiply every one of those lines.

Does a passive Data Guard standby need a full Oracle license?

Yes, in almost every configuration. A standby that runs the Oracle software and applies redo is licensed like production, with the same metric and options. The only free node is a single failover node sharing storage inside one cluster, within ten 24 hour periods a year. Opening the standby for reads adds Active Data Guard.

Can we refuse to hand Oracle raw script output?

You can control the form it takes, and a bank should. Redacted usernames, aggregated counts, a specific NDA and on premises review are all terms banks have secured. The condition is timing: state the regulatory basis in writing before collection starts, because an objection raised after the scripts have run looks like obstruction.

Does DORA give Oracle any extra audit rights?

No. DORA governs your relationship with your supervisor, and Oracle's audit rights come only from its own contract. The effect is indirect. The registers and resilience plans DORA requires describe your Oracle deployment in detail, so any inconsistency with your audit response becomes visible to both sides.

How does VMware affect an Oracle Database audit in a bank?

It sets the processor count Oracle starts from. Oracle's partitioning policy treats VMware as soft partitioning and claims every host in the cluster, which in stretched banking clusters can be several times the hosts that ever ran Oracle. Because the policy is not a contract term, cluster records and vMotion history carry real weight.

Should we settle a bank audit quickly to protect the relationship?

Not before the finding is validated. A fast settlement fixes the inflated option and cluster claims in place and sets the baseline for the next audit. A documented, corrected position rarely damages the commercial relationship, because Oracle's account team deals with evidence based pushback from banks all the time.

When does Oracle usually open a banking audit?

Most often in the months before a support renewal, a cloud migration push or a publicly announced change program. Those are the points where a compliance finding folds most easily into a larger commercial deal. If you track your own renewal and program dates, the evidence can be ready before the letter arrives.

Newsletter
Licensing news that changes what you pay

One email a week on vendor price moves, audit activity and what worked in recent renewals.

Subscribe
Vendor Shield
An advisor on call for every vendor conversation

Always on advisory for renewals, audits and contract questions across your software vendors.

Explore Vendor Shield
Advisory White Paper

Get the Oracle audit response guide, free.

What the LMS scripts collect, how to challenge each line of the finding, and a 90 day response plan that limits exposure.

Gated with a work email on the download page. No sales follow up you did not ask for.

Get the White Paper →
We never share your details with vendors.

Oracle licensing news, once a week.

Price changes, audit activity and what worked in recent renewals. No vendor spin.