Home  /  Research Videos  /  Broadcom
Broadcom · 4:34 · Buyer-side briefing

The Audit, and the Machine That Replaced It

Part 5 of the Negotiating Broadcom series. Three business days to respond, letters arriving within a week of a lapse, and a compliance report every 180 days that degrades your management plane at 270. The audit has been automated, and the ask is a cure period.

Share

The presenters in this briefing are AI generated avatars. The research, figures, and guidance are real, produced by Redress Compliance analysts from our consulting engagements and market network.

Transcript

Full narration of the briefing. Click a section heading to jump the player to that moment.

What happens if you do not accept 0:00

The question we get asked more than any other about this vendor is what happens if you do not accept the number. The answer has changed, and it has changed in a direction most people have not tracked. The classic licence audit still exists, and we will go through exactly what it looks like, because the specifics are documented. But the more important development is that the audit is being replaced by something continuous and automatic, and that is the thing to negotiate about.

I am Tom, Claire is with me on the mechanics.

The cease and desist wave 0:33

Start with May 2025. Broadcom sent cease and desist letters to perpetual licence holders whose support had lapsed, signed by a managing director. The letters told recipients to remove any maintenance release, update, upgrade, patch, bug fix or security fix installed after their support expired. Not stop using.

Remove. They warned that continued use is a material breach, potentially resulting in claims for enhanced damages and attorneys fees. The only carve out was zero days, which Broadcom defines as a severity score of nine point zero or above. Some customers received a letter within a week of their contract ending, which tells you it is automated rather than investigated.

The formal audit 1:17

Then June 2025, and the formal audits. The letter is signed by a Broadcom director of global sales operations, and note that job title, because it is not compliance and it is not legal. It is sales. The audit itself runs through Connor Consulting, and the stated scope is your deployment and entitlements, which may include fieldwork, remote testing, and meetings with your accounting, licensing and management information systems staff.

The response window is three business days. If you take nothing else from this episode, take that number, because almost no enterprise can convene the right people and understand its own position in three business days.

How widespread, honestly 1:58

Now the honest caveat, because you will see confident claims about this. Nobody has published how many audit or cease and desist letters went out. Not Broadcom, not any analyst, not any trade body. So anyone quoting a rate is guessing, and we are not going to.

What is documented is shape rather than volume. Allstate had four audits opened simultaneously in April 2025, across VMware, Tanzu, Agile Operations and Mainframe. Allstate's own filing says the audit began, in its words, once Broadcom was aware that Allstate did not intend to renew. That is an allegation in a live case, and we voice it as one.

The commercial version 2:37

There is also a version of this that alleges nothing at all, described by an analyst who spent years at Gartner and now runs an advisory practice. When Broadcom detects that a customer is downsizing, it offers less generous discounts or none, and those customers face potential licence audits showing they need more entitlements, after which the software is offered at list price or close to it. Read that carefully. It does not require anybody to retaliate.

It describes a commercial process where signalling a reduction moves you into a different pricing treatment. The practical implication is that how and when you disclose a reduction is itself a negotiating decision.

The machine that replaced it 3:15

But here is the structural change, and it matters more than any letter. Version nine of Cloud Foundation and vSphere Foundation carries a mandatory compliance report every one hundred and eighty days. At two hundred and seventy days overdue, the management plane is degraded. That is not an auditor arriving.

That is enforcement built into the product, executing on a timer, with no human decision involved. On the mainframe the same idea already exists, because consumption licensing requires you to submit capacity reports monthly. The audit as an event is being replaced by continuous reporting with a technical penalty attached.

What to negotiate 3:54

So what do you actually ask for. A cure period, written into the agreement before you sign, that gives you a defined window to correct a reporting failure before any penalty or degradation applies. Thirty days is reasonable and it is the single most valuable clause in this whole area. Ask that audit costs sit with the vendor unless a material shortfall is found, define material in numbers, and cap how often an audit can be initiated.

And keep your own entitlement position current, because three business days is only frightening if you do not already know the answer. Next time, Daniel and I ask whether leaving actually saves money.

Negotiating a Broadcom renewal this year?

Redress Compliance works on contingency: our fee is 25 percent of what we save you. Nothing saved, nothing paid. Independent, buyer side only, never vendor funded. Want Redress to contact you? Reach out and we respond the same day.

Talk to a Broadcom negotiator
Browse all 154 research videos