Thirty years of enterprise IT, distilled into something you can use on Monday morning.
Operational ITAM is a podcast about the unglamorous machinery of enterprise technology — hardware and software asset management, licensing, audit defense, SaaS governance, and the money quietly leaking out of all of them. Host Bill Van Nort has led IT asset management, end-user computing, and workplace technology at large organizations across banking, mortgage, and automotive, reclaimed millions in software spend, and survived audits from the biggest publishers on the planet.
No vendor pitches disguised as advice. No jargon for its own sake. When something is an opinion, he says so. When the honest answer is "it depends," he tells you what it depends on.
New episodes cover the fundamentals that never change: know what you have, know where it is, know what it costs, know when it leaves.
Hey everybody, and welcome back to the Operational ITAM Podcast.
I'm Bill Van Nort, and today is the episode I've been promising you since the very first show.
The Audit Defense two-parter starts right now. Part 1. Today.
From the moment the letter lands, through the audit itself. Part 2. Next episode.
The findings, the negotiation, and the handshake at settlement.
If you're new to the show, welcome, truly. This one will stand on its own,
but it stands a lot taller on top of episode 3, where we built the ledger.
Entitlements on one side, deployments on the other, and the effective license position in between.
If you haven't heard it, put it in the queue. Today we find out what happens
when somebody else decides to check your ledger for you.
Good morning, good afternoon, or good evening, wherever you happen to be listening from.
This is the Operational ITAM Podcast. the show where we take the unglamorous
machinery of enterprise technology and make it make sense.
I'm your host, Bill, and today we're talking about the most stressful piece
of mail in enterprise IT.
Welcome in. Grab your coffee, grab your headphones, and let's get into it.
Picture the scene, because I've lived it more times than I care to count.
It's a Tuesday. Somewhere in your legal department, or maybe on your CIO's desk,
an envelope or an email arrives.
Formal letterhead. Careful language. It cites a clause from an agreement somebody
signed years ago, and it informs you, politely, always politely,
that the publisher is exercising its contractual right to verify your usage of its products.
You have, typically, 30 to 45 days to respond.
Congratulations, you've been selected. And I want you to hear the first and
most important thing I will say today.
What you do in the next two weeks will influence the final number more than
anything you've done in the last two years.
I've watched organizations turn seven-figure exposures into manageable outcomes,
and I've watched organizations turn manageable exposures into seven-figure settlements.
And the difference was almost never the compliance position.
It was the response.
Before we get to the response, let's take honest stock of the battlefield,
because I promised you evidence over enthusiasm.
First, this will happen to you. Recent industry surveys put the odds of facing
a major vendor audit in any given year at better than 60% and rising.
Large enterprises should expect a formal audit or license review from at least
one major publisher every three to five years.
And if you run a full portfolio of the big names, the practical answer is that
somebody is auditing something of yours almost every year.
The most active auditors, survey after survey, Microsoft, IBM, Oracle, and SAP.
With Oracle's Java program, the one we covered last episode,
pulling thousands of new companies into audit territory that never expected to be there.
One industry prediction says one in five Java users will face an Oracle audit.
This is not lightning. This is
weather. Second, the auditor at your door frequently isn't the publisher.
Many audits are conducted by third-party firms, including names you'd recognize
from the accounting world, engaged and paid by the publisher.
Now, these are professional organizations, but let's apply the skepticism I
told you to pack last episode.
The engagement is funded by the vendor, scoped to the vendor's metrics,
and the findings are the product.
Treat the auditor's analysis as a position to be tested, never as a neutral fact.
That's not cynicism. That's just knowing who signs whose invoice.
And third, and this one matters more every year, the audit doesn't always announce itself as an audit.
Remember what I said in episode 3. For certain publishers, the audit is a sales function.
Well, the modern version often arrives wearing a smile.
A friendly email from your account team offering a license health check.
Maybe a software asset management engagement. Complimentary, of course.
The usage review to help you optimize.
Microsoft in particular rarely opens with a formal audit letter anymore.
It opens with an invitation.
And here's the thing. The invitation is voluntary. The formal audit is not.
But the data you hand over works exactly the same way in both.
So the house rule is simple. Any request for deployment data gets treated with
audit-level discipline, no matter how friendly the font is.
Which brings us to a listener question. Sandra from Grand Rapids writes,
Bill, our account rep offered us a free licensing assessment before our renewal.
Leadership thinks it's great customer service.
I think it's a trap. Who's right?
Sandra, you are, and I'd frame it this way for your leadership.
It may be sincere, but you can't un-ring the bell.
Whatever that assessment finds is now known, on the record, before your negotiation.
If you want an assessment, run your own, on your side of the table,
and decide what to do with the results yourself.
Never outsource the discovery of your own weaknesses to the counterparty.
That's not customer service. That's discovery, in the legal sense.
All right, the letter has landed. The real one.
Here's the heart of today's episode. The five opening moves.
Learn these five, make them in order,
and you'll be ahead of 90% of the organizations that get that letter.
Move one. Contain it. The moment an audit notice arrives, and understand,
these letters don't always land on the right desk.
Sometimes they show up in a support inbox and wander the org chart for weeks. The clock is running.
So move one is containment. Acknowledge receipt promptly and professionally.
Ignoring the letter accomplishes nothing except making you look evasive, and it will not go away.
Notify senior leadership and legal counsel immediately. This is now a managed
corporate matter, not an IT task.
And most critically, appoint a single point of contact. One person. One voice.
Every communication with the auditor flows through that one channel.
Every email, every question, every file.
How does it fail? Freelancing. The auditor emails a friendly question directly to a server admin.
The admin helpfully replies with a screenshot, and congratulations,
you've just expanded the scope and volunteered evidence, unreviewed,
in a proceeding your legal team is supposed to be managing.
I've seen a single well-meaning email cost more than a year of license spend.
The control. Everyone in the organization knows the rule. Auditor contact goes
to the point of contact. Full stop.
Politely, professionally, without exception.
Move 2. Read the contract.
The audit is not a police raid. It is a contractual proceeding,
and the contract, the one gathering dust in that entitlement library we built
in episode 3, defines the rules.
Before you agree to anything, read the audit clause. What does it actually grant?
Which products? Which legal entities? How much notice?
What confidentiality protections? Who bears the cost?
The letter you received will often be written broadly. We intend to review your
use of our products. All products. Everywhere. Forever.
That breadth is an opening position, not an entitlement. Your obligations are
what the clause says. Not one server more.
How it fails. Nobody reads the clause. The organization assumes the auditor's
request is the requirement and hands over the estate.
The control. Legal and your ITAM lead sit down with the actual agreements.
And remember, if your entitlement library is in order, this takes an afternoon.
If it's not, well, now you know why episode three assigned the homework it did.
If you're enjoying the show, do me a favor, like and subscribe,
post a comment, and share this episode with somebody who's staring at an audit letter right now.
This might be the most valuable 30 minutes of their quarter.
All right, the letter is contained, the contract is read.
Three moves to go, and these are the ones that determine the size of the finding.
Move 3. Control the terms. Before any data changes hands, the engagement itself gets negotiated.
And yes, it is negotiable. Far more of it than most people believe.
Three things go on the table.
First, a non-disclosure agreement specific to the audit.
Most publishers and auditors will agree to one, and it governs how your data
is handled, who sees it, and what happens to it afterward.
Get it before anything else.
Second, scope, in writing. Named products, named entities, named environments,
agreed against the contract language from move two. Not everything.
Third, methodology. What tools will be run, by whom, under what conditions, on what timeline?
If the auditor wants to run collection scripts in your environment,
those scripts go through your change control like any other software,
because that's exactly what they are. You are not obstructing.
You are being the kind of organization that has controls.
Auditors, believe it or not, respect that. And more importantly,
so does the record. How it fails.
The organization is so anxious to appear cooperative that it accepts every default.
The auditor's scope, the auditor's tools, the auditor's timeline.
Cooperation is right. Surrender is expensive. There's a difference,
and the difference is a statement of work.
Move 4. Build your own position first.
This is the move that separates the professionals.
Before the auditor measures anything, you measure it yourself.
Run your own reconciliation. Your entitlements against your deployments.
The same ledger from episode three, focused on the products and scope.
You need to know what the auditor is going to find before they find it.
Because everything downstream, your negotiating posture, your remediation options,
your leadership briefings, depends on whether you're walking into this blind or sighted.
And two warnings here, both non-negotiable. Warning one, do not panic buy licenses
when the letter arrives.
It's tempting, close the gap quick, look clean. But many publishers ignore purchases
made after the notice date when calculating findings, which means you can pay
for the same shortfall twice, once at the store, once at the settlement table.
Hold your wallet until you understand your position.
Warning two, and I shouldn't have to say this but 30 years says otherwise.
Do not start quietly uninstalling software to hide it.
Beyond the ethics, deployment history leaves fingerprints everywhere,
and an auditor who catches one concealment will stop believing every honest
number you show them afterward.
Your credibility is an asset on the ledger too.
Legitimate cleanup of genuinely unused software is housekeeping.
Cleanup because the letter came is evidence tampering with a service ticket.
Know the difference. Document the difference.
Move 5. Control the data.
Here is where audits are won and lost, so lean in.
When collection happens, it happens in a controlled manner. Agreed tools,
your environment, your supervision.
And before one row of output leaves the building, you verify it.
Line by line, against reality, and against the contract's actual metrics.
Because raw discovery output, and you know this from episode three, is a crime scene.
It doesn't know your disaster recovery servers from production.
It doesn't know the lab from the line of business.
It counts the dev environment, the training room, the decommissioned cluster
that still answers pings.
Unverified script output is probably the single biggest driver of inflated audit
claims in this industry. Let me give you the war story.
Years ago, I'll keep the publisher anonymous, they know who they are,
I sat across from a preliminary finding that was, let's say, deeply upsetting.
Seven figures deeply.
And when we tore into the data before releasing it, we found the collection
had swept up an entire disaster recovery site.
Cold standby, contractually covered, explicitly addressed in our agreement,
and counted it as production deployment.
One environment. Roughly a third of the claim. Gone because somebody on my team
checked the output instead of forwarding it.
That somebody earned their salary for the decade that afternoon.
Release only what the agreed scope requires, only after verification,
only through your single point of contact, every single time.
And that's where part one ends. Deliberately, on a cliffhanger,
because that's honestly how it feels in real life.
You've made the five moves. The data is submitted. Weeks pass.
And then a document arrives with a title like Preliminary Findings,
and there's a number in it.
And the number has more digits than your annual budget meeting.
What happens next? How findings become negotiations. How negotiations become settlements.
Why that opening number is almost never the closing number, and what leverage
you actually hold, that's next episode.
I promise you'll never read a true-up demand the same way again.
Let's extend the library one more time before we go, because it has never let
us down. The audit is the inspector arriving to check the loan records.
And here's what part one teaches. When the inspector knocks,
you do not hand them the master key and wave them toward the stacks.
You meet them at the front desk. You examine their credentials. That's the contract.
You agree on which collections they're entitled to inspect.
That's scope. You walk the shelves yourself before they do. That's your own position.
And you accompany them, courteously, clipboard for clipboard, the entire visit.
That's data control. A library with nothing to hide still doesn't hand out master keys. Neither do you.
One closing principle in the tradition of this show.
Hardware asset management is a custody discipline. Software asset management
is an evidence discipline.
And audit defense? Audit defense is a process discipline.
Here's the truth at the center of it. By the time the letter arrives,
you cannot change your compliance position.
That ship sailed with every gate you did or didn't guard.
But you can absolutely change the outcome. Because the outcome is a product
of the process, and the process is yours to run.
Contain, Read, Control, Prepare, Verify.
You can't control the finding. You can control everything that shapes it.
Class dismissed. Homework time. And this one requires no letter,
no budget, and no permission.
This week, pick your biggest publisher, the one whose audit would hurt the most,
and go find the audit clause in your agreement with them.
Actually read it. Answer three questions on one page. How much notice are they required to give?
What exactly are they entitled to examine? And what protections do you have?
Confidentiality, cost, dispute process.
If you can't find the agreement, then your homework just found itself, didn't it?
Because the worst possible time to locate a contract is 30 days after the other
side has already read it.
Next episode, part two. The findings land, the number is enormous,
and the real game begins.
We'll talk about how claims get inflated, how they get deflated,
what the publisher actually wants.
Spoiler, it's usually not the number on the page, and how to walk out of the
settlement with a deal instead of a wound. Bring a calculator.
And bring that skepticism back too. You'll need both.
That's today's episode. The letter doesn't scare you anymore,
and that's the whole point.
I'm Bill Van Nort. This is the Operational ITAM Podcast.
Guard the gates, keep the ledger, run the process, and I'll see you at the settlement
table next week. Take care.