- Home
- it asset management
- software audit guide
How to Prepare for a License Audit

Introduction
A software license audit is a vendor-initiated review of your software installations, usage and licenses to verify compliance with licensing agreements. Vendors initiate audits to identify unlicensed or over-deployed software and collect audit fees if compliance gaps are found. Organizations with clean, organized license data and documented compliance controls complete audits faster, with lower fees and fewer findings.
What triggers a software license audit?
Software license audits are usually triggered by one of three events: a major contract renewal, a merger or acquisition, or an unusual change in license consumption reported by vendor usage analytics.
Contract renewals: Vendors often conduct audits before renewing large agreements to establish a compliance baseline and identify opportunities to increase licensing fees.
M&A activity: When a company acquires another organization or is itself acquired, vendors use the transaction as a checkpoint to audit both entities' software installations.
Usage anomalies: Vendors monitor usage data through license servers. If they detect spikes in usage that exceed purchased licenses, they may initiate an audit to collect licensing discrepancies.
Knowing the trigger lets you prepare before the audit letter arrives. If you see a renewal coming, conduct your own internal audit first. If M&A is underway, prioritize getting your license data clean and current.
How does a software license audit work?
A software license audit follows a standard three-phase process: initiation, data collection and resolution.
Initiation phase
The vendor notifies you (often with little notice) that an audit will begin. The auditor outlines the scope, timeline and requested information. The audit team typically requests: a list of all software installations, license agreements and maintenance contracts, version information for installed software, and deployment location data (on-premises, cloud, virtual environments).
Data collection phase
Your organization provides the requested documentation and access to systems so auditors can verify what software is installed and how it's being used. Auditors compare your license inventory against their usage data to identify discrepancies: over-licensed software (you own more licenses than you use), under-licensed software (you use more software than you've licensed), and unlicensed software (you use software without purchasing licenses).
Resolution phase
The auditor compiles findings into a formal audit report that details compliance gaps, recommended corrective actions and proposed audit fees. Management meets with the audit team to review findings and negotiate final fees and action items.
The entire process typically takes 2–6 months, depending on your organization's size, data organization and the number of discrepancies found.
What will an auditor look for?
Auditors follow a systematic checklist to uncover licensing issues. Understanding this checklist helps you prepare:
1. Complete software inventory: Auditors verify that all installed software is documented. They look for shadow IT—software purchased by departments outside centralized procurement—and software installed on decommissioned systems or disconnected devices.
2. License agreements and contracts: Auditors cross-reference your installed software against your license agreements to verify that every installation is covered by a purchased license.
3. Software version information: License terms vary by version (e.g., a license for Office 2019 doesn't cover Office 365). Auditors verify that installed versions match licensed versions.
4. Deployment location data: Software license metrics vary by deployment model. A per-seat license for on-premises software may not cover cloud deployments. Auditors verify that deployment methods align with license terms.
5. Usage data: Some licenses are concurrent-use or subscription-based, meaning the number of active users matters. Auditors review usage logs to verify that active user counts match licensed user counts.
6. Product use rights: Some vendors allow license mobility, secondary installations or deployment in virtual environments at no extra cost. Auditors verify whether you're claiming rights you're entitled to—or missing optimization opportunities.
7. Open-source and third-party components: Auditors search for unlicensed open-source software or third-party components embedded in applications, which may have licensing obligations.
Key insight: Auditors are looking for discrepancies that generate fees. The better your data organization and compliance documentation, the fewer discrepancies they'll find.
How do you prepare for a software license audit?
Preparation happens in three phases: before an audit is initiated, during the audit itself, and after the audit is complete.
Before an audit
Establish a license inventory
Create a central repository of all software licenses, including: purchase agreements, maintenance contract terms, license quantities and expiration dates, product use rights, and deployment permissions. If you don't have a current inventory, this is your first step.
Conduct a discovery sweep
Deploy automated discovery tools to identify all software installed across your infrastructure—on-premises systems, cloud environments, virtual machines and even disconnected devices. Normalize software titles so that "Microsoft Office 365," "Microsoft 365 Apps" and "MS Office" all map to the same canonical entry, allowing easy reconciliation against license agreements.
Reconcile usage to licenses
Compare your discovered software against your license inventory to identify: over-licensed software (you can reduce or cancel), under-licensed software (you need to purchase more or reallocate), and unlicensed software (you need to purchase or remove).
Document compliance controls
Record the processes, tools and responsibilities in place to manage software procurement, deployment and usage. Auditors want to see that compliance isn't accidental—it's intentional and governed.
Conduct an internal audit
Perform your own internal audit before the vendor auditor arrives. Use your discovery tools and license inventory to identify discrepancies, then address them proactively. This gives you control over the narrative and reduces findings during the external audit.
Identify and remediate issues
For any compliance gaps you find (unlicensed software, over-deployment), decide: purchase the missing licenses, remove the software, or reallocate licenses from over-licensed applications. Implement changes before the external audit begins.
During an audit
Assign an audit response team
Designate a cross-functional team: IT operations (system access and data), procurement (license agreements), legal (contract terms), and finance (budget for remediation). This team will coordinate with auditors and gather requested information quickly.
Provide organized documentation
Submit requested documents in a clear, organized format. Auditors review thousands of documents during an audit; organized submissions signal compliance and reduce back-and-forth requests that extend the timeline.
Be responsive
Answer auditor questions quickly and accurately. Slow responses extend the audit timeline and signal that you're disorganized, which may prompt auditors to dig deeper.
Don't over-disclose
Provide what's requested, but don't volunteer additional information. If an auditor asks for "all Microsoft licenses," provide that data; don't include Adobe, Salesforce and everything else. Over-disclosure opens doors to additional inquiries and potential findings.
After an audit
Review the audit report carefully
Audit reports detail findings (compliance gaps), recommended corrective actions and proposed fees. Review the report with your team and identify any factual errors or disputed findings.
Prepare for the resolution meeting
Gather your own documented findings, license purchase records, usage data and any evidence that contradicts the auditor's findings. Come to the meeting prepared to negotiate, not just listen.
Negotiate fees and action items
Audit fees are often negotiable. If you can demonstrate that certain findings are factually incorrect, or that you've already remediated issues, you can reduce fees. Agree on corrective action timelines and ensure they're realistic for your organization.
Implement corrective actions
Complete agreed-upon remediation within the negotiated timeline. Document completion and communicate results to the auditor as proof of compliance.
What should your software license audit checklist include?
Use this checklist to prepare your organization for a vendor audit. Work through each section before an audit is initiated; this positions you to control the process rather than react to it.
Inventory and Discovery
- Deployed discovery tools to 100% of systems (including disconnected devices)
- Identified all software installed across on-premises, cloud and virtual environments
- Normalized software titles for easy license reconciliation
- Created a centralized software inventory (if one doesn't exist)
- Documented software versions for all installed applications
License Documentation
- Compiled all software license agreements and contracts in one location
- Documented license quantities, deployment rights and version numbers
- Recorded license expiration dates and renewal terms
- Documented product use rights (secondary installations, virtual deployment, etc.)
- Identified any maintenance or support contracts attached to licenses
Usage and Reconciliation
- Collected usage data for all software (users, deployment locations, frequency)
- Compared software usage to license quantities and identified discrepancies
- Identified over-licensed software (opportunities to reduce or reallocate)
- Identified under-licensed software (compliance gaps that need remediation)
- Identified unlicensed software (purchase or remove before audit)
Compliance and Governance
- Documented procurement process and approval authorities
- Assigned a license manager or SAM owner
- Established governance policies for software procurement and deployment
- Conducted an internal audit and documented findings
- Remediated identified issues before external audit begins
Preparation and Communication
- Assembled a cross-functional audit response team (IT, Procurement, Legal, Finance)
- Prepared organized documentation ready for auditor submission
- Trained team on audit process and communication protocols
- Identified potential disputed findings and gathered supporting evidence
Established escalation paths for audit-related questions and decisions
What will appear in a software license audit report?
A software license audit report is an official document that details the auditor's findings and proposed fees. Typical sections include:
Executive summary
High-level overview of audit scope, timeline and key findings. This is what management reads if they don't read the full report.
Compliance findings
Detailed list of every discrepancy found: over-licensed software (with quantities and cost impact), under-licensed software (showing the gap and licensing costs to remediate), and unlicensed software (with potential fees if not remediated).
Audit fees
Proposed fees for remediation. Fees vary by vendor and often depend on the number of discrepancies and their severity. This section is where negotiation happens.
Corrective action plan
Recommended steps to remediate findings, including purchase of missing licenses, removal of unlicensed software, or reallocation of existing licenses. Timelines for completion are often included.
Supporting documentation
Attachments may include: list of discovered software with installation counts and locations, comparison of discovered software vs. licensed software, usage logs or deployment data that support the auditor's findings, and contract terms that define license entitlements.
Key insight
The audit report is a negotiation document. Inaccuracies and disputed findings can be challenged. Come to the resolution meeting with evidence that contradicts the auditor's claims.
Frequently asked questions
How often does a vendor initiate a software license audit?
Frequency varies by vendor and organization. Large vendors (Microsoft, Oracle, IBM, SAP) conduct audits most frequently—often every 2–3 years, particularly around contract renewals. Smaller vendors may audit less frequently. Organizations with mature Software Asset Management programs and documented compliance controls are audited less often, because vendors see lower risk. The key: demonstrating that you're managing licenses seriously reduces audit frequency.
What's the typical financial exposure from a software license audit?
Audit fees depend on the number and severity of compliance gaps. A well-prepared organization with minimal discrepancies might face $50K–$200K in fees. An unprepared organization with significant unlicensed software could face $500K–$2M+ in fees. The largest cost drivers are under-licensed enterprise applications (Oracle, SAP) which have high per-unit licensing costs. Preparation and proactive remediation are the most effective ways to minimize exposure.
Can I negotiate audit fees?
Yes. Audit fees are often negotiable, particularly if you can demonstrate that certain findings are factually incorrect, or that you've already remediated issues. Come to the resolution meeting prepared with: your own usage data showing compliance, evidence of license purchases or deployments you claim, and documented remediation steps you've already taken. Vendors often reduce fees if they see that you're taking compliance seriously and have already fixed some issues.
What's the difference between an internal audit and an external audit?
An internal audit is one you conduct yourself, using your own tools and data, to identify compliance gaps before a vendor audits you. It gives you control and time to remediate issues. An external audit is initiated by a vendor and follows their scope and timeline. The best practice is to conduct internal audits regularly (annually or semi-annually) so that when an external audit happens, you're already compliant or have time to remediate.
What should I do if I find unlicensed software before the audit?
Three options: (1) Purchase licenses for the software if it's critical to your business. (2) Remove the software if it's not essential. (3) Reallocate licenses from over-licensed software if the licensing terms allow it. The key is to remediate before the external audit begins. If you discover the issue and fix it proactively, you're in a much stronger negotiating position if the auditor finds it independently.
How long does an audit typically take from start to finish?
Do I need a Software Asset Management tool to prepare for an audit?
Get in touch with an expert
Do you have questions about our offering? A quick call can be way more helpful than a long email chain. Talk to one of our experts to explore our products and see them in action.

Brian Riley
Sales Development
IT Asset Management
Send us a message
No matter if you like to partner with USU or just have a few questions.



