Audit defence services.
$20M+
$1.25M+
8 weeks
An audit notice is a negotiation, not an inspection.
Most audits begin with a vendor — or their appointed third-party auditor — claiming significant non-compliance. The numbers cited in the initial position paper are rarely the numbers you end up paying. Everything between is negotiation.
That negotiation hinges on three things: how thoroughly you understand your contracts, how accurately you can measure your deployment, and how confidently you can challenge the auditor’s methodology. That’s where most internal teams get into trouble — not because they’re incapable, but because each of those three skills is its own discipline.
We’ve been on both sides of the table. We know how vendor licensing teams build their cases. Our AI forensic engine analyses contracts and deployment data in parallel — surfacing methodology divergences and challenge points before the auditor’s position paper even lands. We know how to negotiate a settlement that protects your bottom line and your operating relationship with the vendor.
We know their playbook.
IBM Software
- ILMT deployment gaps and sub-capacity reconciliation
- ECM product version and metric misclassification
- Passport Advantage contract schedule interpretation
- Authorised User vs. PVU metric disputes
Oracle
- VMware / cloud virtualisation — Oracle's hard partition rules
- Java SE licensing — per-employee metric challenges
- ULA certification scope and product inclusion disputes
- Indirect access and integration point claims
Microsoft
- M365 / EMS license tier over-assignment challenges
- Azure Hybrid Benefit and BYOL eligibility
- SQL Server virtualisation and core factor table disputes
- True-Up vs. MPSA reconciliation methodology
SAP
- Indirect / digital access claim methodology challenges
- Named user reclassification and role consolidation
- S/4HANA transition — legacy metric mapping disputes
- BTP and cloud extension licensing scope
IBM audits involving ILMT/BigFix, ECM, and Passport Advantage can create significant exposure. We challenge sub-capacity calculations, PVU measurements, product classifications, and contract interpretations.
- ILMT deployment gaps and sub-capacity reconciliation
- ECM product and metric classification
- Passport Advantage contract interpretation
- Authorised User vs. PVU disputes
Oracle audits often involve complex virtualisation, ULA, processor, Java, and indirect-access licensing rules. We challenge methodology and help reduce inflated opening claims.
- VMware and cloud virtualisation
- Oracle Java SE licensing
- ULA certification scope
- Indirect access claims
Microsoft audits and true-ups can involve complex user, device, cloud, and licensing-tier rules. We review the contractual position and challenge unsupported claims.
- M365 / EMS licensing
- Azure Hybrid Benefit
- SQL Server virtualisation
- True-Up and MPSA reconciliation
SAP audits can create significant exposure through indirect access, named-user licensing, and complex product metrics. We analyse the claims and build an evidence-based defence.
- Indirect and digital access claims
- Named-user classification
- S/4HANA licensing
- BTP and cloud licensing scope
Four stages. One objective: close the audit clean.
From the moment the notice arrives to post-settlement hardening — every action is sequenced, time-boxed, and AI-assisted. The exposure gauge tracks our progress in real time.
Stage 01 — Triage
Scope assessment, contractual basis review, auditor identity verified, and exposure modelled — before any data leaves your environment.
Stage 02 — Independent Measurement
Forensic-grade parallel measurement using AI-assisted deployment analysis. Our baseline is ready before the auditor’s numbers land.
Stage 03 — Challenge & Negotiate
AI methodology analysis identifies every divergence from contract language. We challenge in writing, line by line, and negotiate directly with the vendor’s audit team.
Stage 04 — Settle & Harden
Audit closed. Automated controls designed to prevent recurrence. Your next audit cycle finds far less to complain about.
AI Forensic Engine
Independent Measurement
Automated Hardening
Six work-streams. One outcome.
Notice review & strategy.
The day the audit notice arrives, we review the scope, the contractual basis the vendor is invoking, and the appointed auditor’s methodology. We agree a defence strategy with you before any data leaves your environment.
- Scope verification — what products and entities are in scope, and whether the audit right is validly invoked
- Auditor identity review — who is conducting the audit, and what methodology they typically apply
- AI-assisted contract analysis — license metrics, schedule terms, and contractual limitations on audit scope
- Initial risk model — exposure range estimated before any data is shared with the auditor
Independent measurement.
We run our own deployment measurement in parallel with the vendor’s — using AI-assisted forensic tools to process infrastructure data at scale. When the auditor’s numbers land, we have an independent baseline ready to compare against — and to challenge from.
- Automated infrastructure discovery across on-premise, cloud, and virtualised environments
- License metric application — we apply the same rules the auditor will, using your actual contract definition
- Forensic-grade output — a defensible baseline our consultants can present directly to the auditor
- Gap analysis — where our numbers diverge from the auditor’s, we identify the specific cause
Methodology challenge.
Vendors routinely apply licensing metrics that diverge from the actual contract language. Our AI engine forensically compares the auditor’s methodology against your contracts and surfaces every point of divergence — which our consultants then challenge in writing, line by line.
- AI contract-vs-methodology cross-reference — every clause compared against auditor claims
- Metric version disputes — auditors frequently apply newer, more aggressive metrics than the contract specifies
- Virtualisation and sub-capacity rule challenges — the most common source of inflated IBM and Oracle claims
- Written challenge documentation — formal, evidence-backed position delivered to the auditor
Position-paper response.
We draft your formal response to the auditor’s findings. Each non-compliance claim is analysed individually — accepted where the evidence is clear, partially contested where the methodology is arguable, or rejected where the contract doesn’t support the claim.
- Finding-by-finding analysis — each auditor claim categorised and evidence-weighted
- AI-generated counter-position data — automated calculation of the corrected exposure under our methodology
- Contractual reasoning — every rejection or partial challenge backed by specific clause references
- Settlement anchor — our response sets the opening position for negotiation at the lowest defensible figure
Direct vendor negotiation.
The day the audit notice arrives, we review the scope, the contractual basis the vendor is invoking, and the appointed auditor’s methodology. We agree a defence strategy with you before any data leaves your environment.
- Scope verification — what products and entities are in scope, and whether the audit right is validly invoked
- Auditor identity review — who is conducting the audit, and what methodology they typically apply
- AI-assisted contract analysis — license metrics, schedule terms, and contractual limitations on audit scope
- Initial risk model — exposure range estimated before any data is shared with the auditor
Post-audit hardening.
Once the audit settles, we fix the upstream process gaps that allowed exposure to build in the first place. Automated controls, continuous AI-powered monitoring, and license alerting prevent the same issues recurring — so the next audit cycle starts from a defensible baseline.
- Root cause analysis — the compliance gaps the audit revealed, mapped to specific process failures
- Automated license controls — deployment guardrails that prevent exposure drifting above entitlements
- Continuous AI monitoring — real-time alerting when license positions move outside defined thresholds
- Audit-ready baseline — a defensible license position maintained year-round, not rebuilt under pressure
Don't go in without specialists.
If you’ve received an audit notice — or you’re hearing rumblings that one is coming — the first 72 hours matter. Book a call now. We’ll review the notice, talk through the vendor’s likely position, and tell you whether you need our help or your internal team can handle it.
What you'll get
- 30-minute call with a senior audit defence consultant.
- Honest read on the vendor's likely position and exposure range.
- Recommended response strategy for the next 30 days.
- Clear view of whether external help is needed at all.