Received an IBM audit notice? Understand what happens next, what to review before providing data, and when to consider independent IBM licensing advice.
Receiving an IBM audit notice can put an organisation under immediate pressure. The audit may require you to evidence what IBM software you are entitled to use, where it is deployed, how it is licensed and whether requirements such as sub-capacity licensing have been met. The auditor will also need information from different parts of the business, which can involve SAM, IT, Procurement, Legal and individual product owners.
Before that information starts being provided, there are some important points to establish. You need to understand which products, licences and parts of the organisation are included in the IBM audit, who will coordinate the response, and how your own view of your IBM licence position compares with the information being requested.
IBM licensing can be difficult to assess across a large software estate. Individual products have their own licensing rules and metrics, while IBM also has specific compliance reporting requirements to consider. Its portfolio changes regularly through acquisitions and divestments, adding another layer of complexity for organisations trying to maintain an accurate view of their position.
In this guide:
First, appoint a central contact to coordinate communication with IBM and the auditor. Confirm the scope and proposed timeline, identify the internal teams that hold relevant evidence, and review information before it is provided.
This becomes particularly important where information needs to come from several technical or business teams. Someone who understands an IBM product operationally may provide perfectly accurate technical information without knowing how that information will be interpreted for licensing purposes. Information supplied without the right context can contribute to compliance findings that take considerable effort to correct later. Keeping a written record of communications and information supplied during the audit also means there is a clear record of how particular conclusions have been reached.
Data handling should be considered at this stage too. An IBM software audit can involve sensitive information such as machine names, software components, IP addresses, usernames and contractual agreements. Existing NDAs may not adequately cover the circumstances of an audit, particularly where a third-party auditor needs to share its findings with IBM, so any confidentiality requirements should be considered before sensitive information starts being exchanged.
An IBM software audit may involve IBM and an appointed third-party auditor, with Deloitte and KPMG among the firms that conduct IBM licence compliance audits. The auditor gathers and reviews information from the customer to establish a compliance position for the IBM software within scope.
Several teams are likely to be involved on the customer side as well. Depending on the organisation and the products under review, this could include Software Asset Management (SAM), IT, Procurement, Legal and the technical teams responsible for individual IBM products. Organisations can also engage an independent IBM licensing advisor to provide additional expertise during the audit, particularly when reviewing data requests, licensing calculations and audit findings.
IBM customers are required to cooperate with a licence compliance audit, but that does not mean every information request or collection method will necessarily be relevant to your environment. The information and methods used to establish the compliance position are therefore areas that can be discussed during the audit.
Auditors may issue questionnaires and procedures for individual IBM products, but every question will not necessarily be relevant or applicable to your environment. Before providing information, it is worth understanding what a request is intended to establish and which internal source provides the appropriate evidence. Additional context may also be required where deployment information alone does not accurately reflect the licensing requirement.
In some IBM audits, scripts may be proposed to collect hardware and software inventory data. These scripts are not mandatory, and any proposed scripts should be reviewed by your internal security teams before they are deployed.
Yes. The scope of an IBM audit can be discussed and should be reviewed early in the process: the products and licences under review, the corporate entities covered, the proposed timeline and the methods that will be used to collect information. Once the audit is underway, changing the agreed scope can become much harder.
Corporate scope can require particular attention following mergers, acquisitions or divestments. Different entities may operate separate IT environments or hold different IBM agreements, so it may be necessary to clarify which organisations and entitlements are included. If the entitlements within scope are unclear, it is reasonable to request a list from the auditor at the beginning of the review.
The timeline can also be discussed. IBM’s Passport Advantage terms indicate that compliance verification should minimise business disruption, allowing busy periods and the time required to collect information to be considered when planning the audit. Enough time should also be allowed towards the end of the process to review the auditor’s findings properly.
An important part of preparing for an IBM audit is establishing your own view of your licensing position. This starts with understanding what IBM licences the organisation is entitled to use. IBM Passport Advantage Order History can provide a historical record of licence purchases, Subscription & Support, reinstatements and trade-ups, while Enterprise Agreements and other contractual documentation may contain additional entitlement information and relevant terms.
The entitlement position then needs to be compared with how IBM software is deployed and used. ILMT, BigFix Inventory or an approved Flexera tool may provide an important source of deployment information, although other inventory sources should also be reviewed where available. Comparing overlapping sources can help identify gaps or inaccuracies before they influence the compliance assessment.
Exactly what needs to be collected will depend on the products and licence metrics involved. Processor Value Unit (PVU) licensing requires information about the hardware on which software is installed, while Authorized User licensing is based on the people who can access the software. Bringing the entitlement and deployment information together gives the organisation its own compliance position against which the auditor’s eventual findings can be assessed.
ILMT deserves particular attention during an IBM audit where software is licensed using processor-based metrics such as PVU or VPC. By default, IBM requires the processor cores in the physical host to be counted, even where the software itself is running on a smaller virtual machine or logical partition. Organisations that meet IBM’s sub-capacity requirements can instead calculate the requirement based on the processors allocated to those virtual environments.
Having ILMT installed alone does not satisfy all of the requirements for sub-capacity licensing. Areas such as BigFix agent coverage, historical report retention, VM Manager connections, software classification and the technical health of ILMT and BigFix should also be reviewed. Problems in these areas can affect the quantities reported and may create a risk of IBM assessing licensing at full capacity.
It is also worth comparing ILMT with another inventory source where possible. The ILMT dashboard can identify a number of technical issues, but it cannot show machines that it has failed to discover in the first place. Comparing its coverage with a CMDB or another inventory source can help identify those gaps.
Once the auditor has reviewed the information submitted during the IBM audit, you will typically receive a draft Effective License Position (ELP).Review it before the final report is shared with IBM. The draft sets out the auditor’s assessment of your compliance position and any licence discrepancies identified.
That review should go beyond checking whether the inventory figures look right. It is important to understand how the auditor reached each conclusion, including any assumptions applied to the data and the licensing terms used in the assessment. IBM licensing can support different interpretations depending on the circumstances, and the relevant License Information documents should be checked as part of the review.
The teams responsible for the IBM products involved should have enough time to assess the findings and provide operational context. Any corrections, disagreements or additional information should be documented in writing and supported with evidence. Auditors may seek to move through this stage quickly, so sufficient time needs to be allowed for a proper internal review before the ELP is finalised.
A confirmed licence shortfall may mean that additional licensing is required, although there can still be different ways of addressing that requirement. Some IBM products are available under more than one licence metric, while existing Cloud Pak entitlements may provide coverage across different products or metrics. Whether these options apply depends on your entitlements and circumstances, so they should be considered before agreeing to acquire additional licences as part of an IBM audit settlement.
The end of the audit may also create follow-up obligations. These could include removing software components, correcting deployments, addressing sub-capacity issues, cleaning up user accounts or submitting an updated ILMT report. Keeping a record of the data sources, contacts, collection methods and licensing methodology used during the audit can also make future compliance reviews easier to manage.
The need for external support will depend on the IBM licensing expertise available within your organisation and the complexity of the software estate being reviewed. Where that expertise is limited internally, getting independent advice early in the IBM audit can help the organisation establish its own compliance position and understand the implications of information before significant amounts of audit data are submitted.
Independent IBM licensing support can also be useful when reviewing the auditor’s findings. If there are significant differences between your internal assessment and the draft ELP, or findings depend on a licensing interpretation you believe needs further examination, an independent advisor can review the underlying data, entitlements and IBM licensing terms from the customer’s perspective.
If you are preparing for an IBM audit or already going through one, our Mastering IBM License Compliance Audits guide looks at each stage of the process in more detail. It covers preparing your entitlement and deployment position, ILMT and sub-capacity requirements, audit scope, data requests, draft ELP review, settlement and the actions that may be required after the audit.