A stage-by-stage guide to IBM license audits, with practical advice on scope, data requests, ELP reviews
An IBM audit asks you to prove that what you’ve deployed matches what you’ve bought, and that you’ve met IBM’s licensing conditions, including the rules for sub-capacity. The evidence is spread across SAM, IT, Procurement and Legal, plus individual product owners, and audits can run for well over a year if nobody takes control of the process.
This guide follows an audit in the order things happen and links to our detailed articles at each stage.
IBM usually appoints KPMG or Deloitte to carry out its audits. After a formal notification, the auditor collects data and analyzes your licenses, reports its findings, and hands over to IBM for a commercial negotiation.
The findings report is the Effective License Position (ELP). For each product in scope, it compares licenses purchased with quantities deployed and records any shortfall. The ELP contains no financial values. Those are added later, when IBM prices the shortfalls during settlement.
IBM positions its CVA program as a collaborative assessment. In practice it works much like IBM’s earlier IASP model, and the commercial consequences can be similar. Our article on IBM CVA sets out three questions to ask before you take part.
Before you hand over any data, agree internally what’s in scope and who is running the response. Work out how your own view of your license position compares with what the auditor is asking for, so you can spot differences early.
Most organizations benefit from having one central contact person who manages all communication with the auditor. Put a non-disclosure agreement in place early so it’s clear who can see your data and how it will be used.
Read more: How to Respond to an IBM Audit Notice in 2026
Start with entitlements. Your Passport Advantage Order History records your license purchases and your Subscription & Support history, including reinstatements and trade-ups. Enterprise Agreements may add further entitlements and terms.
Deployment data will mostly come from ILMT, BigFix Inventory or an approved Flexera tool. Check your other inventory sources as well. Where two sources overlap, comparing them shows you gaps and inconsistencies before the auditor finds them.
Read more: Preparation is Key: Mastering IBM License Compliance Audits
Sub-capacity licensing lets you license only the capacity available to the software, as long as you meet IBM’s requirements. If the auditor decides you haven’t, you can be assessed on the full capacity of the physical server, and the numbers grow quickly. A large part of the $120m exposure we estimated for Altus, a Fortune 500 company, came from the auditor’s view that its sub-capacity requirements hadn’t been met. Our article on meeting sub-capacity requirements explains what IBM expects.
Container deployments have their own licensing rules and are a growing source of findings. Past metric conversions, such as from Processor Value Unit (PVU) to Virtual Processor Core (VPC), are also easy to lose track of. If they aren’t recorded properly, your entitlements can end up understated in the ELP.
Scope and timing are open to negotiation, and they’re much easier to agree at the start.
Plan the timeline around your team’s workload, avoid quarter-end close and holiday periods, and leave enough time at the end to check the ELP for errors. IBM’s Passport Advantage Agreement says audits should minimize business disruption, which gives you a basis to push back on an unrealistic schedule.
Be precise about which legal entities are covered. Mergers, acquisitions and divestments blur the lines, and a subsidiary that is legally and operationally separate may fall outside the audit altogether.
Read more: IBM License Compliance: How to Negotiate the Audit Scope
The audit clause says you must cooperate. It doesn’t say exactly what data you have to provide, and auditors often ask for a wide range, such as server configurations, user access logs and details of custom deployments.
You can ask what each request is for. If a different data source would give the auditor the same insight with less work for your team, propose it. In the Altus audit, data requests were the main thing holding the process up. In many cases we pushed back and found alternative sources that met the evidence requirements with much less effort.
Anomalies need the same early attention. When the auditor queries something like a high user count or a duplicate install, explain it straight away. Once an issue reaches the draft ELP it becomes a license shortfall, and from there it gets a price.
Read more: IBM License Compliance: Understanding Data Requests in Audits
Record how each piece of data was collected: the script, tool or export used, who ran it, and whether it came from IBM tools or your own systems. Add how you validated the figures and why you made any licensing judgments, for example on bundling or exceptions that affected the ELP.
If you keep these records, whoever handles your next audit can repeat the process and see why earlier decisions were made. Our article on documenting audit data collection covers what to capture.
The draft ELP is your best chance to correct the findings before IBM puts a price on them, and the review window can be as short as two weeks.
Check that every entitlement has been credited, including any past metric conversions, and that licensing terms have been applied correctly. Look at how the auditor has interpreted your technical data too, which was one of the areas we corrected in the Altus counter report.
Pay close attention to extrapolation. When data is missing, auditors sometimes estimate, and occasionally they do so even when the data could have been collected with a follow-up request. Collecting that data yourself gives you evidence to replace the estimate.
Read more: IBM License Compliance: How to Review the Draft Audit Report
Buying the licenses listed in the ELP is one way to close a shortfall. A different metric or product can sometimes cover the same use for less. Assess the options before settlement talks start, because once IBM has priced the shortfall, the conversation tends to be about discounts.
Read more: IBM License Compliance: Exploring Licensing Alternatives
Settlements often come with conditions. As part of its settlement, Altus agreed to deploy ILMT. Keep track of what you’ve committed to, because the next audit is likely to check. More in following up on settlement obligations.
Our 10 lessons learned from IBM license compliance audits collects the points that come up again and again in the audits he has worked on.
Mastering IBM License Compliance Audits brings our IBM audit advice together in one document, including scope negotiation, sub-capacity and ILMT requirements, and how to challenge the ELP.
Our IBM team can step in at any stage, including after the auditor has shared a draft report. See our IBM audit defense service
IBM usually appoints a third-party audit firm such as KPMG or Deloitte.
It’s the auditor’s report. For each product in scope, it compares licenses purchased with quantities deployed and shows any shortfall.
The audit clause requires you to cooperate but doesn’t define exactly what data you must share. You can ask what each request is for and propose alternative sources.
IBM presents CVA as a collaborative assessment, but it resembles IBM’s earlier IASP model and can lead to similar commercial outcomes.
In this guide