Knowledge for better technology decisions
Knowledge BaseLicense Management & SAM

License Management & SAM · Foundations

What is software licence compliance—and why does it matter?
How contracts, inventory, and usage form a defensible licence position

Software licence compliance means that installations, deployments, access, and use are covered by valid usage rights. Quantities alone are not enough: metrics, versions, editions, technical environments, and contractual conditions must align.

Compliance comes from reconciliation—not from a licence list.

A defensible conclusion needs four connected views and traceable evidence.

  1. 01Which rights were actually acquired?
  2. 02What is installed, deployed, or accessible?
  3. 03Which product and contract rules apply to the scenario?
  4. 04Is every use covered by a valid right?

Purchased does not automatically mean correctly licensed

An invoice proves a purchase.
It does not prove the complete licence position.

Only by reconciling entitlements, technical inventory, access, usage, and the applicable rules can an organisation identify missing, uncertain, or economically unused rights.

01

Licence compliance answers four connected questions

No single data source can answer them alone. A defensible outcome emerges only when legal, commercial, and technical information is connected.

RIGHT

What may be used?

Contracts, orders, entitlement evidence, maintenance, and product-specific terms describe the available rights.

ESTATE

What has been deployed?

Installations, cloud resources, virtual systems, editions, and versions describe the technical reality.

ACCESS

Who or what can access it?

Assignments, accounts, groups, devices, interfaces, and indirect use can be licence-relevant.

RULE

How must it be counted?

Metrics, minimums, virtualisation, reassignment, failover, geography, and other conditions determine demand.

Important:

Compliance is not a universal vendor seal. It is assessed for a defined scope, point in time or period, and against the contractual and product terms that actually apply.

02

Entitlement and consumption must speak the same language

A licence position becomes unreliable when products, periods, or counting units are interpreted differently on either side.

PerspectiveCore questionTypical evidenceCommon risk
EntitlementWhich rights exist?Contract, order, entitlement statement, invoice, maintenance proofQuantities are known but usage rights are not
DeploymentWhat is installed or provisioned?Inventory, discovery, CMDB, cloud and admin portalsIncomplete technical scope
Usage & accessWho or what uses or reaches the product?Assignments, accounts, groups, logs, interfacesInactive is assumed to mean not licensable
Rules & contextWhich conditions apply?Product Terms, licensing guide, contract, product documentationCurrent terms are applied to historical use

The documents applicable to the product, contract, and period are authoritative. Vendor portals and tools support evidence but do not replace contractual interpretation.

03

From raw data to a traceable licence position

An Effective Licence Position—often called an ELP—is a structured comparison of usable entitlements and calculated consumption. It is a working and decision basis, not a blanket legal guarantee.

ENTITLEMENT

Usable rights

Not every purchase is automatically usable for the product, version, entity, country, or period in scope.

CONSUMPTION

Calculated demand

Installations are not always the unit. Depending on the metric, users, devices, cores, access, or capacity may count.

EVIDENCE

Documented rationale

Assumptions, exceptions, sources, timing, and calculation logic must remain traceable.

usable rights−licence consumption=licence position
  1. 01Normalise products, editions, and versions
  2. 02Translate entitlements and usage rights
  3. 03Calculate consumption using the correct metric
  4. 04Document exceptions and special rights
  5. 05Show the gap, uncertainty, and required action
Make data quality visible

Missing entitlement or technical data does not automatically mean compliant or non-compliant. The position may simply be unknown—and that uncertainty must be reported.

04

Four outcomes—four different actions

Compliance and optimisation belong together, but they are not the same thing.

Underlicensed

Calculated demand exceeds demonstrably usable rights. Validate the cause and scope, then remediate technically, contractually, or through procurement.

Balanced

Validated use is covered by suitable rights within the defined scope. The outcome remains time-bound and must be refreshed after change.

Overlicensed

More rights exist than are currently required. This is usually not a compliance breach, but it may tie up budget and indicate optimisation potential.

Unknown

Data, evidence, or rules are insufficient for a defensible conclusion. Resolve the gaps and assumptions before labelling the position.

05

Compliance risk often comes from change—not intent

Technology, organisations, and contracts change faster than their documentation. These six areas deserve particular attention.

01

Wrong metric

User, device, core, vCore, server, access, or capacity are confused.

02

Virtualisation & cloud

Hosts, clusters, VM mobility, containers, BYOL, and minimums alter the scope.

03

Indirect access

Applications, bots, portals, or interfaces hide the people or devices that ultimately access the product.

04

Organisation

Joiners, leavers, M&A, contractors, and legal-entity boundaries change entitlement and demand.

05

Version & edition

Upgrade, downgrade, maintenance, or edition rights are assumed but not evidenced.

06

Time & change

Inventory and rights use different snapshots; historical peaks remain unexamined.

06

An internal review and a vendor audit do not serve the same purpose

Both require reliable data, but scope, process, deadlines, and legal basis differ.

01

Internal licence review

The organisation assesses its own position before an external trigger arises.

  • Set scope and priority by risk
  • Close data gaps without external time pressure
  • Connect remediation with optimisation
  • Refresh results regularly
02

Vendor audit or verification

A vendor or appointed reviewer requests information under the agreed rights.

  • Review the request and contractual basis centrally
  • Clarify scope, period, and data request
  • Provide coordinated, traceable responses
  • Validate findings technically, contractually, and legally
Do not improvise

For a formal audit request, License Management, IT, Procurement, Legal, and management should coordinate. Deadlines, responsibilities, and communication paths depend on the contract and the specific request.

07

Seven steps for a defensible compliance review

The process should be reproducible and should not begin only after an audit announcement.

  1. 01

    Define the scope

    Specify product, vendor, entities, environments, countries, and period.

  2. 02

    Collect entitlements

    Bring together contracts, orders, evidence, maintenance, and historical rights.

  3. 03

    Capture the technical estate

    Identify installations, systems, cloud resources, accounts, assignments, and access.

  4. 04

    Translate the rules

    Convert metrics, minimums, versions, virtualisation, and special rights into testable logic.

  5. 05

    Reconcile

    Compare usable rights and calculated consumption at the same product and metric level.

  6. 06

    Validate & evidence

    Confirm gaps, assumptions, exceptions, and variances with accountable teams.

  7. 07

    Remediate & monitor

    Reduce risk, optimise rights, and establish reconciliation as a recurring control.

08

Licence compliance is a team effort

License Management coordinates the position, but the information and decisions needed for it originate across the organisation.

LM / SAM

License Management

Translates rights, calculates positions, documents assumptions, and coordinates action.

IT / CLOUD

Technology

Provides inventory, architecture, configuration, access, and environmental change.

PROCUREMENT

Procurement

Secures orders, contracts, renewals, and commercial evidence.

BUSINESS

Owner

Confirms demand, usage, accountability, and the business purpose of an application.

LEGAL

Legal

Assesses contractual interpretation, audit rights, communications, and disputed findings.

09

500 licences, 470 assignments, 420 active users—compliant?

The numbers look clear at first. They are still insufficient for a defensible conclusion.

500

purchased user licences

470

assigned accounts

420

active in 90 days

35

leaver assignments

12

service or shared accounts

Too-fast conclusion

500 minus 420 means 80 free licences.

Defensible assessment

First determine who the contract defines as a licensable user, whether shared accounts are permitted, how reassignment works, and whether leavers have actually been deprovisioned.

  1. 01Are all 500 rights usable for the same edition and entity?
  2. 02Does assignment, entitlement, or active use trigger the licence?
  3. 03Do shared accounts conceal additional people with access?
  4. 04Were licences correctly removed and reassigned after departure?
Outcome

Activity data highlights optimisation potential, but it proves neither compliance nor surplus by itself. A defensible position emerges only after applying the contractual definitions.

10

Good indicators also measure how defensible the conclusion is

A seemingly precise compliance percentage can mislead when the underlying data is incomplete.

  1. 01

    Inventory coverage

    How much of the defined scope is captured reliably by technical sources?

  2. 02

    Evidence rate

    For what share of entitlements is usable contract and purchase evidence available?

  3. 03

    Reconciliation coverage

    Which priority products have a current, validated licence position?

  4. 04

    Open exceptions

    How many unresolved assumptions and data gaps remain—and how old are they?

  5. 05

    Remediation progress

    How quickly are confirmed risks and excess positions addressed?

Remember

Good reporting shows not only the result, but also scope, freshness, data quality, assumptions, and remaining uncertainty.

11

These questions belong in every compliance review

This order prevents a technical number from being converted into a licence quantity too early.

  1. 01Which product, edition, version, and metric are being assessed?
  2. 02Which entities, countries, environments, and periods are in scope?
  3. 03Which rights are evidenced and actually usable in the assessed scope?
  4. 04Which installations, deployments, accounts, and access paths exist?
  5. 05Which minimum, virtualisation, and reassignment rules apply?
  6. 06Are there upgrade, downgrade, test, failover, or disaster-recovery rights?
  7. 07Are indirect access, external users, and technical accounts included?
  8. 08Do entitlement and consumption use the same snapshot or assessment period?
  9. 09Which assumptions, exceptions, and data gaps remain open?
  10. 10Who owns remediation, optimisation, and the next refresh?
12

Compliance is the foundation—the value comes from better decisions

A reliable compliance process reduces more than audit risk. It also improves procurement, architecture, and budget management.

RISK

Reduce surprises

Variances and data gaps are identified before time pressure arises.

COST

Expose excess

Unneeded rights can be reassigned, reduced, or considered at renewal.

DECISION

Plan technology well

Cloud, virtualisation, migration, and architecture are evaluated with their licensing impact.

GOVERNANCE

Embed accountability

Roles, evidence, and controls become part of the normal software lifecycle.

The aim is not to be compliant once. The aim is to manage change so that rights, usage, cost, and evidence continue to align.

Licence compliance is not a document. It is a repeatable reconciliation.

A defensible licence position connects usage rights, technical inventory, actual access, product-specific rules, and traceable evidence—for a clearly defined scope and point in time.

Professionally checked and traceable.

This explanation is based on official standards and vendor information available on 15 August 2026. The applicable contracts, Product Terms, and product-specific licence conditions remain authoritative.

Note: This article provides accessible professional guidance and is not legal advice. A specific licence position must be assessed against the applicable contracts, usage rights, technical environment, and relevant period.

Topic area

License Management & Software Asset Management

Find more foundations, licence metrics, usage rights, and practical guidance in one place.