The License Compliance Gap That Cost $280K at Renewal
A software license compliance gap occurs when an organization’s active software installations exceed its purchased entitlements — exposing IT teams to vendor audit back fees calculated across a multi-year lookback period. For most IT asset management teams, this gap forms not from deliberate misuse but from ITAM records tied to purchase orders rather than discovery-verified install counts. The result is a compliance position that looks accurate in the system and fails catastrophically at renewal.
The vendor audit request arrived in a routine email. The software publisher wanted to schedule a compliance review for one of our enterprise productivity suites, a platform we had been running across the organization for four years. We were not worried. Our IT asset management records showed we had purchased 1,240 seats. We thought we were using approximately 1,100. A software license compliance gap discovered through a vendor audit was not something we had considered possible. We expected to find ourselves over-licensed, not under.
Note: The figures in this case study are illustrative, based on cost structures typical of enterprise software audit settlements.
What the audit actually found
The vendor’s auditor pulled installation counts directly from endpoint telemetry across our estate. Their methodology: every device that had the application installed and had authenticated to the platform in the last 90 days counted as an active seat. Their final count was 1,580 active users.
We had 1,240 purchased seats. We were 340 seats short.
The audit covered a three-year lookback period under the terms of our enterprise agreement. Back fees for 340 seats at historical contract pricing, calculated across 36 months, came to $187,000. The remediation requirement, purchasing the 340-seat shortfall at current renewal pricing (up 22% from our last contract cycle), added $93,000. Total settlement: $280,000, payable within 45 days as a condition of contract renewal.
The conversation with finance was not short.
Why our ITAM records were wrong
Our ITAM team had maintained license records based on purchase orders. When we bought software, we entered the seat count from the PO into our ITAM system. When we renewed, we updated the entitlement count to match the renewal PO. The records were accurate representations of what we had purchased. They were not accurate representations of what was installed.
The gap opened for four reasons:
- Departmental purchases outside central IT. Three business units had purchased seats directly through their own vendor relationships, a total of 220 additional seats that IT had no visibility into because they bypassed the central procurement process. These purchases are a direct example of shadow IT — software running in the environment with no footprint in central ITAM records or software entitlement management systems.
- Seat reassignment without deprovisioning. When employees left the organization, their licenses were frequently reassigned rather than deprovisioned. Over 24 months, 68 seats had been reassigned to new hires who were added to the count without anyone removing the departed users.
- Contractor accounts. We had 52 active contractor accounts that were provisioned by project managers outside the standard IT onboarding workflow. None appeared in our ITAM license records.
- Test and development environments. Our IT team had spun up 18 accounts for testing integrations. These authenticated against the production license pool and counted in the vendor’s audit.
Combined, these four categories accounted for the 340-seat shortfall. Not a single line of our CMDB reflected any of them.


What discovery-sourced install counts would have shown
The vendor’s auditor ran endpoint telemetry to count active users. That is a discovery function. The data they used to calculate our shortfall was discoverable; we were not running discovery against license consumption on any regular schedule.
IT discovery scans can identify installed software by application name, version, and installation path across Windows, macOS, and Linux endpoints. When discovery results are matched against license entitlement records, the reconciliation produces an effective license position: entitlements owned versus installations detected.
Had we been running scheduled discovery scans and reconciling against our ITAM license records quarterly, we would have seen the install count climbing above our entitlement threshold. The 2024 IDC Software License Management report found that organizations running discovery-based license reconciliation quarterly caught compliance gaps an average of 14 months before a vendor audit would have surfaced them (IDC Software License Management Report, 2024). That 14-month window is the difference between a proactive true-up and a negotiated settlement with back fees.
Our ITAM records trusted purchase orders. A discovery-based approach trusts what is actually installed. Those two numbers should match. When they do not, the gap is license risk.


The negotiation and what it cost beyond the $280K
The $280,000 settlement was the direct cost. The indirect costs were harder to quantify.
The cost beyond the settlement: negotiation overhead
We spent 11 weeks in audit and negotiation. That consumed approximately 320 hours across the IT asset management team, the legal team, and two senior IT Directors who had to own the finance escalation. At fully-loaded labor rates, that time cost an additional $68,000. The renewal was delayed by 6 weeks, during which the vendor’s account team had significant leverage over our pricing for adjacent products. Combined direct and indirect exposure: $348,000 — all of it traceable to a compliance gap that discovery-based reconciliation would have surfaced 14 months earlier.
We also lost the position to negotiate proactively at renewal. Customers who come into a renewal with clean, discovery-verified license data have negotiating leverage. They can demonstrate their consumption is below entitlement or bring accurate data to support a reduced-tier negotiation. We came in with a $280,000 deficit. The negotiating dynamic was entirely reversed.
We rebuilt around one principle: install counts — not purchase orders — are the authoritative source of license truth. Moving to a Trusted Runtime Truth model — where discovery-sourced install counts are matched against entitlements on a scheduled basis — gave us verified compliance data rather than PO history. Critically, because our discovery scans are independent of the vendor’s own telemetry, we hold a defensible compliance position the auditor cannot dispute with their own data source.
What we changed after the settlement
Following the settlement, we rebuilt our software license management process around discovery data:
- Scheduled endpoint discovery scans running every two weeks across all managed devices, producing install-count data for all enterprise applications
- Quarterly license reconciliation reports comparing discovery-sourced install counts against ITAM entitlement records, with software entitlement management reviewed each cycle
- A formal under-license threshold alert set at 90% of entitlement, triggering a procurement review when install counts approach the licensed ceiling
- A shadow IT discovery process to identify departmental software purchases not routed through central IT
The first quarterly reconciliation under the new process identified two additional applications where we were under-licensed by margins that would have triggered back fees at the next renewal. Both were corrected proactively, at contract pricing, before the vendor had grounds for an audit.
For software license management teams that rely on purchase orders as their primary data source, the question to ask is: when was the last time your install count was verified by discovery data rather than procurement history? Building a proactive ITAM program that prioritizes discovery data over procurement records is the surest way to close this gap before a vendor forces the issue. Virima’s guide to ITIL change management best practices
Rebuilding ITAM license tracking on discovery data
The $280,000 settlement resolved the audit. What it did not resolve was the process that created the gap in the first place. Until our ITAM system treated discovery-sourced install counts as the authoritative measure of license consumption, rather than purchase orders, we remained exposed to the same risk on every enterprise title in our portfolio.
The teams most at risk from software audit findings are those whose ITAM records are accurate representations of procurement history but silent on what is actually installed. For IT asset managers preparing for renewals or facing audit requests, schedule a demo to see how discovery-based license reconciliation works in practice.






