A software audit is a revenue event dressed as a compliance exercise, and the letter usually lands with intent: near your renewal, near the vendor's quarter end, or near a migration decision the vendor would like to influence. Panic is the response it is engineered to produce. A calendar is the response that works.
Start with what the letter actually is, because its costume matters. Legally, it is the vendor exercising a contractual right you granted, usually years ago, in a clause nobody negotiated. Commercially, it is a sales motion: audit findings convert to license purchases, and license purchases negotiated under compliance pressure close at prices no ordinary deal would bear. The audit team may be independent or a Big Four firm on the vendor's instruction, but the settlement conversation at the end will include the account team, and the account team has a number in mind before the first script runs.
Two facts should set your posture. First, the exposure is usually smaller than the opening claim, because opening claims price every ambiguity against you, and ambiguities resolve with evidence. Second, the deadline in the letter is the start of a negotiation about process, not a statute of limitations. Companies that respond in a controlled sequence consistently settle for a fraction of what the same findings cost companies that respond in a scramble. The plan below is that sequence, compressed into the 30 days the letter typically grants.
Decode before you respond. Drop the letter into the audit drop-box and the decode comes back in minutes: what is actually being asserted, which agreement grants the audit right, what scope the clause really permits versus what the letter requests, the notice and conduct terms the vendor must honor, and the response deadline with the calendar started. Letters routinely request more than the contract allows, entities outside the agreement, tools of the auditor's choosing, timelines the clause does not support, and each overreach is a legitimate point of pushback that also buys time.
One owner, one channel. Appoint a single audit owner and route every vendor and auditor contact through them, in writing. The most expensive findings in audit history came from helpful engineers answering questions directly. From day one: no calls without the owner, no data without a written request matched against the contractual scope, and a short internal note telling anyone contacted by the vendor to forward and not reply.
Tell the vendor something short. Acknowledge receipt, name the owner, state that you will respond on scope and process by a specific date. Nothing else. Silence looks evasive, volume looks scared, and both invite escalation.
Run your own count before theirs. The single biggest determinant of an audit outcome is whether you know your position before the auditor tells you theirs. Pull entitlements from the contracts in the workspace, deployment and usage from the SAM connectors, and reconcile. You are building the same picture the auditor will build, except honestly and first.
Price every gap yourself. Where the count shows genuine shortfall, price it at your negotiated rates and at realistic list, so you know the honest size of the problem before the vendor prices it at full list plus back maintenance. That number is your settlement compass: everything above it is negotiation theater, and knowing it keeps the theater from working.
Remediate what remediation genuinely fixes. Idle installs of unlicensed components, users in the wrong edition, the module enabled by default that nobody uses: where the contract does not freeze the position at the audit date, quiet cleanup shrinks the surface. Where it does, document the state and the intent instead. Your counsel calls this line, not your enthusiasm.
Prepare the counterweight. Audits settle as negotiations, and negotiations respond to leverage. Your renewal calendar, your benchmark position, and any credible migration alternative all belong in the settlement file, because the vendor's endgame is usually a purchase, and the price of that purchase is negotiable like any other.
The response that goes back inside the window does three things: accepts the audit right as the contract defines it, proposes the process, scope per the clause, a named data room, agreed tooling, a reasonable timetable, and reserves your positions on everything the letter requested beyond the clause. You are not stonewalling, you are performing the contract, precisely, which is both your obligation and your entire protection. Every exchange from here lives in the audit file, because the settlement discussion months from now will be won on the record you are building this week.
And the do-not list, which saves more money than any tactic:
The honest closing note: this plan handles the standard commercial audit, which is most of them. A dispute with serious money attached, an aggressive licensor with a litigation history, or anything touching M&A belongs with specialist counsel from week one, with the platform doing what it does best underneath: the decoded contract, the independent count, the priced position, and the file that never forgets. Audits are won on evidence and sequence. Both are now cheap to have.
Morten brings two decades of enterprise and software procurement, with stints across Oracle, IBM, SAP, and Salesforce shaping how he reads a deal. He has led sourcing through hundreds of renewals, from mid market order forms to nine figure global agreements, and learned that the buyers who win are the ones who walk in knowing the market. He built VendorBenchmark to make that pattern recognition repeatable.
What shipped on the platform, and the pricing and licensing moves worth knowing before your next renewal. One email a week, to your work address. Unsubscribe any time.