Document type: Article Practice area: Technology — Technology Transactions Jurisdiction: United States Last reviewed: 5 September 2026


The letter

It arrives by email and by courier, addressed to the chief financial officer rather than to anyone in IT. It refers to a section of an agreement signed nine years ago, states that the publisher has elected to exercise its audit right, names a third-party audit firm, and asks for a kickoff call within fifteen business days.

Nobody in the company remembers the audit clause. The agreement has been amended four times. The people who negotiated it have left. And the systems the audit will examine have been through two acquisitions, a data centre migration, and a virtualization project.

This is a routine event. Large publishers audit a meaningful fraction of their customer base every year, and audits are a recognized revenue channel rather than an enforcement mechanism of last resort. Understanding that changes how a company should respond: the audit is a commercial negotiation with a legal frame, and it will be resolved commercially in almost every case.

But the legal frame determines the size of the number.

Two theories, two very different exposures

A publisher whose software is used beyond the licensed scope has, potentially, two claims.

Breach of contract. The customer agreed to use the software within stated limits and exceeded them. Damages are the licence fees that would have been paid, plus whatever the contract provides — back maintenance, interest, audit costs.

Copyright infringement. Use outside the licence is unauthorized reproduction under 17 U.S.C. § 106 and actionable under § 501. Remedies under § 504 include actual damages plus the infringer's profits, or statutory damages of up to $150,000 per work infringed for wilful infringement, plus attorneys' fees where the work was timely registered — and an injunction.

The gap between these is enormous, and publishers routinely assert the second to make the first easier to settle.

The doctrine that separates them is the distinction between a condition of the licence and a covenant within it. If the restriction the customer breached limits the scope of the grant, use outside it is unlicensed and the claim sounds in copyright. If the restriction is an independent promise, breach is a contract matter and the licence continues to authorize the use.

Graham v. James, 144 F.3d 229 (2d Cir. 1998), states the framework: a copyright owner who grants a non-exclusive licence waives the right to sue for infringement, and can sue only for breach of contract, unless the licence is terminated or the breach relates to a condition. Bourne v. Walt Disney Co., 68 F.3d 621 (2d Cir. 1995), applies the same logic to disputes about the scope of a grant. The Federal Circuit in Jacobsen v. Katzer, 535 F.3d 1373 (Fed. Cir. 2008), found the attribution and notice requirements of an open source licence to be conditions rather than covenants, precisely because the licence used conditional language and the conditions were central to the licensor's purpose.

The practical drafting consequence — for both sides — is that language matters enormously. "Licensee may use the Software solely on the Designated Servers" is a scope limitation. "Licensee shall not install the Software on more than the Designated Servers" reads more like a covenant. Publishers draft the first form; customers should notice when they have signed the second.

The copy-in-RAM problem

Much of software licensing law rests on a proposition established early and never really disturbed: loading software into memory makes a copy for copyright purposes.

MAI Systems Corp. v. Peak Computer, Inc., 991 F.2d 511 (9th Cir. 1993), held that loading an operating system into RAM created a copy sufficiently fixed to implicate the reproduction right, so that a third-party maintenance company that booted a customer's machine infringed. The holding was controversial and Congress responded with a targeted amendment permitting the making of a copy in the course of maintenance or repair by an authorized person, but the underlying principle — that running software makes a copy — survives and is the foundation of software licensing.

The corresponding limitation is 17 U.S.C. § 117, which permits the owner of a copy of a computer program to make a copy as an essential step in utilizing the program, and to make an archival copy. That defence turns on ownership of the copy, which is why publishers structure transactions as licences rather than sales.

Vernor v. Autodesk, Inc., 621 F.3d 1102 (9th Cir. 2010), set out the test: a software user is a licensee rather than an owner where the copyright owner (1) specifies that the user is granted a licence, (2) significantly restricts the user's ability to transfer the software, and (3) imposes notable use restrictions. Under that test nearly all commercial software is licensed, not sold — which means § 117 is unavailable and the first sale doctrine does not permit resale.

Krause v. Titleserv, Inc., 402 F.3d 119 (2d Cir. 2005), took a more functional approach to ownership, holding that a company that paid for custom software, possessed the copies indefinitely, and could discard or modify them was an owner for § 117 purposes notwithstanding the absence of formal title. The circuits are not perfectly aligned, and a customer with a genuinely unusual acquisition history should look at this carefully rather than assume it is a licensee.

Apple Inc. v. Psystar Corp., 658 F.3d 1150 (9th Cir. 2011), confirms that a use restriction in a licence — there, running the operating system only on Apple hardware — can be a condition whose breach supports an infringement claim, and rejected a misuse defence.

The metrics that generate findings

Almost all audit findings come from a small number of licensing metrics, each of which is more complicated than it looks.

Named user. A licence for a specific identified individual. Findings arise from: accounts assigned to departed employees and never deactivated; shared or generic accounts used by multiple people; service accounts; test and training accounts; and — the one that surprises everyone — the definition of "user" extending to anyone who accesses functionality, not just anyone who logs in.

Concurrent user. A licence for a maximum number of simultaneous sessions. Findings arise from disagreement about what a session is, how long it persists after inactivity, and whether pooled connection architectures count sessions correctly.

Processor, core, or socket. A licence keyed to hardware capacity. Findings arise from: core factor tables that differ by processor family; hyperthreading; and hardware refreshes that increase core counts without anyone recalculating entitlements.

Virtualization. The most contentious area in enterprise licensing. Some publishers take the position that software installed on a virtual machine within a cluster requires licensing of every physical host in the cluster to which the VM could migrate, whether or not it ever does. Others license the assigned host only. The contractual basis for the aggressive position is often a policy document rather than the agreement itself, and whether such a policy is contractually binding is exactly the question a customer should ask. A customer that runs a small application in a large cluster can face a finding measured in thousands of cores.

Indirect or digital access. The theory that a person or system that receives data originating from the licensed software requires a licence, even if they never touch it. A customer builds a web portal that displays order status pulled from the licensed system; the publisher asserts that every portal user requires a licence. Or a middleware integration passes data between two systems, and the publisher asserts that the receiving system's users require licences. This theory has produced very large claims and considerable litigation, and publishers have since introduced document-based or outcome-based pricing models partly in response. The contractual question is whether the agreement's definition of "use" reaches indirect access — often it does not, and the publisher relies on a definition of "user" broad enough to be read that way.

Environments. Development, test, staging, disaster recovery, and training environments are frequently assumed to be free and frequently are not. Passive standby is often licensed differently from active-active. A DR environment that is periodically brought up for testing may cross a line.

Geography and entity. Licences granted to a named entity, in a named territory, used by affiliates or in other countries after a reorganization.

What the audit clause actually permits

Most audit clauses are two or three sentences and were negotiated in twenty minutes. Read yours before responding.

Frequency. Often "once per year" or "not more frequently than annually." A publisher that audited eighteen months ago and returns is outside the clause.

Notice. Typically thirty days. An audit demanding a kickoff in fifteen business days may be inconsistent with the contract.

Who conducts it. Some clauses permit the publisher; some require an independent auditor; some require an auditor reasonably acceptable to the customer. That last formulation gives real leverage, because audit firms differ substantially in approach.

Scope. "Records relating to the use of the Software." Note what that does not say: it does not say the customer must run the publisher's scripts across its estate, permit access to systems, or produce architecture diagrams, network topology, or virtualization configuration. Publishers ask for all of these. The clause frequently does not require them.

Location and manner. "At Customer's premises during normal business hours" — which is inconsistent with a demand to run remote collection tools.

Confidentiality. Whether the auditor is bound, and to whom it reports. An audit firm that reports the customer's full estate to the publisher's sales team has given the publisher a competitive map of the account.

Cost. Usually customer-pays if a variance above a threshold is found. Check the threshold and whether it is stated as a percentage or a dollar amount.

Remedy. What the customer owes on a finding: licence fees at list, at then-current pricing, or at the customer's negotiated rate? Back maintenance? Interest? This determines the arithmetic of the entire dispute, and the difference between list price and negotiated price on a large finding can be seventy percent.

Contract or infringement: what the publisher must prove

Where a publisher asserts copyright infringement rather than mere breach, several defences and limitations come into play, and a customer should know them before conceding.

Registration and timing. Attorneys' fees and statutory damages under § 504 are available only for infringement commencing after registration, subject to the grace period for published works. A publisher that registered late may be limited to actual damages.

Actual damages. Where statutory damages are unavailable, the measure is the licensor's actual loss — typically the licence fees that would have been paid — plus any additional profits of the infringer attributable to the infringement. That is close to the contract measure.

Number of works. Statutory damages are per work infringed, not per copy. A publisher asserting thousands of unlicensed installations of one program has one work.

Innocent infringement. Where the infringer was not aware and had no reason to believe its conduct constituted infringement, the court may reduce statutory damages. A customer with a documented compliance programme and a good-faith interpretation of an ambiguous metric is in a materially better position than one with no records.

Wilfulness. Conversely, evidence that the customer knew it was over-deployed and did nothing supports enhanced damages. This is why the internal email saying "we're way over on this, don't tell them" is worth more to a publisher than any script output.

Limitations. A three-year period applies to civil copyright claims, with the accrual rule the subject of continuing development. Contract limitations periods are longer in most states. The interaction can matter where the over-deployment is old.

Costs, and what they cover. Rimini Street, Inc. v. Oracle USA, Inc., 586 U.S. 334 (2019), held that "full costs" under the Copyright Act means the costs specified in the general costs statutes — not expert fees, e-discovery costs, and jury consultant fees, which had been awarded below. The decision meaningfully reduced the cost exposure in software copyright litigation, and it is worth remembering when a publisher describes the potential award.

The underlying Ninth Circuit decision in Oracle USA, Inc. v. Rimini Street, Inc., 879 F.3d 948 (9th Cir. 2018), is also instructive on the merits: it addressed the boundaries of what a third-party support provider may do with a licensee's software, and the court's treatment of local hosting and cross-use is directly relevant to any customer considering third-party support.

Third-party support and the maintenance question

A customer paying twenty-two percent of licence value annually for maintenance it barely uses will eventually consider a third-party support provider at half the price. The legal terrain is worth understanding.

Storage Technology Corp. v. Custom Hardware Engineering & Consulting, Inc., 421 F.3d 1307 (Fed. Cir. 2005), addressed a third-party maintainer's access to diagnostic software and applied the statutory maintenance provision, holding that the mere fact that a copy was made in the course of servicing did not establish infringement where the copy was made by an authorized person and used only for maintenance.

But the boundaries are narrow. What generally causes trouble:

  • Downloading patches and updates from the publisher's support site after maintenance has lapsed, or using another customer's entitlement.
  • Cross-use: a support provider developing a fix using one customer's environment and delivering it to another.
  • Local hosting: the support provider maintaining copies of the publisher's software on its own systems.
  • Derivative works: modifications that go beyond what the licence permits.

A customer moving to third-party support should obtain contractual assurance that the provider will not do these things, an indemnity backed by something, and — the practical point — should expect an audit. Publishers audit customers who leave maintenance.

The economics of an audit, from both sides

Understanding the publisher's incentives makes the negotiation legible.

The publisher's position. Audits generate revenue at very high margin. The audit firm is often paid on a contingent or success-weighted basis. The internal owner is frequently a compliance or licence management group with its own targets, sitting alongside but separate from the account team. Findings are computed at list price, without the discounts the customer would have negotiated, because that maximizes the opening number. And the publisher's real objective is usually not cash: it is a forward commitment — a subscription conversion, a cloud migration, a multi-year renewal — with the finding used as the lever.

That last point is the single most useful thing a customer can know. A finding of $8 million at list will very often settle for a $2.5 million three-year subscription commitment the customer partly wanted anyway. The publisher books recurring revenue and a reference migration; the customer resolves the exposure at a fraction of the demand and gets something it can use. The customers who do worst are those who treat the audit purely as a legal fight and never engage with what the publisher actually wants.

The customer's position. The exposure is real but the opening number is not. Typical settlement outcomes land somewhere between fifteen and forty percent of the initial finding, depending on the strength of the customer's records, the defensibility of the publisher's metric interpretation, and whether the customer has something the publisher wants. Litigation is rare — it is expensive, slow, and exposes the publisher's aggressive licensing interpretations to judicial scrutiny it would rather avoid.

Where the leverage sits. The customer's leverage comes from: accurate entitlement records that contradict the publisher's assumptions; a defensible reading of an ambiguous metric; the ability to remediate quickly and reduce the finding prospectively; a genuine alternative product; an upcoming renewal the publisher needs; and the credible willingness to escalate to litigation over an interpretation the publisher would rather not test. The publisher's leverage is the copyright claim, the statutory damages number, and the customer's reluctance to have this discussion in front of its auditors.

Building the records before you need them

Every audit is easier for a company that already knows what it owns. Very few do.

The entitlement register. One row per licence, with: publisher, product, version, metric, quantity, the contract or order that granted it, the date, the entity that holds it, territory, maintenance status, and any restriction. The source documents — order forms, contracts, amendments, proofs of purchase, migration and upgrade records — collected in one place and readable.

This sounds elementary. In practice, entitlements at a company of any age are scattered across procurement systems, email attachments, a shared drive, and the memory of someone in the infrastructure team. Reconstructing them during an audit, on the auditor's timetable, is both expensive and prejudicial: an entitlement you cannot prove does not exist for audit purposes.

The deployment record. What is installed, where, on what hardware, with what configuration, accessed by whom. Discovery tooling produces most of this, but the tooling has to be configured to capture what the metrics require — core counts and processor models for capacity metrics, account activity for named-user metrics, cluster topology for virtualization.

The reconciliation. Entitlements against deployments, per product, per metric, reviewed quarterly. This is where a company discovers its own exposure while it can still fix it cheaply — by removing installations, deactivating accounts, isolating clusters, or buying licences at negotiated rather than settlement pricing.

The interpretation file. For every metric where the contract is ambiguous, a written note recording the interpretation the company adopted and why. This is the document that converts an aggressive publisher's "you knew you were over" into "we adopted a reasonable reading of an ambiguous term and documented it." It bears directly on wilfulness.

The change log. Hardware refreshes, virtualization changes, acquisitions, divestitures, and new integrations, each with a note on the licensing implication. Most findings originate in a change nobody assessed.

Worked example one: the virtualization finding

Kenji Watanabe is head of infrastructure at Brightwater Utilities. An audit of a database product produces a finding of $6.4 million, almost all of it attributable to virtualization.

The facts: Brightwater runs two database instances on virtual machines within a 44-host cluster. It licensed the four hosts on which the VMs are pinned. The publisher's position is that because the VMs could migrate to any host in the cluster, all 44 hosts require licensing.

Kenji's counsel, Adaeze Nwosu, works through three questions.

What does the contract say? The agreement licenses the software "for use on the servers identified in the applicable Order Form" and defines a processor licence by reference to cores "on which the Software is installed or running." It says nothing about clusters, migration, or potential deployment. The publisher's position rests on a partitioning policy document published on its website.

Is the policy contractually binding? The agreement incorporates "Publisher's then-current documentation," and the publisher argues the policy is documentation. Adaeze's view is that a policy defining licensing scope is not documentation in the ordinary sense — documentation describes how the software works — and that a term this consequential cannot be imported by a general incorporation clause it can amend unilaterally. She writes this position out, in a letter, early.

What are the facts? This turns out to matter most. Brightwater's virtualization team can demonstrate, from configuration and logs, that host affinity rules have prevented the VMs from migrating outside the four licensed hosts since deployment, and that the cluster is configured with hard affinity rather than soft preference. The software has never run on the other forty hosts. Under the contract's own words — installed or running — the finding has no factual basis.

The remediation. Brightwater additionally moves the two instances into a dedicated four-host cluster with no path to the larger estate, which removes the argument prospectively and costs a weekend of engineering time.

The outcome. The finding is settled at $410,000, structured as an incremental licence purchase at Brightwater's negotiated rate, together with a three-year maintenance renewal the company would have signed anyway. The publisher gets a renewal and a clean account. Brightwater pays six percent of the opening number.

What made the difference was not legal argument alone. It was that the infrastructure team could produce configuration evidence, on demand, showing what had actually run where. A company without that evidence would have been arguing about the policy's status, which is a much weaker position.

Worked example two: indirect access

Sofia Brennan is general counsel of Cardinal Freight, which receives a finding of $11 million on the theory that customers using its shipment-tracking web portal are "users" of the licensed ERP system, because the portal displays data originating there.

Cardinal has 2,100 licensed named users. The portal has 340,000 registered customer accounts.

The analysis:

The contract definition. "User" means "an individual authorized by Licensee to access the Software." The portal users are not authorized to access the software; they are authorized to access Cardinal's portal. They have no credentials to the ERP, cannot query it, and receive only data Cardinal has extracted, transformed, and published. Sofia's position is that the definition does not reach them, and she makes it plainly and early.

The architecture matters. Cardinal's integration is batch: an extract runs every four hours into a separate reporting database, and the portal reads from that. Nobody and nothing in the portal path touches the ERP in real time. Sofia has the architecture documented, with data flow diagrams and timestamps, and provides it — this is one of the cases where volunteering technical detail helps, because the architecture is favourable.

The alternative reading. The publisher points to a different clause defining "Use" to include "accessing the Software directly or indirectly, including through any intermediary application." Sofia's response has three parts: that clause governs Cardinal's use, not third parties'; the licensing metric in the order form is named users, and "user" is separately defined; and if the publisher's reading were correct, every customer of every business that publishes any data derived from the licensed system would require a licence, which is not a construction the parties can have intended and which the publisher does not apply consistently across its own customer base.

The commercial resolution. The publisher's real objective emerges in the third call: it wants Cardinal on its newer document-based pricing model, which prices external access by transaction volume rather than by user. Sofia negotiates a migration to that model with a three-year price hold, a defined transaction allowance sized generously against Cardinal's actual volumes, and a full release of the indirect access claim. The net cost is roughly $1.6 million over three years for a licensing structure that actually fits how Cardinal uses the product.

The lesson. Indirect access claims are, more often than not, an argument for a pricing model rather than an argument about copyright. Getting to that conversation quickly saves months.

Worked example three: three audits after a merger

Marcus Delacroix is deputy general counsel at Hollis Group, which has just acquired a competitor roughly its own size. Within four months, three publishers issue audit notices.

This is not a coincidence. Mergers are the most reliable audit trigger in the industry, for reasons that are entirely rational from the publisher's perspective: entitlements do not automatically transfer, licences are frequently entity-specific and non-assignable, the combined entity is usually deploying the acquired company's software beyond its original entity scope, and the integration project has almost certainly moved software onto shared infrastructure without anyone checking the licence terms.

Marcus's response has four parts.

Assignment analysis, first. For every material licence on both sides, does the agreement permit assignment, and did the transaction structure trigger a consent requirement? A stock acquisition may avoid a formal assignment while still tripping a change-of-control clause. An asset acquisition almost certainly requires consent. Licences that did not transfer are not merely unlicensed going forward — the use since closing has been unlicensed, and the exposure is accruing.

Entity scope. Licences granted to "Acquired Co. and its subsidiaries" do not cover Hollis's other operating companies. This is the most common post-merger finding and the easiest to create accidentally during integration.

Freeze the integration where it matters. Marcus does not stop the integration, but he does require that any migration of software or workload onto shared infrastructure be checked against the licence terms first. Three planned migrations are deferred. This is unpopular and correct.

Sequence and coordinate the audits. Three simultaneous audits will consume the same small group of people. Marcus negotiates staggered timelines with each publisher, uses a single internal team and a single data collection effort, and — importantly — ensures that what is produced to one publisher is consistent with what is produced to the others. Inconsistent data across audits is a gift to whichever publisher notices.

The outcome. Two of the three resolve as commercial true-ups tied to enterprise agreements covering the combined entity, which is what Hollis needed anyway and which it negotiates at combined-entity volume pricing. The third, involving a licence that plainly did not transfer, costs more — but the number is contained because Marcus identified the problem in month one and stopped the use, rather than discovering it in month fourteen with a year of accrued exposure.

The prevention. Every acquisition Hollis does now includes software licence transferability in the diligence checklist, a representation on assignability, and a covenant to obtain material consents before closing. That work costs a few days per deal and it is the single highest-return item on the technology diligence list.

Negotiating the settlement

Almost every audit ends in a negotiated resolution. A few observations on how the good ones are reached.

Separate the finding from the remedy. There are two questions — how much unlicensed use occurred, and what should be paid for it — and conflating them helps the publisher. Resolve the factual scope first, in writing, before discussing money. A publisher that has agreed the deployment facts cannot later reopen them when the price discussion goes badly.

Attack the pricing basis, not just the quantity. A finding computed at list price with back maintenance and interest can be two to three times the same finding computed at the customer's negotiated rate going forward. Argue the basis. Publishers concede on pricing basis more readily than on quantity, because quantity is a factual claim their auditor has documented and pricing basis is discretionary.

Bring something the publisher wants. A subscription conversion, a cloud migration, an expansion into another business unit, a reference, an early renewal. The single most effective move in an audit settlement is to convert the conversation from "what do you owe us" to "what are we going to do together." This is not capitulation; it is recognizing that the publisher's compensation structure rewards forward commitment more than one-time cash.

Remediate first, then negotiate. Removing installations, deactivating accounts, and isolating clusters before the settlement discussion reduces the prospective exposure and demonstrates good faith. It also removes the publisher's argument that the problem is ongoing.

Get a real release. The settlement must release all claims — contract and copyright — for all periods through the effective date, for all products audited, for the customer and its affiliates and their respective personnel. A release limited to "the findings identified in the Audit Report" leaves the publisher free to return with a different theory about the same period.

Fix the contract while you have leverage. This is the most valuable and most frequently missed opportunity. At settlement the publisher wants a signature and the customer has more leverage than it will have again for years. Use it to renegotiate the audit clause: longer notice, an auditor reasonably acceptable to the customer, scope limited to records rather than systems access, no more than one audit in any twenty-four months, remediation at negotiated rather than list pricing, a cure period before any claim, and a materiality threshold below which no cost shifting applies. Also fix the metric definitions that caused the finding — a written clarification of how virtualization or indirect access is measured, signed by both parties, is worth more than the money saved on the settlement itself.

Handle the accounting. A material settlement will interest the auditors and may require disclosure. Loop in the CFO early rather than presenting a fait accompli, and understand whether a licence purchase can be capitalized where a settlement payment cannot.

What to do in the first two weeks

The early moves in an audit shape everything afterward, and most of them are procedural.

Do not run the publisher's scripts yet. Data collection tools produce output the customer cannot easily interpret and cannot take back. Understand what the tool collects, what it sends, and whether the audit clause requires the customer to run it at all — frequently it does not.

Read the audit clause. Frequency, notice, auditor identity, scope, location, confidentiality, cost, and remedy. Compare each against what the publisher is asking for and note every gap.

Check the contract stack. Master agreement, order forms, amendments, migration agreements, and any documents incorporated by reference. The governing terms for a licence bought in 2014 may not be the terms in the current master agreement, and publishers sometimes audit against terms the customer never agreed to.

Route everything through counsel. Establish a single point of contact and instruct that no one else responds to the auditor. The technical team's helpful email explaining the architecture is discoverable and often damaging. Conduct the internal assessment under privilege.

Negotiate an NDA with the auditor, covering the customer's information, restricting disclosure to the publisher's compliance function rather than its sales team, and prohibiting use of the customer's data for any purpose other than the audit.

Agree a scope document before producing anything: which products, which entities, which time period, which environments, what data will be produced, in what form, and what will not.

Do your own assessment first. Know your position before the auditor does. If there is real exposure, you want to know its size, its cause, and its remediation path before you are negotiating about it.

Preserve, but do not over-preserve. A litigation hold may be appropriate. A hold that sweeps in the entire IT estate creates cost and signals alarm.

Set the clock. Agree a realistic timetable in writing. Audits that drift for eighteen months cost the customer far more in internal effort than the settlement does.

Contract terms that make the next audit cheaper

Whether at settlement or at the next renewal, these are the provisions worth negotiating into a software agreement:

Audit clause. Not more than once in twenty-four months. Sixty days' notice. An independent auditor reasonably acceptable to the customer, bound by an NDA running to the customer. Scope limited to records reasonably necessary to verify compliance, at the customer's premises, during business hours. No requirement to run publisher tools or grant system access. The auditor reports only the compliance conclusion, not the customer's estate. Cost shifting only above a meaningful variance threshold, and only where the variance is confirmed after the customer's response.

Cure. A period — thirty to sixty days — to remediate any identified non-compliance before any claim arises. This is the single most valuable customer-side provision and it is granted more often than it is asked for.

Remediation pricing. Any shortfall is remedied by purchasing licences at the customer's most recent negotiated price for the relevant product, without back maintenance, interest, or penalty.

No copyright claim for compliance shortfalls. A statement that the publisher's sole remedy for a quantity shortfall identified in an audit is the remediation purchase, and that such a shortfall does not constitute copyright infringement. Publishers resist this, but a limited version — no infringement claim where the customer remediates within the cure period — is achievable.

Metric definitions in the agreement. Not in incorporated policies the publisher can change. Define user, processor, core factor, virtualization treatment, and indirect access expressly. Where the publisher insists on referencing a policy, attach the current version as an exhibit and provide that later versions do not apply.

Environment carve-outs. Development, test, staging, training, and disaster recovery expressly addressed, with a stated allowance.

Affiliate and change-of-control provisions. Licences extend to affiliates, and survive a change of control or reorganization without additional fee, with a mechanism for a divested business to receive a transitional licence.

Records period. The customer's obligation to retain records limited to a defined period, matching the audit look-back.

Nobody gets all of these. A customer that gets the cure period, negotiated remediation pricing, and metric definitions in the agreement has removed most of the exposure that audits are built on.

A note on open source

Software audits by commercial publishers are only half the compliance picture. A company that has built products incorporating open source components faces a different regime with a different failure mode: obligations triggered by distribution, remedies including the termination of the licence itself, and — where a copyleft licence has been breached in a product — a potential obligation to release source code that the business regards as its core asset.

Jacobsen v. Katzer, discussed above, matters here too: by treating open source licence conditions as conditions rather than covenants, it made injunctive relief available for their breach, which changed the enforcement calculus considerably.

The controls are different from those for commercial licences — a software bill of materials, scanning in the build pipeline, an approved licence list, an exception process, and attention to the distribution trigger — but the underlying discipline is identical: know what you have, know what its terms are, and reconcile the two before someone else does.

The audit as a governance signal

It is worth ending on what an audit actually reveals, beyond the licensing position.

A company that can produce, within a week, a complete entitlement register, an accurate deployment inventory, a documented reconciliation, and a written record of how it interpreted each ambiguous metric is a company with functioning asset management. The audit is inconvenient and resolves quickly.

A company that spends four months reconstructing what it bought from email attachments, cannot say what is installed where, and has no record of any decision about virtualization or indirect access is not merely exposed on this audit. It has a control weakness that affects security, cost, resilience, and diligence in any future transaction — and it will face the same problem the next time any publisher, regulator, or acquirer asks a question about its estate.

The most useful outcome of an audit, for many organizations, is not the settlement. It is the register that gets built because of it, and the quarterly reconciliation that follows. Those things prevent the next three audits from being expensive, and they cost less each year than the professional fees of a single contested finding.

Related documents