Key Takeaways
- The exposure sits in a gap nobody owns. Procurement buys the entitlement, IT deploys it and the business consumes it, but in most organisations no one reconciles those three positions. Compliance risk builds without anyone being negligent.
- The licence metric decides what a breach is. Named user, concurrent, device and core based licensing each fail differently. Core based entitlements can be breached by virtualising or moving to larger hardware, without adding a single user.
- The shortfall is the cheapest part of an audit. Backdated liability, withdrawn discounts and the inability to switch off business critical software cost far more, and none of it can be fixed once the vendor has already counted.
A supplier asks for a usage report. It arrives looking like administration, the sort of request passed to whoever has capacity that week. Three months later the organisation owes money nobody budgeted for, and the discount structure it has relied on for years has quietly gone.
This is not bad luck. Usage reviews are a deliberate revenue activity for software vendors, and the organisations on the receiving end are usually competent ones. What they lack is not diligence. It is a function, and that function is software asset management.
The gap nobody owns
Procurement negotiates the contract and buys the entitlement. IT deploys the software. Business units consume it. In most organisations, nobody reconciles those three positions against each other.
Software asset management is the discipline that closes that gap, and the simplest way to think about it is as a warehouse manager for software. Somebody has to own the stock, know what is on the shelf, control who takes what, and confirm that the way it is being used matches the terms it was bought under. Without that role, the stockroom is open and unattended.
The consequence of leaving it unattended is that nobody can answer a basic question. Procurement knows what was purchased but not what is being used. IT knows what is installed but not what the contract permits. The business knows what it needs but has no visibility of entitlement or cost. Each function is doing its job accurately, and the organisation still cannot say whether it is compliant.
Scale makes this harder than it sounds. Our IT Procurement Strategy 2026 report found the average enterprise now runs 275 SaaS applications, at $4,830 per employee on licences alone. Very few organisations have a single owner for that estate.
The licence metric decides what a breach actually is
Compliance exposure is not a headcount question. It depends entirely on the metric the vendor counts, and that metric varies far more than most executives realise.
Named user licences are tied to specific individuals and are not transferable in the moment. You breach by having more distinct named people using the software than you hold licences for.
Concurrent licences work as a shared pool. Fifty licences means fifty simultaneous sessions, drawn from any number of possible users. Breach happens at peak, which means a monthly average can look comfortable while the position is non compliant.
Device licences attach to a machine rather than a person, which suits shared terminals and operational equipment.
Processor, core and capacity licensing is priced on the hardware the software runs on, and it is the metric that catches organisations out. You can breach it without adding a single user. Migrate to a larger server, or virtualise onto a host with more cores than the application actually uses, and the entitlement quietly stops covering the deployment. Because this is standard for the major database and ERP vendors, the sums involved tend to be substantial.
Consumption and subscription models bill on volume or usage, where overage usually appears on an invoice rather than triggering a review.
The procurement implication is concrete. The licence metric, the audit rights, and the transfer and reassignment rights are contractual facts that only procurement sees. They have to be captured at signature and handed to whoever owns consumption. If they stay buried in the contract file, the compliance position is unknowable from the day the deal is signed.
What a review actually costs
The shortfall itself is the smallest part.
Vendors rarely confine a review to the current year. Having established a breach in one period, the natural next step is to look backwards, and the liability compounds across every year examined. Contracts frequently allow it.
Then there is the leverage problem, which is the expensive one. Business critical software cannot be switched off while a commercial argument runs. The vendor knows this and prices accordingly. An organisation that would ordinarily negotiate from a position of credible alternatives finds it has none, at precisely the moment it needs them.
Finally there is timing. The liability is unbudgeted and the vendor wants settlement quickly. Approval cycles in government and in large corporates do not move at that speed. A concession secured under pressure can expire while the money is still working through an authorisation process, and the negotiation restarts at full price.
What this looks like in practice
We worked with a UK public sector organisation running a case management system used by frontline social care teams. Vulnerable people depended on it, so switching it off was never an option.
The vendor initiated a usage review and found that around 300 named individuals were using software licensed for roughly 200. The organisation was approximately a third over its entitlement, and the vendor’s opening position was to extend the review across prior years and charge for the full historical usage.
Nothing about this was deliberate. There was no software asset management function, no reconciliation between the contract and the deployment, and therefore no way for anyone to have known. That distinction mattered in the negotiation, and we used it.
We removed the backdated liability in full and secured the additional licences the organisation genuinely needed, with a fifth of that volume provided at no cost. Alongside the commercial outcome, we committed to addressing the underlying cause rather than the invoice alone. The organisation has since defined a licence management operating model with clear ownership across contract management, business demand owners and licence management.
The model that closes the gap
Preventing recurrence is a governance question rather than a tooling one. The organisation above had discovery tooling deployed and was still exposed, because nobody owned the reconciliation.
Three responsibilities have to be assigned explicitly.
Contract management owns the entitlement baseline: licence metric, purchased quantity, term, permitted users, audit rights, true up and reassignment rights, and the price increase mechanism.
Business demand owners confirm whether the service is still required, who consumes it, and how critical it is. Once, in one shared response, rather than repeatedly to different functions.
Licence management reconciles entitlement against assigned and active usage, identifies underuse, overuse and compliance risk, and confirms the final licence requirement before anyone speaks to the supplier.
Cadence matters as much as ownership. Inputs should be returned within five business days, and the supplier engaged three to six months ahead of the notice date, which is what preserves the option of not renewing at all. Requests for new licences should route to licence management first, so that entitlements already sitting unused are reassigned before procurement buys anything new.
One caveat worth stating plainly. Discovery agents see software installed on managed machines. They do not see the subscription a department bought on a corporate card after a supplier approached them directly. Tooling narrows the gap. It does not close it on its own.
Where to start
Most organisations reading this will not know whether they are compliant. That is the normal position rather than an embarrassing one. What separates the organisations that get caught from those that do not is whether anyone has looked before the vendor does.
The starting point is unglamorous. Identify your ten largest software contracts, find the licence metric in each, and compare the entitlement against actual usage. If you cannot complete that exercise, you have found the gap.
We would welcome a conversation about what that looks like in your organisation. For the wider commercial picture, including renewal governance and the operating model that supports it, our IT Procurement Strategy 2026 report sets out the full framework.
Related reading
The operating model this article describes, assigning explicit ownership across contract management, demand owners, and licence management, is most tested at renewal. An organisation that has closed the gap internally can still find itself on the back foot if the vendor controls the renewal timeline and the conversation starts too late for any real leverage to exist. Our article on software contract lifecycle management and forced renewals sets out why renewal governance is where the commercial outcome is actually decided, how vendors use auto-renewal clauses and notice period windows to reduce a buyer’s options, and what procurement teams need to have in place well before a renewal date to negotiate from a position of genuine choice rather than managed concession.
How Procurato can help
The starting point this article recommends, identifying your ten largest software contracts and comparing entitlement against actual usage, often surfaces a broader question: whether your current procurement tools, processes, and governance structures are equipped to maintain that visibility consistently rather than just at the point someone decides to look. Our Digital Procurement Assessment reviews your current technology landscape and procurement operating model against best practice, identifying where tooling gaps, ownership gaps, or process gaps are leaving your licence position unknowable, and what a fit-for-purpose SAM and contract governance capability would look like for your organisation. If you want to understand where you stand before the next vendor review lands, we are happy to start with that conversation.
Stay ahead of the game with our latest insights