Definitive Guide

Oracle Audit Defense Guide

Everything a CIO, an IT asset manager or a general counsel needs when an Oracle audit letter lands: the GLAS process, the 30 to 45 day window, the findings Oracle leans on, and the buyer moves that bring the number down.

Oracle audit defense is the buyer side process of controlling the scope, reviewing the findings line by line and negotiating the settlement, and an independent line by line review typically cuts a preliminary Oracle claim 60 to 80 percent.

What is Oracle audit defense?

Oracle audit defense is the work of turning an inflated opening claim into a defensible number you can stand behind. An Oracle audit is a negotiation dressed up as an inspection, and the preliminary figure is an opening position, not a bill. Oracle runs audits through GLAS, the team formerly known as License Management Services, under the audit clause in the Oracle Master Agreement. Defense means managing that process on the buyer side: confirming what is in scope, reviewing every measurement, separating policy from contract, and settling on terms that reflect what you actually deployed.

Audits are also a sales channel. Findings feed ULA renewals, OCI commitments and Java subscriptions, and analysts estimate that 20 to 30 percent of Oracle's on premises license revenue flows from audits. Reading the process this way changes how you respond to it.

What triggers an Oracle audit?

Oracle audits rarely arrive at random, and the common triggers are virtualization changes, Java downloads without a subscription, mergers and acquisitions, declining support spend, rejected sales proposals and cloud migrations. Any of these can move you up the list. If one is on your roadmap, the time to get your position in order is before the notice arrives, not after.

Common Oracle audit triggers and the exposure they point at
TriggerWhy it draws attention
Virtualization on VMwareOracle argues for cluster wide licensing under its partitioning policy
Java downloadsThe per employee subscription counts your whole workforce
Merger or acquisitionNew entities and estates fall outside the original agreement
Falling support spendSignals a possible move to third party support or de support
Cloud migrationCounting rules change and back licensing claims appear

How long is the Oracle audit response window?

The Oracle audit response window is usually 30 to 45 days from the formal notice, and you can negotiate the timeline and the scope before you agree to anything. The clock in the letter is a starting point, not a fixed deadline. Use the early days to confirm the named entities, products and time period, to assign a single point of contact, and to agree how data will be gathered. Pace matters: a measured response protects you, a rushed one helps Oracle.

Which findings does Oracle lean on?

The classic findings are processor core shortfalls against the core factor table, options and management packs enabled by accident, cluster wide virtualization claims, Named User Plus undercounts against the minimums, and disaster recovery mistakes around the 10 day rule. Each one is a place where the opening number inflates and where a careful review brings it back down.

Options and packs are the most common surprise. A single click in Enterprise Manager can register usage of Diagnostics Pack or Tuning Pack, and many options install by default. Usage that was never operationally meaningful still shows up in Oracle's collection scripts, which is why every detected feature deserves an evidence test before you accept it.

Should you run Oracle's scripts?

Running Oracle's collection scripts at all is a decision, not an obligation, and the output should be reviewed before submission because those scripts can overcount across virtualization layers. Script results are raw data, not a verdict. Review them against your entitlements, strip the double counts, and document anything that misrepresents real deployment. What you submit frames the entire negotiation, so it pays to get it right.

Does Oracle policy beat your contract?

No. The policy document is not the contract, and contract language beats policy where the two disagree. Oracle's cluster wide virtualization claims rest on partitioning policy papers that are often weaker than the signed agreement, because Oracle's partitioning policy does not recognise VMware, Hyper V or KVM as hard partitioning. When a finding rests on policy rather than on a term you actually signed, that is a finding you can challenge. This is contract dependent, so the first step is always to read your own agreement.

What is the disaster recovery 10 day rule?

The disaster recovery 10 day rule lets you run Oracle programs on an unlicensed failover node for up to 10 separate days in a calendar year for testing or actual failover, and exceeding that can create a licensing requirement on the standby. Many estates trip over this without noticing, because routine failover testing quietly accumulates days. The buyer move is to track failover usage against the 10 day allowance, document it, and confirm how your own agreement defines the right, because this is contract dependent and the detail varies between agreements.

How much can a line by line review cut a finding?

An independent line by line review of Oracle findings typically cuts the claim 60 to 80 percent, because preliminary findings arrive inflated at list price. The reductions come from recomputing the core factor correctly, disabling and disputing options that were never meaningfully used, replacing cluster wide virtualization assumptions with what your architecture can actually demonstrate, and correcting user counts. None of this is adversarial toward Oracle. It is simply holding the number to the contract and the evidence.

The buyer moves, in order

Defending an Oracle audit follows a clear sequence, and each step protects the next.

  1. Acknowledge the letter, name one point of contact, and confirm the scope in writing.
  2. Read the Oracle Master Agreement and the ordering documents before producing any data.
  3. Decide what to measure and how, and review script output before it leaves the building.
  4. Test every finding against the contract, separating policy claims from contractual ones.
  5. Rebuild the number line by line and present a defensible position.
  6. Negotiate the remediation, not the list price, and settle on terms that fit your roadmap.
Next step

Read the deeper playbook in our Oracle License Compliance Guide, see how we work in Oracle Audit Defense, or download The Audit Letter Response Kit.

FAQ Buyer questions

What buyers ask first.

Oracle audit defense is the buyer side process of controlling scope, reviewing every finding line by line, separating policy from contract and negotiating settlement. Independent review typically cuts a preliminary claim 60 to 80 percent.
The Oracle audit response window is usually 30 to 45 days from the formal notice, and the timeline and scope are negotiable before you agree to anything.
No. Oracle's partitioning policy does not recognise VMware, Hyper V or KVM as hard partitioning, but those cluster wide claims rest on policy papers that are often weaker than the signed contract.
Running Oracle's collection scripts is a decision, not an obligation. The output can overcount across virtualization layers, so it should be reviewed before submission.
An independent line by line review of Oracle findings typically cuts the claim 60 to 80 percent, because preliminary findings arrive inflated at list price.
The License Position

Read Oracle's next move before they make it.

The License Position is our free weekly Oracle licensing note. One development that matters, why it matters, and one buyer move you can make this week, in under 400 words.

No public email needed from us. We capture everything through the form. See what it covers

Get a Quote

Have an Oracle audit letter on your desk?

Tell us about your Oracle estate and we will scope a defense. We defend 95 to 100 percent of audit exposure, with more than $500M of Oracle exposure defended across 300 plus audits and compliance reviews.

Two pricing models only. Fixed Fee, scoped and agreed up front. Gainshare, a share of verified savings or avoided exposure, with zero retainer and no risk to you. Our guarantee: we reduce your Oracle exposure or we reimburse our service fee.