IBM Audit Response

Received an IBM audit letter? Before you confirm anything, have the numbers checked by someone independent.

When you write to me, I reply the same or next business day.

Book a 30-minute call today Use the contact form

In the form, pick "Active IBM audit / audit letter received". Those messages get read first.

How an IBM software audit unfolds

Most IBM license audits follow the same script. IBM rarely audits directly. The letter usually names a Big4 firm acting on IBM's behalf. I have been through this process with clients many times, on different products and different auditors. Each stage has room to act, and each has a typical mistake.

Stage 1: The notification letter

IBM announces the audit and names the firm running it. You have more time than the letter suggests. The proposed kickoff date is a proposal, not a deadline. The typical mistake: replying within hours, confirming everything, and volunteering information nobody has asked for yet.

Stage 2: Kickoff and scope agreement

The auditor presents the process and asks you to confirm the scope: legal entities, environments, the product list. What you agree here defines the whole audit. The typical mistake: accepting the widest possible scope without discussion, because "we have nothing to hide".

Stage 3: Data collection

ILMT reports, discovery scripts, questionnaires, sometimes the auditor's own tooling. Everything you hand over becomes evidence. The typical mistake: exporting raw ILMT data without checking agent coverage and scan freshness first, or accepting output from the auditor's tools without comparing it against your own data.

Stage 4: The draft report

Findings per product, license gaps priced at list price. A draft is a position to verify, not a verdict. The typical mistake: signing it without checking whether ILMT was configured correctly when the data was collected. A broken ILMT can turn sub-capacity licensing into full capacity on paper.

Stage 5: The closing meeting

The findings are walked through and either confirmed or disputed. Whatever you dispute needs numbers behind it, not opinions. The typical mistake: showing up without your own verified figures, and not watching what leaves the room. Nothing should go to IBM without your written authorization.

Stage 6: Negotiation and settlement

The commercial discussion moves to IBM. Confirmed gaps can be resolved in more than one way: back payments, new purchases, subscription commitments. The typical mistake in an IBM audit negotiation: starting from the auditor's numbers instead of your own verified baseline.

What I do in the first 48 hours

The first days decide how the rest of the audit goes. This is what I start with, usually before your next call with the auditor.

ILMT data quality review

Agent coverage, scan freshness, VM Manager connections. If ILMT is broken, every number built on it is broken too. This comes first, because it decides how much of the auditor's report will survive verification.

Exposure map, product by product

Not every finding matters equally. I identify where the largest exposures sit per product, so the effort goes where the money is instead of being spread across every line of the report.

The auditor's numbers against yours

I compare the auditor's figures with what a correctly configured ILMT shows. The differences are usually specific and explainable: a missing VM Manager connection, a wrong bundling assignment, a false detection.

Risk quantified in money

The board does not need PVU tables. It needs to know what is actually at stake. I translate the technical findings into a financial exposure, so management knows what this audit is about before anyone negotiates.

Communication plan for the auditor

What gets handed over, what does not, and which authorizations to watch. From this point, nothing leaves your organization unverified, and nothing goes to IBM without your sign-off.

IBM audit defense in practice

Two situations from my own work. No client names, the numbers are real.

Fuel and energy group, Poland

Situation: A Big4 auditor reported license shortfalls. The numbers came from an outdated, misconfigured ILMT installation, and the client was expected to accept them.

What I did: Independent verification of the auditor's findings. I corrected the ILMT configuration, brought the installation up to a supported version, and recalculated the license position from verified data. Along the way I caught procedural errors on the auditor's side, including a report passed to IBM without the client's authorization.

Result: The WebSphere MQ requirement dropped from 1450 to 1050 licenses. Domino dropped from 9220 to 1420 PVU. The reported shortfalls did not hold up, and several positions turned out to be surpluses.

Rail logistics operator

Situation: User-based licensing under audit, with divergent data coming from Maximo and LDAP. The two sources gave different answers to the same question: how many active users are there.

What I did: A conservative analysis of active users across both sources, plus a correction of a false detection in ILMT.

Result: Before negotiations started, the board had a quantified risk of about EUR 1.8 million across three products. They went into the talks knowing the numbers instead of guessing them.

If This Looks Like Your Situation, Let's Talk

The earlier I see the data, the more room there is to act. When you write to me, I reply the same or next business day.

Book a 30-minute call today

Prefer email? Use the contact form and pick "Active IBM audit / audit letter received".

Why an independent expert, not a law firm and not a reseller

A law firm checks the process. I check the data. Most audit findings do not fall on legal arguments. They fall when the underlying measurement turns out to be wrong. I have worked with ILMT and BigFix since 2014, so I verify the auditor at the level where the numbers are made: configuration, agent coverage, detections, bundling.

I do not sell IBM licenses. A reseller who helps with your audit earns on the purchases that settle it. I have no stake in what you end up buying, so my only job is to get your numbers right.

You work with me directly. One person from the first call to the closing meeting, with no team behind me that needs billable hours. Since 2014 I have worked on ILMT and BigFix in around 30 organizations: finance, insurance, energy, and the public sector. The person you talk to is the person who does the work: Tomasz Oniśk, ITT TOMASZ ONISK.

How I start, and what it costs

An active audit does not wait, so I do not put it in a queue. This is priority work.

On the first call, you and I agree the scope of the first week: what data I need from you, what I check first, and what you get back. You receive an individual quote before any work starts. There is no price list, because the scope of the audit, the products involved, and the state of your ILMT change the work completely.

Not under audit yet?

If there is no letter on your desk and you want to know where you stand, start with an ILMT Health Check. It finds the same problems an auditor would, while you can still fix them quietly. If you want the environment kept audit-ready all year, look at Managed ILMT Services.

Frequently Asked Questions

Can I refuse an IBM audit?

In practice, usually not. Most IBM agreements, including Passport Advantage, contain an audit clause you accepted when you bought the licenses. What you can do is negotiate the timing, the scope, and the process. You are not obliged to work at the auditor's pace, and you can push back on a scope that goes beyond the agreement. Check your contract first. That is one of the first things I look at.

Can the auditor use my ILMT data against me?

Yes. Everything you hand over can end up in the findings. That is exactly why the data has to be verified before it leaves your organization. Reports from a misconfigured ILMT can badly overstate your consumption, for example by showing full capacity where sub-capacity applies. Once a bad number reaches the auditor, you spend the rest of the audit arguing against your own export.

What if I do not have ILMT at all?

Then the starting position is harder, but not hopeless. Without ILMT you generally do not qualify for sub-capacity licensing on PVU products, so the auditor counts the full capacity of the machines. There is still work to do: verifying what is actually installed, checking entitlements and bundling, and documenting what can be documented. Deploying ILMT properly often becomes part of the settlement discussion, and it protects the years after the audit.

How much does help with an IBM audit cost?

The quote is individual. It depends on the scope of the audit, the number of IBM products involved, and the state of your ILMT. We agree the scope of the first week on the first call, and you get a concrete number before any work starts. There is no price list, because no two audits are the same. One thing I can say: measured against the exposure in a draft report, it is normally a small position.

Is the conversation confidential?

Yes. An NDA is standard and gets signed before you share any numbers or documents. Yours or mine, whichever your legal team prefers. Audit situations are sensitive and I treat them that way. I work under a contract and an NDA and carry professional liability insurance. The certificate is available on request before we start.

What happens if you are unavailable during the audit?

Audit timelines have more slack than the letters suggest, and the deadlines that matter are written into the engagement plan up front. Planned absences are agreed in advance, and for larger engagements I can bring in a few trusted independent specialists I have worked with for years, under the same NDA.

Do Not Sign Anything Yet

Before you confirm the auditor's numbers, let someone independent check them. When you write to me, I reply the same or next business day.

Book a 30-minute call today

Or use the contact form and pick "Active IBM audit / audit letter received".