The letter is short and strikingly polite. Your vendor would like a picture of your usage "as part of periodic compliance", proposes an introductory call and mentions a delivery deadline. It contains no amount. It also says nowhere that this is a negotiation. Yet that is what it is — and most organisations make the decisions that matter in the first two weeks.
The number that changed this year
Audits are not a constant. They move with the vendor's quarterly figures. And those figures are under pressure.
The US procurement advisory firm NPI reports that 62% of organisations faced a licence audit in the past year. The year before it was 40%. In the same analysis: 45% of companies spent more than a million dollars on audit costs over three years. The most active parties are no surprise: Microsoft, IBM, SAP, Oracle, Red Hat and VMware under Broadcom.
Dimensional Research surveyed five hundred ITAM professionals for Azul and the ITAM Forum. That gives the other side. More than a quarter of organisations spend over half a million dollars a year resolving licence non-compliance. And 73% faced an Oracle Java audit in the past three years.
One warning belongs with these figures. Some of the sources publishing on audits also sell audit defence. That does not make their numbers useless, but it does explain why the drama is sometimes laid on thick. The direction is not in dispute and is reported independently by several parties: frequency is rising.
An audit is not an inspection. It is a sales channel.
This is where the understanding usually goes wrong. It explains almost all the behaviour you will see next.
At the vendor, the outcome of an audit is not booked as enforcement but as revenue. That is not a cynical reading; it is how the teams are organised and what they are measured on. It explains why the conversation almost never ends in a penalty, and almost always in an offer: the shortfall disappears if you sign a larger or longer contract.
That changes the nature of the process. You are not defending yourself against an inspection. You are negotiating with a sales organisation that calculated the opening bid itself, based on data you supplied. Which is precisely why those first two weeks carry so much weight.
The opening claim is not the bill
There is one pattern that everyone recognises who has been through this. It is rarely written down.
An advisory practice that sells audit defence reports that opening claims typically run two to four times the amount finally settled. More important is what the same source says about the difference in approach: organisations that controlled the flow of data and set the pace settled at roughly 30 to 50% of the opening claim. Organisations that co-operated quickly and fully paid considerably more on identical facts.
Take that figure with the appropriate pinch of salt — it comes from a party with an interest in that conclusion. But the underlying logic stands on its own. The opening claim is a position, not a finding. Treat it as a fact and you are negotiating up from a number the other side chose.
For calibration, a figure from another direction. Ivanti cites an average true-up of $263,000 for companies with more than fifty million dollars in revenue. Such a process can run a year or longer. That last part is often the larger cost — not the settlement, but the people tied up in it for months.
Your own terms work against you
Here it becomes specific to the Dutch market, and uncomfortable.
The NLdigital Terms 2025 sit underneath a large share of Dutch IT contracts. Article 42.8 provides that the customer shall co-operate "without delay upon request" with an investigation into compliance with the agreed usage restrictions, including access to premises and systems. Against that, the vendor must keep confidential business information outside of software usage secret — but the obligation to co-operate is drafted unconditionally.
That phrase "without delay" is the problem. There is no notice period against it, no cap on the number of investigations per year, no requirement that the auditor be independent and no allocation of costs. If you have agreed nothing else, this is your starting position.
And then there is the provision that causes most shortfalls. Article 42.6 permits use only within and for the benefit of your own organisation. Article 42.7 prohibits passing the software to third parties or having it hosted by third parties — even where that third party works exclusively for you. Anyone who has outsourced their operations or runs systems at a managed service provider sits exactly on that line. This is not an exotic edge case; it is how a large part of Dutch IT is organised.
What to do in the first two weeks
Four things, and the order matters.
Acknowledge receipt and nothing more. A professional acknowledgement is enough. No commitments on deadlines, no assessment of your position, no "we think it will be fine". Anything you say about your own usage at this stage becomes the foundation of the claim later.
Appoint a single point of contact. From now on all communication runs through that person. Audits produce their best results for the vendor when a system administrator informally co-operates with what looks like a technical request.
Read your own contract before you supply anything. Which audit clause applies, which counting rules were agreed, what your entitlement position actually is. You should know what the answer ought to be before any measurement data leaves the building. That only works if those contracts can be found — and that is exactly where most organisations come unstuck, as we described earlier in where contract value leaks away.
Do not run vendor scripts without a written agreement. You do not know what they measure. The result becomes your own evidence against you. Ask for the counting methodology and the SKU mapping in writing before anything runs.
What to put in the contract in advance
For the next contract or the next renewal there is a short list that caps the damage before anything happens.
Around the audit itself. Require thirty to sixty days' written notice and no more than one investigation per twelve months. Execution happens during business hours without unreasonable disruption. And the auditor must be acceptable to both parties and have no interest in the outcome.
On methodology. Limit the scope to systems touching the licensed products. Set explicit counting rules for virtualisation, disaster recovery environments and indirect access. And agree that a "health check" or self-assessment counts as an audit — otherwise the investigation is simply given another name.
On resolution. Require a preliminary findings letter with thirty to sixty days to respond. Secure a remediation window in which you can reconfigure without penalty. Have the vendor bear audit costs unless a material shortfall of five to ten percent is established. And record full and final settlement, so the same period is not reopened two years later.
None of these points is exotic. They are simply rarely in the contract, because the audit clause is the part nobody looks at during the negotiation.
The letter is polite because it is a sales conversation. Treat it as one.
Note: the cited provisions of the NLdigital Terms 2025 apply only insofar as those terms have been declared applicable to your agreement. Have your specific situation reviewed by your legal adviser.