The audit letter almost never arrives at a convenient time. A publisher’s asset management team emails procurement, or a reseller mentions on a renewal call that “your account has been selected for a compliance review,” and the organization scrambles to reconstruct years of purchase orders and deployment records under a deadline it did not choose. According to Flexera’s 2024 State of ITAM Report, Microsoft alone audited 50% of surveyed organizations, IBM audited 42%, and Oracle audited 31% – and 22% paid more than $5 million in audit-related costs over the prior three years, up from 15% the year before.
What makes these events disruptive is rarely the audit itself. It is discovering, mid-process, that nobody has a defensible answer to a simple question: how many licenses do we actually own, and how many are deployed? That gap is a maturity problem, not a paperwork problem, and it shows up in two places – the processes governing how software is procured and retired, and the tools that discover and reconcile what is really running.
A proper SAM Process and Tool Maturity Assessment looks at both dimensions side by side: a mature tool with no governing process is just an expensive inventory list, and a well-documented process with no reliable tooling is a policy binder nobody can act on. This piece walks through benchmarking each dimension and what to review before an audit notice arrives – not after.
SAM Process Maturity vs. SAM Tool Maturity: Two Different Assessments
Organizations frequently treat “SAM maturity” as a single score, usually anchored to whichever discovery tool they bought last. That framing misses the point of a structured assessment: process maturity and tool maturity answer different questions, and a true-up exposes weaknesses in both independently.
- SAM process maturity asks whether there is clear ownership, documented procurement-to-deployment policy, and a reliable system of record for entitlements and contracts.
- SAM tool maturity asks whether discovery data is accurate, whether reconciliation against entitlements is automated, and whether that data connects to the CMDB and procurement systems rather than a standalone spreadsheet.
ISO/IEC 19770-1, the international standard for software asset management, reinforces this separation with a tiered conformance model, so governance maturity can be demonstrated independent of which tools are deployed. A vendor auditor does not care which tool is installed; they care whether the organization can produce accurate, defensible records. That is why a combined SAM Process and Tool Maturity Assessment is the right lens.
What a SAM Process Maturity Assessment Measures
A SAM Process Maturity Assessment typically evaluates areas that map directly to audit or true-up failure modes:
- Ownership and accountability. Is there a named SAM manager with authority over the software estate, or is responsibility scattered across procurement, IT, and application owners?
- Procurement-to-retirement workflow. Is there a documented, enforced path from request through retirement or reharvesting? Gaps at retirement are a leading source of shelfware.
- Entitlement record-keeping. Are contracts centrally stored and reconcilable, or scattered across email threads and departed employees’ inboxes?
- Policy enforcement. Do requests route through the defined process, or do teams install software outside it because the process is slow?
- Vendor contract awareness. Does the organization understand its use rights, downgrade rights, and virtualization rules well enough to self-assess, rather than only during an audit?
Weak process maturity turns a routine license review into a multi-month fire drill, reconstructing entitlement history instead of pulling it from a maintained record.
What a SAM Tool Maturity Assessment Measures
A SAM Tool Maturity Assessment looks at the technical layer producing the deployment and usage data any compliance position depends on:
- Discovery accuracy. Does the tool reliably capture installed software across servers, endpoints, virtual machines, and cloud workloads, including remote devices and shadow IT?
- Reconciliation automation. Is deployed-versus-entitled reconciliation automatic, or assembled manually only when someone needs the number urgently?
- CMDB and procurement integration. Does data flow into the CMDB and ingest entitlements from purchasing systems, or does someone enter every order manually?
- Normalization quality. Can the tool distinguish editions, versions, and bundled products, a persistent challenge with publishers like Oracle and IBM?
Tool maturity failures tend to be quieter than process failures – numbers seem accurate simply because a dashboard exists, until an audit firm’s methodology surfaces devices the tool never saw.
Why SAM Maturity and CMDB Maturity Are Linked
Every tool maturity item above depends on one thing: accurate, current configuration data. A discovery feed pointed at a stale or incomplete CMDB will understate deployed instances, miss retired assets still listed as active, and misclassify server roles that determine the applicable licensing metric. An organization cannot raise its SAM Tool Maturity score without first raising its CMDB maturity score – deduplication, source reconciliation, and configuration item ownership all have to be solved before license-metric modeling can be trusted. A genuine SAM Process and Tool Maturity Assessment treats a CMDB health check as a prerequisite, not an afterthought.
The Effective License Position: Where Process and Tool Maturity Meet
The output that actually matters during a true-up is the effective license position (ELP): a reconciliation of licenses owned against licenses deployed, adjusted for contractual rights, producing a compliant or non-compliant position per product. Flexera’s glossary describes the ELP as the calculation determining whether an organization is over-licensed, under-licensed, or exactly compliant for a given publisher.
An ELP is only as good as the two maturity dimensions feeding it. Tool maturity supplies the deployment side – accurate data on what is installed and running. Process maturity supplies the entitlement side – a complete record of what was purchased, with its use rights. If either side is unreliable, the ELP is not defensible; it is a guess that looks like a spreadsheet. This is why organizations with a decent discovery tool still get blindsided in audits: the deployment data is fine, but nobody maintained the entitlement side.

The Five-Level SAM Maturity Scale
Benchmarking is more useful on a defined scale than scored pass/fail. A common way to frame SAM maturity, drawing on the tiered logic behind ISO/IEC 19770-1, is a five-level scale applying to both dimensions:
- Level 1 – Chaotic. No defined ownership or central entitlement records; discovery data, if it exists, is unreliable or manually assembled per request.
- Level 2 – Reactive. SAM activity happens only in response to a renewal or audit notice; records are rebuilt from scratch each time.
- Level 3 – Proactive. A named owner and basic policies exist, discovery tooling is in place, but reconciliation is still manual and periodic.
- Level 4 – Managed. An enforced procurement-to-retirement workflow; discovery and reconciliation automated and integrated with the CMDB; ELPs produced on demand.
- Level 5 – Optimized. SAM data informs procurement and vendor negotiations; drift is flagged early; shelfware is reharvested as routine practice, not a special project.

Most organizations, once they map themselves honestly against this scale, find that process maturity and tool maturity sit at different levels – Level 3 tooling paired with Level 2 process discipline, for example. That mismatch is what a combined assessment is designed to surface.
Your Pre-Audit Self-Check: What to Review Before the Notice Arrives
Waiting for an audit letter to start a maturity review defeats the purpose. A practical self-check, run regularly, should cover:
- Entitlement completeness. Can you locate proof of purchase and license terms for your top publishers by spend, without contacting the vendor first?
- Deployment data accuracy. When was the last full discovery scan? Are there known blind spots – offline machines, contractor laptops, unauthorized cloud instances?
- Shelfware identification. Which purchased licenses show no usage in the last 90-180 days? This is your biggest cost-recovery opportunity.
- Edition and version accuracy. Does the inventory correctly distinguish editions and consumption rules, such as named-user versus concurrent?
- Change history since the last true-up. Mergers, divestitures, and virtualization changes alter consumption in ways that are easy to miss.
Running this checklist quarterly, rather than as a one-time cleanup, separates organizations for whom an audit notice is routine from those for whom it is an emergency.
Turning a Maturity Benchmark Into a Defensible Program
A SAM Process and Tool Maturity Assessment is not a compliance exercise for its own sake – it is the groundwork that makes an ELP possible to produce on demand rather than reconstructed under audit pressure. Organizations that know where process and tooling diverge walk into a true-up with documentation instead of guesswork.
DesQcon works with organizations as a vendor-neutral advisory partner, benchmarking SAM process and tool maturity and building the reconciliation discipline an ELP depends on. Learn more about our Software Asset Management services, or talk to us about a Maturity Assessment before your next audit notice arrives.
Sources
- Flexera, “2024 State of ITAM Report Finds that IT Teams Face Increasing Audit Fines and Over Half Lack Complete Visibility into Technology Assets” – globenewswire.com
- ISO, “ISO/IEC 19770-1:2012 – Information technology – Software asset management – Part 1: Processes and tiered assessment of conformance” – iso.org
- ITAM Standards, “ISO/IEC 19770-1” overview – itamstandards.org
- Flexera, “Effective License Position (ELP)” glossary definition – flexera.com
- Block64, “The Software Audit Surge: Why 62% of Companies Faced Vendor Audits in 2024” – block64.com
