Ask a CIO whether software is under control and you will usually get a confident yes. Ask the person who has to answer a vendor audit letter and the answer changes. Somewhere between the contract signed three years ago, the installs on the servers, and the subscriptions someone approved on a corporate card, the picture stops adding up.
We work with mid-size and large organizations on software asset management (SAM), and the pattern is consistent. The program was started with good intent. A discovery tool was bought, a spreadsheet of entitlements was built, a report went to the steering group. Eighteen months later the numbers are not trusted, the person who built the spreadsheet has moved on, and the next audit is handled the way the last one was: in a hurry, at a cost nobody planned for.
This article sets out where SAM programs get stuck, what the recent survey data says about the cost of getting it wrong, and the order of work that fixes it. It is deliberately independent of any product. The problems below exist whichever platform you run, and most of them will survive a tool replacement untouched.
What the Numbers Say About the Cost of Standing Still
Two recent surveys give a useful picture. The Flexera 2026 State of ITAM report, built on responses from 512 technology professionals worldwide, found that 48% of organizations had been audited in the past year, and that 44% had spent more than $1 million on audits over three years. A separate 2025 survey by Unisphere Research for Database Trends and Applications found that about 32% of the companies measured had paid over $1 million in audit-related costs, against only 10% in the 2023 edition. The samples and definitions differ, so we would not compare the two numbers directly. We would read them the same way: the bill is moving up.
The audit pressure is also concentrating. In the same report, 64% of audited organizations said they had been audited by the largest operating system and productivity publisher, and audit activity from two other major publishers rose sharply year on year, from 24% to 38% for one and from 24% to 32% for the other. If your estate leans heavily on a small number of publishers, which most do, your exposure is not evenly spread. It is stacked on a few contracts.
Underneath the cost sits a visibility problem. Only 36% of respondents reported complete visibility of their technology estate and 62% reported partial visibility. For AI software the accurate-view figure drops to 31%, even though nearly half of organizations now track AI as a line in software spend.
One more number worth holding on to: respondents reported spending about 22% of ITAM team time on audit response, and 32% on software optimization. Teams that are busy answering audits are not optimizing. That ratio is a fair description of a reactive program.
Seven Places SAM Programs Get Stuck
These are the seven challenges we see most often in organizations with a few thousand users and upward. They are roughly in the order that causes the damage: the first few make the later ones impossible to solve. The summary below shows the root cause and the first fix for each, and the sections after it go through them one at a time.
Challenge 1: An Inventory Nobody Trusts
Almost every large organization has several sources that claim to know what is installed: an endpoint management system, a server discovery tool, a CMDB, cloud consoles, and sometimes a separate scan run by security. They disagree, and nobody has decided which one wins. When a license position is built on top, it inherits every disagreement.
The usual causes are unglamorous. Raw publisher and product names are never normalized, so one product appears under six spellings. Virtual hosts and clusters are only partly scanned. Decommissioned machines stay in the data for months. None of this is a tool defect. It is a data ownership gap.
What fixes it. Decide, per asset class, which source is authoritative and write it down. Map raw discovery output to a single product catalog so that counts mean the same thing to everyone. Then measure coverage as a number you report, for example the percentage of the estate scanned in the last thirty days, and refuse to publish a compliance position for a publisher until coverage for that publisher’s platforms is acceptable. Start with the five publishers that carry the most spend or risk, not with everything. Our post on closing the software blind spot between SAM, the CMDB and ITSM covers the integration side.
Challenge 2: Entitlements Scattered Across Teams and Files
You cannot compare usage with entitlement if the entitlement lives in a procurement inbox, a legal repository, a reseller portal and a spreadsheet owned by a former employee. We still meet organizations that cannot say, within a reasonable margin, what they own for their top three publishers.
The deeper problem is that a purchase order is not an entitlement. The entitlement is the contract line with its metric, quantity, term, and use rights, such as whether downgrade, virtualization or secondary-use rights apply. Those details sit in the contract, not in the invoice.
What fixes it. Build one entitlement record per contract line, with the metric, quantity, term, and a link to the signed contract and the purchase order. Make procurement the gate: no purchase order is closed until the entitlement record exists. Start with the top five publishers and backfill the rest as renewals come up. A record that is complete for five publishers is worth more than one that is half-complete for fifty.
Challenge 3: License Metrics and Use Rights Nobody Has Time to Read
Licensing rules are not uniform. One publisher counts processor cores, another counts named users, another counts concurrent sessions, and a growing number charge by subscription tier or by consumption. The same product can carry different rules depending on when the contract was signed. Virtualization, disaster recovery, and bundled products add more exceptions.
This is where interpretation risk lives. Two competent people can read the same clause differently, and the first time that difference is tested is often during an audit, when the other party has the advantage of having asked the question first.
What fixes it. Write a short rule book for each of your top publishers: the metric, how you count it, the use rights you rely on, and the contract clause behind each. Have legal and procurement sign off on the interpretation. Where a clause is genuinely ambiguous, ask the publisher for a written answer before you are under audit, not after. Revisit the rule book at each renewal. It does not need to be long. Two pages per publisher is usually enough.
Challenge 4: Cloud, SaaS and Shadow IT
The scope of SAM has widened faster than most programs. In the Flexera data, 75% of ITAM teams now manage cloud licenses and 64% manage SaaS. Gartner has estimated that 41% of employees acquire or build technology outside IT’s visibility, and projected that figure to reach 75% by 2027 (as reported by Auvik). Whatever the true number in your organization, the direction is not in doubt.
Shadow IT is rarely malice. People buy what they need because the approved route is slow. A program that tries to stop this with policy alone loses, and one that makes the approved route faster than the workaround wins.
What fixes it. Treat discovery of SaaS as a data-fusion job: card and expense data from finance, sign-in logs from your identity provider, and billing exports from your cloud accounts, reconciled against the application catalog. Give every application a named business owner. Create an intake path that gives a decision in days, not weeks, with a short checklist for security and data protection. Run a renewal calendar that surfaces every subscription ninety days before its date, because that is the window in which you can still change quantity or walk away.
Challenge 5: AI Features and Metered Usage
This is the newest gap and it is widening. In the Flexera report, 59% of organizations said wasted AI software spend had risen year on year, and only 31% reported accurate visibility of AI software. Capabilities are being added to products you already own, sometimes at a higher tier and sometimes billed by use, and the commercial terms differ from the licensing models your program was built around.
What fixes it. Add AI products, AI add-ons and consumption-billed services to the same catalog and entitlement process as everything else, rather than letting them live in a separate corner. Ask for the intended use case at intake. Track consumption against purchased credits or seats monthly, with an alert before the limit and a named owner for each budget. Set a clear policy on which public tools are approved and which are not, and publish an approved alternative so that the policy is something people can follow.
Challenge 6: Nobody Owns the Whole Thing
Procurement owns the contract. IT owns the installs. Finance owns the budget. Security owns the risk. Each holds one piece of the SAM picture, and none of them is accountable for the sum. SAM tends to land in an infrastructure team as a side duty, with no authority over the processes that create the problems: onboarding, offboarding, change, purchasing and cloud provisioning.
What fixes it. Give SAM a sponsor who can speak to both the CIO and the CFO, and a named owner with time allocated to it. Define who decides what in a short responsibility matrix. Then wire SAM into the processes that create license events: a leaver triggers reclaim, a change triggers a position check for the affected publisher, a purchase request triggers an entitlement record. Concepts in ISO/IEC 19770-1, the standard for IT asset management systems, are a useful reference for this structure even if you never pursue certification. If you are not sure where your program stands, a structured benchmark helps; our guide on benchmarking your SAM program and audit readiness sets out how.
Challenge 7: Audits Treated as Events, and Savings Nobody Believes
When the audit letter arrives, the clock starts. In the 2025 DBTA survey, more than a third of audits took three to six months, 11% took six months to a year, and some ran longer. An organization that begins gathering contracts, scan data and explanations on day one of that period will make avoidable concessions.
The mirror image is the savings story. SAM programs often report large “cost avoidance” numbers that finance does not accept, and after two years the program loses its sponsor. Credibility is a design choice.
What fixes it. Keep a standing readiness pack for each top publisher: the current effective license position, the contracts, the rule book, and a named responder with legal support. Write an audit response runbook that covers who receives the notice, what is shared and when, how scope is agreed in writing, and how data is checked before it leaves the building. For reporting, separate hard savings (avoided true-ups, reclaimed licenses, reduced renewals, supported by invoices) from soft cost avoidance, and show them in different columns. Finance will trust the first and tolerate the second. See also our post on cutting audit risk and cost through SAM compliance.
A Fix Sequence That Holds
The seven fixes above fit into one loop. The order matters because each step needs the one before it: you cannot reconcile what you have not entitled, and you cannot entitle what you have not normalized.
Two pieces of advice about running it. First, run the loop on a short list of publishers, finish it, and then widen. A complete loop on five publishers beats a partial one on fifty, because the first one produces a number you can defend. Second, treat the loop as a recurring cycle with a cadence, not a project with an end date. Monthly for the publishers where audit risk is highest, quarterly for the others, is a reasonable starting rhythm.
The First 90 Days
What does the start look like in practice? The plan below assumes a handful of high-spend publishers and some existing discovery capability. Organizations with less in place will need longer for the first phase, which is fine. Do not skip it.
At the end of ninety days you should be able to say, for each of your top five publishers, what you own, what you use, and what the gap is, along with how confident you are in each number. That statement is the foundation for everything else, including renewal negotiations and audit response. It will not be perfect. It will be defensible, which is the standard that matters.
Symptoms, Likely Causes and the First Move
| What you see | Likely cause | First move |
|---|---|---|
| Different teams quote different install counts | No authoritative source per asset class, no shared catalog | Name the source of record and normalize to one product catalog |
| Cannot say what you own for a major publisher | Entitlements held as invoices, not contract lines | Build the entitlement record for the top five publishers |
| Position changes after every reading of the contract | Metric and use rights interpreted informally | Write the rule book and get legal sign-off |
| Renewals arrive as a surprise | No renewal calendar, no business owner per application | Start a ninety-day renewal calendar with named owners |
| AI spend appears in several budgets | AI products bought through general channels | Add AI and metered services to the catalog and intake |
| Audit response starts from scratch every time | No standing readiness pack or runbook | Build both for the top publishers |
| Finance questions the savings figure | Hard and soft savings reported together | Report them separately and tie hard savings to invoices |
Measuring Whether It Is Working
A short set of measures keeps the program honest, and each of them is something you can calculate from data you already hold once the steps above are in place.
- Discovery coverage: the share of the estate scanned in the last thirty days, by platform.
- Entitlement coverage: the share of spend, by publisher, that has a complete entitlement record.
- Position confidence: for each top publisher, the gap between use and entitlement, and a stated confidence level.
- Renewals reviewed early: the share of renewals reviewed at least ninety days ahead.
- Reclaim rate: licenses and subscriptions reclaimed per quarter, with the value that translates to.
- Audit response time: days from notice to a complete, reviewed data submission.
Frequently Asked Questions
Should we buy a tool first or fix the process first?
Fix the ownership and data questions first, or at least in parallel. A tool will faithfully reproduce whatever your catalog, entitlement and ownership gaps are. Define what you need it to do, then compare options against that. Our tool assessment and selection approach and SAM tool assessment are built around that order.
How long before we see results?
A defensible position on the top few publishers is realistic in about ninety days where discovery already exists. Embedding the habits, such as the renewal calendar and the procurement gate, takes closer to a year.
Is a full-time SAM team necessary?
That depends on spend and risk concentration more than on headcount. An organization with a few very large contracts can need dedicated people at modest size, while one with many small subscriptions may be better served by a part-time owner supported by good intake and finance data. What cannot be skipped is an accountable owner and a sponsor.
Does ISO/IEC 19770-1 apply to us?
Certification is optional, and many organizations never pursue it. The standard is still a sensible checklist for what a SAM system should cover, including roles, processes and records.
What about hardware and the rest of ITAM?
SAM sits inside the wider IT asset management picture, and the same data discipline applies. Our write-up on what to diagnose before you invest in new ITAM tooling covers the wider view.
Sources
- Flexera, 2026 State of ITAM Report press release (512 respondents, June 2026)
- Flexera, State of ITAM 2026: audit findings
- DBTA and Unisphere Research, The Rising Cost of Software Compliance: 2025 Survey on Software Audits
- Auvik, Shadow IT statistics (citing Gartner on employee technology use outside IT visibility)
Where to Go From Here
If the seven challenges above read like a description of your own program, the most useful next step is an honest baseline: where you stand on process, data, ownership and tooling, and which publishers carry the most exposure. Our approach is vendor-neutral and built around your own estate, and you can read more on the software asset management page.
Start your software asset management transformation
Begin with the Desqcon online maturity assessment and see where your program stands today. Or talk to one of our senior consultants about a deep-dive assessment plan and a strategy shaped around your estate.
