UK Insurance Organisation

IBM audit defence eliminating a £200,000 potential license shortfall

£200k potential license shortfall successfully negotiated away

£0 additional IBM software costs following the audit

IBM audit completed with no outstanding compliance obligations

Introduction

The client was a UK insurance company which had invested heavily in IBM products over several years, especially in the business analytics, marketing, ecommerce and infrastructure portfolios.  The client had been targeted for an IBM software license review and received notification that it would be conducted by one of the “Big Four” audit companies.

Their Challenges

The client had several challenges to overcome for this audit:

  • A key member of the SAM team was on long-term absence leaving a skills and knowledge gap at the time of the audit.
  • The client was in the middle of a change in SAM tooling, leaving some areas of the software estate without coverage.
  • Some of the products in use had complicated licensing metrics, which were a legacy of their pre-IBM ownership, e.g., Sterling and Tealeaf.

Their Objectives

The client’s objectives were:

  • A clear audit strategy to support them in their interactions with the audit team.
  • To understand their IBM license position and ensure compliance.
  • To ensure a strategy was in place to deal with and negotiate on any compliance shortfalls.

bedigital’s Solution

We followed our standard audit defence process for IBM, which involves five key stages:

  • Initial advice to the client on how to engage with the auditors and the audit process.
  • Contract, entitlement and deployment data analysis.
  • Risk identification and mitigation.
  • Data testing and audit ELP feedback.
  • Negotiation with the vendor.

How bedigital delivered

Once a non-disclosure agreement (NDA) was agreed, the client decided to put bedigital at the front of the audit and make us the single point of contact with the auditors for its progression.  The early stages of the audit focused on understanding the auditors’ proposed timeline, scope and process, whilst evaluating the audit questionnaire with client stakeholders.

In the meantime, we were working with all relevant client stakeholders to gather data on license entitlements and software usage, so that we could create an early ELP and assess any risks that were prevalent.  This involved collecting data from IBM License Metric Tool (ILMT) for virtualisation capacity-licensed products, Active Directory for user-licensed products and some reports directly from the software programs themselves for more complex metrics.  At one stage, we even consulted the IBM sales team for one of the products in use to find out the correct report to extract.

Early on, we discovered a slight risk in sub-capacity licensing for one product but, in conjunction with the client, were able to formulate a negotiation strategy that demonstrated how the issue was linked to the original project configuration, which was performed by IBM’s own professional services teams.

This audit defence required a deep dive into some of IBM’s lesser-known license metrics, which also highlighted knowledge gaps in the audit team.  With two of the in-scope product families, we discovered that the auditors had no real knowledge of how the license metrics worked – in one case, they were pulling information from the product datasheet and in the other, they were attempting to measure the wrong license metric entirely.  We were able to correct them on both of these products to ensure the ELP they created was accurate.

 

Challenges overcome

There were several challenges to overcome during the audit process:

  • An audit team which was lacking in knowledge of some of the products they were being asked to audit usage of by IBM.  This led to some challenging email exchanges, but by maintaining a calm, professional demeanour, showcasing our knowledge and providing supporting evidence, we were able to steer the auditors to the correct conclusions in their draft ELP.
  • An unavoidable full capacity license shortfall equating to approximately £200,000 at list, was negotiated away with IBM by demonstrating a link between the IBM professional services team and the license gap, and by committing to adding the product to ILMT and offering periodic reports to demonstrate continuing compliance.

Outcomes

  • The client was left with renewed confidence in its IBM licensing position and knowledge of what was required to manage it more effectively in the future.
  • Gaps in the client’s knowledge were left filled, thanks to our work on compiling the license position and the valuable insights we were able to give them.
  • The one identified compliance gap was mitigated and negotiated away with our support.

Benefits

  • We ensured the client was left with no additional costs related to its IBM software estate.
  • The audit identified some gaps in the client’s data coverage with regards to software license usage, which were closed as a result.

Testimonial

“Well done bedigital! Some really excellent work during this engagement and we could not have achieved this outcome without your support.”  – The client’s Head of Technology Sourcing

Conclusion

As with all software vendor audits, there are time pressures and challenges to overcome.  We created a plan at the beginning of the audit and followed it throughout, helping to ensure the client had no obligations to IBM.

Sample products

  • Algorithmics Financial Modeller Enterprise
  • Cognos Disclosure Management
  • Cognos Impromptu
  • DB2 Enterprise Edition
  • Sterling B2B Integrator Standard
  • Tealeaf CX
  • WebSphere Application Server
  • WebSphere MQ
bedigital