Software Due Diligence

Building a Software License Position During Diligence

A license position is the measured truth of what a target deploys against what it is entitled to use. Here is how to build one that withstands challenge and becomes a deal lever.

Building a software license position during diligence is the step that produces the number everything else depends on, because a license position is the measured truth of what a target deploys against what it is entitled to use. Without it, the deal team has contracts on one side and systems on the other and no bridge between them. With it, the team has a per publisher compliance gap that can be priced, indemnified or made a condition of close. This reconciliation is the analytical core of software due diligence, and it is what separates a real exposure estimate from a guess.

An effective license position, often shortened to ELP, is built from four inputs: entitlement, deployment, the metric rules that connect them, and the reconciliation that produces the gap. Each input has a source and a method, and the discipline is in doing all four defensibly rather than relying on the target own assurance that it is compliant. The steps below set out how the position is built and why each one matters.

Building a software license position during diligence

Building a software license position during diligence means establishing entitlement from the contracts, measuring deployment from discovery data, applying the correct metric rules, and reconciling the two into a compliance gap per publisher. Entitlement comes from the agreements, order forms and purchase history. Deployment comes from discovery tools and system records. The metric rules, drawn from publisher policy and the contract definitions, decide how each unit is counted. Reconciling deployment against entitlement on those rules produces the gap, and pricing the gap produces the exposure.

Building a license position in four stepsTimeline showing the four steps that build an effective license position during diligence: gather entitlement, measure deployment, reconcile the two, and quantify the gap into an exposure range.Building a license position in four steps1EntitlementContracts andpurchase records2DeploymentCounted on eachpublisher metric3ReconcileDeployment versusentitlement4QuantifyGap into anexposure range

The order matters. Entitlement is established first, because it defines what the target is allowed to deploy and on what metric. Deployment is measured second, against that metric rather than a generic count. The reconciliation is third, and it is where the gap appears. Quantifying that gap into a range, list price, likely settlement and cost to cure, is the final step, and it is described in quantifying software audit exposure before you sign.

What goes into an effective license position
InputSourceWhat it establishes
EntitlementContracts, order forms and purchase historyWhat the target is licensed to deploy and on what metric
DeploymentDiscovery data, deployment tools and system recordsWhat is actually installed and used across the estate
Metric rulesPublisher policy and the contract definitionsHow each unit is counted, including virtualisation rules
ReconciliationDeployment measured against entitlementThe compliance gap or surplus per publisher
Exposure rangeGap priced at list, settlement and cost to cureThe number the deal team can price or indemnify

Why entitlement is harder than it looks

Establishing entitlement sounds like reading the contracts, but in practice it is rarely that simple. Entitlement is scattered across master agreements, order forms, amendments, and the purchase history of software the target acquired through its own past deals. A target that has grown by acquisition often holds entitlement under several entities, with overlapping and stranded licenses that no one has consolidated. Reconstructing the true entitlement is a research task in itself, and it draws directly on the contract reading described in reading a target software contracts in due diligence.

Why deployment must be measured, not asked

The second input, deployment, is where most positions go wrong, because the target own view of what it runs is usually incomplete. Deployment has to be measured from discovery data and system records, not taken from a spreadsheet the target maintains. The most common surprise is virtualisation: an Oracle or IBM workload on a virtualised cluster can pull far more capacity into scope than the target believes, because the metric counts physical cores the target did not think were relevant. Measuring deployment on the publisher own rules is what turns an optimistic self assessment into a defensible count.

Key takeaways

  • A license position is the measured truth of what a target deploys against what it is entitled to use.
  • It is built from four inputs: entitlement, deployment, the metric rules, and the reconciliation.
  • Entitlement is scattered across agreements, order forms and inherited licenses, so it must be reconstructed.
  • Deployment must be measured from discovery data on publisher metrics, not taken from the target own view.
  • The reconciliation produces a per publisher gap that is then priced into an exposure range.

Why the position must be defensible

A license position is only useful if it can withstand challenge, because it will be challenged twice: by the seller in negotiation and, potentially, by the publisher in an audit after close. Every figure should show its working, the metric applied, the deployment data behind it, and the entitlement it was measured against. A position that cannot show its basis collapses at the first push and takes the buyer leverage with it. As of mid 2025, SAP pursued AB InBev for a reported 600 million dollars and Diageo for a reported 60 million in disputes tied to indirect and inherited licensing, the kind of claim a defensible position is built to withstand.

How the position becomes a deal lever

Once built, the license position stops being an analysis and becomes a lever. A quantified gap can be priced into the model, converted into a specific indemnity, or made a condition of close that the seller must remediate. A surplus, where the target is over licensed, can be a saving the buyer captures after close. Either way the position gives the deal team a number to negotiate around, and the way that number is carried into the committee is described in how to present software risk to an investment committee.

Recommendations for buyers

  1. Build the position in order: entitlement first, deployment second, reconciliation third, exposure last.
  2. Reconstruct entitlement across every entity and inherited license, not just the headline master agreement.
  3. Measure deployment from discovery data on publisher metrics, paying close attention to virtualisation.
  4. Document every figure so the position is defensible against both the seller and a later publisher audit.
  5. Convert the gap into a priced lever: a price adjustment, a specific indemnity, or a condition of close.

A defensible license position is the deliverable that makes the rest of the software due diligence method actionable, because it is the number the deal turns on. The full workstream is delivered through our software due diligence service.

Independent and buyer side. We act only for the acquirer. We hold no affiliation with any software publisher or reseller and are paid solely by you. This page is commercial and licensing guidance, not legal advice. Confirm any contractual interpretation with your own counsel.

Frequently asked questions

What is a software license position?

It is the measured truth of what a target deploys against what it is entitled to use, reconciled per publisher on the correct metric. It produces the compliance gap, also called an effective license position or ELP.

How do you build a license position during diligence?

Establish entitlement from the contracts and purchase history, measure deployment from discovery data, apply the publisher metric rules, and reconcile the two into a per publisher gap that is then priced into an exposure range.

Why is entitlement harder than reading the contracts?

Because entitlement is scattered across master agreements, order forms, amendments and licenses inherited through the target own past deals, often under several entities. Reconstructing the true entitlement is a research task in itself.

Why must deployment be measured rather than asked?

Because the target own view of what it runs is usually incomplete. Virtualisation is the common surprise: an Oracle or IBM workload can pull far more capacity into scope than the target believes, on physical cores it did not count.

Why must the license position be defensible?

Because it will be challenged by the seller in negotiation and potentially by the publisher in an audit. Every figure must show the metric, the deployment data and the entitlement behind it, or it collapses under challenge.

How does the position become a deal lever?

A quantified gap can be priced into the model, converted into a specific indemnity, or made a condition of close. A surplus where the target is over licensed can be a saving the buyer captures after close.

Build a license position the deal can turn on.

We reconcile entitlement against deployment on each publisher own metrics and hand your team a defensible license position and exposure range before you sign.

Request a software due diligence