LIVE INDEX 214 verified firms 41 countries $1.4B+ in disputed claims defended
Index/IBM audit defense
VENDOR PROFILE · IBM

IBM Audit Defense

IBM runs one of the most active license-audit programs in enterprise software, and most outcomes turn on two things: how Processor Value Units (PVUs) are counted and whether your sub-capacity reporting through the IBM License Metric Tool (ILMT) was complete and on time. The firms below defend IBM audits worldwide; the single most useful first move is to fix your ILMT position and re-check the PVU math before you accept any finding.

AUDIT AGGRESSION
6
FIRMS LISTED

LAST REVIEWED: JUNE 2026 · REVIEWED QUARTERLY

01 — HOW IBM AUDITS

IBM's global audit operation

IBM conducts software compliance reviews globally, both directly and through appointed third-party auditors, typically under the audit rights in the IBM International Passport Advantage Agreement (IPAA). It sits among the most audit-active publishers reaching enterprises in 2026, alongside Microsoft, Oracle, SAP, Red Hat and Broadcom VMware. Across the market, an estimated 62 to 63 percent of companies report being audited within any 12-month window (industry surveys, 2025 to 2026), and roughly 52 percent now bring in outside defense help rather than face a publisher review alone.

An IBM review usually opens with a formal audit notification naming an audit firm, followed by a request to deploy data-collection tooling and to produce deployment and entitlement records. The decisive question is almost always sub-capacity eligibility: IBM allows many products to be licensed for the virtual capacity actually used rather than full physical capacity, but only if the IBM License Metric Tool (ILMT) was installed, kept current, and producing quarterly reports throughout the period. Where ILMT was missing or lapsed, IBM's default position is to charge at full capacity, which can multiply the claim. Red Hat, an IBM company, is also escalating subscription-compliance reviews sharply in 2026, and IBM estates increasingly span both.

The mechanics: PVU, sub-capacity and ILMT

IBM's core metric for many middleware and infrastructure products is the Processor Value Unit (PVU), a per-core figure that varies by processor type, so the same workload can carry very different PVU totals depending on the hardware and how cores are mapped. Sub-capacity licensing lets you count only the cores assigned to IBM workloads in a virtualized environment, but eligibility is conditional on continuous, accurate ILMT reporting. Common findings arise from a late or incomplete ILMT deployment, virtualization or container sprawl that makes point-in-time measurement contentious, ambiguity over whether a component is licensed standalone or only as part of a bundle, and Passport Advantage terms that place the burden of proof on the customer. Gaps are frequently charged retroactively, compounding exposure.

⚠ DON'T DO THIS FIRST

Do not accept a full-capacity finding or hand over raw tooling output before the ILMT history and PVU mapping have been independently reviewed. A late ILMT report does not automatically forfeit sub-capacity rights in every case, and the PVU math is frequently contestable.


02 — TACTICS

How IBM audits you

The recurring moves. Recognize them early and you keep leverage.

MEASUREMENT

PVU counting

Processor Value Unit math across mixed environments is complex and easy to compute in IBM's favor when core-to-PVU mapping is not checked.

THE TRAP

Sub-capacity / ILMT gaps

Miss the ILMT deployment or a quarterly reporting window and IBM's default is to charge at full physical capacity.

LICENSING

Bundling ambiguity

Whether a component is entitled standalone or only within a bundle is interpreted to maximize the claim.

CLOUD

Container & VM sprawl

Dynamic and containerized infrastructure makes point-in-time measurement contentious and inflates apparent deployment.

CONTRACTS

Passport Advantage terms

IPAA program rules shift the burden of proof onto the customer to demonstrate compliant deployment.

PRESSURE

Back-dated charges

Reporting gaps are charged retroactively across the period, compounding exposure well beyond current usage.


03 — WHAT GETS AUDITED

The IBM product map

The portfolios where IBM findings most often arise, described factually.

MIDDLEWARE

WebSphere & MQ

PVU-licensed application and integration middleware, where sub-capacity eligibility and core mapping drive the result.

DATA

Db2 & Information Management

Database and data-platform products licensed by PVU or authorized user, sensitive to virtualization assumptions.

AUTOMATION

Cloud Pak & container bundles

Modern Cloud Pak entitlements use Virtual Processor Cores (VPC), and container deployments complicate measurement.

SECURITY

Security & QRadar

Capacity and event-based metrics that are easy to exceed as data volumes grow.

OPEN SOURCE

Red Hat subscriptions

As an IBM company, Red Hat is escalating subscription-compliance reviews on RHEL and OpenShift in 2026.

STORAGE

Spectrum & Storage

Capacity-based storage software licensing where measured terabytes can drift past entitlement.


04 — SPECIALIST FIRMS

Firms that defend IBM audits

Listed alphabetically with balanced pros and cons — a directory, not a ranking. Every firm below is independent and buyer-side; none resells IBM licenses.

Fjord Licensing Advisory ✓ Verified Independent demo

HQ Switzerland · Serves CH · DE · FR · AE

Zurich boutique serving regulated industries, including banking and pharma, with discretion-first engagements across Oracle, SAP, IBM and Broadcom.

Pros
  • Discretion-first model suited to banking, pharma and regulated industries
  • Deep Oracle ULA and SAP S/4HANA migration experience that transfers to IBM contract work
  • Independent advisory with no reseller ties
Cons
  • Premium positioning aimed at large regulated clients
  • Smaller geographic footprint (DACH, France, UAE)
  • IBM is one of several focuses rather than the core specialism
OracleSAPIBMVMware / Broadcom
View profile

Harborview Advisory ✓ Verified Independent demo

HQ United States · Serves US · CA · AU · SG

Infrastructure-licensing focus with deep data-center and virtualization modeling that applies directly to IBM PVU and sub-capacity disputes.

Pros
  • Strong on infrastructure and data-center licensing, including core-count modeling
  • Virtualization expertise that maps onto IBM sub-capacity arguments
  • Independent and buyer-side, with no licenses to sell
Cons
  • Relatively new practice built around the Broadcom/VMware wave
  • IBM is adjacent to its core infrastructure focus rather than central
  • Smaller jurisdictional footprint in Europe
VMware / BroadcomMicrosoftIBM
View profile

Kessler & Roth Lizenzrecht ✓ Verified Independent demo

HQ Germany · Serves DE · CH · AT · NL

Munich-based licensing law boutique combining German contract-law litigation with technical measurement across SAP, Oracle and IBM.

Pros
  • Qualified German lawyers combining contract-law litigation with technical measurement
  • Native DACH practice fluent in local court procedure
  • Independent, buyer-side, with no reseller relationship
Cons
  • Coverage limited to the DACH region and the Netherlands
  • Narrow vendor set (SAP, Oracle, IBM)
  • Law-firm engagement model and rates rather than fixed-fee advisory
SAPOracleIBM
View profile

Lattice Compliance Group ✓ Verified Independent demo

HQ Netherlands · Serves NL · DE · FR · GB

Ex-IBM PVU and sub-capacity experts who close the ILMT reporting gaps that auditors turn into full-capacity charges.

Pros
  • Ex-IBM experts on PVU counting, sub-capacity and ILMT reporting
  • Closes the ILMT gaps that turn into full-capacity charges
  • Independent, buyer-side advisory with no reseller ties
Cons
  • IBM-weighted; lighter on Microsoft, Broadcom and SaaS
  • EU-only footprint
  • Limited cloud and container-licensing depth
IBMOracleSAP
View profile

Meridian License Counsel ✓ Verified Independent demo

HQ United States · Serves US · CA · GB · DE

Founded by former Oracle LMS auditors; a litigation-ready advisory that also defends IBM matters and is willing to contest findings rather than only negotiate.

Pros
  • Litigation-ready and willing to contest findings, not just negotiate
  • Auditor-trained founders who understand measurement methodology from the inside
  • Independent and buyer-side, with no licenses to sell
Cons
  • Oracle-centric; IBM is a secondary practice area
  • Coverage limited to the US and parts of Western Europe
  • Boutique capacity can mean lead times during audit-heavy quarters
OracleIBMMicrosoft
View profile

Redress Compliance ✓ Verified Independent

HQ Global · Serves worldwide

Independent enterprise licensing advisory covering Oracle, SAP, IBM and Microsoft. No vendor partnership, no reseller relationship and no commission.

Pros
  • Fully independent: no vendor partnership, no reseller relationship, no commission, so incentives align with reducing your claim
  • Broad multi-vendor coverage including IBM alongside Oracle, SAP and Microsoft
  • Buyer-side only, advising on contract negotiation and audit defense rather than selling licenses
Cons
  • Heaviest depth is Oracle and Java; IBM coverage is broad rather than ex-IBM specialist
  • Boutique advisory scale rather than a global Big-Four footprint
  • Outcome figures (60 to 90 percent claim reductions) are self-reported and not independently audited
OracleSAPIBMMicrosoft
View profile

Listed alphabetically — not a ranking.


05 — BY JURISDICTION

IBM audit defense, by country

Audit posture and local procedure differ by market. Pick yours for the firms and local guidance.

06 — FAQ

IBM audits: common questions

What is the single biggest driver of an IBM audit finding?

Sub-capacity eligibility. IBM lets many products be licensed for the virtual capacity used rather than full physical capacity, but only where the IBM License Metric Tool (ILMT) was installed, current and producing quarterly reports. A missing or lapsed ILMT is the most common reason findings balloon to full capacity.

What is a PVU and why does it matter?

A Processor Value Unit is IBM's per-core licensing unit, and its value depends on the processor type. Because the same workload can carry very different PVU totals depending on hardware and core mapping, the PVU calculation is frequently where claims are overstated and where re-measurement reduces them.

If our ILMT reporting lapsed, have we automatically lost sub-capacity rights?

Not necessarily in every case. IBM's default is to charge at full capacity, but the facts, the contract terms and any reconstructable historical data can support a sub-capacity position. This should be reviewed before any full-capacity finding is accepted. This is information, not legal advice.

Does Red Hat fall under IBM audits now?

Red Hat is an IBM company and is escalating its own subscription-compliance reviews on products such as RHEL and OpenShift in 2026. Estates increasingly span both, so defenders often address IBM and Red Hat exposure together.

Do you recommend a specific firm?

No. This is a directory, not a ranking. We list firms with balanced pros and cons and give you what you need to choose for yourself, including whether a firm is independent or also resells the vendor's licenses.

Is the matching service really free?

Yes. The directory and matching are free for buyers. We are not a law firm and take no money from software publishers.