Polestar Solutions

Field Notes

The audit letter arrives: a 30-day defense plan

A software audit letter is a revenue event dressed as a compliance exercise, and it is usually timed to land near your renewal. The 30-day plan: decode the letter, appoint one owner, count independently, and answer narrowly, with the do-not list that protects your position.

Key points

  • The money is in the gap between claims: opening claims price every ambiguity against you at list plus back maintenance, so if the letter opens at $2M and your own honest count prices the true shortfall at $400,000, everything above your number is negotiation theater you can now see through.

Decode the letter, appoint one voice, freeze the chatter

Decode before you respond. Drop the letter into the audit drop-box and the decode comes back in minutes: what is actually being asserted, which agreement grants the audit right, what scope the clause really permits versus what the letter requests, the notice and conduct terms the vendor must honor, and the response deadline with the calendar started. Letters routinely request more than the contract allows, entities outside the agreement, tools of the auditor's choosing, timelines the clause does not support, and each overreach is a legitimate point of pushback that also buys time.

One owner, one channel. Appoint a single audit owner and route every vendor and auditor contact through them, in writing. The most expensive findings in audit history came from helpful engineers answering questions directly. From day one: no calls without the owner, no data without a written request matched against the contractual scope, and a short internal note telling anyone contacted by the vendor to forward and not reply.

Tell the vendor something short. Acknowledge receipt, name the owner, state that you will respond on scope and process by a specific date. Nothing else. Silence looks evasive, volume looks scared, and both invite escalation.

app.isvcosell.com/contracts

The audit right, decoded from your own paper: what the clause permits, and where the letter overreaches.

THE SAME JOB, TWICE

TODAY, BY HAND

The audit letter lands near your renewal, and the scramble starts: legal, IT, and procurement trade panicked emails about what to send.

A helpful engineer answers the auditor's questions directly and runs their scripts unreviewed, creating findings you did not need to have.

The license position gets reconstructed by hand from contract PDFs and deployment spreadsheets, weeks behind the auditor's own count.

The settlement gets negotiated inside the audit, under compliance pressure, at prices no ordinary deal would bear.

Weeks of scramble, and a settlement priced by fear

WITH ISVCOSELL

Drop the letter into the audit drop-box: the decode returns in minutes with the asserted claims, the governing clause, the scope the contract actually permits versus what the letter requests, and the deadline on a calendar.

Appoint one audit owner, freeze direct contact, and send the short acknowledgment the plan prescribes for days 1 to 7.

Run your own count first: entitlements from the contracts in the workspace, deployment from the SAM connectors, reconciled, and every genuine gap priced at your negotiated rates.

Respond inside the window accepting the audit right as the clause defines it, propose the process, and keep every exchange in the audit file for the settlement months later.

The letter decoded in minutes, the 30 days run on a sequence instead of adrenaline

What changes: the panicked scramble becomes a 30-day sequence, and you know your position before the auditor states theirs, which is the single biggest determinant of the outcome. The money is in the gap between claims: opening claims price every ambiguity against you at list plus back maintenance, so if the letter opens at $2M and your own honest count prices the true shortfall at $400,000, everything above your number is negotiation theater you can now see through.

DAYS 8 TO 21

Count independently, price the truth, fix what you can

Run your own count before theirs. The single biggest determinant of an audit outcome is whether you know your position before the auditor tells you theirs. Pull entitlements from the contracts in the workspace, deployment and usage from the SAM connectors, and reconcile. You are building the same picture the auditor will build, except honestly and first.

Price every gap yourself. Where the count shows genuine shortfall, price it at your negotiated rates and at realistic list, so you know the honest size of the problem before the vendor prices it at full list plus back maintenance. That number is your settlement compass: everything above it is negotiation theater, and knowing it keeps the theater from working.

Remediate what remediation genuinely fixes. Idle installs of unlicensed components, users in the wrong edition, the module enabled by default that nobody uses: where the contract does not freeze the position at the audit date, quiet cleanup shrinks the surface. Where it does, document the state and the intent instead. Your counsel calls this line, not your enthusiasm.

Prepare the counterweight. Audits settle as negotiations, and negotiations respond to leverage. Your renewal calendar, your benchmark position, and any credible migration alternative all belong in the settlement file, because the vendor's endgame is usually a purchase, and the price of that purchase is negotiable like any other.

"The single biggest determinant of an audit outcome is whether you know your position before the auditor tells you theirs."

DAYS 22 TO 30

Respond narrowly, negotiate the process, keep the record

The response that goes back inside the window does three things: accepts the audit right as the contract defines it, proposes the process, scope per the clause, a named data room, agreed tooling, a reasonable timetable, and reserves your positions on everything the letter requested beyond the clause. You are not stonewalling, you are performing the contract, precisely, which is both your obligation and your entire protection. Every exchange from here lives in the audit file, because the settlement discussion months from now will be won on the record you are building this week.

And the do-not list, which saves more money than any tactic:

1 Do not volunteer data. Answer what is asked, within scope, in the agreed format. Every extra spreadsheet is raw material for a finding you did not need to have.

2 Do not run the auditor's scripts unreviewed. Collection tooling gets tested in a controlled environment and its output reviewed by your side before anything leaves the building. This is standard, and a vendor who resists it is telling you something.

3 Do not negotiate the settlement inside the audit. Findings first, agreed and evidenced. Money second, as its own negotiation, on your renewal timeline if you can get it there. Vendors love a single blurred conversation because the compliance fear prices the commercial ask.

4 Do not sign a settlement without fixing the next audit. The settlement agreement is your one chance to negotiate audit conduct terms, notice, frequency, scope, tooling, into the relationship. Companies that skip this meet the same letter again in three years, with the same clause.

The honest closing note: this plan handles the standard commercial audit, which is most of them. A dispute with serious money attached, an aggressive licensor with a litigation history, or anything touching M&A belongs with specialist counsel from week one, with the platform doing what it does best underneath: the decoded contract, the independent count, the priced position, and the file that never forgets. Audits are won on evidence and sequence. Both are now cheap to have.

MA

About the author

Morten Andersen, Cofounder, ISVCOSELL

Morten brings two decades of enterprise and software procurement, with stints across Oracle, IBM, SAP, and Salesforce shaping how he reads a deal. He has led sourcing through hundreds of renewals, from mid market order forms to nine figure global agreements, and learned that the buyers who win are the ones who walk in knowing the market. He built ISVCOSELL to make that pattern recognition repeatable.

More posts by Morten Connect on LinkedIn →

See it in the product

How benchmarking works → Browse the use cases → Every feature → Calculate your time saved →

FREE TRIAL · FULL PLATFORM · NO CARD REQUIRED

Got the letter? Decode it today.

The free trial opens the benchmarking database, 1,483 vendors deep, plus the negotiation guides, playbooks, and talking points for your own renewals. No card needed, a corporate email is all it takes.

Start your free trial → Or decode a contract free, no account

Free for 30 days, no card needed. Your data stays isolated at the database, and you can export or delete it any time.

Watch it in action

The audit letter Nobody read the contract The invoice does not match

Browse the full demo library →

THE ISVCOSELL AI BRIEF · WEEKLY

The week in enterprise software buying, in one email.

What shipped on the platform, and the pricing and licensing moves worth knowing before your next renewal. One email a week, to your work address. Unsubscribe any time.

Subscribe

More in Field Notes

1,483 vendors, one method: how the benchmark library is built

A benchmark is only as good as the deals behind it and the honesty of how it is compared. How the library is built from modelled deal cohorts, normalized, placed in the right peer cohort, and graded by confidence.

Read

300 vendors, 52 weeks, one team: the renewal calendar problem

The average enterprise runs 300+ software vendors and every one of them renews. Why notice windows are where budgets quietly die, and how a renewal desk with AI agents turns the calendar from a threat into leverage.

Read

A calmer desk, and Main Apps where the work starts

The platform now wears the desktop look: warm paper, one interactive colour, and Main Apps folded into Home so your instruments live where you start.

Read

A live analyst in your ear: inside the call copilot

The vendor call is where prepared positions meet improvisation, and the rep does this every day. The live call copilot runs a whisper rail beside the conversation: live transcript, grounded prompts, and the exact fact you need at the moment the claim is made.

Read

Adobe ETLA vs VIP: seat reclaim, right-profiling, and the walk away

An Adobe ETLA renewal is decided before you discuss price, by how many seats sit idle and how many are over-profiled. How to reclaim the waste, right-profile the rest, and build the VIP walk away Adobe respects.

Read

Agent to agent: how the Agent Negotiation Protocol works

When a buyer's AI agent negotiates with a vendor's AI agent, someone has to keep the record straight. How the open Agent Negotiation Protocol handles identity, mandate, and a ledger neither side can rewrite.

Read

Want help putting this into practice?

Contact us to discuss your project.

Get in Touch