An Oracle Audit, Traced — A Worked Example
A licence review that arrived with 45 days' notice — what the scripts found, how a monitoring tool had been accruing exposure for two years, and the difference preparation made to the outcome.
This is an illustrative example. The organisation, figures and outcome are composed to show how these reviews unfold, not drawn from a named engagement. Nothing here is legal or contractual advice — Oracle agreements vary and the detail decides the outcome.
A letter arrives giving formal notice of a licence review, with 45 days before the data collection scripts are to be run.
The infrastructure lead has nine Oracle databases, contract records in three places, and no current picture of what is actually in use.
Days 1–5: establish the position internally, first#
The single most consequential decision was made in the first week: find out what the scripts will find, before they run.
Feature usage was extracted from each database and compared against entitlements.
| Databases | |
|---|---|
| Reviewed | 9 |
| Matching entitlement cleanly | 5 |
| Using a separately licensed pack | 4 |
| Edition mismatch | 1 |
What the packs finding actually was#
Four databases showed Diagnostics and Tuning Pack usage. One was licensed for it.
The cause was not a person. A monitoring platform installed roughly two years earlier collected performance data through views that fall under those packs. It was doing exactly what it had been configured to do, and every collection incremented a usage counter that nobody looked at.
Estimated exposure: £120,000–£160,000 before any negotiation, accrued over two years.
🔴 This is the most common finding in Oracle reviews and it is almost always innocent. Intent is not the measure — usage is.
The edition mismatch#
One database licensed as Standard Edition was using Partitioning, an Enterprise feature. A DBA had solved a genuine performance problem on a large table using a standard technique. Nothing in the change process surfaced the edition constraint at the point of the decision.
Estimated exposure: £45,000–£60,000.
Days 6–20: stop the accrual, take advice#
Two actions, in this order:
Stopped the ongoing usage. Monitoring collection was disabled on the three unlicensed databases and usage confirmed to have stopped. This does not remove historical exposure, but it stops it growing during the review itself — and a counter still incrementing while a review is under way is a poor position to negotiate from.
Engaged a licensing specialist before responding. Not the vendor, and not the reseller. The value was in knowing which findings were genuinely contractual, which were negotiable, and what a reasonable settlement looked like — none of which the infrastructure team had any basis to judge.
Days 21–45: the virtualisation question#
The specialist's first question was not about the packs. It was about how the databases were hosted and how cores would be counted in the virtualisation platform.
That turned out to be a larger potential exposure than both findings combined, and it depended entirely on contract terms rather than on technical configuration. The infrastructure team had assumed that isolating the workload technically also isolated it contractually. It does not necessarily.
This is the finding that would have been missed by an internal review focused on feature usage.
The outcome#
The review ran. The findings matched what the internal exercise had already established — no surprises in the room, which is itself worth a great deal.
Settlement reached at a fraction of the worst-case exposure, structured as a forward-looking licence purchase rather than a back-dated penalty. The specialist's view was that arriving with a known position, a stopped accrual and a proposed remedy materially changed the tone.
What changed afterwards#
- Feature usage extraction runs monthly and is reviewed alongside the operational report
- An edition check was added to the change process for schema work
- Contract records consolidated into one location with a named owner
- Non-production databases consolidated onto fewer instances
- Any new monitoring tool is reviewed for pack usage before installation
Item 5 is the one that prevents recurrence. The exposure came from a tool doing its job.
What transfers#
Find out what they will find, first. Forty-five days is enough to establish your position. Being told your own exposure by the auditor is the weakest place to start.
Stop the accrual immediately — it does not undo history and it stops the number growing during the review.
Take specialist advice before responding. This is a contractual exercise, not a technical one, and the internal team has no basis to judge what is negotiable.
Check the hosting question. How cores are counted in virtualised environments is frequently the largest exposure and it is invisible to a feature-usage review.
See Oracle, the health and licensing checklist, and the licensing position report for the shape of the internal exercise.