Post Certification Audit Defense · Defense

Defending your certified counts in an audit.

Audit interest rises in the first two years after certification. The evidence file behind your certified counts is the defence, and it is built at exit, not assembled after the notice arrives. The strength of your position was decided the day you certified.

By the Meridian advisory team · Ex Oracle licensing analysts · Updated June 2026

Can Oracle audit you after you certify a ULA?

Yes. Certification ends the unlimited deployment right, but it does not end Oracle's audit rights. In practice audit interest tends to rise in the first two years after certification, the window in which the certified counts and the deployment behind them are most likely to be tested against the perpetual entitlement you declared. This is not a reason for alarm, but it is a reason for preparation. The certification letter asserts a set of numbers, often signed by a senior executive, and an audit asks you to stand behind them. A buyer who certified with a clean evidence file meets that question from strength. A buyer who certified on assertion alone meets it from weakness. The difference is set well before any notice arrives.

The buyer takeaway

Your audit defence is the evidence file behind the certified counts. It is built at exit and retained, not assembled after an audit opens. Keep the server lists, the tool output, and the documented methodology that produced each number, track deployment against the certified position over time, and license genuine growth deliberately. The work done at certification is the defence you draw on later.

What defends a certified count in an audit?

The evidence file. A certified count is only as strong as the record that explains how it was reached. That record is the server lists showing where each product ran, the tool output that measured the deployment, the processor counting and core factor working, and the methodology documentation that ties it all together into a defensible number. When a certified count is questioned, this file is what answers. A number asserted without it is an opinion; a number supported by a clean, contemporaneous file is a position. The crucial point is timing: this evidence is contemporaneous to the certification, captured when the deployment was live and measurable. Reconstructing it years later, after systems have changed, is far harder and far weaker. The file is the defence precisely because it cannot be convincingly recreated after the fact.

What the file should contain

A strong file holds the inventory of servers and instances in scope, the output of whatever discovery tooling measured them, the core factor and processor calculations for each product and option, and a written methodology that explains the choices made. It distinguishes production from test and disaster recovery, records how cloud deployments were treated against the contract, and notes any judgement calls with their reasoning. The aim is that a reviewer, internal or external, can follow the path from raw deployment to certified number without having to take anything on trust.

Why retention matters

The file only defends you if you still have it. Evidence captured at certification and then lost in a reorganisation or a system migration cannot answer an audit two years on. Retaining the file as a deliberate record, owned and findable, is part of the certification itself, not an afterthought. The cost of keeping it is trivial against the cost of facing an audit without it.

What happens if deployment grew beyond the certified count?

Growth beyond the certified perpetual entitlement needs new licenses bought deliberately. The certification fixed what you own; usage above that count is not covered, and in an audit it becomes a remediation discussion rather than a settled position. The disciplined response runs through the whole post certification period: track deployment against the certified position, see growth as it happens, and license it on its own terms rather than letting a gap accumulate quietly. The outcome to avoid is the panic re ULA, where a buyer faced with an audit gap reaches for another unlimited term as a settlement vehicle. That trades a manageable licensing decision for a far larger commitment. Genuine growth is a normal cost to plan for, not an emergency to be solved by re entering the cycle you just left.

PositionAudit exposureThe disciplined response
Certified count, full evidence fileLow, defensibleRetain and present the file
Certified count, thin evidenceHigher, hard to defendStrengthen the record where you still can
Deployment grew, licensed deliberatelyCoveredShow the deliberate purchases
Deployment grew, unlicensedRemediation discussionLicense genuine growth, avoid a panic re ULA
An indicative illustration

Consider an organisation, figures indicative only, audited eighteen months after certifying. Its certified counts were challenged, but it produced the contemporaneous evidence file, server lists, tool output, and methodology, that supported each number. The questioned counts held, and the discussion narrowed to a small amount of genuine post certification growth, which had been tracked and was licensed deliberately. The audit closed without a material finding, because the position had been built to be defended.

Where to go next

A defensible certification is the foundation of a calm audit, and the evidence file is the heart of it. Read the evidence file that wins the audit for how to build and retain that record, and the cloud exposure after certification for the area auditors test most closely. Our post certification audit guide is the pillar that frames the whole defence. When you want a read on your own evidence and exposure, the next step is a confidential assessment.

Frequently asked

Yes. Certification ends the unlimited right but not Oracle's audit rights. Audit interest tends to rise in the first two years after certification, when the certified counts and the deployment behind them are tested against the perpetual entitlement you declared. The defence is the evidence file that supports each certified number, retained from the exit.

The evidence file. Server lists, tool output, the counting methodology, and the documentation that shows how each certified number was reached are what stand behind the count when it is questioned. A count asserted without evidence is weak; a count supported by a clean, contemporaneous file is defensible. The strength of the defence is set at certification, not after.

Growth beyond the certified perpetual entitlement needs new licenses bought deliberately. Usage above the count you certified is not covered, and in an audit it becomes a remediation discussion. The disciplined response is to track deployment against the certified position over time and license genuine growth as it happens, rather than discovering the gap when an audit opens.

Book a ULA assessment

Book a ULA assessment