Oracle running in an entity or territory outside your ULA scope is not covered by the unlimited right, cannot be certified, and becomes a remediation demand at exit. The fix exists, but it almost always has to happen before you certify, while you still control where the workload lives.
Out of scope deployment is licensing in the wrong place. It is unlicensed because the unlimited right does not reach the entity or territory it runs in, so it cannot be certified and it sits as exposure. Found before certification it is fixable. Found in an audit it is a bill.
Two clauses define the boundary of your unlimited right. The customer definition sets which legal entities are covered, and the territory clause sets which countries or regions are covered. A deployment can be perfectly normal Oracle usage and still be out of scope because it runs in a subsidiary the customer definition does not include, or in a country the territory clause does not name. The software does not know the difference. The contract does, and so will Oracle.
Out of scope usage fails twice. It cannot be certified, so it adds nothing to your perpetual count even though you deployed it. And it is unlicensed, so it is countable as a shortfall at exit or in an audit. This is the worst of both outcomes: you carried the deployment cost and the risk, and got no entitlement for it.
Out of scope deployment is the one exposure that often gets worse the longer you wait, because certification freezes the picture. Find it during the assessment, not in the audit.
There are four practical fixes, and the right one depends on your contract and the workload. The table lays them out with what each requires.
| Fix | What it does | Best when |
|---|---|---|
| Migrate in scope | Move the workload to an entity or territory inside the definition | The workload can be relocated before certification |
| Consolidate | Bring the deployment onto in scope infrastructure | An in scope platform can absorb it |
| Amend | Add the entity or territory to the contract by agreement | The value justifies a negotiation with Oracle |
| Decommission | Retire the out of scope deployment entirely | The workload is no longer needed |
Each fix has to be completed and evidenced before the certification letter is signed, because certification converts the picture as it stands on that date. A workload that is still out of scope when you certify is a workload you have just declared you cannot license.
Wrong entity deployment is most common after an acquisition, a reorganisation, or a shared services consolidation, because those events move workloads across legal boundaries without anyone checking the ULA scope. A workload that was in scope can be migrated into a newly acquired entity that is out of scope, and nobody notices until certification. This is why corporate change during the term needs to be managed against the ULA clock, not just the project plan. Every entity move is a scope question waiting to be asked.
If your estate has been through any corporate change, the highest value first step is a scope reconciliation: map every Oracle deployment to a legal entity and a territory, and test each against your customer definition. Find the out of scope usage while there is still time to fix it. Two companion notes connect directly: acquisitions during the ULA term on how scope expands or breaks, and the corporate change checklist for ULA holders for the controls that prevent it. The wider method sits in our ULA exit strategy guide.
Deployment in an entity or territory outside your customer definition is not covered by the unlimited right. It cannot be certified into your perpetual count and it is unlicensed usage, which means it can trigger a remediation demand at exit or in an audit.
Often yes, if you act before certification. Migrating the workload to an in scope entity, consolidating it onto in scope infrastructure, or amending the customer definition can bring the usage into the perpetual count. The right fix depends on your contract.
Yes. Many ULAs limit the territory in which the unlimited right applies. A deployment in a country outside the defined territory is out of scope just as an out of scope entity is, and it carries the same remediation risk at exit.
We reconcile every Oracle deployment to its entity and territory, find the out of scope usage, and fix it before the certification letter locks the picture. Book a confidential assessment.