The Annual Self Review that prevents findings.

A short, private review run once a year keeps your Oracle estate inside your certified count and keeps the evidence file current. It is the cheapest insurance against an audit finding, because it turns surprises into planned purchases long before Oracle asks a single question.

The takeaway

An Oracle audit finding is almost never a surprise to the data. It is a surprise to the customer who never looked. A yearly self review removes that gap by comparing deployment to entitlement on your terms, with time to act, before any external clock starts.

What is a licensing self review?

A self review is an internal, private comparison of what you have deployed against what you are entitled to hold. After a ULA certification your entitlement is the fixed perpetual count in your certification letter, product by product, including options and packs. The review gathers current discovery data, converts it to a license requirement, and sets it next to the certified line. Where deployment is below the line you are clean. Where it is above, you have found an exposure while you still control the response.

It is the opposite of an Oracle audit. There is no notification, no clock, and no list price settlement. You are simply doing privately, once a year, the arithmetic that an auditor would do publicly and on Oracle's timetable.

The Meridian principle

The evidence file that won your certification only keeps its value if it stays current. A self review is how you keep it alive, so the defense is ready before the letter arrives.

What does the self review check each year?

Run the review against six areas in order. Each maps to a place where post certification estates drift above the line.

  1. Engines. Processor counts for each database and middleware product against the certified line, with current core factors applied.
  2. Options and packs. Where Partitioning, Diagnostics Pack, Tuning Pack, and similar are switched on, because options drift fastest and travel with the database.
  3. Virtualization. Cluster topology and host membership, because a single migration can sweep new hosts into scope under Oracle's partitioning stance.
  4. Cloud. Every Oracle workload in every cloud account, converted under the policy that applies to that provider.
  5. Corporate change. Any acquisition, divestiture, or entity change that moved Oracle deployments across the boundary of your certified scope.
  6. Evidence. Whether the server lists, tool output, and methodology behind every number are current and retrievable.

A simple cadence that works

The review does not need to be heavy. It needs to be regular and honest. The indicative cadence below suits most estates in the first years after exit, when audit interest is highest.

WhenActionOutput
AnnuallyFull six area reviewPosition statement and refreshed evidence file
Each quarterOptions and cloud spot checkEarly warning on the fastest drifting areas
On any changeTargeted review of the affected estateDecision before the change settles

The figures and frequencies above are indicative. The right cadence for your organisation depends on the pace of change in your estate and the terms in your specific agreement.

What do you do when the review finds a gap?

Finding a gap early is the win, not the failure. You then have the full menu of responses that an audit would deny you: buy licenses deliberately at a negotiated rate, move a workload to OCI where core counting is kinder, repatriate to capacity you already own, decommission what is idle, or reconfigure virtualization to isolate the in scope hosts. Each of these is available because you found the gap on your clock. None of them is available the morning an audit notice arrives.

The next step

The self review is the habit that makes every other piece of post certification defense work. Set it once, run it on a calendar, and keep the evidence current. The full method sits in our post certification audit defense guide, and two companion notes give the detail behind two of the six areas: growth after certification and the compliance line and cloud compliance after the exit.

Common questions

The annual self review

At least once a year, and after any material change such as a cloud migration, a virtualization project, or an acquisition. Audit interest is highest in the first two years after certification, so the early reviews matter most.

No. A self review is internal and private. It uses your own discovery data to compare deployment against your certified count. It is the opposite of inviting Oracle in. It prepares you so that if Oracle does ask, your evidence is already current.

Server and instance lists, options and packs usage, virtualization topology, cloud inventory, and the methodology behind the counts. This is the same evidence file that defended your certified count and it must be kept current to keep its value.

Strictly confidential

Run the review before Oracle runs the audit.

We set up the self review, run the first cycle with you, and leave you a repeatable method and a current evidence file. Book a confidential assessment to start.

Book a ULA assessment