A short, private review run once a year keeps your Oracle estate inside your certified count and keeps the evidence file current. It is the cheapest insurance against an audit finding, because it turns surprises into planned purchases long before Oracle asks a single question.
An Oracle audit finding is almost never a surprise to the data. It is a surprise to the customer who never looked. A yearly self review removes that gap by comparing deployment to entitlement on your terms, with time to act, before any external clock starts.
A self review is an internal, private comparison of what you have deployed against what you are entitled to hold. After a ULA certification your entitlement is the fixed perpetual count in your certification letter, product by product, including options and packs. The review gathers current discovery data, converts it to a license requirement, and sets it next to the certified line. Where deployment is below the line you are clean. Where it is above, you have found an exposure while you still control the response.
It is the opposite of an Oracle audit. There is no notification, no clock, and no list price settlement. You are simply doing privately, once a year, the arithmetic that an auditor would do publicly and on Oracle's timetable.
The evidence file that won your certification only keeps its value if it stays current. A self review is how you keep it alive, so the defense is ready before the letter arrives.
Run the review against six areas in order. Each maps to a place where post certification estates drift above the line.
The review does not need to be heavy. It needs to be regular and honest. The indicative cadence below suits most estates in the first years after exit, when audit interest is highest.
| When | Action | Output |
|---|---|---|
| Annually | Full six area review | Position statement and refreshed evidence file |
| Each quarter | Options and cloud spot check | Early warning on the fastest drifting areas |
| On any change | Targeted review of the affected estate | Decision before the change settles |
The figures and frequencies above are indicative. The right cadence for your organisation depends on the pace of change in your estate and the terms in your specific agreement.
Finding a gap early is the win, not the failure. You then have the full menu of responses that an audit would deny you: buy licenses deliberately at a negotiated rate, move a workload to OCI where core counting is kinder, repatriate to capacity you already own, decommission what is idle, or reconfigure virtualization to isolate the in scope hosts. Each of these is available because you found the gap on your clock. None of them is available the morning an audit notice arrives.
The self review is the habit that makes every other piece of post certification defense work. Set it once, run it on a calendar, and keep the evidence current. The full method sits in our post certification audit defense guide, and two companion notes give the detail behind two of the six areas: growth after certification and the compliance line and cloud compliance after the exit.
At least once a year, and after any material change such as a cloud migration, a virtualization project, or an acquisition. Audit interest is highest in the first two years after certification, so the early reviews matter most.
No. A self review is internal and private. It uses your own discovery data to compare deployment against your certified count. It is the opposite of inviting Oracle in. It prepares you so that if Oracle does ask, your evidence is already current.
Server and instance lists, options and packs usage, virtualization topology, cloud inventory, and the methodology behind the counts. This is the same evidence file that defended your certified count and it must be kept current to keep its value.
We set up the self review, run the first cycle with you, and leave you a repeatable method and a current evidence file. Book a confidential assessment to start.