The evidence file that wins the audit

A certified count is only as strong as the proof behind it. In the first two years after exit, audit risk rises, and the evidence file is what lets you answer with records instead of reconstruction. Build it at certification, and an audit becomes a formality rather than a fight.

The short answer

What is a ULA certification evidence file?

It is the documented proof behind the numbers you certified: the server inventory, the measurement output, the counting methodology, and the contractual basis for what was counted. It exists so that if Oracle audits in the years after certification, you can show exactly how each certified quantity was derived rather than reconstructing it under pressure. The certified count is the claim you made in the letter. The evidence file is what makes that claim hold. Without it, even a correct count can look unsupported, and an unsupported number invites challenge.

The Meridian principle

You do not defend a certification with arguments after the fact. You defend it with the file you built at the time. The number you can prove is worth more than the number you merely believe.

When is audit risk highest after a ULA certification?

Audit risk rises in the first two years after certification. Once the unlimited right has ended and your entitlement is fixed, Oracle has a clear interest in testing whether the certified counts were complete, properly derived, and consistent with the contract. That window is precisely when the evidence file earns its keep, because it lets you respond to detailed questions with contemporaneous records rather than memory and best guesses. Organizations that assemble the file at certification answer quickly and from strength. Those that did not are forced to rebuild the picture months or years later, often without the people or the system snapshots that existed at the time.

What should the evidence file contain?

A complete file ties every certified number to something you can show. The core components are consistent across engagements, even though the exact composition depends on your contract and estate.

  • A dated deployment inventory. A server and instance list as it stood within the term, identifying every environment where the certified products ran, including production, test, and disaster recovery.
  • Measurement output. The tool or script results used to measure deployment, retained with the dates they were taken, so the count traces back to observed data rather than estimates.
  • The counting methodology. A written explanation of how you counted, including core factor treatment, how processor and any Named User Plus metrics were applied, and how virtual and cloud environments were handled.
  • The contractual mapping. A reconciliation of each count to the agreement terms, showing why each environment was in scope and how the certified quantity follows from the contract.
  • The certification letter. The signed declaration itself, kept with everything that supports it, so the claim and its proof live together.

Why methodology matters as much as the number

An audit rarely turns on whether a single server existed. It turns on how you counted, especially in the areas Oracle interprets aggressively. Core factor application, the treatment of disaster recovery and non production, and how virtualized environments were measured are all places where two reasonable people can reach different numbers. A documented methodology shows that your approach was deliberate, consistent, and grounded in the contract, which is far more persuasive than a bare total. It also protects you from the most common audit tactic, which is to propose a different counting interpretation and let the burden fall on you to justify yours. With the methodology written down at the time, that burden is already met.

Worked example, indicative

A manufacturer certified out of a database ULA and, as part of the engagement, retained a dated inventory, the measurement output, and a written methodology covering core factor and virtualization. An audit opened roughly eighteen months later and questioned the treatment of a virtual cluster. Because the methodology and the contemporaneous evidence were on file, the manufacturer answered with the original records and the position held without remediation. A version of the same company without the file would have faced reconstructing the environment as it existed at certification, a much weaker footing. Outcomes are indicative and depend on the specific contract language.

Building the file so it lasts

Two habits make the difference. First, assemble the file as the certification happens, not as an afterthought, because the records you need are easiest to capture while the work is live and the people are still in their roles. Second, store it so it survives staff changes and infrastructure refreshes, with a clear owner and a known location, because the audit may arrive after the team that did the work has moved on. The evidence file is a standing asset of the post certification estate, not a one time deliverable, and treating it that way is part of the broader governance that keeps a certified position safe.

Your next step

If you have certified recently, audit the file you actually hold against the components above while the records still exist. Start with the post certification audit pillar guide, then read virtualization compliance after the exit and standing compliance governance post ULA.

Questions

The evidence file, asked plainly.

It is the documented proof behind the numbers you certified: the server inventory, the measurement output, the counting methodology, and the contractual basis for what was counted. It exists so that if Oracle audits in the years after certification, you can show how each certified quantity was derived rather than reconstructing it under pressure. The certified count is the claim, and the evidence file is what makes the claim defensible.

Audit risk rises in the first two years after certification, when Oracle has an interest in testing whether the certified counts were complete and properly derived. This is exactly the window in which the evidence file matters most, because it lets you answer questions with contemporaneous records rather than memory. Building the file at certification, not after an audit letter arrives, is what keeps the position strong.

A dated server and instance inventory, the tool or script output used to measure deployment, the counting methodology including core factor treatment and how virtual and cloud environments were handled, the mapping of each count to the contract terms, and the certification letter itself. Together these show that every certified number was measured, sourced, and reconciled to the agreement. The exact composition depends on your contract and estate.

Strictly confidential

Defend the count with the file.

Book a confidential assessment and we will review the evidence behind your certified counts, close the gaps, and make sure an audit meets records rather than reconstruction.

Book a ULA assessment