Best practices charter 2021 for Software license audits: recommendations from Cigref members for customers and their suppliers

6 janvier 2022 | ACTUALITÉS, Cigref in english, Communiqués, Publications du Cigref, Relations Fournisseurs

Cigref’s Supplier Relationships Club is proposing an update of its 2015 Charter of best practices for software license audits, produced with the active contribution of a dozen lawyers, buyers and software asset managers from Cigref member organizations, formed into an « audit management » taskforce.

The charter is also available in French.

Audits remain a reality

Software license audits are a right of the software publisher recognized by customers, but they expose the audited companies to significant legal and economic risks. Moreover, Cigref members believe that the advent of the cloud does not make audits any less crucial for vendors, who can use identified non-compliances to encourage their customers to migrate to the cloud. This is especially true since most organizations that use digital services are moving to a hybrid cloud approach and their migration path to the cloud takes place over several years. They must therefore deal with their legacy IS, and in particular their existing on-premise software, while adopting new licensing and billing models linked to the consumption of services in the cloud.

Audit management therefore remains a major concern for Cigref members, who have expressed the need to update the Charter of Good Practices for Software License Audits, a document initially developed in 2010 by Cigref and then updated in 2015. 

A good audit is an anticipated and supervised audit

Too often, the audit is still experienced by the audited organizations as a heavy constraint, consuming internal resources, generating tensions with the supplier and creating budgetary uncertainties. In order to take place under the right conditions, the right to audit must be anticipated and contractually supervised at every stage of the process.

This charter is intended for both users and software or cloud service providers, and is therefore a reminder of some of the main principles required to establish a balanced relationship based on trust between the parties, before proposing recommendations and best practices for conducting an audit.

The charter is also available in French.

IT for Green : contributions des directions numériques aux enjeux RSE et de décarbonation des organisations

Dans un contexte où les réglementations environnementales européennes se renforcent vis-à-vis des grandes organisations (CSRD, CS3D, Taxonomie verte, …), les organisations doivent de plus en plus s’outiller pour mener à bien leur politique de décarbonation et...

Géopolitique et stratégie numérique : défis et leviers d’actions pour les directions du numérique

À l’ère de la transformation numérique, les entreprises doivent composer avec un environnement international en constante évolution. La montée des tensions géopolitiques, la fragmentation du cyberespace et les nouvelles contraintes réglementaires redéfinissent les...

Guide de mise en œuvre de l’AI Act : Recueil de notes thématiques sur les principaux enjeux juridiques

Nous avons le plaisir d’annoncer la parution d’un nouveau livret du « Guide de mise en œuvre de l’AI Act », guide visant à accompagner les praticiens du numérique dans leur mise en œuvre du règlement européen relatif à l’intelligence artificielle. [calameo...

Le Cigref publie son rapport d’activité 2024

Le Cigref publie le bilan de ses activités sur la période 2023/2024. Ce rapport, visible en ligne, présente la vie de l’association, et revient sur les enjeux portés par les nombreuses activités réalisées au cours de l’exercice. Ce document est aussi l’occasion pour...