Almost certainly, yes. Most small businesses that have been running for more than a few years are paying for seats belonging to people who left, tools a single department trialled and abandoned, and duplicate products that do the same job. The fix isn’t complicated, but it does require one thing nobody has: a single current list of what’s installed, who uses it, and what’s being paid for.
That gap costs money in two directions, and the second one is the expensive surprise. Unused seats leak a few hundred dollars a month quietly. But software running without provable entitlement turns into a bill you didn’t budget for the moment a vendor asks you to reconcile, and unknown software doesn’t get maintained, patched or renewed by anyone, because nobody knows it’s there.
What Does Software License Management Actually Involve?
Three lists and the discipline to compare them. One list of what’s installed and running, one of what the business pays for, and one of who actually uses each thing. Where those lists disagree, you’ve found either wasted money or an entitlement you can’t prove. Everything else is bookkeeping.
For a business under about fifty people this is a spreadsheet, not a platform. The vendors bidding aggressively on this topic sell tooling built for organisations with thousands of endpoints, and buying that tooling is usually the wrong first move. Build the record by hand once, find out how bad the gap is, and only then decide whether anything needs automating.
Why the record goes stale so fast
Because software gets bought by whoever needs it. A manager expenses a subscription, a project adds a tool for six weeks, someone renews an annual plan on a personal card and claims it back. None of that is misconduct, and all of it is invisible to whoever pays the bills. Within two years the business genuinely doesn’t know what it runs, and one current record of every device and application is the only thing that stops the drift compounding.
How Do You Find What You’re Actually Paying For?
Start from the money, not the machines. Pull twelve months of card and bank statements and mark every recurring charge that looks like software. Twelve months matters because annual renewals hide from a quarterly review. Then check the admin console of each service for seat counts, and only afterwards look at what’s installed.
- Card and bank statements, twelve months back. Include personal cards being expensed, because that’s where the forgotten subscriptions usually sit.
- Seat counts inside each admin console. Compare licensed seats against active users in the last ninety days, not against your headcount.
- Installed applications on every machine. Most management tools can report this centrally; without one, it’s a walk around the office.
- Connected and single-sign-on apps. Services authorised against your main identity provider often never appear on a statement at all.
- Purchase records and agreements. Keys, invoices and entitlement documents, which are the only proof you’ll have if a vendor asks.
That last list is where most businesses discover a problem. Reconstructing entitlement six years after a purchase, from an email account belonging to someone who left, is genuinely hard. It’s also the exact evidence a vendor will ask for, so it’s worth collecting while it still exists rather than when it’s demanded. Save what you find somewhere central and shared rather than in one person’s mailbox, because a proof of purchase nobody else can reach isn’t much better than one that was never kept.
Why Does Unknown Software Become a Security Problem?
Because nothing maintains what nobody knows about. An application outside your inventory gets no updates, no review and no attention when its maker stops supporting it. It just keeps running quietly on a machine, holding whatever access it was given, long after the reason for installing it disappeared.
Federal guidance for businesses puts the inventory first for exactly this reason, advising firms to maintain an up-to-date inventory of authorized devices and applications. Remove or replace any that are outdated or unauthorized. Notice the word authorised. The point isn’t only knowing what’s there; it’s deciding what’s allowed to be there and removing the rest.
The access side matters as much as the code. Tools authorised against your main business accounts can keep read or write permissions long after anyone opens them, which is a separate audit worth running alongside this one. If you haven’t looked at the connected apps still holding access to your data, the licence review is a natural time to do both, because you’re already going service by service.
What Should You Do With What the Review Finds?
Sort every finding into one of four actions and put a date on each. Cancel what nobody uses, right-size what’s over-licensed, buy entitlement for anything running without it, and consolidate where two products do one job. Then decide who owns the record so the same review isn’t needed from scratch next year.
Cancel and right-size at the renewal, not before
Most annual agreements won’t refund a mid-term reduction, so cancelling in month three often saves nothing while removing a tool someone still uses. Note the finding, note the renewal date, and act then. The exception is month-to-month services, where you should cancel the moment you confirm nobody’s touched the account.
Close entitlement gaps before someone asks
If a product is running and you can’t produce proof you’re allowed to run it, that’s a live liability. Buying the licence now costs the list price. Buying it during a vendor’s compliance review costs more, sometimes with back-dated fees attached, and it arrives on their timetable instead of yours. This is the finding worth acting on fastest.
Consolidate before you buy anything new
Reviews almost always surface two or three products doing overlapping work because different teams solved the same problem separately. Consolidating cuts spend and shrinks the number of places your data lives. It’s also the finding most likely to reduce next year’s budget, which is worth remembering when you look at where software and subscriptions sit in an IT budget.
Who Should Own the List Once It Exists?
One named person, with a standing checkpoint. The list decays the moment it becomes nobody’s job, and it decays fastest at the two moments things change most: when someone joins or leaves, and when a renewal comes up. Tie the record to those events and it stays current almost by itself.
The practical rule is that no software gets bought without being added to the list, and nobody leaves without their seats being reclaimed. That second one is where the fastest savings live, because departure usually triggers an account being disabled while the paid seat quietly rolls on. A quarterly fifteen-minute review of the largest lines catches almost everything else.
When we run a software review for a business, the first pass is never about price: we build one list of what’s actually installed and in use, a second list of what’s being paid for, and then look at where the two lists disagree, because that gap is where both the wasted money and the compliance problems live. The savings tend to come out of the first list and the risk out of the second, and you can’t see either one without both.
Frequently Asked Questions
Can we move a license from one computer to another?
Sometimes, and the agreement decides. Some licences are tied to a device, some to a named user, and some to a maximum number of simultaneous installs. Reassigning a device-locked licence to a replacement machine is usually fine; splitting one licence across two people who both use it usually isn’t. Check the terms before assuming.
What actually happens in a software audit?
A vendor asks you to demonstrate what you’re running and produce entitlement for it, usually starting with a questionnaire and a self-report. It’s a commercial process rather than a legal one in most cases. Businesses that can answer from an existing record get through it quickly; businesses reconstructing from memory take weeks and often pay more.
Is free or open-source software a licensing risk too?
It can be, in two ways. Some free tools are free only for personal use and require a paid licence in a business, which is a common and genuinely accidental breach. Others carry obligations that matter mainly if you redistribute software. Free doesn’t mean unconditional, so free tools belong on the inventory like everything else.
How much does this kind of review usually save?
It varies far too much to promise a number, and anyone quoting you a percentage before looking hasn’t looked. What’s consistent is where the savings sit: seats for departed staff, duplicate tools, and tiers bought for features nobody enabled. The review’s real value is often the entitlement gap it closes rather than the subscriptions it cancels.
Do we need a license management product to do this?
Not at small-business scale. Dedicated tooling is built for estates with thousands of endpoints and prices accordingly. A spreadsheet plus the reporting already inside your existing management and identity tools covers a business of a few dozen people. Build the record first and let the size of the problem decide whether tooling is worth it.
Where do the fastest wins usually come from?
Seat counts for people who’ve left, and month-to-month subscriptions nobody has opened in ninety days. Both are reversible if you get one wrong, both can be actioned immediately without waiting for a renewal, and between them they typically account for most of what a first review recovers.
Start With the Statements, Not the Software
You don’t need a project to begin this. Pull twelve months of statements, mark every recurring software charge, and check the seat count against active users for the three largest lines. That alone usually pays for the afternoon, and it tells you whether the rest of the estate needs the same treatment or a much harder look.
If nobody in your business can say today what software you run and what you’re entitled to, that’s the gap worth closing before the next renewal lands. You can have the O&O Systems team run the review with you, reconcile what’s installed against what’s paid for, and leave you with one record that stays current instead of one you rebuild every year.