“What software is actually installed on the PCs in your Thai plant right now?” Very few Japanese manufacturers can answer that question on the spot. The hardware register may be immaculate, yet nobody can confirm whether the number of software copies sitting on those machines matches the number of licenses the company actually owns. Software asset management (SAM) is the discipline that fills that gap. This article looks at three specific losses — vendor audits, compliance breaches, and overspending on licenses — and how Japanese manufacturers with sites in Thailand and the wider ASEAN region can prevent them, using published data as the reference point.
What Is Software Asset Management | How It Differs from PC Asset Management
Let us start with the vocabulary. If this stays vague, internal discussions drift toward a false sense of security along the lines of “we already have an asset management tool, so we are fine.”
Defining software asset management (SAM)
Software asset management is the ongoing practice of reconciling three things for every piece of software an organization owns or uses — the quantity and terms of the licenses purchased, the number of copies actually installed, and how those copies are actually being used — so that shortfalls, surpluses, and contract breaches are eliminated. It is commonly abbreviated to SAM.
The critical word is “ongoing.” Software starts changing state the moment it is purchased. Staff turnover changes who uses what. PC refreshes trigger reinstallations. A department starting a new workflow means somebody quietly downloads a trial version. An annual spreadsheet stocktake is already drifting from reality the week after it is finished.
Where the hardware register stops
Most manufacturers already run a physical asset register covering PCs, servers, and network equipment — asset numbers, purchase dates, locations, assigned users, lease expiry dates. It is usually in place because fixed-asset accounting and internal control require it.
That register, however, does not look inside the box. Behind the single row that represents one laptop sit a dozen or more pieces of software — the operating system, an office suite, a CAD viewer, PDF editing software, a production management client, a remote access tool, a compression utility. Each of those dozen items carries its own contract terms and its own ceiling on license counts.
We covered hardware asset management, and the way contracts and registers need to be thought about before you get there, in Factory IT Asset Management 2026. This article picks up one step further along — how to manage what is inside the PCs already listed in that register.
The differences between the two look like this.
| Perspective | Hardware asset management | Software asset management (SAM) |
|---|---|---|
| What is managed | Physical items such as PCs, servers, peripherals | License contracts and installed instances |
| How it is counted | Counting the physical items settles it | The counting method depends on contract terms |
| Judging shortfall or surplus | Presence or absence of the item decides it | Requires reconciling entitlements against usage |
| How risk shows up | Loss, obsolescence, overrunning a lease | Back charges at audit, compliance breaches |
| Speed of change | Turns over on a multi-year cycle | Installation status changes day to day |
Physical assets can be settled by counting. With software, the counting method itself depends on the contract, and that is the fundamental difference. The very same “installed on ten machines” can require ten licenses or three, depending on whether the agreement is named-user or concurrent-use.
Why Software Asset Management Matters in 2026 | The Audit Reality
The working assumption that “audits do not happen to companies like ours” no longer holds up statistically.
48 percent of organizations were audited (Flexera 2026)
According to the 2026 State of ITAM Report published by Flexera on 24 June 2026, a survey of 512 IT professionals, 48% of organizations underwent a software audit in the past year. That is roughly one company in two.
The cost side is more serious still. The same report finds that 44% of organizations spent more than USD 1 million on software audits over the past three years. That figure has held steady across multiple years of the report, which suggests it is not a temporary spike but a structural cost that has settled in.
That “more than USD 1 million” is not just back-charged license fees. It includes the internal hours poured into responding to the audit, fees paid to outside advisers, and legal costs. In other words, even if the company turns out to be in perfect compliance, the act of responding to an audit is itself a heavy burden.
Audit exposure varies by vendor
The same report also tallies which vendors ran audits over the past three years.
| Vendor | Audit rate over the past three years | Trend |
|---|---|---|
| Microsoft | 64% | Consistently ranked first across multiple years |
| Oracle | 38% | Sharply up from the previous 24% |
| Adobe | 32% | Up from the previous 24% |
Microsoft stands out partly because it is simply deployed in more companies, but the increases at Oracle and Adobe deserve attention. Oracle moved from 24% to 38% and Adobe from 24% to 32%, so both are auditing more frequently. For manufacturers that run database and CAD products at the core of their operations, these two movements are not somebody else’s problem.
The visibility gap as the underlying issue
In the same report, only 36% of organizations said they had full visibility of their IT assets. That figure is trending down year on year. Cloud services and SaaS keep expanding the estate that has to be managed, and governance is not keeping pace with the growth.
For AI-related software the picture is worse. Only 31% of organizations can accurately account for how it is actually being used. Generative AI tools are spreading rapidly at the department level while IT departments fail to capture the contracts and usage behind them — a new form of shadow IT.
The distortion reaches ITAM teams’ own calendars. The report finds that 32% of an ITAM team’s working time goes to software optimization and 22% to audit response. More than half their time, combined, disappears into work that ought to be compressible through better systems.
How Registers Fragment Across Thailand and ASEAN Sites

From here the discussion becomes specific to Japanese companies with manufacturing sites in Thailand. The problem presents differently than it does for companies operating only inside Japan.
Site-by-site local optimization stacks up
At Japanese manufacturers running multiple sites across Thailand and ASEAN, both PC procurement and software deployment are in practice optimized separately at each site. It is not unusual to find a Thai plant buying PCs from a local dealer, a Vietnamese site sourcing through a different channel, and an Indonesian site still running terminals the head office shipped over years ago.
Software follows the same pattern. Sometimes a Thai site buys a product individually without realizing the Japanese head office already holds an enterprise agreement with that vendor. Sometimes the opposite happens — a site assumes it is covered by the head office agreement when in fact no license has ever been assigned to it.
The real problem with this state of affairs is that nobody can aggregate group-wide entitlements against group-wide usage. Registers do exist. They just sit with different people, in different formats, at each site. Often the person holding one also covers general affairs or accounting, and updates it once a year at stocktake time.
The double blind spot | invisible locally and at head office
The deeper issue is people. It is rare for a Thai subsidiary to have a resident specialist who understands software license audit response. Local IT staff are consumed by daily troubleshooting, the network, connectivity with production equipment, and user support. There is no room in the day to work through license contract clauses.
Meanwhile the information systems department in Japan does not see what is installed on the machines overseas. Years of running on the principle that “local matters are handled locally” have produced a structure in which the local reality never travels up to head office.
The result is a double blind spot in which neither the local site nor head office can see the actual position. Typically this only becomes apparent when an audit notice arrives and it turns out nobody holds the whole picture. This is not negligence on anyone’s part — it is a structural gap in how responsibilities were divided in the first place.
Internal control auditors raise it too
Another angle that gets overlooked is internal control. When auditors review J-SOX readiness or the state of ITGC (IT general controls) at a Thai subsidiary, proper management of software licenses is a common source of findings.
The reason is simple — the evidence is hard to produce. Demonstrating that no unlicensed software is in use requires a list of installations reconciled against corresponding purchase evidence. When the registers are fragmented across sites, that document cannot be assembled in a short window.
Being asked about “the software license management framework” during a financial audit, failing to answer, and having it recorded as an improvement item is a sequence that arrives through a route entirely separate from vendor audits — and with comparable frequency.
Why Manufacturing License Models Are Difficult

Software environments in manufacturing are structurally more complex than a general office environment. That complexity is exactly why a general-purpose PC asset management tool cannot keep up on its own.
Counting rules differ product by product
ERP, CAD, CAM, production management systems, PLM, analysis software for measurement instruments. Each of the business applications used on a manufacturing site carries its own license model. Here are the main ones.
| License model | How it is counted | Management pitfalls |
|---|---|---|
| Device license | By the number of devices it is installed on | Missed deactivations at PC refresh accumulate |
| Named user license | By the number of individuals authorized to use it | Dormant leaver accounts drive the count over |
| Concurrent (floating) | By the maximum number of simultaneous users | Unverifiable unless peak concurrency is logged |
| Server license | By server CPU or core counts | Virtualization and clustering change the terms |
| Client access license (CAL) | By the devices or users connecting to the server | Easy to overlook that it is separate from the server itself |
If you look at that table and cannot immediately say which model applies to which of your own products, that in itself is the definition of an immature SAM position.
The combination most prone to accidents is server licenses paired with CALs. The assumption is that buying the server product is enough, so the client-side licenses are never purchased. This is one of the items auditors check most readily, and because the shortfall widens with every additional connected device, the back charge tends to be large by the time it surfaces.
Virtualized environments deserve equal caution. When several virtual machines run on one physical server, some products require licensing based on physical core counts, and calculating from the number of virtual machines alone leaves a large shortfall. The more a company has consolidated factory production management servers onto a virtualization platform, the easier it is to fall into this trap.
SAM as a shadow IT countermeasure
The other issue is shadow IT. Here it means software and services being deployed and used on the judgment of the front line, without the information systems department knowing about it.
Typical cases on a manufacturing site look like this.
- A design engineer personally downloads a trial viewer to open CAD data received from a customer, and keeps using it after the trial expires
- A staff member signs up for a cloud spreadsheet service on a personal account to drive an improvement project, and starts entering production data into it
- A maintenance contractor brings in a PC attached to a machine, carrying several utilities of unknown purpose
- A department contracts a generative AI tool on a departmental credit card, and IT never learns it exists
Shadow IT tends to be discussed in the context of data leakage, but from a licensing perspective it is just as serious. It happens frequently that a tool being used as “the free version” turns out to require a paid license for commercial use. A vendor audit does not ask who installed something or why. The only question is whether it is installed on a company machine.
And as the Flexera data above shows, only 31% of organizations can account for how AI-related software is actually being used. Front-line use of generative AI has widened further through 2026, making it the new main battleground for shadow IT.
Wasted license spend, the loss running the other way
So far the discussion has been about the risk of having too few licenses, but in practice the reverse happens just as often — paying year after year for licenses nobody uses.
Leaver accounts renewed rather than cancelled. High-end editions maintained long after the project ended. Duplicate agreements left in place after a departmental merger. This kind of waste has no external party pointing it out the way an audit does, which is precisely why it gets left alone.
The value of building a SAM capability is not limited to risk avoidance. Once you know the actual position, renewal time gives you leverage — cut the unused portion, step down an edition. That connects directly to the ROI discussion later in this article.
What Happens When a Software License Audit Arrives

Now let us look concretely at what happens once an audit notice actually lands.
Audits are conducted under the contract
The starting point is that a software license audit is the exercise of a right granted by the vendor contract. In Microsoft’s case, the official compliance verification FAQ explains that audits are carried out by an independent auditor under the terms of the agreement. So it is not a surprise raid — it presupposes an audit clause in a signed contract.
Most companies agreed to that clause the moment they signed a volume licensing or enterprise agreement. “We had no idea the contract contained anything like that” is a common reaction, but the clause itself is entirely standard.
Three numbers you will be asked to produce
As the ITR report on the initial response to a software license audit sets out, audit response work in practice requires compiling and submitting the following three items for each software product.
| Item to submit | What it covers | Where the difficulty lies |
|---|---|---|
| Number of devices in use | Devices on which the product is installed | Achieving complete coverage across sites and departments |
| Number of software copies in use | Copies actually installed | De-duplicating deleted and reinstalled copies |
| Number of licenses held | Legitimate licenses held through purchase | Tracing historical purchase evidence and reading contract terms |
They look like three simple numbers, but compiling them product by product with guaranteed accuracy and coverage takes an enormous amount of time. The proof of “licenses held” is the usual sticking point. Evidence for software bought five years ago survives only in a former employee’s mailbox. The reseller that sold it has since wound up its business. Situations like these are not unusual.
And once overseas sites are in scope, the work becomes a matter of asking counterparts in each country, standardizing the format, and chasing down queries as you aggregate. Cases arise where normal operations have to stop in order to respond.
The size of the burden is set in the first few days
What determines the outcome of an audit response is the initial handling. The practical points are as follows.
- Consolidate the internal point of contact the moment the notice arrives. If several people answer separately, contradictions surface later and credibility suffers.
- Check the audit clause in the contract and establish precisely the scope, deadline, and products covered. There is no obligation to volunteer information that was not requested.
- Hurriedly buying extra licenses or deleting installations after the review has begun can make the situation worse. The priority is to establish the facts accurately.
- Record the basis and procedure behind your own figures, in case they diverge from the auditor’s tally.
Whether a company can execute those steps is not something to start thinking about when the notice arrives. Whether the register was in order during normal operations changes the effort involved by an order of magnitude. With a maintained register, the task is simply exporting numbers. Without one, it becomes an investigation project spanning every site.
It is also worth noting that interest in license compliance is rising across Southeast Asia in its own right. The Business Software Alliance (BSA) has opened a software compliance helpline covering Thailand, Indonesia, Malaysia, and the Philippines, aimed at the engineering, construction, and manufacturing sectors, and continues to push for the correction of unlicensed software use. For companies with plants in Thailand, the fact that this area is under regional scrutiny is worth registering.
What Software Asset Management Costs and What It Returns
“We understand the need, but we do not have the capacity to go that far” is a fair reaction. So let us look at the cost-benefit in numbers.
Program cost runs at 0.4 to 1.2 percent of IT budget
According to the Software License Compliance Cost Benchmark 2026, with data collected from the fourth quarter of 2025 through the first quarter of 2026, companies running a SAM and license compliance program spend 0.4% to 1.2% of their IT budget on the program, with a median of 0.7%.
That is the total including tool costs, staff time, and external support. At the median it comes to just under 1% of the whole IT budget — not trivial, but nowhere near the scale of standing up a dedicated department.
ROI of 6x to 14x
The same benchmark reports a return on investment of 6x to 14x for SAM programs. The benefit is broken down into three components.
- Lower audit response costs. With the register in order, both the internal hours and the external fees consumed by an audit drop sharply. Given that 44% of organizations spent more than USD 1 million on audits, as noted above, that reduction is not something to wave away.
- License optimization. Eliminating unused licenses, over-specified editions, and duplicate agreements cuts spend directly.
- Stronger renewal negotiating position. A company that can show actual usage in numbers negotiates renewals from a position of strength. The renewal that costs the most is the one where nobody knows the position, so last year’s quantity is simply repeated.
The third point is the one most often overlooked and, in practice, the one that pays best. The vendor knows how its product is being used inside your company. If you do not, the negotiation proceeds under an information asymmetry. The starting point of any negotiation is being the party that knows your own environment best.
Maintenance contracts and license agreements are separate things that are easily conflated, and failing to separate them lets opaque spend accumulate at every renewal. We cover that issue in Business System Maintenance Costs 2026.
What happens if it is left unmanaged
Conversely, here is what follows from leaving the position unmanaged.
| Risk area | What actually happens | How the impact shows up |
|---|---|---|
| Vendor audit | Back charges for shortfalls plus response effort | Unbudgeted one-off spend and operational disruption |
| Compliance | Legal and reputational exposure from unlicensed use | Findings in customer assessments and head office audits |
| Internal control | Improvement findings under ITGC and J-SOX | Continuing explanation work for the auditors |
| Cost | Continued payment for licenses nobody uses | Preserved as fixed cost at every annual renewal |
| Shadow IT | Deployment and usage growing outside IT’s view | Unexpected installations surfacing at audit time |
| Business continuity | Suspension of access to critical software | Design and production work stops directly |
The last row is the heaviest item. Where a license breach is confirmed, some vendors can suspend use of the product until it is remedied. If CAD or the production management system stops, design stops and shipping stops with it. License management is a compliance question and a business continuity question at the same time.
Six Steps to Put Software Asset Management Into Practice
So where do you start? Sequence matters. Buying a tool first achieves nothing if there is no design for what goes into it.
Step 1 | Set the scope and name an owner
The first decisions are what is in scope and who is accountable. Taking on every site and every product at once guarantees the initiative stalls. Start with the high-value, high-audit-risk products — operating systems, office suites, databases, CAD, ERP.
On ownership, write down the division of roles between the Japanese head office and the local sites. A line such as “head office manages group-wide contract information, local sites report installation status” needs to exist as a document rather than a verbal understanding. That pays off later.
Step 2 | Consolidate contract information in one place
Gather purchase evidence, contracts, license certificates, and volume licensing portal information into a single location across all sites. This is the least glamorous step and the most time-consuming.
Some historical evidence will inevitably turn out to be missing. The important thing is not to stop there. Record what cannot be found as “unknown” and list it as something to renegotiate cleanly at the next renewal.
Step 3 | Collect installation data mechanically
Collecting installation status through manual surveys has hard limits. Use the inventory function of an asset management or endpoint management tool and collect it mechanically.
What matters here is driving the number of uncollected devices toward zero. Machines attached to equipment that are not permanently on the network, laptops taken off site, terminals returned by leavers and sitting in storage. When devices like these fall out of the tally, they become the source of the unexpected installations found at audit time.
Step 4 | Reconcile and expose the gaps
Match contract information against installation data product by product and identify both shortfalls and surpluses. Only at this point does the company’s true position become visible.
In most companies, shortfalls and surpluses appear at the same time. One product is ten copies short while another is thirty copies over. Negotiating the cancellation of the surplus together with the purchase of the shortfall can sometimes correct the position without increasing spend at all.
Step 5 | Run the operating rules
This is the step that stops it from being a one-off stocktake. Build the following three items into your business processes.
- Make register entry a mandatory step inside the procurement process whenever something new is purchased
- Include the release of license assignments in the account handling for joiners, leavers, and transfers
- Confirm the treatment of installed software when PCs are disposed of or refreshed
With those three running, the rate at which the register degrades drops dramatically.
Step 6 | Communicate internally and close the shadow IT entry points
The last step is communication to the front line. Listing prohibitions alone achieves nothing. The realistic approach is to provide a working path — “if you need software for the job, request it and you will get it” — and only then shut down unauthorized deployment. Tightening the ban while requests still take six months to fulfil simply pushes deployment further out of sight.
In-house or outsourced
Running all six steps with the limited headcount available at a Thai site is not easy. Step 2, consolidating contract information, and step 4, the reconciliation, in particular demand specialist knowledge plus blocks of time that other work will not interrupt.
A realistic option is to outsource the operational portion of SAM. Handing over the whole thing does not work, though. The line needs to be drawn so that contract decisions and internal communication stay in house, while the repeatable parts — inventory collection, reconciliation, report production — go outside. We set out that thinking in detail in IT Department Outsourcing in Thailand 2026.
Software Asset Management Trends for 2026
Finally, a look at where this is heading.
Toward predictive, AI-assisted SAM
According to OpenLM Japan’s commentary on SAM trends for 2026, the direction of travel is toward AI-enabled SAM tools that capture installation and usage status automatically and forecast the number of licenses that will be needed in future.
Where traditional SAM focused on counting the present state correctly, SAM from here on moves toward telling you how many you will need next period. If required license counts can be estimated ahead of headcount plans and new project launches, the panicked mid-year top-up purchase disappears.
The prerequisite for any forecast, however, is accurate current data. Deploying an AI tool while the registers are still fragmented only produces bad forecasts from bad data. In sequence, visibility of the present comes first.
Scope widening to SaaS and AI
The other change is the widening of what has to be managed. SAM once centered on perpetual software installed on PCs. Today it also covers SaaS subscriptions, licenses held in the cloud, and rights to use generative AI tools.
Because these can be contracted on a credit card without going through procurement, they slip through the traditional asset management net easily. The Flexera findings cited at the top of this article capture exactly how coarse that net has become.
At Thai sites too, local staff increasingly sign up for assorted cloud tools individually to make their own work more efficient. The scope of SAM has to be designed to cover the whole population of subscription agreements, not just installed software.
Frequently Asked Questions
How many people does software asset management take to run
It depends on scale, but with a handful of sites and the scope limited to major products, one dedicated person is enough to run it properly. Many mid-sized manufacturers start by allocating a few days a month within an existing IT staff member’s workload. What matters more than headcount is whether the operating rules from step 5 are embedded in the procurement and HR processes. Without those rules, the register degrades no matter how many people you assign.
Can it wait until an audit actually arrives
Statistically, no. As noted above, 48% of organizations were audited in the past year. On top of that, there is a separate route by which auditors raise findings on internal control grounds even when no vendor audit comes, and payments for unused licenses continue to accrue every year regardless. Even without the external pressure of an audit, the cost case alone justifies getting organized.
Can we manage this with free tools or a spreadsheet
At one site, a few dozen devices, and a handful of products in scope, a spreadsheet will do the job. Once sites span multiple countries and device counts pass a few hundred, synchronizing the aggregation and keeping updates timely become the problem. A useful rule of thumb is how many weeks it takes to complete a stocktake. If it takes more than a month, it is time to consider a tool.
Is there any point in organizing only the Thailand site first
Yes. In practice, building the model first in a bounded unit such as the Thai site and then rolling it out to other locations is the approach more likely to succeed. Starting everywhere simultaneously tends to stall because the differences between sites cannot all be absorbed at once. The recommended sequence is to make it work at one site, then expand.
Summary
The key points of this article.
- Software asset management is the ongoing reconciliation of three things — licenses held, copies installed, and actual usage. Both its scope and its difficulty differ from hardware register management.
- Flexera’s 2026 State of ITAM Report, published 24 June 2026, finds that 48% of organizations were audited in the past year and 44% spent more than USD 1 million on audits over the past three years.
- Audit rates by vendor are Microsoft 64%, Oracle 38%, and Adobe 32%, with Oracle and Adobe both clearly up from the previous 24%.
- Only 36% of organizations have full visibility of IT assets and only 31% can account for AI software usage, so governance is not keeping pace with the expanding IT estate.
- At Thailand and ASEAN sites, site-by-site optimization fragments the registers and creates a double blind spot in which neither the local site nor head office can see the real position.
- ERP, CAD, and production management systems in manufacturing count licenses differently product by product — server licenses, CALs, concurrent use — so a general-purpose PC asset management tool cannot keep up on its own.
- An audit requires compiling and submitting device counts, installed copy counts, and licenses held for each product, and the effort involved differs by an order of magnitude depending on whether the register was maintained beforehand.
- SAM program cost runs at 0.4% to 1.2% of IT budget with a median of 0.7%, and ROI is reported at 6x to 14x. Lower audit response costs, license optimization, and stronger renewal negotiation are the pillars of that return.
Software asset management is the kind of work that cannot be started once the audit has arrived. Put the other way round, for a company whose register is in order during normal operations, an audit turns into the simple task of exporting numbers. Whether you can create that difference is the practical dividing line.
You may still be at the stage of working out where your own organization stands and where to begin, and that is a perfectly good place to start a conversation. TOMAS TECH is based in Bangkok and supports Japanese manufacturers on the ground, from taking stock of IT assets and software licenses through to designing how they are run day to day. We are happy to talk through the current issues or the sequence of work even at an early research stage, so please feel free to Contact us.
References
- Flexera 2026 State of ITAM Report – Flexera (published 24 June 2026, survey of 512 IT professionals)
- Software License Compliance Cost Benchmark 2026 – Vendor Benchmark (data collected Q4 2025 through Q1 2026)
- BSA helpline to fight unlicensed software – Bangkok Post (BSA compliance helpline for Southeast Asia)
- Initial Response to a Software License Audit – ITR (the items to be compiled for an audit response)
- Compliance Verification Frequently Asked Questions – Microsoft (audits conducted by an independent auditor under the agreement)
- The Future of Software Asset Management (SAM) – Trends to Watch in 2026 – OpenLM Japan (commentary on AI-enabled SAM tool trends)