Audit Rights

An audit rights clause gives one party the right to inspect the other party’s records, systems, or premises to verify compliance with the contract.

What it does

Some obligations cannot be verified from the outside. A software licensor cannot see how many users a customer really has. A customer cannot see whether its supplier’s security controls match what was promised. A company paying usage-based fees cannot check the meter. Audit rights fill the gap by allowing a party to look.

The clause defines who may audit, what they may look at, how often, on how much notice, who pays, and what happens with the findings. Three types are common. Licence audits let a software vendor check that usage matches the licence. Compliance audits let a customer check a supplier’s security, data protection, or regulatory obligations, often satisfied by third-party certifications or audit reports rather than a site visit. Financial audits let a party verify fees or royalties calculated by the other side.

The audit clause is usually paired with a confidentiality obligation on the auditor and a remedy: payment of any shortfall found, sometimes with interest and the audit costs if the shortfall exceeds a threshold.

Example wording

Not more than once in any twelve (12) month period, and on at least thirty (30) days’ written notice, the Supplier may audit the Customer’s use of the Software to verify compliance with this Agreement, during normal business hours and in a manner that does not unreasonably disrupt the Customer’s business. If the audit reveals use in excess of the licensed scope, the Customer shall pay the applicable Fees for the excess use within thirty (30) days. Each party shall bear its own costs of the audit, save that the Customer shall reimburse the Supplier’s reasonable costs if the excess exceeds five percent (5%) of the licensed scope.

Risks for SMBs

Software licence audits as a revenue tool. Large software vendors run licence audits systematically. An SMB that has grown, added users, or deployed software in ways the licence did not anticipate can face a large back-payment demand, at list price, with penalties. Keep records of deployments and licences, and negotiate a true-up process instead of a punitive audit.

Unbounded audit rights. “At any time, without notice, at the Customer’s premises” is disruptive and open-ended. Limit frequency, require notice, restrict to business hours, and confine the scope to what is needed to verify the specific obligation.

Who does the auditing. An audit by a competitor’s staff, or by an auditor paid on a percentage of the shortfall found, is a conflict of interest. Require an independent auditor bound by confidentiality, and give the audited party a right to object to the choice.

Cost allocation. If the audited party pays regardless of outcome, the right will be used freely. The usual middle ground is that the auditing party pays unless a material shortfall is found.

Data protection audits. Under GDPR, a controller must be able to audit its processors. Suppliers should offer certifications and audit reports to satisfy this in the normal course, and reserve on-site audits for cases where those are insufficient. See data processing.

Common variants and negotiation points


This page is general information about a common contract clause. It is not legal advice and does not account for your jurisdiction, industry, or the specific contract in front of you. Talk to a qualified lawyer before relying on it.

Tracking renewal dates, notice periods, and other contract obligations is what Trackado does.