Audit, review, true up: three letters, three problems.
Red Hat opens three distinct procedural surfaces against a buyer that are frequently confused with one another. A formal compliance audit, a softer compliance review, and a contractual true up are different instruments with different defenses and different escalation paths. The framing of the inbound letter is rarely a reliable guide to which one the buyer is actually in. The wrong response to the wrong letter inflates the eventual figure. The right response begins with naming the instrument correctly before the first piece of evidence leaves the building.
The audit.
A Red Hat audit is a formal procedural instrument defined in the subscription agreement and cited by clause when it is opened. The letter is dated. The letter names a response window, typically between twenty one and forty five days, during which the buyer is asked to produce evidence of entitlement against deployment for the named products. The letter is structured to anticipate a settlement letter at the end, which restates the deployment figure, restates the entitlement figure, names the delta, and proposes a financial figure to resolve the delta.1 The audit is the instrument with the highest financial stakes of the three.
The audit is also the instrument with the most well developed playbook on the Red Hat side. The account team is no longer the principal counterpart by the time the letter is issued; the conversation moves to the software asset compliance function and, in larger matters, to external counsel acting on Red Hat's behalf. The buyer's instinct to call the account representative for an explanation is rarely productive at this point. The account team has been routed around by the very instrument that produced the letter. The defense surface for the buyer is the audit defense engagement.
The contractual basis for the audit is the audit clause in the subscription agreement, which grants Red Hat the right to verify compliance on reasonable notice. What "reasonable notice" means in practice is the response window cited in the letter. The clause does not specify what evidence the buyer must produce, only that the buyer must produce sufficient evidence. The latitude on what counts as sufficient is the negotiation surface that audit defense addresses. A buyer who responds to the audit by producing everything asked for has surrendered that latitude before the negotiation begins.
The review.
The review is the softer instrument. It arrives with language such as "compliance check", "subscription assessment", "entitlement review", or "true up preparation". The scope named in the letter is typically narrower than an audit, sometimes a single product line or a single business unit. The tone is consultative; the requested evidence is, on a careful reading, functionally similar to what an audit would request, but the framing positions the conversation as collaborative rather than adversarial.
The review is frequently a precursor to a formal audit. The pattern the practice sees often runs as follows. The review letter goes out. The buyer treats it lazily, on the reasoning that the language is soft and the figures named in the eventual report are negotiable. The buyer produces evidence loosely, without narrowing scope. The evidence reveals a delta the buyer had not surfaced internally. The review report cites the delta. Some weeks later, a formal audit letter follows, citing the same products and using the review evidence as a starting baseline for the formal exercise. The buyer is now defending against the figure produced in the unprotected review rather than against a clean sheet.
The treatment for the review in the practice runs through the subscription assessment engagement. The objective is to produce the buyer's own reconciliation first, on the buyer's terms, before any evidence leaves the building in response to Red Hat. Once the buyer holds the reconciliation, the response to the review can be calibrated to it, and the figure on the eventual review report is one the buyer has already framed.
The true up.
The true up is the mechanical instrument. It is contractual rather than adversarial, and it is triggered when deployment exceeds entitlement on a known SKU during the contract term. The buyer has consumed more managed nodes than the Ansible Automation Platform entitlement allows, or more cores than the OpenShift entitlement allows, or more sockets than the RHEL entitlement allows. The agreement names the procedure for resolving the overage, which is typically a co terminus order for additional entitlement at the standard pricing on the contract.2
The true up is not, on its own, a compliance event in the punitive sense. The contract anticipates that consumption will move during the term and provides for the order to be placed without renegotiating the underlying terms. What the buyer is buying is additional entitlement, not an absolution; the underlying pricing has already been negotiated. The leverage on the true up is therefore narrow, but it is not zero. The figure the buyer pays depends on which SKU the additional entitlement is ordered against and on whether the order can be folded into the upcoming renewal rather than processed as a standalone instrument. Renewal negotiation is the surface where that folding is structured.
Why the three are confused.
Three reasons, in the practice's record. First, the letterhead is the same on all three. The instrument is identified by the clause cited and the body text, not by the envelope. A buyer who triages by appearance triages incorrectly. Second, the account team voice on the early outreach is the same on all three. The first email is often a soft note from the account representative asking for a meeting, regardless of which instrument has been opened internally on the Red Hat side. The instrument hardens after the meeting, not before it. Third, the evidence requested overlaps materially. All three want a deployment inventory against a product family. The shape of the request is similar enough that the buyer cannot reliably tell from the evidence ask alone which instrument is in play.
The two recurring misreadings the practice sees follow from this overlap. Buyers read the soft letter as a true up; in fact it is a review, and the response to a true up is mechanical while the response to a review must be carefully scoped. Buyers read the formal letter as a review; in fact it is an audit, and the response window is shorter than the buyer assumes. The first misreading inflates the figure on a future audit. The second misreading triggers a missed window on the present one. Both compound. The companion brief on the fourteen day response window treats the timing problem in detail, and the brief on Red Hat audit against IBM audit treats the cross vendor framing question that often arises in parallel.
Response calibration by instrument.
For the audit, the response is narrow and disciplined. The buyer answers the questions actually asked, no more, in the format actually requested, and routes every outbound communication through a single named responder. Volunteered evidence is the most common source of avoidable exposure. The buyer's general counsel or external counsel is the appropriate responder on the formal channel; the account representative is not.
For the review, the response is reconciled internally first. The buyer runs the reconciliation against its own deployment data, in scope to the products named in the review letter, before any evidence leaves the building. The response to Red Hat is then calibrated to the internal reconciliation, on the buyer's framing rather than Red Hat's. The responder is a procurement lead with internal counsel on the cc line.
For the true up, the response is procedural. The buyer confirms the overage figure against its own deployment data, confirms the SKU on which the order will be placed, and routes the order through the standard purchasing channel. The responder is the procurement lead. The leverage is on the SKU selection and on whether the order folds into the upcoming renewal, not on the figure itself.
| Attribute | Audit | Review | True up |
|---|---|---|---|
| Formal status | Clause invoked | Soft, consultative | Contractual mechanic |
| Typical window | 21 to 45 days | Open, weeks | Co terminus order |
| Evidence requested | Full inventory | Inventory, narrower scope | Overage confirmation |
| Financial exposure | Highest | Moderate, can escalate | Mechanical, bounded |
| Escalation path | Settlement letter | Can graduate to audit | Renewal fold or order |
How the practice treats each.
The audit is handled inside the audit defense engagement. The work begins with naming the clause cited, mapping the response window onto the buyer's internal calendar, and producing a single point of communication on the buyer's side. The engagement concludes with a settlement letter the buyer signs, on a figure the buyer has had time to frame.
The review is handled inside subscription assessment, with audit defense held in reserve in case the review graduates. The work begins with the buyer's own reconciliation against deployment data, in scope to the products named. The response to Red Hat follows the reconciliation, not the other way round. Where the review does graduate, the reconciliation becomes the evidence base for the audit defense, and the buyer is not starting from a clean sheet.
The true up is handled inside renewal negotiation where the order can be folded into an upcoming renewal, and inside subscription assessment where the overage figure needs verification before the order is placed. The structural question is rarely the figure itself; it is the SKU selection and the timing relative to the renewal calendar.
Notes & references
- 1. The response window cited in a Red Hat audit letter is the window the practice has observed most frequently across the trailing twelve months, typically between twenty one and forty five days. Specific windows are set by the clause language and the jurisdiction. Buyers should not infer that the response window is uniform across all audit letters.
- 2. The co terminus order mechanic for a true up is the standard contractual procedure under most Red Hat subscription agreements in force in 2026. Buyers operating under earlier agreement vintages or under bespoke negotiated terms should confirm the specific clause language before assuming the mechanic applies.
- 3. Figures in Fig. 5.1 reflect practice observations across Red Hat correspondence handled in the trailing twelve months. Escalation paths are typical rather than exhaustive; a review can also be closed without escalation where the reconciliation matches the contract.
- 4. The 82% trailing twelve month average exposure reduction figure the practice publishes is computed across audit defenses settled in the same period. The figure is not generalised to reviews or to true ups, where the financial exposure profile differs.
- 5. The fourteen day window discussed in the companion brief refers to a frequently observed internal triage window between letter receipt and the first formal response, not to the contractually cited response deadline. The two windows interact and are sometimes conflated by buyers reading the letter for the first time.
Preparing a response? The practice keeps a one-page Red Hat audit response checklist — what to acknowledge, what to preserve, and what not to volunteer in the first fourteen days after the letter arrives.