Insights · Audit defense · Issue I, MMXXVI.

The audit clock, phase by phase.

How long Red Hat audits take. Five phases, observed durations across the practice's trailing twelve months, and what materially stretches or compresses the clock at each phase.
By The Buyer-Side Desk, an independent advisory practice. 190+ engagements, $180M+ recovered. Published
Abstract

A Red Hat audit looks short from the outside and long from the inside. The practice's reading across the trailing twelve months is that a Red Hat audit settled by the practice runs roughly four to nine months end to end, and the variance across that range is the customer's posture rather than Red Hat's process. This note breaks how long Red Hat audits take into five phases, sets out observed durations at each, and identifies the levers that stretch or compress the clock.

§ 1

The five phases.

How long Red Hat audits take depends on which phase the audit is in. A Red Hat audit is not a single event. The audit is a sequence of five phases that each have their own clock, their own gating, and their own posture work. The practice's reading is that customers who treat the audit as a single event are surprised at almost every phase boundary; customers who treat the audit as a sequence are not.1

The five phases are notice, evidence, finding, response, and settlement. Each opens with a Red Hat action and closes with a customer action or vice versa. The figure in § 2 sets out observed durations across recent audit defenses settled by the practice. The intent of the figure is not prediction; it is calibration. A customer who is two months into the response phase has a different posture from a customer who is two months into the notice phase, even though both have been under audit for the same elapsed time.

The note on the fourteen day response window treats the operational compression of the earliest moments of phase one. The present note steps back to the full arc of phases one through five.

§ 2

Observed durations, twelve defenses.

Across the twelve audit defenses settled by the practice between July 2025 and April 2026, the durations of each phase varied significantly. The figure below sets out the observed range for each phase. The range is calibration data only; a particular audit will sit somewhere inside the range depending on the customer's posture and Red Hat's escalation cadence.

Fig. 2.1 · Observed phase durations, twelve audit defensesRHLA · 2026 Q2
PhaseObserved rangeMedian
1 · Notice and acknowledgement10 to 21 days14 days
2 · Evidence gathering30 to 90 days55 days
3 · Initial finding from Red Hat20 to 45 days after evidence30 days
4 · Response and counter analysis30 to 75 days45 days
5 · Settlement negotiation and close30 to 90 days55 days
Total end to end4 to 9.5 months6.5 months
Phase durations observed across twelve recent Red Hat audit defenses. The range reflects customer posture variance more than Red Hat process variance. The median is the most common outcome but is not the expected outcome for a particular case until the case posture is read.

The settled audits in the practice's sample averaged roughly six and a half months end to end. The shortest closed inside four months; the longest sat at nine and a half months at the cutoff. None settled before three months. Customers who entered the audit with current entitlement records and a clean Insights inventory ran shorter; customers who entered with reconciliation work outstanding ran longer because the reconciliation work could not be skipped, only deferred.

§ 3

What stretches the clock.

The three factors that most reliably stretch a Red Hat audit are reconciliation debt, response fragmentation, and settlement language disputes. Each is set out below.2

Reconciliation debt is the gap between the customer's entitlement records and the customer's deployment estate at the moment the audit notice arrives. The gap must be closed inside the response phase, which means reconciliation work that should have been done across years has to be done in weeks. The work cannot be skipped; the audit team will not accept a response that does not reconcile entitlement against deployment. Customers with material reconciliation debt regularly add thirty to sixty days to the response phase.

Response fragmentation is the pattern where the customer's response is constructed by multiple voices on multiple timelines. The platform team sends one document; the procurement team sends another; the account team conveys a third version informally. The audit team reads the fragmentation as inconsistency and treats inconsistency as a request for further evidence. Customers with fragmented response posture regularly add fifteen to thirty days at the response phase boundary.

Settlement language disputes happen when the customer reaches commercial agreement with Red Hat but the settlement letter contains language that opens new questions. Release scope, indemnification, audit waiver, payment terms. Each can extend the settlement phase by two to four weeks. The note on reading the settlement letter treats the language question directly.

"We thought the audit was a quarter long matter. It took seven months end to end, and the seven months ran in parallel with the renewal. Knowing the duration ahead would have changed how we sequenced the contract calendar."
Testimony of record. Head of IT Procurement, regional bank.
§ 4

What compresses the clock.

The three factors that most reliably compress a Red Hat audit are clean inventory at notice, single channel response, and pre staged settlement language. Each is set out below.

Clean inventory at the moment of notice means the customer can produce its own deployment estate within ten business days. The customer's reconciliation is current; the customer's Insights or Satellite inventory matches the customer's own records; the customer's contract owner can hand the audit team a complete view of the deployment estate without doing the reconciliation work inside the audit. Customers with clean inventory at notice routinely close the audit inside five months.3

Single channel response means one voice from the customer to the audit team, one document, one timeline. The contract owner is the only customer voice on record; the platform team, the procurement team, and the executive sponsor route through the contract owner. The audit team reads consistency and stops asking for further evidence. Customers with single channel response routinely shorten the response phase by twenty to thirty days against the median.

Pre staged settlement language means the customer has prepared its preferred settlement language in advance, including its preferred release scope, audit waiver duration, and payment terms. When Red Hat sends the first settlement draft, the customer's redlines are ready within days rather than weeks. The settlement phase closes faster because the language exchange runs on the customer's pace rather than Red Hat's. The companion note on settlement negotiation leverage treats the leverage points the pre staged language captures.

§ 5

What the durations are useful for.

Knowing how long Red Hat audits take is useful for two purposes. The first is calendar planning. Customers who model the audit as a six month engagement budget their internal time correctly; customers who model the audit as a quarter consistently underestimate. The internal time cost on the customer side is roughly fifteen to twenty five hours per week for the contract owner across the duration; engagements run alongside, not instead of, the regular contract management workload.

The second is renewal sequencing. The audit timeline frequently collides with the renewal cycle, and the collision is the lever that converts audit findings into renewal damage. Customers who see the audit duration ahead can schedule renewal negotiations either before the audit begins or after the audit settles, and avoid the worst case where renewal opens with audit findings on the table. The note on migration timing versus renewal cycle treats a related sequencing question.

If the audit notice is in hand and the clock has started, the first useful hour is a call with the practice to read the phase the audit is currently in and the duration the response is likely to require. The note on Red Hat audit defense as a service sets out the engagement protocol; the present note treats the duration question that sits inside that protocol.

Notes & references

  1. 1. Phase boundaries. The five phase model is the practice's working model across recent Red Hat audit defenses. Red Hat does not formally publish a phase model; the boundaries are inferred from observation across the practice's engagements.
  2. 2. Reconciliation debt. Across twelve recent defenses, customers with material reconciliation debt at notice averaged seventy days in the response phase against the practice median of forty five. Customers with clean reconciliation at notice averaged thirty five days.
  3. 3. Inventory currency. Customers who registered their Red Hat estate comprehensively with Insights or Satellite and reconciled monthly were able to produce a clean inventory at notice. The operational discipline outside audit translates directly into duration compression inside audit.

Preparing a response? The practice keeps a one-page Red Hat audit response checklist — what to acknowledge, what to preserve, and what not to volunteer in the first fourteen days after the letter arrives.

§ 6 · Engagement

Engage before the clock works against the response.

Two analyst calls. No fee. We tell you which phase the audit is in, the duration the response is likely to require, and what compresses the clock from here. If the audit notice is in hand, the first call happens within twenty four hours.