Microsoft Audits Hosting Providers Every Other Year Now, and Most Have No Governance Plan

Man looking anxiously through a window, representing the risk of facing an SPLA audit unprepared

Summary

SPLA audits now reach nearly half of Microsoft’s hosting providers within any given year, according to SAMexpert’s State of SPLA 2026 survey, a rate higher than the researchers expected to find. Only 15% of providers run SPLA as a dedicated function, and 47% have no audit governance plan at all, with a further 17% working from one that’s out of date. SAMexpert’s Alexander Golev and Daryl Ullman find that the providers reporting the highest confidence often have the least ability to prove their compliance position, and that the largest SPLA budgets sit with the least controlled providers. The survey’s warning extends past SPLA: any licensing obligation handed to a team with a bigger remit ends up with the same diffuse ownership and untested plan.

Microsoft audits its hosting providers far more often than the market assumes. In SAMexpert’s State of SPLA 2026 survey, 45% of respondents reported that their last SPLA audit or license verification took place within the previous twelve months. That is nearly half the sample inside a single year, and a higher rate than SAMexpert expected to find.

Just under half of respondents describe themselves as managed service providers or systems integrators, and around a third as hosting providers running IaaS or PaaS. SPLA is the Services Provider License Agreement, the route Microsoft offers providers who host its software for customers and report usage monthly rather than buying entitlements up front.

Key takeaways

  • Nearly half of service providers surveyed were audited or verified within the past twelve months, putting SPLA audits on a biennial cycle rather than treating them as rare events.
  • Only 15% run SPLA as a dedicated function. For everyone else, it sits with software asset management (SAM), licensing, or IT operations, alongside a larger job, or with no one in particular.
  • 47% have no audit governance plan, and a further 17% are working from an out-of-date one.
  • Half lack a purpose-built reporting tool, and a governance plan without a way to measure deployment does not provide defensible confidence.
  • The largest SPLA budgets sit with the least controlled providers, and manual billing hides both unbilled revenue and unreported usage until an audit surfaces them.

The rest of the survey describes what the SPLA audits find.

SPLA ownership sits with whoever is closest to it

Only 15% of respondents have a team dedicated to SPLA. A third place it with the software asset management or licensing team, and almost as many with IT operations, both of which carry it on top of much larger remits. The remaining fifth describe ownership as shared or ad hoc, with no single function accountable.

Alexander Golev, SAMexpert’s founder and CEO, reads that as a rational choice rather than negligence. SPLA is a specialist field, and most providers cannot justify a full-time team for something sitting at the edge of the business, so it gets handed to whoever is closest. The arrangement works, in his words, “until the complexity of SPLA outgrows the attention anyone can spare for it,” which is usually the point at which something has already gone wrong.

Daryl Ullman, SAMexpert’s chief negotiation officer, puts the same finding against what providers say about strategy. Elsewhere in the survey, most respondents call SPLA either a strategic enabler or a core business driver. Very few staff it that way. When responsibility is shared or parked with a team whose real priorities lie elsewhere, audit readiness belongs to no one until an SPLA audit forces the question. Daryl’s remedy is a single named owner with authority across both the commercial and technical sides, which he calls the cheapest structural improvement that most providers can make.

Anyone who has watched an ITAM function assembled from goodwill and part-time attention will recognize the shape of the issue. License compliance results in several contributors and no owner.

Nearly half the market has no governance plan at all

47% of respondents handle SPLA audit governance on an ad hoc basis without a plan. A further 17% have an out-of-date plan. 28% maintain one that is current and tested.

Whether a provider keeps a plan aligns with two other survey answers: how confident it is in its compliance position and whether it can measure its own usage. Providers with a current, tested plan report strong confidence almost without exception, and providers operating in an ad hoc manner account for nearly all the reported doubt. Providers with no purpose-built reporting tool are, with very few exceptions, the same providers with no plan. Where a tool is present, governance varies widely. Where no tool is present, a current and tested plan is seldom documented.

Alexander’s point is that the plan and the tool work together or barely at all, because a plan that cannot be checked against real deployment can only take a provider so far. The providers with a tested plan and no way to measure usage are about as likely to doubt their position as to trust it. Defining who owns the plan and how often it gets tested is standard ITAM best practice.

Managed service providers come out of this section worst. Among managed service provider and systems integrator respondents, outdated governance plans are more common than in any other business model, and reported compliance confidence is the weakest among the two main provider types. Hosting providers, whose licensing exposure is more obviously central to what they sell, report a stronger position on both counts.

Owning a tool is not the same as having visibility

Half of respondents have no purpose-built SPLA reporting tool. 32% have built their own, which is the largest single group, and only 17% use a commercial third-party product. The rest work from raw virtualization or operating system platform data, or consolidate everything by hand.

Whether a tool helps depends less on owning one than on what it was built to do and how it is configured. Platform data was never designed to answer licensing questions. An internally built tool covers the situation it was written for and sees less of whatever falls outside that as the estate grows. A purchased tool left half-configured carries the same weakness. What determines whether usage is measured correctly is whether the tool and the process around it account for everything the provider has deployed.

Daryl calls tooling the clearest divider of compliance confidence in the survey. Almost every provider using a commercial tool reported strong or moderate confidence in its SPLA compliance position, with a single exception reporting lower confidence. Among providers with nothing purpose-built, confidence spread much more widely, reaching into outright uncertainty. Daryl stops short of calling this “cause and effect,” though it matches what he sees in client work, where nobody feels secure about a position they cannot measure.

The providers who should worry are the confident ones

Alexander’s concern is not with the providers reporting doubt. It sits with the small group reporting high confidence, yet with no way to measure what an SPLA auditor would find. Their confidence has nothing behind it they could show anyone.

At the audit frequency recorded in this survey, this group is likely to be asked for evidence it cannot provide. Daryl frames the cost of that. A provider that cannot produce its own numbers has nothing to put against the auditor’s findings, and arguing after the fact is expensive.

The SPLA gap has a price attached

SPLA is a substantial monthly cost for most of these providers. Around a third spend $150,000 or more a month, and only 17% spend under $10,000.

SAMexpert also cross-checked that group against the governance answers. Among respondents spending $150,000 or more each month, most conduct audit governance on an ad hoc basis and have no purpose-built reporting tool. The largest SPLA budgets are held by providers with the least control over them.

Where the money leaks is visible in how providers bill. A third bill customers on contracted capacity at a fixed fee. Among those billing on measured usage, manual reporting and spreadsheets together account for more than automated tracking does. Both routes depend on data pulled from the IT department, which may be incomplete or out of date, and on someone interpreting it correctly, which requires specialist knowledge that is uncommon.

Under a fixed-capacity contract, anything deployed beyond the agreed ceiling is delivered without charge. On a contract meant to flex with usage, consumption that goes untracked is never invoiced. Alexander’s warning covers what happens after that. The same people usually produce both the customer’s bill and the figure reported to Microsoft, so the two agree. Nothing looks wrong until an audit reconstructs what was deployed, and the usage nobody recorded shows up as a penalty.

None of this is unique to SPLA

The survey looks at one Microsoft licensing program, though the pattern it describes is not confined to SPLA. Any asset or licensing obligation bolted onto a team with a bigger remit ends up with diffuse ownership, an aging plan, no reliable measurement behind it, and the first proper test comes from outside the organization. Vendor audits are a predictable demand on an IT function, and they can be planned for like any other recurring demand, with an owner, a tested process, and data that somebody trusts.

SPLA FAQs

What is SPLA?

SPLA stands for the Services Provider License Agreement, the route Microsoft offers to providers who host its software for customers and report usage monthly rather than buying entitlements up front.

How often does Microsoft audit SPLA providers?

SAMexpert’s State of SPLA 2026 survey found that 45% of respondents had their last SPLA audit or license verification within the previous twelve months, putting audits on a close-to-biennial cycle, a higher rate than the researchers expected to find.

Who typically owns SPLA compliance inside a provider?

Only 15% of respondents have a dedicated SPLA team. About a third place it with software asset management or licensing, almost as many with IT operations, and the rest describe ownership as shared or ad hoc, with no single function accountable.

Why does shared or ad hoc SPLA ownership create risk?

Alexander Golev, SAMexpert’s founder and CEO, describes it as a rational choice that works only until SPLA’s complexity outgrows the attention anyone has left to give it, usually the point at which something has already gone wrong. Daryl Ullman, the firm’s chief negotiation officer, points out that most providers call SPLA a strategic priority but rarely staff it that way, so audit readiness belongs to no one until an audit forces the question.

How many providers have an SPLA audit governance plan?

47% handle governance on an ad hoc basis with no plan at all, a further 17% work from an outdated plan, and 28% maintain one that’s current and tested.

Does having a governance plan guarantee compliance confidence?

Not on its own. Providers with a current, tested plan report strong confidence almost without exception, but a plan without a way to measure real deployment only goes so far. Alexander Golev found that providers with a tested plan and no measurement tool are about as likely to doubt their compliance position as to trust it.

Do most SPLA providers have a purpose-built reporting tool?

No. Half have none. 32% have built their own tool, the largest single group, and only 17% use a commercial third-party product. The rest rely on raw platform data or manual consolidation.

Which providers should be most concerned about an SPLA audit?

According to Alexander Golev, it’s not the providers reporting doubt about their position. It’s the smaller group reporting high confidence with no way to measure what an auditor would actually find, since that confidence has nothing behind it they could show anyone.

How much do providers typically spend on SPLA?

Around a third spend $150,000 or more a month, and only 17% spend under $10,000. Among the highest spenders, most conduct governance on an ad hoc basis and have no purpose-built reporting tool, meaning the largest budgets are held by the providers with the least control over them.

Is this pattern specific to SPLA?

No. The survey covers one Microsoft licensing program, but SAMexpert notes the same pattern shows up wherever a licensing obligation gets bolted onto a team with a bigger remit: diffuse ownership, an aging plan, no reliable measurement, and the first real test coming from outside the organization.

Sophie Danby
Sophie Danby

Sophie is a freelance ITSM marketing consultant, helping ITSM solution vendors to develop and implement effective marketing strategies.

She covers both traditional areas of marketing (such as advertising, trade shows, and events) and digital marketing (such as video, social media, and email marketing). She is also a trained editor.

Want ITSM best practice and advice delivered directly to your inbox? Why not sign up for our newsletter? This way you won't miss any of the latest ITSM tips and tricks.

nl subscribe strip imgage

More Topics to Explore

Leave a Reply

Your email address will not be published. Required fields are marked *