Chapter 10. Preparing for an Audit as the Acquirer
As the acquirer, you need to take action and make decisions before commissioning an audit, and there are additional obligations after receiving the results.
10.1 Choose the Audit Model and Auditor That Fit Your Needs
As discussed earlier, three main audit methods are available, and you need to decide which one best fits your specific situation.
10.2 Understand What Matters to You
A source code audit report can provide a substantial amount of information depending on the complexity of the code scanned. It is important to identify which licenses and use cases are considered significant.
10.3 Ask the Right Questions
An open source audit report provides a great deal of information about the target company’s source code and its associated licenses. However, clarifying or confirming compliance-related concerns requires further investigation into a number of other data points. This section summarizes what matters and offers a set of questions as a starting point for framing the questions to raise with the target company.
- Has the target company used code under a license that could jeopardize the target’s or the acquirer’s intellectual property (IP)?
- Are there any code snippets of unknown origin or unknown license?
- Are the target company’s open source compliance practices sufficiently mature and comprehensive?
- Does the target company track known vulnerabilities in its own open source components?
- When distributing its products, does the target company provide all the materials needed to satisfy open source license obligations (written offers, all required notices, and source code where applicable)?
- Does the target company’s compliance process keep pace with its development speed, so that it can meet product release schedules?
- Does the target company have a process in place to respond to source code requests in a timely manner?
10.4 Identify Items to Resolve Before Deal Execution
In some cases, an open source audit may reveal instances of licenses or compliance practices that are unacceptable to the acquirer. In such cases, the acquirer can request that these instances be mitigated as a condition of closing. For example, the target company may use a code component provided under License A, while the acquirer has a strict policy prohibiting the use of any source code licensed under License A. In such situations, both sides need to discuss the matter and find a possible resolution.
10.5 Develop a Post-Acquisition Compliance Improvement Plan
Developing a compliance improvement plan is especially important when the acquirer is a large company acquiring a small startup that will continue to operate as a subsidiary. In such situations, the acquirer often helps the target company establish formal compliance policies and processes, provides training on its own practices, and offers ongoing guidance and support.