Received Audit Letter
It is not always what is true, it is often what can be proven and seen from the data that wins. Generally the best data wins.
Build the core cross functional team
Build a core cross functional audit response team usually involving stakeholders from IT, Procurement, Legal and other business units depending on the nature of the software.
Seek specialized external help
You are outclassed from the start of the audit. Auditors have unpublished rules for interpreting data. Auditors are extremely specialized because they do this all the time and have access to a warehouse of details. If you receive the audit letter don't feel embarrassed to seek external help early in the process.
Perform an internal health check to understand and optimize your risk
Before sending any data to the customer you should get a through understanding of your software deployments and entitlements. Perform an internal health check on your SAM tools because they might be incomplete or reporting false positives. There are many avenues available to you to optimize your real estate before receiving the bill from the software vendor. Determine your risk and where allowed to make remediations before submitting the data to the auditors.