Forscope

How to verify the origin of secondary software and what an independent auditor's report proves

This article explains how to safely verify the origin of secondary software and what an independent auditor's report delivers. Discover how to ensure legal certainty when purchasing licenses, protect the seller's sensitive business data, and streamline approval processes without forwarding stacks of historical contracts.

The first company wants to sell software it no longer needs. The second wants to buy it, but needs proof of its origin. At the same time, the first company does not want to send its historical contracts and commercial data to every subsequent customer. The second company cannot settle for the phrase "everything is fine." An independent auditor's report can help both. However, its value lies neither in the stamp nor in the title of the document, but in the work that actually stands behind it.

Imagine a company that has changed its IT environment. It no longer uses a portion of its software licenses and would like to sell them to raise funds for further investments. It has the documentation for their acquisition, but also an understandable reservation: it does not want its contracts, former purchase conditions, and company name to start circulating uncontrollably among other companies.

On the other side stands a new customer. They are looking for savings, not a problem that will only become apparent during an audit. They need to know what they are buying and on what basis they can trust the software.

These interests are not contradictory. However, they require more than forwarding a folder of documents or an assurance from a salesperson. They require a way to preserve the verifiability of origin while simultaneously limiting the unnecessary spread of sensitive information.

Working software is still not a guarantee

With software, it is easy to mistake technical functionality for authorization to use. The program installs, accepts a key, and starts working. However, the activation key itself is not the same thing as a license. The consumer portal of the Bavarian Ministry of Consumer Protection explicitly points out this difference when it states that a product key must be linked to a valid license (Verbraucher Bayern).

And the same approach applies to other European markets. The legal basis of the European market for used software rests on a judgment of the Court of Justice of the European Union (curia), which confirmed back in 2012 that under specified conditions software can be resold, including software originally obtained via internet download.

However, the circumstances of the first placement on the market are essential. These state that resale may concern software that was first sold in the European Union by the manufacturer or with its consent and with a right of use for an unlimited period. At the same time, the original owner must render their copy unusable upon sale and stop using it, and it is also not possible to divide a single license for multiple users and sell only its unused part. Therefore, this is not a general permission to resell any key that is found.

For the buyer, a practical question arises from this: how to prove that their specific purchase meets the relevant conditions. The answer begins with documentation. However, it should not end with the mere statement that some documents exist.

Originals are the basis. Verifying them is additional value

At Forscope, we have previously offered secondary market software with complete documentation. We are now expanding our offering to include an option with a report from an independent auditor who saw the original documents, checked them, and recorded the result of their work.

The purpose is not to replace real evidence with a new document. The purpose is to add an independent check to the existing documentation and hand the result over to the customer.

The difference can be demonstrated in a simple situation. The buyer receives several contracts, invoices, and statements. They have the background documents, but they still need to understand how they relate to each other, which licenses they concern, and whether there is any contradiction between them. The mere handover of documents does not yet say who verified their continuity and connection.

If this continuity is part of the work of an independent auditor, the customer gains an additional verification step that is not performed solely by the seller itself. Such a review can draw attention, for example, to discrepancies in product designations, numbers of licenses, or the identification of individual transfers. The benefit, of course, depends on the actual scope of the audit performed.

The benefit lies not just in a smaller quantity of documents, but also in the activity performed over them by someone independent.

The word "audit" itself does not verify anything

It is right here that an important line is drawn between an independent auditor's report and a document issued by the trader itself.

A seller can act honestly and thoroughly check its goods. However, a confirmation issued by it remains merely its own statement. Writing "audit report" in the header does not change the author or the nature of the check performed. Such a document cannot be confused with the result of work by an independent third party.

A past German court judgment from 2013 (JurPC) shows that this is not a matter of mere semantics. In it, the Federal Court of Justice dealt with a notarial certificate according to which the notary received a declaration from the original buyer regarding the ownership of licenses, payment of the price, and termination of their use. The court pointed out that such a certificate does not in itself prove that the original buyer actually rendered their copies unusable. What mattered was what the document proved, not merely who issued it.

This case is not a rejection of independent verification. It is a warning against confusing a confirmed statement with the verification of fact.

A trustworthy report should therefore make it possible to ascertain who issued it, which licenses it concerns, what documents were submitted, and what exactly was the subject of the audit. It is equally important that its origin can be verified directly with the issuer. Not only the software documentation deserves verification, but also the claim itself that someone independent checked it.

Transparency does not mean sending around someone else's archive

Another benefit relates to information that is associated with the licenses, but which a new customer does not necessarily need to require in every routine purchasing decision.

Historical contracts and records may contain prices, contact details, signatures, or information about business relationships. Forwarding them en masse means that along with proving the software's origin, details about the previous owner are also spread.

A model with an independent auditor allows these two things to be better separated. The auditor works with the original documents, while the customer receives a report on the performed check. The identity of the former owner and the contents of their business archive do not have to be an automatic part of every regular delivery.

For a company selling licenses, such discretion can be essential. Not because there is anything inappropriate about selling unused software, but simply because it may not want its name to become part of the commercial materials of other entities or its former purchases to be evaluated by every subsequent recipient of the documentation.

However, protection of confidentiality must not mean an opaque origin. A well-set-up process is meant to limit the routine dissemination of sensitive data, not to make it impossible to substantiate them when actually necessary. Discretion and traceability should not be mutually exclusive.

Instead of unraveling documents, here is a clearer basis for decision

A third advantage can be simpler work on the customer's side. Imagine that a purchase is being evaluated by an IT department, a buyer, and an internal lawyer. Each needs slightly different information, but all must understand how the delivered documentation relates to a specific order. If they only receive a set of historical documents without an explanation of their continuity, everyone may have to start over from scratch.

A well-prepared report offers a common starting point. It allows focusing on the identified licenses, the described scope of the check, and specific findings. It can thus limit repetitive inquiries and facilitate the transfer of information between people who approve the purchase or inspect it later.

This does not mean that the company does not have to read anything or that the auditor will solve all questions for it. It means that it does not have to reconstruct the whole story from individual attachments every single time.

Clarity, however, must not come at the expense of concealing the terms of use. The mentioned German judgment also emphasizes the importance of the new acquirer receiving, in a suitable manner, the information necessary to determine the permitted use of the program. An origin report therefore cannot leave the customer in uncertainty about what they are actually allowed to use and to what extent (JurPC).

Discretion can also open the way to buyouts

The same principle can also help companies that have so far only been considering selling unused licenses.

If their primary concern is the uncontrolled spread of original documents, independent verification combined with controlled access to the records can remove one of the obstacles. The company can prove the necessary facts without its entire purchasing archive having to travel with every subsequent delivery.

This is also important for the software buyout service that Forscope offers. Alongside the economic sense of the transaction, the manner of handling documentation and the seller's identity can be part of the decision-making process.

Documents have not disappeared. The way they are handled has changed

An independent auditor's report is not a universal confirmation that removes the need for all other evidence. Its conclusions and findings apply within the scope of the work performed. It cannot fix a missing authorization or retroactively create documentation that does not exist.

Therefore, this model only makes sense when the original documents are preserved, can be assigned to specific licenses, and it is clear in advance how they will be made available in justified cases. A customer should not have to wait until an audit to find out who holds the documents and whether they can access them at all.

With such a setup, the report can connect what the mere handover of originals does not automatically guarantee: an independent check, an understandable result, and more sensitive handling of the original owner's information.

At Forscope, we therefore do not view the audit variant as a step back from documentation, but as a logical way to build upon it further. The origin of the software should remain provable, the customer should understand what they are buying, and the former owner should not unnecessarily lose control over their commercial data. Trust when purchasing software should not depend on how convincing a seller's promise sounds. It should rest on the supporting evidence, on the work performed, and on the ability to verify both.