The short answer: The BSA (the Business Software Alliance, now styled “BSA | The Software Alliance”) is an industry trade group that polices software copyrights for members like Adobe, Microsoft, and Oracle. If you got its letter, someone — usually a disgruntled employee or former employee, via the BSA’s paid tip program — told them your company is running unlicensed copies of member software. The letter asks you to self-audit within about 30 days. Do not ignore it (silence invites a federal copyright lawsuit), do not admit anything in your first reply, inventory your own licenses before you let them in, and get a software-licensing lawyer before your second communication.
This guide is educational, not legal advice — and an audit letter is not a do-it-yourself project. Our prevention companion, [The Shelfware Audit](/software/saas-shelfware-audit/), covers the annual license true-up that keeps this letter from arriving in the first place.
This guide is educational, not legal advice. Software licensing is fact-specific and contract-specific — nothing here tells you how to respond to your specific letter. A software-licensing lawyer does.
What the BSA is (and isn’t)
BSA | The Software Alliance is a Washington, D.C.-based trade group whose members are commercial software companies — per its roster, Adobe, Microsoft, Oracle, Autodesk, Salesforce, SAP, Cisco, IBM, and others are currently listed. It was founded as the Business Software Alliance and dropped “Business” from its name in 2012 (Wikipedia, verified October 2026). It is funded partly by member dues and partly by the settlements it collects.
What matters most for a small business owner:
- The BSA is not a government agency. It has no power to subpoena you, fine you, or raid your office without a court order. It is a private enforcer working for its member publishers.
- Its primary weapon is a threatening letter asking for a “voluntary” self-audit, backed by the implicit threat of a federal copyright lawsuit if you refuse.
- It concentrates on small businesses. An Associated Press analysis (published 2007, so treat it as vintage) found that of the $13 million the BSA collected in North American settlements in a single year, almost 90 percent came from small businesses. The BSA’s own explanation: that’s where the unlicensed use is most rampant. Critics’ explanation: small companies have the fewest legal resources to fight back.
That last point is the entire reason this guide exists in a small-business library. You are the target demographic.
Why you got the letter
BSA audits are rarely random. The typical triggers, in rough order of frequency:
- A disgruntled employee or former employee tipped them off. This is the big one. The BSA runs a paid whistleblower program — its U.S. reporting site (nopiracy.org-family pages) currently advertises rewards of up to $20,000 on a sliding scale, paid when a tip leads to a settlement. Robert J. Scott, a software-audit defense attorney who has represented more than 250 defendants, says a typical audit request arrives after “a tip by a disgruntled employee or former employee, often seeking to recover advertised reward money” (TorrentFreak, 2016). Layoffs, firings, and mergers are classic trigger events.
- A reseller or competitor reported you. Software resellers who suspect you’re running unlicensed copies — or a competitor looking to even the playing field — can file the same report.
- A member vendor’s own data pointed at you. Activation records, support tickets, or license-server data that show more users than licenses can route through the BSA.
The unsettling implication: the person who decides whether the letter arrives is often someone who recently stopped liking you. You can’t prevent that. You can make sure the letter, if it comes, finds nothing.
What the letter actually asks
A standard BSA letter typically:
- States that the BSA represents major software publishers and has “received information” that your company may be using unlicensed copies of member software — without naming the source.
- Asks you to conduct a self-audit of the named publishers’ software across your computers and report the results, usually within about 30 days.
- Invites you to “voluntarily” cooperate to resolve the matter without litigation.
What it is: an invitation to count your own unlicensed copies and hand them the list. The AP’s reporting on BSA tactics notes that after the audit, the BSA generally demands at least twice the retail price of the noncompliant software — and counts “unbundled” prices for suite components (your one Microsoft Office install becomes separate charges for Word, Excel, and PowerPoint), which inflates the bill further. Defense counsel has argued this unbundling misreads the law; the BSA disagrees. Either way, the number they hand you is the opening bid, not a verdict.
What ignoring it gets you: the next step is a federal copyright infringement lawsuit, where the damages exposure is far worse than any settlement demand. Engagement is necessary — but on your terms, not theirs.
The math behind the letter: why the threat works
The BSA’s leverage is federal copyright law, and the numbers are genuinely frightening:
- The infringement theory: Installing a copy of software you don’t have a license for violates the copyright owner’s exclusive rights of reproduction and distribution under 17 U.S.C. §106 (current text verified October 2026). Each title is a separate work.
- Statutory damages: The copyright owner can elect statutory damages instead of proving actual losses. Under 17 U.S.C. §504(c), a court can award $750 to $30,000 per work — and if the infringement was willful, up to $150,000 per work. Attorney’s fees can be added. (Framework confirmed via the Congressional Research Service summary, October 2026; the statute is long-standing and stable.)
- Settlement reality: Actual BSA settlements are far below statutory maximums — the BSA uses the $150,000-per-work figure as the stick that makes the settlement look reasonable. The directional shape, per a detailed December 2025 survey of software-audit demand mechanics (terms.law): retroactive licenses priced at MSRP times a 1.5–3x multiplier, plus true-up purchases to get current, plus a compliance commitment. Small-company settlements typically start around $50,000; large-company cases run into the millions. These are directional ranges, not quotes — every case is negotiated. But they explain why “most companies settle”: federal copyright litigation costs six figures before you even reach a verdict, so settling is the rational move for both sides.
One more number worth knowing: the BSA’s position, per AP reporting, is that software you can’t produce a receipt for is treated as pirated — no matter how long ago you bought it, and no matter what the certificate of authenticity says. This is why the prevention section below is really about filing cabinets.
The response protocol
If the letter is in your hand, here’s the order of operations. This is the part where a panicked first move is the expensive mistake — the letter is designed to make you panic.
1. Do not ignore it. Do not trash it.
Ignoring a BSA letter is the single worst response. The audit doesn’t go away; it escalates to a lawsuit, where every number above gets bigger. Acknowledge the letter exists. That’s all you do for now.
2. Admit nothing in writing.
Your first communication back should acknowledge receipt and say you are reviewing the matter. That’s it. Do not volunteer explanations (“some employees installed things on their own”), do not offer numbers, do not let anyone on your team email them casual assurances. Anything you write becomes the record they negotiate against. The AP documented exactly how this goes wrong: one owner told the BSA his employees had worked around licensing problems on their own — an honest explanation that became an admission of unlicensed use. (Security Info Watch, AP reprint.)
3. Preserve everything. Destroy nothing.
Put a litigation hold on all software inventory records, purchase receipts, invoices, license keys, and installation logs — immediately. Do not delete, uninstall, or “clean up” anything. Deleting records after receiving an audit letter is obstruction exposure that turns a licensing dispute into something far more serious. Deleted files also look like guilt, which they will argue.
4. Inventory your own licenses BEFORE you let them in.
You have no obligation to grant the BSA access to your systems or hand over data on their timeline. Before you agree to anything:
- Inventory installations: What’s actually on every workstation, server, and laptop?
- Gather proof of purchase: Receipts, invoices, license certificates, reseller records. Remember: no receipt, no credit — in their eyes.
- Count the gap: Installations minus licenses, by title. This is your actual exposure. Compute it yourself before they compute it for you.
- Check your contracts: Do your license agreements include audit provisions? What’s the stated scope, notice period, and methodology?
This self-audit is the single highest-value action you can take. Knowing your gap before negotiations start is the difference between bargaining from knowledge and bargaining from fear.
5. Get a software-licensing lawyer before your second communication.
This is the guide’s CTA and it’s not optional decoration. A lawyer who defends BSA audits knows the negotiation shape: challenging inflated counts, negotiating the multiplier down (the terms.law survey notes settlements can move from 3x toward 1x, especially where noncompliance was inadvertent), insisting on an NDA before any data changes hands, and limiting audit scope to the publishers the BSA actually represents. The lawyer’s fee is a rounding error next to the settlement. Do not hire your general business attorney for this unless they do software-licensing defense — it’s a specialty.
6. Negotiate the audit itself, if you agree to one.
If (on your lawyer’s advice) you proceed with an audit:
- Limit scope: only the member publishers at issue, not your entire software estate.
- Agree the methodology in writing: what tools, what counts as an “installation” (virtual machines, test environments, and unused hand-me-down PCs are classic dispute areas).
- Demand confidentiality: an NDA covering your business data before anything is shared.
- Build in dispute resolution: a process for challenging findings you think are wrong — because findings are frequently inflated.
The prevention checklist (so this never happens)
Every item here is cheaper than one settlement:
- Keep purchase receipts for all software, forever. The BSA treats no-receipt as pirated. Invoices from resellers, OEM line-items, volume-license confirmations — file them somewhere you can find in 48 hours.
- True-up license counts annually. Count installations against licenses once a year, like inventory. If you’re short, buy the licenses before anyone asks — voluntary compliance costs MSRP, not 3x MSRP.
- Clean up hand-me-downs. The most common small-business violation isn’t piracy; it’s sloppiness. An employee gets a new PC, the old one goes to the front desk with the old software still on it — and you’ve doubled your installations without noticing. Delete licensed software from retired machines, or reassign the license properly.
- Offboard properly. When an employee leaves, reclaim and reassign their licenses instead of buying new ones while the old seat quietly keeps a licensed copy alive.
- Write the policy down. A one-page acceptable-use policy — “install only approved software; IT approves purchases” — won’t win you an audit by itself, but it documents good faith and makes the sloppy-install problem rarer.
Prevention is a once-a-year habit, not a project. [The Shelfware Audit](/software/saas-shelfware-audit/) walks through the full annual software-inventory procedure — catching unused subscriptions *and* licensing gaps in the same afternoon.
Methodology
Copyright mechanics are from primary sources verified in October 2026: the exclusive-rights text of 17 U.S.C. §106 from uscode.house.gov (current as of the fetch date); the statutory-damages framework of 17 U.S.C. §504(c) ($750–$30,000 per work; up to $150,000 for willful infringement) confirmed via the Congressional Research Service’s federal remedies summary. The BSA’s member roster and its “BSA | The Software Alliance” styling are per the organization’s own public materials and Wikipedia’s member listing, verified October 2026. Settlement mechanics (1.5–3x MSRP multiplier, $50,000+ small-company floor, retroactive-license structure, response-protocol shape) are from a December 2025 practitioner survey of software-audit demand letters (terms.law) — directional, not authoritative, and presented as such. The disgruntled-employee trigger pattern is per TorrentFreak’s 2016 interview with defense attorney Robert J. Scott (250+ BSA cases). BSA’s whistleblower reward (up to $20,000 in the U.S. program) is per BSA’s own reporting pages, current October 2026. The “90% of $13M settlements from small businesses” figure is from an Associated Press investigation published in 2007 — presented with its vintage, not as a current claim. The unbundling and no-receipt-equals-pirated practices are likewise per that AP reporting. No anecdote here is a verified case study; legal mechanics are verified, outcomes are illustrative. This page is educational, not legal advice.
Sources
- 17 U.S.C. §106 (exclusive rights in copyrighted works) — uscode.house.gov, text verified October 2026
- 17 U.S.C. §504(c) statutory-damages framework — via CRS federal remedies summary, verified October 2026
- BSA | The Software Alliance — bsa.org (reporting program: bsa.org “Report Piracy” pages, reward up to $20,000 U.S., verified October 2026); member roster via Wikipedia, verified October 2026
- Software audit demand-letter mechanics (multiplier, settlement ranges, response protocol) — terms.law, December 2025 (secondary; directional)
- BSA enforcement tactics and the small-business concentration — Associated Press via Security Info Watch, published 2007 (vintage-attributed)
- Disgruntled-employee trigger pattern — TorrentFreak, 2016 interview with Scott & Scott LLP (secondary; illustrative)
Frequently asked questions
Is the BSA a government agency? Can it force me to open my office? No to both. The BSA is a private trade group. It cannot subpoena you or inspect your computers without your consent, a contract clause requiring it, or a court order. The letter asks for voluntary cooperation — the compulsion comes from what happens if you refuse (a lawsuit), not from any authority the letter itself carries.
I got the letter but I think we’re compliant. Can I just ignore it? No. Even if you’re fully licensed, ignoring the letter escalates the matter toward litigation, where you’d spend real money proving what you could have demonstrated in a cooperative process. Respond (briefly, through counsel), run your own inventory to confirm compliance, and then you can resolve it from strength.
How much is this going to cost me? Honest answer: it depends entirely on the gap your self-audit finds. Directionally, practitioner reports describe small-company settlements starting around $50,000, structured as retroactive licenses at 1.5–3x MSRP plus true-up purchases. Federal litigation, the alternative, costs six figures in defense fees alone — which is why almost everyone negotiates. A software-licensing lawyer gives you a case-specific range after seeing your inventory.
Can they really count a copy I legitimately bought? If you can prove you bought it — with a receipt or invoice — generally no. That’s the entire game: the BSA’s default position is that undocumented software is unlicensed software. Your purchase records are your defense, which is why the prevention section starts with receipts.
Do I actually need a lawyer, or can I handle this myself? You need a lawyer — specifically one who defends software audits, not your general business attorney. The negotiation turns on licensing-arcana (unbundled suite pricing, what counts as an “installation,” multiplier arguments) and procedural protections (NDA, scope limits, dispute mechanics) that generalists don’t practice daily. The fee is small relative to the settlement at stake.
My employees installed software without approval. Am I still liable? Your company is generally responsible for what’s installed on company machines — “my employees did it” is an explanation, not a defense, and putting it in writing to the BSA just admits the unlicensed copies exist. This is exactly the situation where you stop talking and let a lawyer handle the narrative.
How do I make sure I never get this letter again? Annual license true-ups, permanent purchase records, hand-me-down cleanup, and a one-page installation policy. The Shelfware Audit covers the procedure.