A stock licence audit request lands in your inbox on a Tuesday morning, and suddenly every team member is scrambling through Shutterstock dashboards, old Slack threads, and shared Google Drives looking for proof that the agency actually paid for the images in last quarter's campaigns. The scramble costs hours, stresses the team, and exposes gaps nobody knew existed. This guide walks through exactly how to build an audit-ready licence archive so the next request gets answered in minutes, not days.

person using computer office
Photo by Ketut Subiyanto from Pexels
TL;DR:
  • A stock licence audit requires you to prove that every asset used in client work was properly licensed at the time of use.
  • Preparation means building a central repository, standardizing file naming, and running internal audits on a quarterly cycle.
  • Agencies that stay audit-ready cut compliance response time dramatically and avoid costly legal exposure.

Why audits happen to agencies

Stock platforms like Shutterstock, Adobe Stock, Getty/iStock, and Envato reserve the right to audit commercial licensees. So do clients. A brand's legal team might request full licence documentation before renewing a retainer. An acquiring company might demand it during due diligence. And copyright holders themselves sometimes flag usage through automated image-matching tools.

The trigger does not matter. What matters is whether you can respond with organized, verifiable proof. Agencies that handle hundreds of assets per month across multiple platforms and multiple client accounts face a unique challenge: the licence trail is fragmented by default.

0%
of agencies lack a centralized licence archive

That number is not surprising when you consider how stock platforms work. Each one stores licence records differently. Shutterstock provides downloadable CSV logs. Adobe Stock ties licences to Creative Cloud accounts. Envato Elements generates a licence certificate per download. Freepik buries proof inside account history. When your team uses three or four of these platforms simultaneously, the records live in three or four separate silos.

Key takeaway: Audit readiness is not a one-time project. It is an ongoing process built into how your agency handles every stock asset from the moment of download.

What auditors actually request

Before you can prepare, you need to know what a stock licence audit typically asks for. The documentation requirements vary by platform and by the requesting party, but they generally fall into a consistent pattern.

Core documents auditors expect:

  1. Licence certificate or receipt for each asset, showing the licence type (Standard, Extended, Editorial, etc.)
  2. Proof of the licensee matching your agency or the specific client account
  3. Date of purchase/download to confirm the licence was active when the asset was used
  4. Usage context showing where and how the asset appeared (campaign name, client, deliverable)
  5. Platform account details confirming the subscription or credit pack that covered the download
"The assessment includes a review of the design and implementation of key internal controls over financial reporting, including the adequacy of staffing and appropriate segregation of duties."
>, Preparing for a Successful IPO: What CFOs Need to Know

That quote comes from financial audit preparation, but the principle applies directly to licence audits. Internal controls, clear ownership, and separation of responsibilities are exactly what makes the difference between a smooth audit and a painful one.

Pro tip: Keep a mapping between each asset's platform ID (e.g., Shutterstock image ID 2184759321) and the client project it was used in. This single link is the most valuable piece of metadata during an audit.

How to compile documentation

person organizing documents
Photo by cottonbro studio from Pexels

Gathering licence documentation after the fact is painful. Gathering it as part of your daily workflow is almost effortless. Here is the step-by-step approach that works for agencies processing dozens or hundreds of assets weekly.

Step 1: Inventory your platforms. List every stock platform your agency uses. Include team accounts, individual accounts held by freelancers, and any legacy accounts from past employees. Common ones: Shutterstock, Adobe Stock, iStock/Getty, Envato Elements, Freepik, Canva Pro, Depositphotos.

Step 2: Export existing records. Log into each platform and download whatever licence history is available. Shutterstock offers a download history CSV. Adobe Stock shows licence history in the Libraries panel. Envato Elements lets you re-download licence certificates. For platforms that do not offer bulk export, a tool like Licence Downloader can pull certificates across multiple platforms in one batch.

Step 3: Standardize file naming. Every licence file should follow a consistent naming convention. A pattern like [Platform]-[AssetID]-[ClientCode]-[Date].pdf works well. Example: shutterstock-2184759321-ACME-20260415.pdf.

Step 4: Tag with project metadata. Each licence record needs to be linked to the project it served. Use a simple spreadsheet or your project management tool (Monday, Asana, Notion) to maintain this mapping.

Step 5: Verify completeness. Cross-reference your download history against your project asset lists. Flag any gaps where an asset was used but no licence record exists.

Documentation completeness after first pass
0%

Most agencies find they can account for about 85% of their assets on the first pass. The remaining 15% usually involves assets downloaded by freelancers on personal accounts, assets from cancelled subscriptions, or assets pulled from free tiers where licence proof is harder to locate.

Build a central repository

A central repository is not a fancy tool. It is a single, agreed-upon location where every licence file lives. The specifics depend on your agency's stack, but the principles are universal.

Option A: Cloud folder structure. Create a top-level folder called Licence Archive in Google Drive, Dropbox, or SharePoint. Inside, organize by year, then by client, then by platform. Every licence PDF goes into the matching folder.

Option B: DAM integration. If your agency uses a Digital Asset Management system (Bynder, Brandfolder, Canto), attach licence certificates as metadata to each asset. This keeps the proof physically linked to the file it covers.

Option C: Dedicated compliance tool. Tools built specifically for licence management, including Licence Downloader, can serve as the repository themselves, automatically organizing certificates by platform, date, and asset ID.

Whichever option you choose, enforce two rules:

  • Single source of truth. Licence files exist in the repository and nowhere else. No desktop folders, no email attachments treated as the "real" copy.
  • Access control. At least two people (not one) should have admin access. When someone leaves the agency, their access transfers cleanly.
Here is a visual overview of how the full audit preparation process connects:
Preparing Your Agency for a Stock Licence Audit process
Figure 1: Preparing Your Agency for a Stock Licence Audit at a glance.

The flow moves from Inventory Platforms through Export Records, Standardize Naming, Tag Metadata, Verify Completeness, and finally into the Central Repository. Each step feeds the next, and the repository becomes the single point auditors interact with.

Establish an internal audit cycle

freelance designer working laptop
Photo by Anna Shvets from Pexels

Collecting documentation once is a start. Keeping it current requires a recurring internal audit. Quarterly works well for most agencies. Monthly is better if you process more than 500 assets per month.

What an internal audit covers:

  1. New assets check. Pull download logs from every platform for the quarter. Confirm each download has a corresponding licence file in the repository.
  2. Freelancer reconciliation. Verify that any assets downloaded by external contractors have been transferred to the agency's archive with proper licence documentation.
  3. Subscription status. Confirm all platform subscriptions are active. A lapsed Envato Elements subscription, for example, does not retroactively revoke licences for assets downloaded while active, but you need proof the subscription was active at download time.
  4. Client offboarding. When a client relationship ends, archive their licence folder and note which assets were delivered. This prevents confusion if a question arises years later.
  5. Gap report. Document any assets where licence proof could not be located. Decide whether to re-licence, replace, or accept the risk.
0x
faster audit response with quarterly reviews

Agencies that run quarterly internal audits consistently report responding to external audit requests about four times faster than those that compile documentation only when asked.

Warning: Do not assume that "we have a subscription" equals "we have proof." Platform subscriptions can be cancelled, accounts can be deleted, and download histories can be purged. The licence certificate PDF in your repository is the only reliable proof.

The following interactive card summarizes what a healthy audit-readiness dashboard looks like for a mid-size agency processing around 200 stock assets per month across three platforms:

Audit Readiness Dashboard (Example)

Licences archived this quarter 587 / 612
Coverage rate 95.9%
Gaps flagged for review 25
Freelancer assets reconciled 100%
Platforms connected 3 of 3
Last internal audit 2026-06-28
Lapsed subscriptions 1 (Envato, cancelled May)

Real-world audit preparation

Consider a 25-person digital marketing agency running campaigns for eight clients. They use Shutterstock (team plan, 750 downloads/month), Adobe Stock (integrated with Creative Cloud), and Envato Elements (single seat used by the motion graphics team). Two freelance designers also download assets on their own Freepik accounts.

Before implementing a structured process, an audit request from their largest client took 11 business days to fulfill. The ops lead had to contact every designer individually, dig through email receipts, and manually screenshot download histories from three platforms.

After building a central Google Drive repository, standardizing naming, and running quarterly internal audits for two quarters, the same type of request now takes less than a day. The ops lead exports the client folder from the repository, cross-references it against the project tracker, and sends a ZIP file with every licence certificate organized by campaign.

The key changes that made the difference:

  • Onboarding rule: Every new team member and freelancer receives a 10-minute walkthrough on how to save licence certificates to the shared repository immediately after downloading an asset.
  • Automated reminders: A recurring Slack reminder on the first Monday of each quarter triggers the internal audit checklist.
  • Freelancer clause: Contracts with external designers now include a line requiring them to provide licence documentation for any stock assets used in agency deliverables.
Audit response time reduction after 6 months
0%

Benefits of audit readiness

Staying audit-ready is not just about avoiding penalties. It creates tangible operational advantages:

  • Faster client onboarding. New clients see that your agency takes IP compliance seriously. That builds trust before the first campaign launches.
  • Lower legal costs. When a copyright question arises, you resolve it with a PDF, not a lawyer.
  • Clean offboarding. When a client leaves, you hand over a complete licence archive. No loose ends, no liability.
  • Team confidence. Designers stop worrying about whether they downloaded the "right" version or whether their licence covers the use case. The archive answers those questions.
  • Scalability. Adding a new platform or a new team member does not break the system. The process absorbs growth.
|
Without Audit PreparationWith Audit Preparation
11+ days to respond to audit requestsLess than 1 day
Licence files scattered across 4+ platformsSingle central repository
Freelancer assets untrackedReconciled quarterly
Lapsed subscriptions discovered during auditFlagged proactively
Manual screenshots as "proof"Standardized PDF certificates
Legal exposure on every projectDocumented compliance

Stock Licence Audit Readiness Checklist

Your progress is saved automatically in your browser.

FAQ

Frequently Asked Questions

At minimum, you need the licence certificate or receipt for each asset, showing the licence type (Standard, Extended, Editorial), the licensee name matching your agency, and the date of download. Auditors also expect to see which project or client the asset was used for and confirmation that the platform subscription was active at the time of download. Some auditors request the actual asset file alongside the certificate so they can verify the match.
Quarterly is the standard recommendation for agencies processing up to 500 stock assets per month. If your volume exceeds that, monthly reviews prevent gaps from accumulating. The internal audit does not need to be a full-day event. A focused 2-3 hour session where the ops lead cross-references download logs against the repository is usually sufficient. The goal is to catch gaps while they are still easy to fix.
Consequences range from financial penalties to relationship damage. Stock platforms can revoke access and pursue statutory damages for unlicensed use, which in some jurisdictions can reach $150,000 per infringement. Clients who discover compliance gaps may terminate contracts or withhold payment. In acquisition or partnership scenarios, unresolved licence issues can delay or kill deals. Beyond the direct costs, the reputational damage of being known as an agency that cannot manage basic IP compliance is hard to recover from.
Yes, in most cases. Platforms like Envato Elements and Shutterstock grant perpetual usage rights for assets downloaded during an active subscription period. The licence does not expire when the subscription ends. However, you must be able to prove the subscription was active at the time of download. This is exactly why saving the licence certificate at download time is critical. If the subscription is cancelled and the account is deleted, retrieving that proof later may be impossible.
Absolutely. Any stock asset a freelancer downloads on their personal account and uses in your agency's deliverables needs to come with licence documentation. The cleanest approach is to include this requirement in your freelancer agreement and make it part of the deliverable handoff process. Alternatively, require freelancers to use the agency's stock accounts so all downloads are automatically tracked under your team licence.

Additional Resources

What does your agency's current licence documentation process look like, and where are the biggest gaps you have noticed?