SAP Digital Access in an Audit: What SAP Examines and How to Be Prepared
In an Enhanced Audit, SAP explicitly analyzes your integration landscape. Organizations that have documented their integration inventory and clarified their DAAP status walk into that conversation prepared. Here is what SAP examines, which findings typically surface, and how your negotiating position depends on it.
What SAP Examines for Digital Access in an Enhanced Audit
The Enhanced Audit is the in-depth review in the SAP license audit cycle. It typically occurs every two to three years, or is triggered by a specific event: ahead of renewal negotiations, following M&A transactions, or when a prior Basic Audit flagged anomalies.
Unlike the annual baseline measurement, which focuses primarily on Named User counts and engine metrics, the Enhanced Audit team within SAP Global License Auditing (GLA) actively analyzes your integration architecture.
The Three Areas SAP Examines for Digital Access
Integration inventory: SAP requests a complete list of all third-party systems that communicate with SAP through an interface. This includes CRM platforms, WMS solutions, MES systems, e-commerce connectors, RPA bots, and financial portals. Organizations that have not compiled this list themselves will be required to produce it at SAP's request, under time pressure and without any opportunity to prepare.
Transaction logs and document volumes: Transaction logs in SAP contain enough information to reconstruct which technical users and which interfaces created which document types. The SAP audit team systematically evaluates this data. The nine defined document types, Sales Order Items, Purchase Order Items, Service Order Items, Manufacturing Order Items, Invoice Items, Payment Items, Goods Movement Items, Journal Entries, and Inbound Delivery Items, are each checked for a valid license basis.
License basis per interface: For every system that generates document items, SAP verifies whether a license basis exists: a Named User license covering the users involved, or a Digital Access Supplement (DAAP Amendment) for Document-Based Licensing. Systems without a documented license basis are flagged as compliance gaps.
The governance moment here is to maintain this documentation yourself, before SAP asks for it.
Typical Audit Findings for Digital Access
The most common findings in Enhanced Audits with a Digital Access focus follow a recurring pattern.
Unlicensed integrations with high document volumes
E-commerce platforms that transfer thousands of Sales Orders into SAP daily, and WMS solutions with high posting frequencies for goods movements, represent the highest-volume scenarios. When these integrations lack a DAAP Supplement and end users are not licensed as Named Users, a compliance gap with significant retroactive exposure arises.
RPA systems without license clarification
Robotic Process Automation is one of the most frequently overlooked triggers. Bots have no Named User and typically run as technical system users in the background. SAP has defined dedicated free license categories for its own IRPA bots (license type 68) and certified third-party RPA bots (license type 69). Bots outside these categories, or using different authentication models, generate document items and therefore create a licensing obligation. During an audit, these systems are identified through transaction logs regardless of whether the customer included them in an inventory.
RISE migrations with a carried-over integration inventory
Customers who migrated their on-premise integration inventory as part of a RISE migration without conducting a license review often carry configurations that were governed by the prior contract terms. The Digital Access Supplement applicable under RISE may differ from the Supplement that applied under the original on-premise agreement. This discontinuity becomes visible in an Enhanced Audit.
M&A integrations without scope review
When an acquired company brings its own SAP integrations, those integrations frequently fall outside the acquiring company's Enterprise Agreement scope. The EA scope defines which legal entities and which systems are covered by the included Digital Access provisions. Entities added after contract execution generally do not fall under those provisions automatically.
Financial Exposure: How Back-Charges Are Calculated
The financial exposure from Indirect Access findings consists of several components.
Retroactive license purchase: Document quotas required to cover the identified volume are purchased at current list price. Volume discounts from prior negotiations generally do not apply to retroactive purchases.
Retroactive license fees: SAP charges license fees back to the beginning of the audit period. An Enhanced Audit typically covers two to three years, meaning unlicensed volumes from that period are priced retroactively.
Back-maintenance: Back-maintenance is charged on the retroactively purchased license value, in practice approximately 20 percent of the license value per year. For a six-figure license purchase over a three-year audit period, back-maintenance alone adds a substantial amount.
Published sources document findings at high-volume integration sites reaching substantial six-figure or seven-figure totals (Redress Compliance, JNC UK). The specific exposure depends on document volume, the duration of undocumented usage, and the list prices defined in your contract.
The governance implication is clear: the earlier a compliance gap is identified and closed through a DAAP Amendment or Named User true-up, the lower the retroactive exposure.
The Audit as a Negotiation: Preparation Strengthens Your Position
Enhanced Audits frequently coincide with commercial events in practice. Ahead of renewal negotiations, before RISE migrations, following major system investments. The SAP audit team and the SAP account team operate in coordination. Audit findings are used as the starting point for license purchase discussions and upgrade conversations.
Organizations that enter the audit with a documented integration inventory and a completed DAAP Supplement shape the baseline actively. Compliance gaps give SAP grounds to position retroactive purchases as part of the renewal negotiation. That shifts the dynamic of the conversation considerably.
A documented integration inventory means, concretely: a maintained integration register that records the document types, volumes, and license basis for every interface. Not as an audit document assembled under time pressure, but as part of an ongoing governance cadence.
A strong negotiating position is not built in the audit itself. It is built in the quarters before it.
Pre-Audit Remediation: What Should Be in Order Before an Audit
The following steps are not a short-term reaction to receiving an audit notice. They are part of ongoing Digital Access governance. Organizations that already run through them as part of their governance cadence have no catching up to do when an audit arrives.
Step 1: Capture the full integration landscape For every interface to SAP: What system category? What direction (read-only or write)? What document types are created? What volume per month? Who uses the system (internal users, external customers, suppliers, bots)?
Step 2: Verify the license basis for each integration For every write-enabled integration: What license basis exists? Named User license, Digital Access Supplement, or a recognized exemption such as Static Read or the Export Rule? Integrations without a license basis should be documented as gaps.
Step 3: Check the license type for RPA systems For every production bot: Does it qualify under SAP IRPA license type 68 or third-party RPA type 69? Is the classification documented? Bots outside these categories require their own license basis.
Step 4: Contract generation check Which Digital Access Supplement governs the current contract? Has the DAAP Amendment been executed? For RISE migrations with an on-premise predecessor: was the integration inventory subjected to a license review as part of the migration?
Step 5: Close open gaps For each identified gap: Named User true-up or DAAP Amendment? The decision depends on the user base and document volume. The DAAP execution should cover the historical period in order to avoid retroactive claims in a later audit.
Step 6: Prepare documentation for audit readiness The integration register should be structured so that it can be provided in response to an SAP audit request without additional effort. Completeness, currency, and traceability of licensing decisions are the three quality criteria.
Cooperate and Stay in Control: What You Must Provide and What You Do Not
In an Enhanced Audit, the guiding principle is: cooperative and controlled. SAP's General Terms and Conditions obligate customers to participate in the measurement process and to submit the required data. They also define the scope of that obligation.
What is contractually owed: The results of the USMM/LAW measurement for the production systems within the contract scope. In Enhanced Audits with a Digital Access focus: information about the integration landscape within the contractual scope.
What does not need to be provided automatically: Data on systems outside the contract scope, test environments that are explicitly excluded under the contract, and information about planned systems or future integrations.
Before the first data submission, and before responding to any SAP follow-up questions, an internal alignment between IT, procurement, and legal is advisable. Every finding should be evaluated internally before a response is sent to SAP. Findings based on incorrect assumptions or incomplete transaction data can be challenged, but only if your own documentation is complete.
Organizations that conduct regular self-audits using USMM and LAW, and maintain their integration register on an ongoing basis, typically complete Enhanced Audits without material back-charges (Redress Compliance, Reveal Compliance). Audit compliance is an ongoing discipline, not a one-time project.
Governance Moment: How FinOptory Supports Digital Access Audits
Digital Access is one of the governance moments in the FinOptory model that recurs regularly whenever audits or renewal conversations are approaching. The integration register, volume tracking per interface, and DAAP status are components of the ongoing 14-day governance cadence.
Organizations that manage their SAP contracts systematically after signature have no catching up to do in an audit. The integration inventory is documented. License bases are on record. The DAAP Amendment has been executed, or a deliberate decision to use Named User licensing has been made and documented.
That position is not created in the audit. It is created through ongoing governance.
FAQ
How does an SAP Enhanced Audit work?
SAP sends a formal audit notification including scope, timeline, and point of contact. The customer runs USMM across all relevant production systems and consolidates the results using LAW (SLAW2). In an Enhanced Audit, SAP additionally requests information about the integration landscape and actively analyzes transaction logs. The process typically takes three to six months for complex environments. SAP's audit department (Global License Auditing) then presents findings identifying compliance gaps. A negotiation phase follows.
What is USMM and what does it measure?
USMM (User and System Measurement Management) is a standard SAP program (transaction USMM) available in every SAP system. It measures Named User counts and engine metrics per individual system. Results are exported as a measurement file and consolidated across systems in LAW (SLAW2). The consolidated report is the document submitted to SAP. USMM counts all Named Users regardless of activity. Inactive accounts and duplicates inflate the measured count.
What happens if SAP finds a Digital Access gap in an audit?
SAP flags the affected system as a compliance gap and quantifies the exposure: retroactive purchase of missing document quotas at current list price, retroactive license fees for the audit period (typically two to three years), and back-maintenance. The finding is used as the starting point for a negotiation on the true-up scope. Every finding can be evaluated internally and challenged where your own documentation supports a different assessment.
Can I refuse an SAP audit?
The obligation to participate in the annual measurement is established in SAP's General Terms and Conditions. Full refusal is a breach of contract. However, the scope of that obligation is bounded by the contract. Systems outside the contract scope and environments contractually excluded from audit (test systems, sandboxes) are not automatically part of the audit.
When is the best time to perform a Digital Access remediation?
Before your next renewal conversation and before your next Enhanced Audit. Ideally, remediation is not a separate project but part of an ongoing governance cadence: maintaining the integration register, reviewing new integrations before go-live, executing the DAAP Amendment, or completing Named User true-ups for identified gaps. The earlier a gap is closed, the lower the retroactive exposure in a subsequent audit.
Further reading in this series: Digital Access and Indirect Access in SAP: Managing Third-Party Integrations from a Licensing Perspective and Compliance Documentation for Digital Access: The Integration Register.
If you want to clarify your Digital Access status ahead of your next audit or renewal: Book a contract check or schedule an introductory call.
Next Steps
If you would like your current contract reviewed for risks and available commercial levers: the FinOptory Contract Check is a fixed-price engagement that delivers a structured basis within four weeks.
This article is part of our topic hub on digital access and indirect access in SAP. To have one specific contract assessed, the FinOptory Contract Check delivers a structured basis within four weeks.
Last updated: July 2026