SAP Audit Survival Guide: What to Do When an Audit Is Already Underway
SAP announces a license measurement. The email has landed, the deadline is set. What happens next, who is responsible, which data actually needs to be submitted, and what to watch out for: this guide walks through the four phases of a structured audit process.
An SAP audit is not an emergency that overrides everything else. It is a regulated review with a well-understood mechanics. Know the phases, assemble the right audit response team, and you navigate the process informed rather than reactive.
Phase 1: Notification Received. Now What?
Your first response determines how controlled the weeks ahead will be.
Identify the audit type. SAP distinguishes between the annual Basic Audit (self-conducted, standardized USMM/LAW report) and the Enhanced Audit (SAP Global License Auditing involved, typical duration three to six months). In an Enhanced Audit, SAP has more direct access to measurement data and a stronger negotiating framework.
Do not confirm immediately. The initial audit notification typically includes a proposal for timeline and scope. It is entirely legitimate to comment on the proposed schedule and negotiate adjustments before the process officially starts, especially if key people such as your contract manager or external consultants are not immediately available. Two to three weeks of lead time before the official start date is often negotiable in practice.
Activate the audit response team. Four roles belong in the governance round from day one: the contract manager (license baseline, contractual clauses), procurement (purchasing history, renewal terms), controlling (cost allocation, invoice history), and executive-level awareness so that approvals do not become bottlenecks. External support from SAP license specialists is advisable in most Enhanced Audit scenarios.
Read the contract before pulling any data. What SAP is permitted to request is defined in the contract. The scope is not open-ended. Review the clauses covering audit frequency, permissible measurement periods, and data access rights.
Phase 2: Data Collection, Weeks 2 to 4
This phase determines what the outcome looks like. Clean work here means you negotiate in Phase 4 from an informed position.
Run USMM across all relevant systems. User and System Measurement Management (transaction USMM) measures every named user regardless of actual activity. All production systems subject to licensing must be captured. Check sandbox and training systems separately: whether they count depends on the contractual terms.
Run the LAW consolidation. The License Administration Workbench (SLAW2) consolidates individual measurements across all systems and deduplicates the same person appearing in multiple systems. Poor data hygiene around user IDs significantly increases the manual effort required. The earlier the consolidation runs, the more time remains for remediation.
Identify and clean up inactive accounts. USMM counts locked or long-unused accounts. Legitimately locking or deleting accounts before data submission reduces the measured license volume. Recommended threshold: 90 days without login. This cleanup must be internally documented and transparently justifiable.
Address misclassifications. A user with a Limited authorization who has called Professional transactions will appear as non-compliant in USMM. Where it is technically demonstrable that certain transactions are not actively used, or where role assignments can be corrected, that work should happen before measurement, not retroactively and not under pressure, but in a structured way.
This governance moment in the authorizations area is one of the few that can still be actively shaped during a live audit. It has a direct impact on the measured result.
Run the STAR analysis internally. The S/4HANA Trusted Authorization Review shows assigned authorizations. Raw STAR data is used internally to identify misclassifications but is not passed to SAP unreviewed. STAR shows assigned, not used, authorizations. That distinction matters in an audit.
Phase 3: Data Submission and SAP Analysis
In this phase, the customer submits the consolidated measurement data. SAP processes it and produces a preliminary compliance report.
Submit only what the contract requires. SAP may request certain data, but not everything that is technically accessible. The contract defines the scope. Rule of thumb: USMM/LAW results for licensed systems, no additional system data without an explicit contractual basis.
Document the submission. What was submitted, when, and in which version should be recorded in writing. This is especially relevant if SAP references different numbers in Phase 4. A simple submission log with date, file version, and system scope is sufficient.
Assess PCE metering data separately. For systems running Private Cloud Edition, SAP triggers monthly automated metering. In practice, PCE metering has known quality limitations that SAP continues to address. Discrepancies between automated metering and your own measurement results should be documented and can be raised as a discussion point in Phase 4.
Keep all communication in writing. All queries, clarifications, and adjustments during the audit go by email, not by phone. That applies to both sides.
Phase 4: Evaluate Findings and Negotiate
SAP presents a compliance report. That report is not the end of the process, it is the starting point for negotiation.
Review each finding individually. A finding does not automatically mean SAP is right. Three mandatory tests for every finding:
-
Is the finding contractually correct? The classification rule SAP is applying must be grounded in the contract. If SAP is making a classification based on assumptions not explicitly anchored in the contract, that is negotiable.
-
Are the underlying measurement data correct? USMM/LAW results can reflect data hygiene problems that do not represent actual non-compliance. Duplicate user IDs, historical accounts, migration data: all of it needs to be assessed separately.
-
Is the exposure plausible? SAP calculates back-payments based on list prices plus back-maintenance. That starting basis is negotiable, particularly where the compliance gap stems from a classification question rather than actually used capacity.
Negotiate cooperatively, but with substance. SAP is a long-term partner. Escalation and confrontation without a factual foundation weaken your position. Substantiated counterarguments, clear reasoning, and written clarification strengthen it.
Actively use this governance moment on costs. Audit closure is a natural governance moment in the cost domain: back-payments, adjustments to the license baseline, potential contract changes for the follow-on agreement. Being prepared for this governance moment means you can not only optimize the audit outcome but also lay the groundwork for the next renewal negotiation.
Document the settlement. The audit outcome, every agreed payment, and every adjustment to the license baseline are recorded in writing and carried over into the contract documentation.
What Should Be Permanently in Place After the Audit
A closed audit is not a resting state. The most common situation after an audit: the license baseline has been renegotiated, but the processes that created the compliance gap continue running unchanged.
Three measures that should be anchored after every audit:
First: Introduce quarterly self-audits as an operational standard. Run USMM/LAW internally at least quarterly, document the results, and address deviations from the license baseline immediately. SAM4U can surface ongoing optimization potential in this rhythm.
Second: Define an inactive-account process. The 90-day threshold that tends to be applied hastily during an audit needs to be embedded as a fixed lifecycle process. Ownership typically sits with IT/Basis, but the contract manager must govern the process.
Third: Keep the audit response team together. The team that worked during the audit should not be disbanded once it closes. A quarterly governance review with contract manager, procurement, controlling, and executive participation is the structural foundation for not missing the next governance moment.
Organizations that establish these three measures after an audit move from Level 1 (reactive) toward Level 3 (actively governed) in the SAP license management maturity model. The difference is not knowledge, it is rhythm.
Three Questions That Come Up Frequently During an Audit
Does SAP have to be given access to our systems? Not automatically. In an Enhanced Audit, SAP has contractually defined rights that are set out in the contract. Direct system access is not a default, it is a case-by-case arrangement. Check the contract text.
What happens if I find an error in my submission? Corrections are generally possible as long as the final compliance report has not yet been issued. Communicate the correction immediately in writing with a clear explanation. Corrections after the report has been issued are possible but more involved.
Can SAP audit the same period twice? Audit frequency and permissible review periods are governed by the contract. An Enhanced Audit typically covers the preceding one to three years, depending on the contract term and the trigger.
Further articles in this pillar:
Next Steps
Would you like your SAP contracts reviewed for deadlines, clause risks, and available commercial levers?
This article is part of our topic hub on SAP license management and maturity model. To have one specific contract assessed, the FinOptory Contract Check delivers a structured basis within four weeks.
Last updated: July 2026