Editorial photograph of a Swiss multinational headquarters running an SAP framework
SAP · Case Study · Switzerland

Swiss multinational SAP audit defense. Ninety percent exposure reduction.

SAP opened with an exposure built from an uncorrected system measurement. Reclassifying users and counting documents properly took ninety percent of it away.

Contact Us SAP RISE Negotiation Guide
90%Audit exposure reduction
500+SAP engagements
Watch the briefingResearch briefing · 3:48

Optimize the Estate First: The SAP Work That Pays for the Negotiation

SAP prices your future from your present, so a bloated estate converts into a bloated subscription. The user cleanup, engine and shelfware rationalization, resolving indirect access on your terms, and converting clean with the credits you earned.

Industry Recognized
500+ Enterprise Clients
$2B+ Under Advisory
11 Vendor Practices
100% Buyer Side Independent
Customer
Swiss multinational
Anonymised. Leading Swiss multinational.
Vendor
SAP
SAP audit cycle.
Outcome
90% reduction
Against SAP's opening audit position.
Engagement
Audit defense
Multi phase audit defense engagement.

A leading Swiss multinational running SAP across Europe, North America and APAC received an audit finding it could not immediately explain. The exposure was large, the timeline was short, and the number had been produced by the company's own system measurement.

That last point is the one worth sitting with. SAP audits are largely self reported. You run the measurement, you submit it, and SAP prices what you tell it. An uncorrected measurement is the vendor's opening position written in your handwriting.

The engagement reduced audit exposure by 90 percent. No litigation, no settlement purchase, and no argument about the contract. The finding was simply rebuilt from an accurate picture of what the estate actually did.

See the SAP advisory practice, the SAP audit defense service, and the SAP audit defense framework.

Five things decide an SAP audit outcome.

  1. The audit posture. Whether SAP is running a routine measurement review or a targeted commercial exercise.
  2. Deployment data. What you can actually evidence about your own estate, from your own systems.
  3. Entitlement. What you are contractually allowed, including everything acquired through mergers.
  4. Exposure. The gap between the two, split by cause rather than reported as one number.
  5. The response. What you say, in what order, and when.

The audit

SAP audits arrive in three broad shapes, and reading which one you are in changes how you respond.

A routine measurement review follows the annual system measurement and is largely administrative. A structured audit is a formal review with defined scope and timeline. A commercially motivated audit tends to arrive near a renewal or during a migration conversation, and its purpose is leverage rather than compliance.

This one arrived with a large indirect access component, which usually signals the third kind. See the SAP EAM and industry engine licensing playbook.

Deployment data

The party with better data sets the terms of an SAP audit. In this case SAP had a measurement the customer had submitted without reviewing, and the customer had nothing else.

We rebuilt the picture from four sources: the configuration management database, discovery tooling already deployed across the estate, the service management records, and the existing software asset management data.

Most organizations already own everything they need for this. It sits in tools bought for other reasons, and nobody has ever pointed them at the licensing question.

Entitlement

Entitlement is rarely one document. It accumulates across the original contract, subsequent amendments, support agreements, and anything inherited through acquisition.

Acquisitions are where entitlement goes missing. Licences bought by a company you purchased are frequently still valid and frequently absent from the central record, which means you may be buying something you already own.

Reconstructing the full entitlement position before responding is unglamorous and it is where a meaningful part of this reduction came from.

Exposure driverWhat SAP countedWhat the evidence showedWhy the gap existed
Named user typesProfessional licences across the estateA minority genuinely using Professional functionalityTypes assigned at implementation and never reviewed
Engine metricsFull engine entitlement against headline metricsActual measured consumption on each engineMetrics inherited from a much older deployment shape
Digital accessDocument counts from the raw measurementChargeable documents after duplicates removedSystem generated and duplicate documents counted as business events
Inherited licencesNot counted at allValid entitlement from an acquired entityNever consolidated into the central entitlement record

Where the exposure actually came from

Split by cause, the finding stopped looking like one large number and started looking like four correctable ones.

Named user drift was the largest. SAP user types range from Professional down to far cheaper categories, and the classification is meant to reflect what a person actually does in the system. In practice everyone gets Professional at go live and nobody revisits it.

Digital access was the second. SAP's document based model charges for documents created in SAP by external systems, and a raw count will happily include duplicates, reversals and documents SAP's own processes generated.

Engine metrics and unrecorded inherited entitlement made up the rest. See the SAP digital access licensing notes.

The response, in four phases

Acknowledge, scope, then answer. In that order, and not faster than that order allows.

  1. Acknowledge. Confirm receipt and agree a workable timeline. Do not send data with the acknowledgement.
  2. Scope. Establish exactly which entities, systems and periods are in scope, in writing, before producing anything.
  3. Findings. Answer the finding line by line with evidence, rather than disputing the total.
  4. Settlement. Close the corrected position, and fix the classification process so the same drift does not rebuild.

The most common mistake is answering too quickly. A prompt, uncorrected submission feels cooperative and hands the vendor a number you then have to argue back down.

Where the common advice on SAP audits is wrong

The standard advice is to run the annual system measurement, submit it promptly, and demonstrate good faith. We disagree with the sequence. SAP audits are self reported, which means the measurement you submit becomes the vendor's opening position and the anchor for everything that follows. Run the measurement, absolutely, but run it for yourself first. Review the user classifications, strip duplicate and system generated documents out of the digital access count, and reconcile inherited entitlement before anything leaves the building. Submitting an uncorrected measurement is not good faith, it is doing the vendor's work for it, and it is far harder to argue a published number down than to submit an accurate one in the first place.

Editorial photograph of a licensing team reviewing SAP named user classifications and digital access document counts
SAP audits are self reported. The measurement you submit is the number you will spend the next six months arguing against.

The eleven moves

These are the moves that produced the reduction. The first three did most of it.

  1. Review user classifications before submitting anything. Actual usage, person by person, against the type assigned.
  2. Rebuild the digital access count. Remove duplicates, reversals and documents generated by SAP's own processes.
  3. Reconstruct the full entitlement position. Including everything inherited through acquisition.
  4. Scope the audit in writing. Entities, systems and periods, agreed before data moves.
  5. Measure engine consumption. Rather than accepting the headline metric.
  6. Use the discovery data you already own. It is usually sufficient and already deployed.
  7. Answer line by line. Disputing a total invites a negotiation; disputing a line invites a correction.
  8. Keep the commercial conversation separate. An audit is not a renewal, however much it is framed as one.
  9. Fix the classification process. Otherwise the same drift returns within two years.
  10. Put digital access on a documented counting rule. Agreed internally and applied consistently.
  11. Measure annually for yourself. Long before SAP asks.

What to do next

If an SAP audit letter has arrived, or you think one is coming, do these in order.

  1. Acknowledge receipt and agree a timeline. Do not attach data to that acknowledgement.
  2. Get the scope agreed in writing: which entities, which systems, which periods.
  3. Run your own system measurement and review every Professional user against actual usage.
  4. Rebuild the digital access document count, excluding duplicates, reversals and system generated documents.
  5. Reconstruct entitlement from every source, including licences inherited through acquisitions.
  6. Answer the finding line by line with evidence, and keep any renewal conversation firmly separate.

How we engage

  • SAP audit scoping. A six week engagement that reviews user classification, rebuilds the digital access count, and reconstructs entitlement before anything goes to SAP. SAP advisory practice.
  • SAP audit response. We run the response through all four phases, answering line by line with evidence. SAP audit defense service.
  • SAP renewal negotiation. Kept deliberately separate from the audit, and run on its own timetable. SAP contract negotiation service.
  • SAP S/4HANA advisory. Including the FUE conversion, which is negotiable and usually presented as arithmetic. SAP S/4HANA advisory service.
  • Vendor Shield. Always on cover across SAP and the wider software estate. Vendor Shield.
  • Check your readiness. The audit defense readiness checklist takes about ten minutes.
SAP RISE Negotiation Guide

Forty pages. The full SAP audit defense.

The eleven moves, named user reclassification, engine metrics, digital access document counting, the FUE conversion, and the buyer side position at every phase of an SAP audit.

Used across more than five hundred enterprise clients. Independent. Buyer side.

Get the white paper →
Opens the white paper landing page. We only email you about this download.
Run the audit defense readiness checklist against your SAP estate in under five minutes.
Open the Tool →
90%
Audit exposure reduction
11 moves
Buyer side moves
5 dimensions
Audit defense scope
500+
SAP engagements
100%
Buyer side
90%
Audit exposure removed
500+
SAP engagements
100%
Buyer side, no vendor income

Source: Redress Compliance advisory engagement file.

SAP's opening number came from our own system measurement, which nobody had corrected in years. Half our Professional users had never needed a Professional licence, and the digital access claim counted documents twice. Ninety percent of the exposure came off.

Chief Information Officer
Leading Swiss multinational
More Reading
Try Vera AI · free 30 day trial
Before the auditor finds it, Vera already has.
  • Your agreements decoded into plain English before the auditor interprets them for you
  • Coverage grid: liability caps, IP protections, and SLAs checked in one pass
  • A defensible position paper generated in minutes, not weeks
Start the free Vera AI trial →30 days free · no credit card · cancel anytime

More from this practice.

SAP Practice →
SAP Practice
SAP · Practice
SAP Advisory Practice
The full SAP advisory practice across the renewal cycle.
22 min read
SAP Audit Service
SAP · Service
SAP Audit Defense Service
The SAP audit defense service.
18 min read
SAP Audit Framework
SAP · Framework
SAP Audit Defense.
The SAP audit defense.
20 min read
SAP Digital Access
SAP · Framework
SAP Digital Access Licensing
The indirect access.
18 min read
UK Engineering
SAP · Case Study
UK Engineering SAP
UK engineering SAP audit case study.
12 min read
Editorial photograph

Your next renewal is an opportunity.

Independent. Buyer side. The advisory firm enterprise software vendors do not want you to hire.

SAP intelligence, monthly.

Audit signals, named user signals, engine licensing signals, indirect access signals, FUE conversion signals, and the broader SAP licensing leverage signals.

Cover of The Software Audit Defense Playbook from Redress Compliance

White Paper · Advisory

The Software Audit Defense Playbook

Turn an audit notice into a controlled negotiation: control scope, build your ELP, and compress the opening claim toward ~30%. Read it free.

Read the white paper
Need help? Try our AI agents. Ask the SAP licensing AI agent → Scoped to one vendor and one problem. Runs in your browser.

Frequently asked questions

How much did the Swiss multinational reduce its SAP audit exposure?

The company cut its SAP audit exposure by roughly 90 percent against the publisher's opening claim. The reduction came from reframing the audit as an indirect access conversation rather than a named user count. The headline claim was never the defensible number.

What was the core issue in the SAP audit?

The core issue was SAP indirect access, where third party systems touch SAP data and SAP seeks to license those connections. SAP's opening position valued every integration at full list. Scoping the genuinely licensable access shrank the claim sharply.

What is SAP indirect access and why does it matter?

SAP indirect access is use of SAP data by non SAP applications or external users, which SAP can claim requires licensing. It matters because integrations multiply the apparent user base. The buyer side move is to map real document flows and price only what the contract covers.

How did Redress Compliance defend the audit?

Redress reconstructed the actual document and integration flows, challenged the publisher's measurement basis, and negotiated against a defensible scope rather than the opening claim. Audit defense is a measurement argument first. The data, not the relationship, moved the number.

Is Redress Compliance independent of SAP?

Yes, Redress Compliance is 100 percent buyer side independent and earns no SAP commission or referral fee. That independence means the advice targets the lowest defensible settlement. Benchmarks from comparable SAP audits give the leverage.