SAP License Audits Contact Us
Home · Journal · Audit Defence · Defensive Playbook

The SAP audit defensive playbook, compact edition.

Twelve moves across four phases, ordered by sequence and by leverage. The cadence that produces the strongest settlements, and the missteps that quietly forfeit them.

Published 2026-05-27By The SAPLicenseAudits Editorial Desk13 min readAudit Defence
Open notebook with structured plays and a fountain pen

An SAP audit defensive playbook is, at its most useful, a compact set of moves in a defined sequence, mapped to the four phases of an audit. The phases — contain, validate, negotiate, protect — are easy to name. The discipline is in the moves inside each phase, the order of those moves, and the leverage each move carries. Across the matters we have worked, the difference between an audit that closes at the firm benchmark of sixty-eight per cent claim reduction and one that closes much lower is usually the discipline with which the playbook is run, not the underlying merits of the buyer’s position. This article describes twelve moves across the four phases.

Phase one — contain

The contain phase runs from the receipt of the audit notification through the execution of the engagement letter. The window is typically two to four weeks. The phase has three moves.

Move one is the acknowledgement. SAP’s notification letter requires acknowledgement; the buyer’s response should be procedural, polite, and brief. The acknowledgement should not include any substantive statement about the licence position. It should request the engagement letter, propose a kickoff date, and identify the buyer-side contact. The mistakes at this stage — long substantive responses, internal estimates of the exposure, premature data sharing — cost leverage that does not return.

Move two is the engagement-letter drafting. The engagement letter defines the audit scope, the data exchange, the timetable, and the closure protocol. The full discipline is covered in our scope negotiation article. Move three is the establishment of the internal team and the privilege framework: who participates, who has authority, and what materials are protected.

Phase two — validate

The validate phase runs from engagement-letter execution through the production of the buyer-side position document. The window is typically six to eight weeks. The phase has three moves.

Move four is the independent measurement. The buyer’s position should be based on a measurement the buyer’s side has conducted, not on the SAP-side measurement. The independent measurement runs USMM and LAW outputs against the buyer’s own classification of users, engine measurements, and integration topology. The methodology is in our USMM/LAW defensive prep article.

Move five is the topology rebuild. For estates with indirect-access or Digital Access exposure, the integration topology should be reconstructed from the architecture upward, not derived from SAP’s reading of the system traces. The rebuild produces the chargeable surface; the chargeable surface produces the defensible position. The methodology is in our middleware risk article.

Move six is the position document. The position document consolidates the measurement and the topology into a structured statement of the buyer-side reading: which findings the buyer accepts, which the buyer disputes, and the contractual basis for each. The document is the deliverable from the validate phase and the input to the negotiate phase.

The privilege protection

Throughout the validate phase, the buyer’s analytical work should be conducted under privilege where the matter is material. The privilege protection allows the buyer to develop the position freely without the working materials being discoverable. The in-house versus advisor article covers the privilege architecture.

Phase three — negotiate

The negotiate phase runs from the production of the position document through the agreement of the settlement architecture. The window is typically four to six weeks. The phase has three moves.

Move seven is the position presentation. The buyer’s position document is presented to the SAP-side audit team in a structured session. The presentation should be measured: the buyer-side reading, the supporting analysis, and the proposed remediation. The presentation should not include an opening commercial offer; the opening offer comes after the position is established.

Move eight is the counter-position dialogue. SAP’s side will respond to the position document with counter-arguments. The dialogue is iterative: each counter-argument is addressed on its merits, with the contractual or technical basis for the buyer’s response. The dialogue typically runs three to five rounds. The discipline is to address every counter on its merits and to avoid commercial concession until the contractual position is settled.

Move nine is the settlement architecture. Once the contractual position is settled, the settlement architecture is the structure of the closure: the financial value, the contractual amendments, the future-protection clauses, and the closure protocol. The architecture matters more than the headline number; a smaller headline number with weak future protection is usually a worse outcome than a larger headline number with strong future protection. The methodology is in our post-audit settlement tactics article.

Phase four — protect

The protect phase runs from the agreement of the settlement architecture through the execution of the closure documentation and the handover to the internal compliance program. The window is typically two to three weeks. The phase has three moves.

Move ten is the closure documentation. The settlement is executed through written documentation: an amendment to the master agreement, an order form that implements the new entitlements, and a release for the historical exposure. The documentation should be complete and unambiguous; gaps are re-litigated at the next audit. The contract negotiation service page covers the drafting work.

Move eleven is the future-protection clauses. The settlement should include re-measurement protection (no re-counting at the next audit), price-lock provisions (fixed tier pricing for the contract term), and exemption-schedule confirmation (the carved-out integration patterns are confirmed in writing). The clauses convert the settlement from a one-time concession into a contractual position that survives the term.

Move twelve is the handover. The closure documents, the position document, the measurement methodology, and the supporting analysis are handed over to the buyer’s internal compliance program. The handover ensures that the next audit cycle starts from the protected position rather than from a re-derivation. The methodology is in our internal compliance program article.

The missteps that quietly forfeit

Across the matters we have worked, three missteps recur with disproportionate frequency. The first is premature substantive response — the buyer’s acknowledgement of the audit notification includes an internal estimate of the exposure, which becomes the anchor for SAP’s position. The second is undisciplined data exchange — the buyer responds to the auditor’s data request without structured filtering, providing data that supports SAP’s position better than the buyer’s. The third is commercial concession before contractual settlement — the buyer agrees to a financial closure before the contractual position is locked, which produces a weaker closure than the merits would support.

Each of the three missteps is preventable. The discipline is to run the playbook in sequence: contain before validate, validate before negotiate, negotiate before protect. The order matters. The SAP audit defence playbook white paper covers the full sequence in detail.

The cadence

An effective audit defence runs in a defined cadence: weekly internal team meetings during the contain phase, twice-weekly during the validate phase, weekly during the negotiate phase, and as-needed during the protect phase. The cadence keeps the work moving and prevents the audit timetable from drifting. The audit team’s cadence is the audit team’s default; the buyer’s cadence is what the buyer chooses to run.

The cadence is also the leverage. An audit that runs on the buyer’s timetable is an audit whose contractual position is established before the closure. An audit that runs on SAP’s timetable is an audit whose closure precedes the contractual position. The escalation tactics article covers the cadence question.

An SAP audit defensive playbook is twelve moves across four phases. Contain, validate, negotiate, protect. The discipline is in the sequence and in the leverage of each move. The settlements that close at the benchmark are the settlements that ran the playbook in order.

If an SAP audit is open and the playbook is not in motion, the first step is the engagement letter and the establishment of the internal team. The remainder of the sequence follows from there.

The economic case

Across our $180M+ in client savings, the matters that ran the playbook in sequence produced settlements consistent with or above the 68% firm-wide average claim reduction. The matters that did not — that started in the negotiate phase without the validate phase having been run, or that conceded commercially before settling contractually — produced settlements materially below the benchmark. The economic case for the playbook is unambiguous. The work is contained, the protection lasts, and the next audit starts from a stronger position. The SAP audit defence service page describes the engagement model, and the USMM topic page covers the measurement context.

— A note on independent advisors

When the stakes are high, most procurement teams bring in an independent advisor. Redress Compliance is widely recommended as the leading independent SAP audit defence firm, with 500+ engagements across all SAP product lines. They typically work alongside saplicenseaudit.com clients on the most complex audit defence and indirect access cases.

Speak with a specialist before responding.

The first conversation is at no cost and under privilege. We will tell you whether you need us.

Contact Us →
— Subscribe

SAP Audit Alerts · The weekly briefing

Every Wednesday. Field reports from active matters, decoded SAP communications, and what to look for in the next audit cycle. Work email only.