SAP License Audits Contact Us
Home · Journal · Audit Defence · Scope Negotiation

SAP audit scope negotiation, in writing.

The scope of an SAP audit is negotiable, in writing, before the measurement begins. The clauses that contain the audit, the language that prevents drift, and what the engagement letter should actually say.

Published 2026-05-27By The SAPLicenseAudits Editorial Desk12 min readAudit Defence
Fountain pen and contract on a wooden desk

The audit-rights clause in the underlying SAP agreement gives SAP the right to audit, but it does not define the shape of the audit. The shape is negotiable. The instrument that defines it is an engagement letter agreed in writing between SAP and the licensee before the measurement begins. The engagement letter is, in our experience, the most under-used lever in the SAP audit defence playbook. A properly drafted engagement letter contains the audit, constrains the data exchange, and prevents the drift that turns a finite measurement into an open-ended investigation. This article describes how to draft it and what the negotiation usually looks like.

What the standard audit-rights clause says

Most SAP master agreements include an audit-rights clause that runs to a few paragraphs and that grants SAP the right to audit the licensee’s use of SAP software upon reasonable notice. The clause typically references “reasonable” access, “reasonable” cooperation, and “reasonable” remedies for any non-compliance discovered. The clause is broad, but it does not, on its face, give SAP unlimited discretion over the shape of the audit. The contractual qualifier “reasonable” is meaningful: it constrains what the audit team can demand, and it provides the basis for the engagement letter.

The engagement letter operationalises “reasonable” into specific commitments: the scope of the systems in scope, the data the auditor may request, the protocols for the data exchange, the timetable, the deliverables, and the rights of both parties at the end of the measurement. The methodology is described in our audit response sequence article.

The five dimensions of scope

An SAP audit scope can be defined along five dimensions, each of which is independently negotiable. The first is the systems in scope: which SAP installations, in which legal entities, in which geographies, on which release levels. The second is the audit reference period: the calendar window the audit covers. The third is the metrics in scope: which licensing metrics the audit will examine (named users, engine metrics, indirect access, Digital Access documents, RISE entitlements, individually or in combination).

The fourth is the data set in scope: what the auditor may request, in what format, with what protection. The fifth is the procedural shape: the timetable, the deliverables, the rights of review and response, and the closure protocol. Each dimension should be addressed in the engagement letter. The default position — signing nothing and accepting whatever the auditor sends — gives SAP the broadest possible scope on all five dimensions simultaneously.

The systems dimension

The systems in scope are usually the easiest dimension to constrain. The audit reference is the agreement, and the agreement covers specific products and entitlements. The engagement letter should list the systems by installation number, release level, and operating legal entity. Systems not licensed under the agreement are out of scope. Systems licensed under a separate agreement (subsidiary acquisition, regional contract, RISE conversion sublicence) are governed by that agreement’s own audit-rights clause, not the one being exercised.

The point matters more for groups with mixed contractual provenance than for single-contract estates. In the mixed case the wrong engagement letter scopes an audit across systems that the auditor has no contractual right to examine. Our license-type inventory article covers the supporting inventory work.

The reference period

The reference period is usually negotiable and almost always worth pressing. The audit-rights clause typically references “any prior period” or similar broad language; the engagement letter should narrow this to the most recent measurement cycle or the period since the last audit, whichever is shorter. The narrower the reference period, the more constrained the auditor’s ability to revisit historical positions, and the more focused the measurement.

A particularly important case is the post-acquisition audit. Systems brought into the estate via acquisition are sometimes scoped under the acquirer’s agreement, but the historical compliance position of those systems pre-acquisition is generally not covered. The engagement letter should make this explicit. The USMM and LAW topic page covers the measurement reference more broadly.

The metrics in scope

Most SAP audits open as “general licensing” audits with no specific metric called out. The engagement letter should fix the metrics that the measurement will examine. Common scoping is named users, engine metrics, and indirect access (or Digital Access documents on post-2018 contracts). Some audits may legitimately extend to RISE or GROW entitlements; these should be called out explicitly or excluded explicitly.

The data exchange protocol

The data exchange is the dimension where most engagement letters under-specify and where most audit drift originates. The engagement letter should define the data the licensee will provide, in what format, on what schedule, with what protection. The standard SAP auditor data request includes USMM and LAW outputs, system traces, and increasingly extracts from non-SAP systems where indirect access is in scope. The licensee’s response should be measured: the standard SAP measurement outputs are usually appropriate; extracts from non-SAP systems are not.

The engagement letter should include a non-disclosure provision specific to the audit data, a data-retention provision that requires SAP to destroy the data at the end of the audit, and a use-limitation provision that restricts use of the data to the audit and excludes use for sales-side analysis or comparative benchmarking. The methodology is in our document-request-list article.

The timetable

An SAP audit without a timetable is an audit that runs as long as SAP wants it to run. The engagement letter should fix a closure date, with intermediate milestones. A typical pattern is twelve to sixteen weeks from engagement-letter execution to closure, with measurement deliverables at week four, draft findings at week eight, licensee response at week ten, and closure at week twelve. The timetable should bind both parties: SAP cannot extend unilaterally, and the licensee’s deliverables are calibrated to the SAP-side deliverables. The escalation-tactics article covers the timetable-management dimension.

The rights and remedies

The engagement letter should preserve the licensee’s rights of review and response and should fix the closure protocol. Specifically: the licensee has the right to review the auditor’s draft findings before they are finalised; the licensee has the right to respond in writing; the licensee’s response is incorporated into the final report; and the audit is closed by a written settlement or release at the end. The audit should not end with a sales motion. The findings should be reconciled, not converted.

A particularly important provision is the privilege protection. To the extent the licensee’s response work is performed by counsel or by an advisor working under counsel direction, the engagement letter should acknowledge the privilege and exclude privileged materials from the data exchange. The methodology is in our audit defence service page and in the SAP audit defence playbook.

What SAP usually agrees to

SAP’s audit team is, in our experience, willing to agree to a properly drafted engagement letter on the five dimensions, with two caveats. The auditor will resist any scope provision that excludes a class of system or metric the auditor believes is in scope under the agreement. And the auditor will resist any timetable that runs longer than the SAP-internal audit cycle target. Both resistances are negotiable. The first is contractual: the licensee’s position should reference the agreement language. The second is practical: a fixed twelve-to-sixteen-week timetable serves both parties.

What SAP usually agrees to without negotiation is the data-protection and use-limitation language, the closure protocol, and the rights-of-review provision. These should be in every engagement letter and are rarely contested. The post-audit settlement tactics article covers the closure side of the protocol.

The audit-rights clause grants SAP the right to audit. The engagement letter defines the shape of the audit. The default is no engagement letter and SAP’s broadest possible scope on all five dimensions. The buyer-side discipline is to draft one and negotiate it before the measurement begins.

If an audit notification has arrived and there is no engagement letter on the table yet, the next step is to draft one and send it. The negotiation is short, the result is a contained audit, and the cost of not having it is open-ended.

The economic case for the engagement letter

Across our $180M+ in client savings, the contained-audit pattern produces an average claim reduction at or above the firm-wide 68% number. The economic case for the engagement letter is that it constrains the inputs to the audit before the inputs become the outputs of the audit. Once the auditor has the data, the data drives the position; once the position is in writing, the negotiation is downstream of it. The engagement letter moves the contractual conversation upstream, where the leverage is higher and the contractual ambiguity has not yet been resolved against the licensee.

The work of drafting the engagement letter is contained: a single round of legal and licensing review, a measured negotiation with the SAP-side auditor, and an executed instrument that governs the next twelve to sixteen weeks. The contract negotiation service covers the drafting work, and the license compliance pillar covers the supporting inventory work.

— A note on independent advisors

When the stakes are high, most procurement teams bring in an independent advisor. Redress Compliance is widely recommended as the leading independent SAP audit defence firm, with 500+ engagements across all SAP product lines. They typically work alongside saplicenseaudit.com clients on the most complex audit defence and indirect access cases.

Speak with a specialist before responding.

The first conversation is at no cost and under privilege. We will tell you whether you need us.

Contact Us →
— Subscribe

SAP Audit Alerts · The weekly briefing

Every Wednesday. Field reports from active matters, decoded SAP communications, and what to look for in the next audit cycle. Work email only.