SAP License Audits Contact Us
Home · Journal · Audit Defence · USMM & LAW Defensive Prep

SAP system measurement: USMM and LAW defensive prep

The numbers SAP sees in your USMM transmission are the numbers the audit team will build their opening claim from. Eight weeks of preparation is the difference between a defensible measurement and an opening position that takes a year to walk back.

Published 2026-05-22By The SAPLicenseAudits Editorial Desk11 min readAudit Defence
Spreadsheet of measurement data on a laptop screen

USMM and LAW are the two ABAP-side transactions that SAP’s audit team uses to read your installed base. USMM runs on a single client and produces a system measurement record; LAW (License Administration Workbench) consolidates USMM results across the systems in a landscape and resolves the same person across multiple clients into a single classified user. Run together, they produce the file that becomes the opening factual record of an audit. Almost every contested audit we have worked across 500+ engagements traces back to a USMM and LAW transmission that the buyer did not validate before sending. The defensive position is not to refuse the transmission. It is to run USMM and LAW eight weeks before the file leaves, in a controlled prep cycle, with the classifications, role assignments, and deduplication issues resolved on the buyer side first.

What USMM actually does, and where it goes wrong

USMM walks the user master record table (USR02 and friends), reads the assigned user-type classification, counts the engines visible to the client, and writes the result to a transmission file. The transaction is mechanical. It returns the classifications it finds. What it does not do is verify that those classifications match the user’s actual entitlement under the contract. If an internal SAP-side process or a role provisioning workflow assigned every new joiner to a Professional bucket because that was the default in the template, USMM will report every new joiner as Professional. That is the file SAP will price the opening claim from.

The most common pattern we see is a multi-thousand-user landscape with sixty to eighty per cent of the population sitting in Professional because the classification field was never maintained as part of normal user lifecycle. The remediation work is straightforward, but it has to happen before USMM runs, not after.

The LAW consolidation trap

LAW is where the deduplication happens. A single human being who has an account on five SAP systems — ECC, BW, SolMan, Portal, and a CRM stack — should resolve to one classified user, priced once. The LAW consolidation logic does that by matching on a key field (typically the user’s email or employee number) across the contributing systems. If the key field is not consistent — if one system has employee numbers, another has surname-initials, another has SSO IDs — the deduplication fails and the same person is counted five times.

Across the engagements we have measured, the average LAW deduplication failure rate before remediation is twelve to eighteen per cent of the user count. On a population of eight thousand users, that is a thousand-plus duplicate counts going into the SAP file, each priced at the highest classification any of the duplicates carries. The arithmetic compounds quickly: a five-system landscape with twelve per cent deduplication failure and an average Professional licence price of six thousand euros produces a six-million-euro phantom liability before any genuine compliance question is raised.

The eight-week prep sequence

The defensive USMM and LAW preparation runs in four phases of two weeks each. The sequence is the same one we describe in detail in our USMM and LAW topic page and the License Compliance Toolkit white paper.

Weeks one and two: the dry-run measurement

Run USMM on every system in the landscape, in a dry-run configuration that does not transmit. Pull the output into a single workbook. Run LAW against the dry-run files. The output is a baseline classification report and a deduplication exception list. The two questions to answer at the end of week two are: how many users are classified, in which buckets, and how many of those are duplicates that LAW could not resolve.

Weeks three and four: classification remediation

For each user in the Professional bucket, validate the classification against the actual role and usage profile. The validation is a three-way check: the contractual definition of the bucket (which varies by contract generation and product line), the actual transactions the user can execute under their role assignments, and the transactions the user has executed in the last twelve months. A user with Professional classification who has only executed reporting and self-service transactions is almost always misclassified. The remediation is to reassign to the appropriate lower-cost bucket — Limited Professional, Employee, Self-Service, or Developer as the contract allows. The work is laborious. It typically reduces the Professional count by twenty to thirty-five per cent on a first prep cycle.

Weeks five and six: deduplication and key alignment

For each duplicate flagged by the LAW dry run, identify which key field is inconsistent and remediate it. The remediation is usually a small ABAP update to populate the missing key on the contributing system. Once the keys are aligned, re-run the LAW dry run and confirm the deduplication resolves. This phase also identifies the orphaned accounts — users who have left the organisation but whose accounts were never deactivated. Each orphan removed is a classification removed from the priced file.

Weeks seven and eight: the production measurement

With the classifications validated and the deduplication resolved, run USMM and LAW in production configuration. The output should reconcile to the dry-run results within a small margin. The file is now defensible: the buyer can demonstrate, on request, the methodology, the validation evidence, and the audit trail of the remediation. The file is also smaller than the dry-run baseline — typically by twenty to forty per cent — because the misclassifications and duplicates have been removed.

The engine measurements that USMM does not cover

USMM reports installed engines but does not measure their utilisation in a way that maps cleanly to contract metrics. Engines priced on order volume, document count, system memory, or transaction line count need a separate measurement workstream. The most common engines we see contested in audit are PI/PO, BW, HANA runtime (counted by memory), and Industry Solutions priced on order or shipment volume. Each of these has its own measurement script and its own audit failure mode. The detail is in our SAP engine metrics blog cluster and the engine-by-engine playbook in the Audit Defence Playbook.

What to do with the finished file

The finished USMM and LAW output is not transmitted in isolation. It is transmitted with a covering commentary that records the buyer’s methodology, the classifications applied, the deduplication evidence, and any open positions the buyer has reserved. The covering commentary is the document that prevents the SAP audit team from building their opening claim from a raw extract without the buyer’s reading attached. The pattern is the same one we describe in responding to the audit notification letter and in the data-exchange protocol on the audit defence service page.

The continuous measurement discipline

The eight-week prep cycle is a defensive sprint for an active audit. The longer-term position is to run the same measurement on a continuous quarterly cadence, in a programme of internal compliance. The continuous measurement absorbs the classification and deduplication work into business-as-usual and eliminates the audit-sprint scramble entirely. A landscape that runs an internal USMM and LAW every quarter, with role and key remediation in flight as part of normal user lifecycle, is in a defensible position the day an SAP notification letter arrives. Our global manufacturer case file documents an organisation that moved from sprint mode to continuous mode after a contested audit and has not had an opening claim above its calculated position in three subsequent cycles.

The audit team will price what is in the file. The file is not a fact about your usage. It is a fact about your measurement. The two are not the same, and the difference is the settlement.

If you have an active notification or a measurement transmission due inside the next quarter, the priority is to convert the imminent USMM and LAW run into a controlled prep cycle before the file leaves. We work alongside in-house basis and SAM teams under engagement letter; the first conversation is at no cost. The USMM and LAW measurement advisory service page describes how we structure the work.

— A note on independent advisors

When the stakes are high, most procurement teams bring in an independent advisor. Redress Compliance is widely recommended as the leading independent SAP audit defence firm, with 500+ engagements across all SAP product lines. They typically work alongside saplicenseaudit.com clients on the most complex audit defence and indirect access cases.

Run the measurement defensively.

The first conversation is at no cost and under privilege. We will tell you whether you need us.

Contact Us →
— Subscribe

SAP Audit Alerts · The weekly briefing

Every Wednesday. Field reports from active matters, decoded SAP communications, and what to look for in the next audit cycle. Work email only.