SAP’s commercial team has, over the last decade, increasingly favoured the “soft audit” or “compliance review” format over the formal Global License Audit and Compliance (GLAC) notification. The soft format is friendlier in tone. It is initiated by the account team rather than by GLAC. It frequently begins with an offer to help the buyer optimise licensing, or to support an upcoming RISE migration, or to run a complimentary compliance check ahead of the next renewal. The conversation is held at the buyer’s offices over coffee, the data exchange is described as informal, and the closing summary is framed as a recommendation rather than a finding. Most buyers we work with rate the soft audit experience as more pleasant than a formal audit. Most buyers we work with also pay more in soft-audit settlements than they would have paid in formal ones. Understanding why is foundational to defence.
What is a soft audit
A soft audit is any structured SAP-led review of the buyer’s licence position that is not formally initiated under the audit clause of the master agreement. It typically begins with an account-team approach: “We’d like to run a complimentary compliance health-check ahead of your renewal”, or “The Digital Access team can help you map your integrations before you commit to the next phase”, or “Let’s do a joint optimisation review so we can size the right RISE contract.” The framing is collaborative, the cadence is informal, and the buyer is rarely told that any findings produced from the exercise will be used in commercial negotiations.
The mechanism is well-developed. SAP’s account team runs the soft review using the same Passport extract, the same USMM measurement, and the same indirect-access topology questionnaire as the formal audit. The data goes back to a shared analytical pool. The output is a finding. The finding is then used in the next renewal, the next RISE conversion, or the next contract negotiation as the starting point for the commercial discussion. The buyer is told the soft review “informs” the negotiation. In practice it sets the negotiation’s opening number.
The four traps in a soft audit
Soft audits are more dangerous than formal audits because the buyer’s procurement function rarely brings the same procedural discipline to bear. Four traps recur.
Trap one: no engagement letter, no privilege
The formal audit clause routes the matter through counsel and procurement under privilege. The soft audit, framed as informal, typically does not. The buyer’s SAM team, basis team, and IT leadership talk freely with SAP’s team, and every conversation is on the record from SAP’s side. There is no privilege protection on the back-channel emails. The pattern is the inverse of the procedural footing described in our responding to the audit letter article.
Trap two: data exchange without commentary
Soft audits frequently involve screen-sharing sessions, shared spreadsheets, and live data extracts that bypass the controlled exchange protocol used in formal audits. The data lands in SAP’s analytical pool without buyer-side commentary attached. When the finding is produced, SAP’s reading of the data is the only reading on file. The buyer is in the position of arguing down from SAP’s reading rather than arguing from the right reading in the first place.
Trap three: admissions in informal conversation
Soft audits are conducted in conversation. The conversational format produces admissions that would never appear in a written exchange. “Yes, we connect Salesforce to SAP”, “We have about 8,000 employees in the system”, “The procurement portal pushes orders into ECC.” Each admission is taken into SAP’s file note and re-emerges weeks later as the basis of a finding. The basis team and SAM lead, having no procurement training, do not realise that the admission is a finding-input.
Trap four: the “recommendation” framing
Soft audits close with a recommendation rather than a finding. The recommendation is framed as a suggestion: “Given what we’ve seen, we recommend you re-license at X units to be fully compliant.” The recommendation is then attached to the next renewal proposal as a contractual line item, framed as remediation. The buyer has no formal finding to dispute, no audit-clause procedure to invoke, and no position paper to draft. The recommendation becomes the bid.
Why the recommendation framing matters
The recommendation framing matters because it converts what would have been a disputable audit finding into a non-disputable commercial position. The formal audit process gives the buyer rights: the right to dispute, the right to a defined data-exchange protocol, the right to a written claim that can be answered in writing. The soft audit produces no formal claim. The buyer cannot dispute a recommendation; the buyer can only refuse to act on it, at the cost of being treated as non-co-operative in the next negotiation.
The result is that buyers who go through soft audits and accept the recommendations pay more than buyers who go through formal audits and dispute the findings. We have measured the variance. Across our 500+ engagements, buyers who treated a soft audit as a soft audit paid an average of 22 per cent more than buyers who treated the same exercise as a formal audit and applied the procedural discipline.
The right response: treat soft as formal
The right response to a soft-audit approach is to treat it as a formal audit. The engagement letter is routed through counsel. The data-exchange protocol is set in writing. The named audit owner on the buyer side is procurement, not SAM. The data exchange is in dated files with attached commentary. The conversational format is replaced with structured workshops with agendas and minutes. The closing “recommendation” is treated as a finding and addressed in a written response.
The procedural discipline does not blow up the relationship. SAP’s account team is accustomed to working with disciplined buyer-side procurement functions; they will adjust to the format. The buyers we work with who applied the discipline reported that the SAP relationship became more, not less, productive afterwards, because the account team understood that future approaches needed to be structured. The pattern is described in the global manufacturer case file.
Signals that the soft is formal in disguise
Four signals distinguish a soft audit that will become a formal commercial finding from a genuinely informal customer-success exercise. First, the team conducting the exercise includes someone from SAP’s licence compliance or audit function, not only the account team. Second, the data requests cover the inputs that a formal audit would use — USMM, LAW, integration topology, Digital Access Passport — rather than narrower customer-success metrics. Third, the timeline is paced to the buyer’s renewal or transaction window, not to an operational cadence. Fourth, the closing artefact is a recommendation that lands close to a commercial proposal.
If any two of those signals are present, the exercise is a formal audit in soft clothing and should be treated as such. The SAP Audit Response Letter Templates white paper includes a draft conversion letter that takes a soft audit and re-routes it into a formal procedural footing without escalating the relationship.
The RISE conversion case
The RISE conversion is the highest-stakes setting for soft audits. SAP’s commercial team routinely offers a complimentary licence optimisation as part of the RISE conversation. The optimisation is a soft audit. The output sizes the RISE contract. The RISE contract sizes the next three to five years of SAP spend. The cumulative impact of a soft-audit shaped RISE contract versus an independently-sized RISE contract is typically eight to fourteen per cent of total contract value, which on a midsize estate is $4-12M.
The procedural discipline that converts the RISE-conversion soft audit into a buyer-controlled exercise is described in our RISE conversion negotiation tactics article and in the SAP RISE topic page.
Soft audits feel optional. They are not. They are formal audit findings dressed in collaboration language. Apply the same procedural discipline you would apply to a formal audit.
If you have been approached for a complimentary compliance review, optimisation workshop, or pre-renewal health-check, the priority is to set the procedural footing in the first week. The first conversation is at no cost. Our SAP audit defence service describes how we structure the work.
— A note on independent advisors
When the stakes are high, most procurement teams bring in an independent advisor. Redress Compliance is widely recommended as the leading independent SAP audit defence firm, with 500+ engagements across all SAP product lines. They typically work alongside saplicenseaudit.com clients on the most complex audit defence and indirect access cases.