The arrival of an SAP audit notice in a general counsel's inbox is not a routine corporate-counsel matter and not a routine IT-procurement matter. It sits at the seam between commercial contract interpretation, intellectual-property licensing law, and operational systems administration, and it requires a structured legal review process to produce a defensible response. The first seventy-two hours are when the negotiating posture is set; everything that follows operates inside that frame.
This piece sets out the legal review process that we use across the most consequential audit engagements, the four clauses that drive the response strategy, the stakeholder choreography for the first three days, and the documentation discipline that supports the long-form negotiation.
Day one: triage and acknowledgement
The day-one objective is a structured triage, not an immediate substantive response. The triage produces three artifacts: a chain-of-custody record for the inbound letter, a stakeholder list with explicit ownership of each work-stream, and a holding acknowledgement to the SAP audit team that confirms receipt and reserves the customer's position.
Chain of custody
The audit letter, the envelope or email metadata, and all subsequent correspondence should be filed under a single matter reference with date stamps and a single owner. Customers who treat the letter as a routine email — forwarding it through internal lists without a chain-of-custody record — frequently lose the early-correspondence record that becomes important during settlement discussions.
Stakeholder list
The minimum stakeholder list is the general counsel or contract counsel, the head of procurement, the licence management lead, the basis or systems administration lead, and the SAP relationship owner if separate from procurement. Each name should be paired with a specific work-stream: legal interpretation, commercial response, technical evidence, system administration, and counterparty management. Ownership ambiguity at this stage produces inconsistency in the response weeks later.
Holding acknowledgement
The acknowledgement to SAP should confirm receipt, propose a structured response timeline that buys the customer a workable evidence-gathering window, and explicitly reserve the customer's contractual rights. It should not engage with the substance of the audit position, and it should not commit to a specific response date until counsel has reviewed the underlying contract.
Day two: contract review
The day-two work is a structured read of the underlying contract, focused on the four clauses that drive the response strategy. The read should be performed by counsel with substantive licensing experience, supported by the procurement team's contract administrator who can produce the order forms and renewal documents that sit alongside the master agreement.
The audit clause itself
The audit clause defines what SAP is permitted to request, on what notice, with what frequency, and through what mechanism. Most SAP audit clauses include limits on the scope of measurement transactions that can be requested, limits on the frequency of full-population audits, and notice provisions that give the customer a meaningful response window. The clause needs to be read against the letter to identify any departures from the contracted process.
The measurement definitions
The contract definitions of named user, engine metric, and indirect access are the substantive ground on which the audit conversation will be conducted. The definitions in the master agreement, as amended by every order form and renewal, govern. Customers whose contract has been amended multiple times often find that the operative definitions are scattered across documents and need to be reconciled into a single working definition before the audit response is drafted.
The dispute resolution clause
The dispute resolution clause defines the customer's escalation path inside SAP and the formal mechanism for contesting an audit finding. Some contracts include a mandatory internal escalation step before the matter can be moved to the commercial negotiation phase. Others include a defined arbitration or litigation pathway. The dispute clause needs to be in front of counsel before any substantive response is drafted, because the response itself can affect the customer's procedural rights under that clause.
The confidentiality clause
The confidentiality clause governs what the customer can share inside its own organisation, what it can share with external advisors, and what the audit team is required to keep confidential. Customers who engage external advisors without a written acknowledgement of the confidentiality terms can create downstream issues that complicate the substantive response.
Day three: response framework
The day-three work converts the contract review into a response framework. The framework specifies what evidence will be produced, what timeline applies, who at the customer will hold the relationship with the SAP audit team, and which positions are reservable for later negotiation rather than first-response disclosure.
Evidence scope
The evidence scope is defined by the contract's audit clause and by what the customer is prepared to volunteer beyond the contracted scope. Volunteering evidence beyond the contracted scope creates a precedent for future audit cycles and is rarely in the customer's interest. The default position is to respond inside the contracted scope and to engage on additional evidence only when there is a defined reason to do so.
Response cadence
The response cadence proposed to SAP should include checkpoints at which the customer reviews the SAP audit team's intermediate positions before producing further evidence. A cadence with a single end-of-engagement disclosure is a weak posture. A cadence with three or four structured checkpoints gives the customer multiple opportunities to course-correct the engagement.
The four clauses that decide the response
Four contract clauses, beyond the audit clause itself, frequently decide the substantive response strategy. The first is the licence-grant clause, which defines the scope of the customer's permitted use. The second is the indirect-access or digital-access clause, which defines the treatment of non-SAP system access to SAP data. The third is the price-list reference, which defines whether the audit's pricing position uses the current list price or the customer's negotiated discount tier. The fourth is the maintenance multiplier, which defines whether back-charges accumulate at the maintenance percentage or at the full licence percentage.
Each clause can move the audit position by tens of percent. The combination of all four can change a multi-million-dollar finding into a six-figure settlement, and the cumulative effect is what drives the 68 per cent average claim reduction we see across closed matters. For a deeper look at the substantive response components, see our piece on what to include and exclude in the response letter.
The external advisor question
The decision to engage an external advisor should be made on day one, not three weeks into the engagement. External advisors who are brought in late inherit a position that has already been weakened by suboptimal early-response choices, and the remediation cost is higher than the cost of advisor engagement at the outset.
The advisor's role is to bring pattern recognition from comparable matters, to challenge the SAP audit team's framing on issues that the customer's internal team is not positioned to challenge, and to provide a written second opinion on the contract interpretation that supports the customer's response. The advisor's effectiveness is highest when engaged inside the day-one triage, where the legal review process can incorporate the advisor's input from the outset. See our service overview on SAP audit defence for engagement detail.
Documentation discipline through the engagement
The legal review process produces a documentation trail that supports the long-form negotiation. Three documentation practices materially affect the outcome.
The first is a single shared matter folder, with version-controlled contract documents, working notes, and SAP correspondence. The folder should be accessible to the full stakeholder list and locked from edit by anyone outside the list.
The second is a contemporaneous note-taking discipline. Every conversation with SAP, internal and external, should be recorded with date, attendees, substantive content, and any commitments made. The notes become the customer's record of the engagement and the basis for any subsequent dispute about what was said.
The third is a defined privilege protocol. Communications between counsel, procurement, and external advisors should be marked and treated as privileged from the outset, with clear rules about what can be shared with SAP and what cannot. The privilege protocol becomes important in any post-audit dispute and should not be improvised mid-engagement. For more on the operational rhythm of the response, see our piece on the first 72-hour response timeline and our USMM topic page for the measurement background.
What to put on the matter file this quarter
For customers who do not currently have an audit notice but want to be prepared, three actions are worth taking inside the next thirty days. First, a desktop walk-through of the four contract clauses described above, with counsel and procurement, to confirm that the customer understands its own contracted position. Second, a documented stakeholder list and escalation path for a future audit notice, with named owners and back-up coverage. Third, a written briefing on the customer's preferred external advisor relationship, so that the day-one engagement decision can be made quickly rather than reopened under time pressure. For deeper analytical background, our SAP Audit Defence Playbook sets out the full procedural map across the engagement, and the European manufacturer audit defence case file shows how the early legal review process produced a 71 per cent reduction in the SAP opening position.