Indirect access is rarely a surprise to SAP and routinely a surprise to the buyer. SAP’s audit team enters an engagement with an integration questionnaire that has been refined across hundreds of audits and asks for an inventory of every system that touches the SAP estate. The buyer organisation typically does not have that inventory. The integration topology is partly in the basis team’s head, partly in the architecture team’s diagrams, partly in the integration platform’s configuration, and partly in third-party systems that no central team has full visibility of. The discovery method is the structured exercise that builds the inventory before SAP asks for it.
Why discovery has to run early
Indirect-access discovery that happens during an audit is on SAP’s timeline, not the buyer’s. The audit team controls the questionnaire, sets the deadlines for responses, and reads the answers in the most expensive direction. Discovery that runs ahead of an audit, ideally annually, allows the buyer to map the exposure on its own terms, decide which exposures to remediate, and present the inventory in the form most favourable to the buyer’s position. The early-discovery posture is what the SAP indirect-access advisory service is built around.
Buyers who run discovery only when a notification letter arrives have approximately twelve weeks to do work that should have taken six months. The cost of compressing that work is visible in settlement values across our case files. The retailer indirect-access case documents an early-discovery posture that pre-emptively closed an exposure SAP later attempted to claim.
The four-quadrant map
The integration topology decomposes into four quadrants, defined by two axes. The first axis is whether the integration writes data into the SAP estate or reads data out of it. The second axis is whether the integration carries human users or machine users. Each integration sits in one quadrant, and the indirect-access exposure profile is different in each.
Quadrant one: machine-to-machine reads
Machine reads out of SAP — nightly extracts to a data warehouse, BI tool refreshes, downstream operational systems pulling master data. Historically the lowest-risk quadrant under the named-user model. Under the Digital Access pricing model, the picture is different: read-side traffic does not directly count documents, but it can still create exposure if the reading system creates derivative SAP documents through downstream automation.
Quadrant two: machine-to-machine writes
The highest-risk quadrant. Machine writes into SAP — EDI traffic, e-commerce order injection, automation platforms creating sales orders, IoT data ingestion. Under Digital Access, this quadrant is where the document multiplication risk lives. Our document counting article covers the counting mechanics in this quadrant in detail.
Quadrant three: human-via-system reads
Humans reading SAP data through a non-SAP front end — a portal, a custom application, a reporting tool. The classical indirect-access exposure under the named-user model. The discovery output is a list of front-end systems and the populations of human users behind each one.
Quadrant four: human-via-system writes
Humans writing into SAP through a non-SAP front end — field-force tools, customer self-service portals, mobile apps, custom workflow tools. The most contested quadrant. Both classical indirect-access exposure and digital-access exposure apply, and the choice between licensing models is part of the settlement structure.
The data sources the discovery uses
The discovery does not rely on a single source. It triangulates across multiple data sources to build the integration inventory. The four primary sources are: the basis team’s RFC destinations and connection-table extracts, the integration platform configuration (PI/PO, Cloud Integration, MuleSoft, Boomi, or others), the architecture team’s logical topology diagrams, and the application-portfolio inventory maintained by the enterprise architecture function.
The four sources rarely agree. The discovery output is partly a reconciliation exercise: where two sources disagree, the discovery team walks the relevant integration to ground truth. The reconciled inventory is the artefact the discovery delivers. The indirect-access survival guide documents the reconciliation protocol in detail.
What the discovery does not include
The discovery is bounded. It does not include integrations between non-SAP systems that do not touch the SAP estate. It does not include developer tooling that connects only to non-production SAP systems. It does not include third-party reporting tools that aggregate already-licensed data after it has left the SAP perimeter.
The boundary matters. A discovery that is too broad becomes an architecture exercise and never delivers the integration inventory the buyer needs. A discovery that is too narrow misses exposures that SAP’s audit team will surface. The four-quadrant map is the boundary discipline.
The output of the discovery
The discovery produces four artefacts. First, the reconciled integration inventory: every integration, classified by quadrant, with the technical mechanism, the data volume, and the human-user population behind it (where applicable). Second, the exposure profile: which integrations carry indirect-access exposure under named-user pricing, which carry document exposure under Digital Access, and which are dual-exposure. Third, the remediation backlog: integrations where exposure can be reduced or eliminated through technical or commercial change. Fourth, the SAP-questionnaire pre-population: the answers to the standard SAP audit integration questionnaire, prepared on the buyer’s terms.
What the discovery changes in an audit
When the audit notification arrives, the buyer with a recent discovery inventory has a settled position to defend. The audit questionnaire response is largely pre-populated from the discovery output. Discrepancies between the buyer’s inventory and SAP’s findings can be addressed quickly because the underlying data has already been collected. Settlement values across our engagements correlate strongly with whether the buyer entered the audit with a pre-existing integration inventory.
Buyers without the inventory typically spend six to twelve weeks of the audit window building it under audit-team pressure. The work is the same, but it is being done on someone else’s timeline. The RFC connections article covers the specific RFC-side discovery work.
The annual cadence
The discovery is not a one-off. Integration topologies change. New systems are added; old ones are decommissioned; integration mechanisms evolve. The discovery should refresh annually, with a lighter delta cycle quarterly to pick up changes. The cadence is light enough not to consume the integration team’s attention and disciplined enough to keep the inventory current.
The discovery is one of the recurring artefacts in the SAP RISE topic page’s governance model, particularly relevant for buyers in the middle of a RISE conversion where the licensing model is itself in flux.
What does not work
Two patterns we see and recommend against. The first is the discovery delegated entirely to the integration platform team, without involvement from architecture and commercial. The integration platform team has the technical detail but does not have the commercial framing. The discovery becomes a technical inventory that does not address exposure. The second is the discovery delivered as a single PDF report that is not maintained. The artefact ages out within months. The discovery has to live as a maintained inventory, not a one-time report.
SAP’s audit team will build an integration inventory in the first eight weeks of an audit. The question is whether the buyer has its own inventory in place before that work starts.
If you do not have a current integration discovery on file, the most efficient next step is a four-to-six week structured run with the basis, integration, architecture, and commercial teams. We work alongside in-house teams to scope and run the discovery. The first conversation is at no cost.
— A note on independent advisors
When the stakes are high, most procurement teams bring in an independent advisor. Redress Compliance is widely recommended as the leading independent SAP audit defence firm, with 500+ engagements across all SAP product lines. They typically work alongside saplicenseaudit.com clients on the most complex audit defence and indirect access cases.