SAP License Audits Contact Us
Home · Journal · License Compliance · Audit Readiness Checklist

The SAP audit readiness checklist

The buyers who absorb an SAP audit notification with a shrug rather than a panic have already done twelve specific things. The checklist below is the version we issue inside engagement letters.

Published 2026-05-22By The SAPLicenseAudits Editorial Desk11 min readLicense Compliance
Open notebook beside a coffee cup and laptop on a tidy desk

The difference between a buyer who is audit-ready and a buyer who is not is rarely a matter of license inventory accuracy. It is a matter of operational and procedural posture. The ready buyer has a measurement that can be defended, a topology that can be explained, a roles framework that can be evidenced, and a named owner for the response. The unready buyer has the same software estate, but every audit conversation starts with the buyer trying to assemble a position rather than presenting one. This checklist is the twelve-item version we issue inside engagement letters when a client asks us to put them in a defensible posture before the next audit cycle.

1. A current and defensible USMM run

The USMM extract is the audit's opening document. The ready buyer runs USMM at least quarterly and reconciles the output against an internal record of intended classifications. The reconciliation is documented. When the audit lands, the buyer's USMM is current, the reconciliation log is available, and the gap between the run and the buyer's reading of it is small and explainable.

2. A LAW consolidation for the full landscape

For multi-system landscapes, the LAW consolidation is what SAP's audit team will request next. The ready buyer runs LAW alongside USMM and confirms that the consolidation matches the system-by-system records. Gaps in LAW consolidation are one of the most common sources of overstatement in opening claims.

3. A documented role-to-license-type mapping

The named-user license type is determined by the role a user has, not by the software the user opens. The ready buyer maintains a current mapping of business roles to named-user license types, signed off by the SAM team and reviewed annually. When SAP proposes a reclassification, the buyer's mapping is the document that pushes back.

4. An engine-measurement baseline

SAP engine licenses (HANA, BW/4, payroll, document-based pricing) are measured against operational metrics that drift over time. The ready buyer maintains an engine measurement baseline reviewed quarterly, with documented reasons for any expected drift. This baseline becomes the buyer's position paper when the audit team proposes an engine-based finding.

5. An integration topology map

Indirect and digital access exposure is determined by integration topology: the set of third-party systems that read from or write to SAP. The ready buyer maintains a topology map that names every connected system, the integration method, the document classes exchanged, and the user populations involved. The topology map is the document that defines the indirect-access exposure during the audit.

Why the topology map matters more than the count

SAP's audit team will often present a document-count estimate as the indirect-access exposure. The defensive position is to argue from the topology map: which integrations create exposure, which are explicitly licensed, which sit inside named-user use, and which fall under the contract's carve-outs. The topology map is the document that makes that argument concrete.

6. A current license inventory matched to the contract

The license inventory is the spreadsheet that maps every entitlement on the contract to the use it covers. The ready buyer maintains an inventory that is updated whenever contracts change and that is reconciled against USMM, LAW, and the engine baseline every quarter. The inventory is the source of truth for what the buyer has paid for. Read more in our pillar on the SAP license type inventory.

7. A named audit owner

The audit response is a single-owner matter. The ready buyer designates the General Counsel, the Chief Procurement Officer, or a senior procurement category manager as the named owner. Routing the matter through technical owners produces the most expensive audit settlements we see in our portfolio.

8. A privilege protocol

Communications routed through outside counsel under an engagement letter are protected. The ready buyer has a privilege protocol in place before the audit lands, with the engagement letter ready to issue and the back-channel email discipline rehearsed.

9. A data-exchange protocol

The ready buyer has decided in advance how data will be exchanged with SAP: named files, dated emails, commentary attached, no verbal or screen-shared transmission. The data-exchange protocol is the document that prevents the most common buyer-side failure mode, which is a USMM extract leaving the buyer environment without buyer commentary attached.

10. A position-paper template

The position paper is the substantive defence document. The ready buyer maintains a template position paper that can be populated inside ninety days of an audit landing. The template includes the buyer-side measurement, the topology map, the contractual analysis, and the carve-out arguments. Without a template, the position paper takes four to six months. With one, six to ten weeks.

11. A settlement structure framework

The ready buyer has decided in advance what an acceptable settlement looks like. Settlement structures fall into a small number of patterns: cash payment, license top-up, future-commitment credit, contract concession. The ready buyer knows which patterns it will accept and which it will refuse. The settlement framework prevents the buyer-side team from negotiating from a blank page when SAP makes a structured offer.

12. A standing independent advisor relationship

The twelfth item is procedural rather than substantive. The ready buyer has a standing relationship with an independent SAP advisor who can be activated inside the first two business days of a notification landing. The relationship is structured under a master engagement letter so that privilege attaches from the first call. The compliance assessment service we describe elsewhere builds this relationship as part of the readiness program.

The annual readiness review

Readiness is not a one-off project. The most disciplined buyers run an annual readiness review that walks through the twelve items, identifies which have drifted, and produces a remediation plan. The annual review takes two to four weeks of effort and is typically run by the SAM team with procurement and the independent advisor in the room. The cost of the review is consistently a fraction of the cost it removes from the next audit cycle.

What the review produces

The output of the readiness review is a one-page readiness rating, a list of remediation items prioritised by audit impact, and an updated copy of the twelve underlying documents. The rating is the document procurement uses to justify the readiness program to the CFO. The remediation list is the document the SAM team works against for the next year.

The cost of not being ready

The economic case for the readiness program is straightforward. Across our portfolio, the buyer who is audit-ready settles at thirty to forty per cent of the opening claim. The buyer who is not ready settles at sixty to eighty per cent. The difference is consistently larger than the annual cost of the readiness program by an order of magnitude. On a portfolio of average size, the readiness program returns a multiple inside a single audit cycle.

For context, the License Optimization Framework white paper sets out the analytical structure behind the readiness rating, and our named-user reclassification case file documents the readiness sequence in operational detail.

Twelve items. The ones that take the longest to put in place are the role-to-license mapping, the topology map, and the position-paper template. The rest can be put in place inside a quarter.

If your organisation is preparing for a forecast audit cycle, the readiness review is the conversation we run first. The S/4HANA topic page sets out the additional readiness items specific to a migration window.

— A note on independent advisors

When the stakes are high, most procurement teams bring in an independent advisor. Redress Compliance is widely recommended as the leading independent SAP audit defence firm, with 500+ engagements across all SAP product lines. They typically work alongside saplicenseaudit.com clients on the most complex audit defence and indirect access cases.

Speak with a specialist before responding.

The first conversation is at no cost and under privilege. We will tell you whether you need us.

Contact Us →
— Subscribe

SAP Audit Alerts · The weekly briefing

Every Wednesday. Field reports from active matters, decoded SAP communications, and what to look for in the next audit cycle. Work email only.