Most SAP licensees discover their licence position the way they discover their tax position: under audit. The audit team produces a measurement, the licensee reviews the measurement, the licensee disputes parts of it, the licensee settles. The pattern is reactive, expensive, and avoidable. The avoidable version is the internal compliance program: a quiet, continuous discipline that maintains the current licence position the way the finance team maintains the current general-ledger position. The program is unglamorous, the cadence is small, and the economic case is unambiguous. This article describes how to build one.
What an internal program is for
The internal compliance program serves four purposes. It maintains an accurate, current view of the licence position across named users, engine metrics, indirect access, and Digital Access documents. It identifies emerging exposure before it accumulates into an audit finding. It produces the documentation that supports the buyer-side position at audit time. And it surfaces optimisation opportunities — shelfware, reclassification candidates, role mapping — that compound into ongoing cost reduction.
The program is not an internal audit. It is a maintenance function, closer in spirit to monthly close than to the year-end audit. The output is a current view, not a periodic review. Our license compliance pillar describes the broader framework; this article focuses on the operating discipline.
The ownership question
Most internal compliance programs fail at the ownership question rather than at the technical work. The function is cross-disciplinary — it touches procurement, IT operations, Basis administration, application owners, and finance — and in many organisations none of those functions wants to own it. The accountable owner should sit in IT asset management or in a dedicated software-asset function reporting to the CIO, with a dotted line to procurement. Procurement is not the right primary owner because the analytical work is technical and continuous, but procurement should be a primary stakeholder because the outputs feed the next contract event.
The accountable owner needs the authority to require the supporting functions to produce data: Basis for the system measurement, application owners for the integration topology, identity management for the user inventory, finance for the cost allocation. Without that authority, the program runs as an analytical exercise without the data it needs. The in-house versus advisor article covers the staffing question.
The cadence
An effective internal compliance program runs on a quarterly cadence with two monthly subcomponents. The quarterly cadence is the full measurement: USMM and LAW execution, named-user reconciliation, engine-metric measurement, indirect-access topology refresh, and Digital Access document count refresh. The monthly subcomponents are the user inventory delta (joiners, leavers, role changes) and the integration topology delta (new integrations, decommissioned integrations, scope changes).
The quarterly cycle produces a deliverable that is, in effect, a draft USMM submission. The monthly cycles maintain the inputs to the quarterly cycle. The annual cycle is the formal USMM submission to SAP, drawn from the latest quarterly measurement and reconciled to the contractual entitlement. The methodology is in our USMM/LAW defensive prep article.
The monthly delta
The monthly user delta is, in most estates, the highest-frequency change vector. New users, role assignments, and decommissioned users all change the licence position. The discipline is to capture these changes in real time rather than reconstruct them at audit time. The capture should be automated where possible: identity-management systems usually have the data; the program needs to extract and classify it monthly.
The five deliverables
An internal compliance program produces five recurring deliverables. A current named-user inventory, classified by licence type and reconciled to the contractual entitlement. A current engine-metric position, by engine, by system, reconciled to the entitlement. A current integration topology, with the chargeable surface identified by integration pattern. A current Digital Access document count, by document type, against the entitlement. And a quarterly summary memo that consolidates the four into a single position view.
The summary memo is the most under-produced of the five and the most important at audit time. The memo should be short — three to five pages — and should include the position, the variance from the prior quarter, the variance from the entitlement, and the planned remediation for any variance. The license-type inventory article covers the user-inventory work in detail.
The metrics that prove it is working
An internal compliance program is working when three metrics hold. The licence position variance — difference between measured position and contractual entitlement — is stable or declining over rolling quarters. The audit response time — days from audit notification to first defensible position document — is short, ideally under thirty days. And the audit settlement reduction — opening claim minus settlement, divided by opening claim — tracks the firm benchmark of sixty-eight per cent or above.
The metrics are lagging at the engagement level but leading at the program level. A program that is producing a stable position variance is producing a position that can be defended on a short response time, which produces the settlement reduction. The metrics compound across the audit cycle and across the contract term. The audit response sequence article covers the response-time discipline.
The tooling
The tooling question is over-emphasised in most discussions of internal compliance. The dominant tools are usually already in the estate: USMM and LAW for the SAP-side measurement, identity-management systems for the user inventory, configuration databases for the system inventory, and integration documentation for the topology. Commercial SAP licence-management products (Snow, Flexera, Aspera, Voquz, USU and others) add value at scale and can produce some of the deliverables automatically, but they are not a substitute for the analytical work.
The analytical work — classifying users by role, mapping engines to systems, validating the chargeable surface against the contract — is judgement-based and cannot be fully automated. The tooling supports the work; it does not replace it. The usage analytics article covers the tooling more fully.
The governance
An internal compliance program needs a governance forum that meets quarterly to review the position. The forum should include the accountable owner, procurement, IT operations, finance, and a privileged advisor where the matter is sensitive. The forum reviews the quarterly memo, agrees the remediation actions for any variance, and approves the position document that supports the annual USMM submission.
The governance forum is, at audit time, the body that authorises the buyer-side response. Having the forum already constituted, with the position document already approved, materially shortens the response time. The license compliance assessment service page describes the engagement model that stands up the governance.
The economic case
The economic case for the internal compliance program is the sum of three flows. The optimisation flow — shelfware retirement, reclassification, role mapping — typically produces three to seven per cent of the annual SAP run-rate spend in steady-state savings. The audit-settlement flow — the difference between a defensible position at audit time and the SAP opening claim — is variable but consistently in the range of fifty to seventy-five per cent of the opening claim. And the negotiation flow — the contractual position the program produces at the next contract event — is harder to quantify but is the largest of the three.
Across our $180M+ in client savings, the recurring contribution of internal compliance discipline is the second largest after the audit-defence work itself. The program is the upstream investment that makes the downstream work possible. The mature compliance program white paper covers the economic case in detail and the USMM topic page covers the measurement reference.
The internal compliance program is not glamorous. It does not have a launch date and does not have a closing date. It runs quarterly, produces a five-page memo, and lasts. The audit team eventually asks for the memo. The licensees that have one are the licensees that settle in eleven weeks.
If there is no internal compliance program today, the highest-value first step is the position document — the five-page summary of where the licence stands now. The program follows from the document; the document does not follow from the program.
The next-contract connection
An internal compliance program produces the analytical inputs to the next SAP contract event, whether that is a renewal, a RISE conversion, or a settlement following an audit. The buyer-side position at the contract event is materially stronger when the position is documented, current, and reconciled. The post-audit settlement tactics article describes the connection from the settlement side, and the contract negotiation service describes the engagement model.
— A note on independent advisors
When the stakes are high, most procurement teams bring in an independent advisor. Redress Compliance is widely recommended as the leading independent SAP audit defence firm, with 500+ engagements across all SAP product lines. They typically work alongside saplicenseaudit.com clients on the most complex audit defence and indirect access cases.