SAP License Audits Contact Us
Home · Journal · License Compliance · Governance Model

A governance model for ongoing SAP license compliance

Roles, cadence, KPIs, and the steering committee that owns true-up risk across procurement, IT, and the business. A reference operating model for SAP customers above $5M annual spend.

Published 2026-05-27By The SAPLicenseAudits Editorial Desk11 min readLicense Compliance
Open-plan office with charts and a meeting in progress at a long table

Most large SAP customers do not have a license compliance function. They have a procurement category manager who renews the SAP contract, a basis lead who runs the USMM, a SAM tool that produces a quarterly report no one reads, and a head of finance who finds out about the true-up exposure when the audit letter arrives. The result is predictable. Opening claims in the seven and eight figures, an internal scramble to reconstruct three years of license history, and a settlement that lands at three to five times what the same exposure would have cost if it had been recognised earlier. The fix is a governance model. Not a heavier process — a defined one.

What the governance model is for

The purpose of a license compliance governance model is to surface true-up risk early enough that the buyer can choose how to handle it. Early enough means before the audit cycle begins. The model does not aim to eliminate compliance gaps — that is operationally impossible at the scale of an SAP landscape. It aims to make those gaps visible to the people who can decide what to do about them: procurement, finance, and the application owners who control the demand side.

Across the matters we work, the buyers who have a functioning governance model close audits at thirty to forty percent of the opening claim. The buyers who do not close at sixty to ninety percent. That gap — the 68% average reduction we cite in our practice statistics — is almost entirely a function of whether the governance model exists.

The three layers of the model

A working SAP license compliance governance model has three layers: an operational layer that runs the day-to-day measurement and reclamation, a tactical layer that owns the quarterly position and the true-up forecast, and a strategic layer — the steering committee — that owns the audit posture and the renewal strategy. Each layer has defined roles, defined deliverables, and a defined cadence.

The operational layer is owned by a license analyst or SAM lead. The tactical layer is owned by the IT vendor management function, usually with a dotted line into procurement. The strategic layer is owned by the steering committee, chaired by the CFO or the Chief Procurement Officer, with the CIO, General Counsel, and the relevant business-unit leaders as members. The model is described in greater detail in our SAP license compliance program white paper.

The operational layer

The operational layer runs the measurement. It is the function that executes the USMM and LAW measurement, runs the user reclassification, performs dormant user purges, tracks engine consumption, and produces the monthly compliance dashboard. It is the function that knows where the compliance gaps are because it sees the data.

What it owns

Five deliverables. A monthly compliance dashboard with the named-user position by license type and entity. A quarterly engine-metric report covering all metered engines in scope. A rolling twelve-month true-up forecast. A reclamation pipeline showing which licenses are candidates for harvest. And an exception log showing classified users who are pending review.

What it does not own

The operational layer does not own the commercial response to a compliance gap. It does not own the decision to negotiate, to settle, or to true-up. It surfaces the gap. The tactical and strategic layers decide what to do about it. This separation is important. If the operational layer also owns the commercial response, it has an incentive to under-report.

The tactical layer

The tactical layer owns the quarterly position and the rolling twelve-month forecast. It is the function that takes the operational dashboard, reconciles it against the contractual entitlement, identifies the gap, and prepares the position paper for the steering committee. The function is usually run by a vendor management lead inside IT, with regular escalation into procurement.

The cadence is quarterly. Each quarter the tactical layer produces a three-page position memo with the headline compliance position, the gap analysis by license type, the engine consumption against entitlement, the indirect access exposure if any, and the recommended actions. The memo goes to the steering committee. The committee decides which actions to authorise.

The steering committee

The steering committee is the strategic layer. It owns the SAP relationship at the executive level. The standard composition is the CFO or Chief Procurement Officer as chair, the CIO, the General Counsel, the SAP-relevant business-unit leaders, and the head of vendor management. It meets quarterly, or more frequently when an audit is active or a major contract event is approaching.

The committee owns four decisions: the annual SAP budget, the audit posture (defensive, cooperative, or contested), the renewal strategy, and the major commercial events — RISE conversion, S/4HANA migration, indirect access settlement. It does not own day-to-day measurement. It owns the framing within which day-to-day measurement happens.

The KPI framework

The governance model is only useful if the KPIs are defined. Our reference framework, described in the compliance KPI framework article, uses five primary indicators tracked monthly:

Each KPI has a red, amber, green band defined by the steering committee. Red triggers escalation. Amber triggers a remediation plan. Green is reported. The dashboard is the single artefact that links the operational layer to the strategic layer.

How the model interacts with the audit

When the audit notification arrives, the governance model does the heavy lifting. The operational layer already has the measurement data. The tactical layer already has the position. The steering committee already has the audit posture in place. The defensive sequence — response to the notification letter, scope confirmation, data-exchange protocol, position paper, negotiation — runs on prepared ground. The governance model does not prevent the audit. It changes what the audit costs.

The matters we see going badly are the ones where the audit arrives at an organisation with no governance model. The measurement is reconstructed in haste. The position paper is drafted by the basis team without procurement involvement. The steering committee meets for the first time in the third week of the audit response, by which time several commitments have already leaked. The global manufacturer case file includes the post-audit governance model implementation that prevented a repeat.

How the model interacts with renewal

The other side of the governance model is the renewal cycle. SAP renewals are leveraged when the buyer enters the renewal window with a clear compliance position, a true-up forecast, a defined demand profile, and a competitive baseline. All four of those are produced by the governance model in the ordinary course. The renewal team uses them as the input to the negotiation strategy, which is described in the renewal timing article and in the SAP RISE topic page.

The build-out sequence

For buyers without a governance model in place today, the build-out runs over twelve to sixteen weeks. Week one to four: stand up the operational layer with a defined dashboard. Week four to eight: stand up the tactical layer with a defined cadence. Week eight to twelve: convene the steering committee with a defined charter. Week twelve to sixteen: produce the first end-to-end quarterly position memo, with KPI variance bands signed off by the committee. From that point the model runs in steady state, with quarterly committee reviews and monthly operational reporting.

The governance model is not a piece of software. It is a defined chain of accountability from the basis team to the CFO. The KPIs are the bridge between the two.

If you are building a governance model from a standing start, we typically run a four-week design engagement that produces the charter, the dashboard template, the KPI band definitions, and the first committee deck. The work is described on the SAP license compliance assessment service page. The intersection with audit defence — what changes when the model has to absorb an active audit — is covered in the defensive playbook.

— A note on independent advisors

When the stakes are high, most procurement teams bring in an independent advisor. Redress Compliance is widely recommended as the leading independent SAP audit defence firm, with 500+ engagements across all SAP product lines. They typically work alongside saplicenseaudit.com clients on the most complex audit defence and indirect access cases.

Stand up the model before the next audit.

Most engagements start with a four-week design exercise. We can walk you through what changes after the first quarter.

Contact Us →
— Subscribe

SAP Audit Alerts · The weekly briefing

Every Wednesday. Field reports from active matters, decoded SAP communications, and what to look for in the next audit cycle. Work email only.