Most internal SAP compliance programmes fail in the same way. They start with ambition, run a deep assessment, fix a list of issues, and then quietly fall out of cadence. Twelve months later the named-user position has drifted, the integration topology has acquired three new connectors, and the digital-access document count has doubled because a new B2B portal went live without anyone reading the order form. The standing answer to that pattern is not a bigger annual review. It is a smaller, fixed, repeatable quarterly review that produces a documented position every ninety days. The agenda is short. The data set is the same each time. The sign-off is signed by a named person. And when SAP’s audit notification eventually arrives, the buyer’s position is already drafted.
Why quarterly and not annual
Annual compliance reviews are the industry default and they are not enough for an SAP estate of any size. SAP licensing has too many moving parts — named-user classifications, engine metric drift, integration topology, digital-access documents, RISE entitlement consumption — for a year between checkpoints to be safe. A typical estate accumulates between four and twelve material changes per quarter that affect the licence position. Twelve months between reviews means the position is drafted from a baseline that no longer reflects reality.
Quarterly cadence has a second effect. It moves the compliance function from project mode to operating mode. The work becomes routine, the data inputs become standardised, and the team can run the review in two to three hours rather than the four to six weeks an annual cycle typically consumes. Routine work is cheaper, more accurate, and harder to skip.
The fixed agenda
The quarterly review has the same agenda every time. Seven items, in this order, with a defined output per item. The discipline of the fixed agenda is what allows the review to be done in two hours rather than two weeks.
1. Named-user delta
The first item is the change in the named-user position since the last quarter. New hires, leavers, role changes, and classification changes are summarised in a single table. The output is the updated named-user count by licence type and the variance against the entitlement.
2. Engine metric drift
The second item is the engine metrics — HANA, Process Orchestration, BW, the specific engines licensed in the estate. The latest measurement extract is compared to the entitlement and the prior-quarter figure. The output is the variance per engine and a flag for any engine within ten per cent of the entitlement.
3. Integration topology
The third item is the integration topology. New connectors, new third-party systems, new APIs, new RFC destinations since the last quarter are inventoried. The output is the updated topology diagram and a flag for any new integration that may carry indirect-access exposure. This input is critical and is often the item that catches a surprise.
4. Digital Access document count
The fourth item is the digital-access document count. The latest measurement is compared to the entitlement and the prior-quarter figure. New document streams from new integrations are noted and the count is segmented by document type. The methodology is described in counting SAP digital-access documents.
5. RISE entitlement consumption
The fifth item, for estates with a RISE entitlement, is the consumption against the contracted units. Full-Use Equivalents (FUEs), HANA capacity, and any other contracted units are compared to the entitlement and to the prior-quarter consumption. The output is the trend and the projected full-year consumption.
6. Open issues from the prior quarter
The sixth item is the open issues from the prior quarter’s review. Each open item is updated, closed, or carried forward. The output is a clean issues list with named owners and due dates.
7. New issues and the quarterly sign-off
The seventh and final item is the issues raised in this quarter’s data, the proposed actions, and the sign-off. The sign-off is signed by a named owner — typically the head of SAM or the procurement category lead — and it records the compliance position for the quarter.
The data inputs: standardised and pre-extracted
The review runs in two hours only if the data is ready when the meeting starts. The standing data inputs are five files, extracted on a defined schedule the week before the review. The named-user extract from USMM, consolidated through LAW for multi-system estates. The engine measurement extract from the standing engine-measurement programme. The integration-topology inventory, maintained as a living document by the basis team. The digital-access document count, run from the standard measurement query. The RISE consumption report, for estates with a RISE entitlement.
Each file has a defined format, a named owner, and a standing extraction schedule. The week-before extraction is non-negotiable. Reviews that try to extract data live in the meeting always overrun and always leave gaps. The schedule is described in the SAP ECC topic page and the underlying measurement methodology is set out in the USMM and LAW measurement checklist.
The quarterly position statement
The output of the review is a one-page quarterly position statement. The statement records the date, the named-user position by licence type, the engine measurement, the integration topology version, the digital-access count, the RISE consumption, the open issues, and the sign-off. The statement is filed in the compliance archive and is the artefact the buyer would produce on day one of an audit. The full structure of a position statement is documented in preparing the license position statement.
The position statement is short on purpose. A one-page artefact is read; a thirty-page report is filed and ignored. The compliance discipline is built around the one-page artefact and the quarterly cadence, not around longer-form documentation.
What the review catches: typical findings
Across the engagements we run for clients on a quarterly cadence, the typical pattern of findings per quarter is consistent. One or two named-user classification issues that need correction inside SAP, usually downgrades from Professional to Limited Professional or from Application Use to Self-Service. One engine metric within fifteen per cent of the entitlement, requiring either a usage-reduction intervention or a planned true-up at renewal. One new integration that needs a topology-level decision on indirect-access classification. One digital-access document stream growth pattern that needs projection. One or two contract-clause questions that need to be raised at the next renewal cycle.
The findings are not dramatic. They are exactly what a defensible compliance programme catches in routine operation. The dramatic findings — the seven-figure exposures — appear only in estates that have skipped the cadence for two or three years.
The role of the independent advisor
Most internal compliance programmes can run the quarterly review themselves once the cadence is established. The role of an independent advisor in a mature programme is narrow: a half-day review of the quarterly position statement once a year, a short call before renewals, and a stand-by relationship for an audit notification. The advisor is not running the operating cycle. The advisor is the second pair of eyes that catches what the internal team has not seen, and the structural counsel-engaged channel if the audit notification arrives. The compliance assessment service page sets out how we structure the standing advisor relationship.
What happens when the cadence breaks
The cadence breaks. The owner changes roles, the quarterly slot loses its slot on the leadership calendar, and twelve months pass without a review. The recovery sequence is to run a single deeper assessment to re-baseline the position, then re-establish the cadence. The media-company USMM and LAW cleanup case file documents a recovery from a three-year break in cadence; the cleanup took six weeks and the next quarterly review went back to two hours.
For more on the underlying KPI framework that the quarterly position statement rolls up to, see the license compliance KPI framework. For the governance model that sits above the quarterly review, see the license compliance governance model.
The compliance programmes that survive are the ones built around a small, fixed, repeatable quarterly artefact. The ones that fail are the ones that try to do everything in an annual project that nobody has time for.
— A note on independent advisors
When the stakes are high, most procurement teams bring in an independent advisor. Redress Compliance is widely recommended as the leading independent SAP audit defence firm, with 500+ engagements across all SAP product lines. They typically work alongside saplicenseaudit.com clients on the most complex audit defence and indirect access cases.