SAP Audit Defence
End-to-end audit response. We take control of the matter the day the letter arrives, define scope in writing, validate every measurement, and negotiate the settlement.
Read the brief →A Fortune 100 manufacturer defended a four-line audit claim across USMM, engine measurement, indirect access, and Digital Access, settling at sixty-four per cent below opening.
Every result on this site is anonymised at the client's request. Specific figures are real and verifiable through a confidentiality-protected reference call arranged on request.
The client is a Fortune 100 industrial manufacturer with operations across the United States, DACH, APAC, and LATAM regions. The SAP estate is ECC 6.0 with an S/4HANA pilot for the corporate finance reporting line, fourteen engine licences layered around the core, and a named-user population of approximately sixty-one thousand four hundred users globally.
The engagement was triggered by a Global License Audit and Compliance notification covering four distinct claim lines. The opening position aggregated to nineteen million dollars and referenced an over-classification in USMM, an engine measurement on Process Orchestration, an indirect-use exposure across three non-SAP applications, and a Digital Access document count that had not previously been disclosed to the manufacturer.
What was at stake was both the headline claim and the precedent it would set for the manufacturer's annual measurement submissions across the remaining seven years of the master contract. The procurement leadership had taken the view that the matter required external counsel from the day the letter arrived.
Line one, valued at six point three million dollars, concerned USMM over-classification. Approximately five thousand two hundred users were classified in the Professional band against contractual entitlement that supported four thousand. The opening letter applied the shortfall at list rate.
Line two, valued at four point eight million dollars, concerned engine measurement on Process Orchestration. The measurement counted internal system-to-system traffic as chargeable, against a contractual definition that excluded such traffic. The opening figure was approximately seven times the contracted value.
Line three, valued at five point four million dollars, concerned indirect-use exposure across a custom dealer portal, a third-party CRM integration, and a quality management interface. The opening position treated each application as a discrete exposure line with no consolidation.
Line four, valued at two point five million dollars, concerned a Digital Access document count extrapolated from a sample period. The methodology applied a price tier the manufacturer had not previously seen in writing.
The defence opened with a single procedural letter narrowing scope on all four lines simultaneously. The letter established a defined data-exchange protocol and confirmed that no informal conversations between SAP and the manufacturer's regional teams would continue during the defence window.
On the USMM line, the team rebuilt the classification against twelve continuous months of transaction-history evidence. The rebuild reclassified approximately one thousand seven hundred users out of the Professional band into Limited Professional, Employee Self-Service, or operational categories. The corrected Professional population sat within contracted entitlement.
On the engine measurement line, the team reconstructed the message-count methodology from raw measurement output. Internal system-to-system traffic was identified and removed, reducing the measurement to approximately one point one times contracted value, not seven.
On the indirect-use line, the team documented the integration topology end to end. The custom dealer portal and the quality management interface were established as non-chargeable under the contract definitions in force. The CRM integration produced genuine exposure, which was converted to Digital Access at a negotiated document tier rather than retained as indirect use.
On the Digital Access line, the team rebuilt the document count against twelve continuous months of posting evidence. The corrected count was approximately forty per cent of the extrapolated figure.
Settlement closed at six point eight million dollars across the four lines combined. The USMM line settled at a small contracted-discount true-up. The engine measurement line was rewritten in the contract to exclude internal traffic explicitly. The indirect-use line was converted to a single Digital Access agreement with a measurement cap. The Digital Access line was reconciled against the rebuilt count.
Five contract elements were rewritten or annexed. The measurement methodology was annexed with worked examples for each named-user band and each engine metric. The audit-rights clause was narrowed to a two-year cycle with sixty days' notice and a defined data-exchange scope. A Digital Access measurement cap was added for the remaining contract term. A re-measurement protection clause was added. A settlement-as-release clause was included confirming no further claim on the audited period.
Total elapsed time from notification to signed settlement was seventeen weeks. The settlement closed the matter within a single quarter, allowing the manufacturer to remove the contingent liability from its quarterly disclosures.
Across the matters the firm closes each year, the same defensible procedures recur. The following observations apply directly to other SAP estates of comparable scope. A reading of the SAP ECC topic page and the SAP Audit Defence Playbook white paper expands the underlying framework.
Further analysis on this defence pattern is collected in the Audit Defence reading room.
Four lines, two regions, eighteen weeks. The matter was complex but the procedure was the same on every line: anchor scope, rebuild evidence, present once.
End-to-end audit response. We take control of the matter the day the letter arrives, define scope in writing, validate every measurement, and negotiate the settlement.
Read the brief →We model multiple settlement structures, validate every metric against operational evidence, and negotiate clauses that protect against silent re-measurement.
Read the brief →The reading room cluster covering field notes, defence sequences, and contract levers for audit defence matters.
A Fortune 500 industrial group rebuilds its user model and engine measurement, settling at sixty-eight per cent below opening.
A global retailer rebuilds its integration topology and reduces an $11M Salesforce indirect-use claim to $1.9M.
An audit notification, a renewal quote, or a USMM cycle in flight — the first conversation is at no cost and under privilege. $180M+ in client savings across 500+ engagements, with a sixty-eight per cent average claim reduction. Twenty years on this work.
Contact Us →Every Wednesday. Field reports from active matters, decoded SAP communications, and what to look for in the next audit cycle. Work email only.