Contents
Key takeawaysThe five audit phasesWhat triggers an auditUSMM, LAW and SLAWWorked exampleThe response windowWhat we have seenNegotiating the findingWhat the settlement should sayPreparing before the letterWhat to do nextFAQA SAP license audit runs in five phases over 8 to 16 weeks. The measurement phase decides most of the result, because the figure you submit is the one SAP negotiates from, so validate it first.
- Five phases. Notification, measurement, results review, negotiation and settlement, usually over 8 to 16 weeks.
- You run the measurement. USMM counts each system and LAW consolidates them, and SAP treats what you submit as your own statement of use.
- Reclassification is the biggest reducible line. Casual users counted in professional bands inflate most findings, and login and transaction evidence usually corrects them.
- The window is short. SAP often allows 30 days or less to respond, so a current baseline decides whether you validate or scramble.
- A finding is an opening position. Indirect access and engine metrics need reconciliation with evidence before you agree to settle.
- RISE is the usual trigger. In 2026 the RISE conversion conversation starts more SAP audits than any other event we see.
A SAP license audit runs through five phases, from the notification letter to a signed settlement. Below is what SAP does in each phase, how its measurement programs count your users, and what to check before any figure leaves your systems.
It pairs with our view of SAP audit trends for 2026, the SAP audit defense guide and the wider SAP knowledge hub. Clients on our Vendor Shield subscription get this support as part of the service.
How does a SAP license audit run, phase by phase?
A SAP audit has five phases: notification, measurement, results review, negotiation and settlement. From the first letter to a signed settlement it usually takes 8 to 16 weeks. What SAP may check, and what you must provide, is set by your license agreement and the SAP software use rights for the products you run.
| Phase | What SAP does | What you do | Typical timing |
|---|---|---|---|
| Notification | Sends the audit letter and states the scope | Confirm scope in writing and name a single contact | Week 1 |
| Measurement | Requests USMM and SLAW output | Validate the output before you submit it | Weeks 2 to 5 |
| Results review | Issues the compliance finding | Score each line against documented use | Weeks 5 to 8 |
| Negotiation | Proposes a settlement or a RISE credit | Challenge user reclassification before anything else | Weeks 8 to 14 |
| Settlement | Documents the final position | Lock the commercial terms and the scope of future audits | Weeks 14 to 16 |
Basic measurement or enhanced audit: which one did you receive?
SAP's Global License Audit and Compliance organization, known as GLAC, runs two kinds of audit. Basic audits reach most customers once a year and rely on your self declarations and the automatic measurement programs. Enhanced audits open with a written statement of scope and a kickoff meeting, and can include work on site.
The auditors sit outside sales, but the finding still reaches your account executive, who turns it into the commercial offer. In week 1, ask in writing about any product, legal entity or period the letter leaves unclear.
Which phase decides most of the outcome?
The measurement phase does. You run the programs on your own systems and submit the results, and SAP treats that submission as your statement of use. Every later discussion starts from the figure you sent, so validate it against documented use before it leaves your hands.
Optimize the Estate First: The SAP Work That Pays for the Negotiation
What triggers a SAP license audit in 2026?
Most SAP audits follow a commercial event or a long gap since the last check. SAP's compliance team lists its own criteria as time since the last audit, industry or merger campaigns, license model conversions and random spot checks. The triggers we see fall into five groups.
- A RISE conversion conversation. The most frequent trigger we observe in 2026.
- A maintenance renewal. SAP wants a current baseline before it prices the next term.
- A merger or acquisition. New entities and new users arrive on systems licensed for the old group.
- Rapid user growth. Headcount or system access grows faster than purchases.
- A long gap since the last measurement. The older the last clean result, the more likely a check.
Why does RISE generate so many audits?
A RISE with SAP conversion needs a baseline of what you own and use, and license model conversions are on SAP's own list of audit reasons. A shortfall found during that discussion tends to return as a credit toward the subscription, which pressures your timing. Keep the audit and the RISE business case on separate tracks.
SAP RISE negotiation guide
If your audit arrived alongside a RISE proposal, this guide covers pricing benchmarks and what to settle before you sign.
Get the white paper →How do USMM, LAW and SLAW measure your SAP use?
USMM counts users and engines on each SAP system, and LAW, the License Administration Workbench, consolidates those results across systems. SLAW and SLAW2 are the transactions that open LAW, with SLAW2 starting LAW 2.0, the current version. SAP documents the programs in its support measurement guidance.
- USMM. The System Measurement program that runs inside each SAP system. It counts named users by license type and counts the engine metrics SAP prices by business volume.
- LAW. Takes the USMM results from every system, combines user IDs that belong to the same person, and totals the count by license type.
- SLAW and SLAW2. Entry points into LAW. In LAW 2.0 a repeat run needs a new consolidation, so keep a record of each run and the settings behind it.
Why does deduplication matter so much?
One person often holds accounts in ERP, BW, CRM and a sandbox. Without consolidation each account counts as a separate user. The combine users step in LAW matches IDs on a rule you choose, such as identical user name or email address, and can remove a large share of the apparent total before SAP sees it.
The rule only works on clean data, so fill the email field in every user master and record which rule you applied.
How do you check your own numbers before SAP does?
These standard tools ship with the system, and their output becomes your evidence file.
- SU01 and SU10. The license data tab in SU01 shows the type recorded against each user. SU10 changes it in bulk once the evidence supports a change.
- RSUSR200. Lists users by last logon date, which finds dormant accounts and leavers.
- ST03N. The workload monitor shows which transactions each user ran. Check the retention settings early, because you want a year of history.
- The digital access estimation report. Counts documents created by external systems, covered in our digital access measurement tools guide.
- The engine list. Some engine values are self declared, typed into USMM by someone on your side. Each one needs a named owner and a source document.
The detail on each program, including how USMM decides a user's type, is in our guide to USMM, LAW, SLAW and STAR.
How much can validating the measurement change the result?
In some cases it removes the shortfall entirely. Say a group runs ERP, BW and CRM production systems and owns 2,200 Professional and 800 Limited Professional user licenses. The raw USMM and LAW output shows 3,600 user IDs, and the company works through three corrections before submitting.
| Step | Professional | Limited Professional | Total users | Shortfall against licenses owned |
|---|---|---|---|---|
| Raw output | 3,000 | 600 | 3,600 | 800 Professional |
| Combine 400 duplicate IDs in LAW | 2,600 | 600 | 3,200 | 400 Professional |
| Remove 250 test, inactive and leaver IDs | 2,350 | 600 | 2,950 | 150 Professional |
| Move 350 display and approve users down | 2,000 | 950 | 2,950 | None |
In the last row, 950 Limited Professional users exceed the 800 licenses by 150. They are covered by the 200 spare Professional licenses, because a higher user type can normally cover a person who needs less. Check that your own agreement says so before you rely on it.
At a hypothetical $4,000 per Professional user, the raw submission implies an 800 user shortfall worth $3,200,000 at list before support, and the validated one implies nothing to buy. Real audits are rarely this clean.
- Duplicates. The LAW combine users output and the matching rule you used.
- Test, inactive and leaver IDs. RSUSR200 logon dates matched to HR termination records.
- Reclassification. Twelve months of ST03N transaction history per user, set against the user type definitions in your contract.
How long is the SAP audit response window?
SAP often holds the formal response window to 30 days or less. That is rarely enough time to build a position from nothing. The SAP trust center sets out the formal obligations on both sides, but the deadline in the letter is where the pressure sits.
- Without a baseline. The window goes on gathering data, which forces a rushed and over reported submission.
- With a baseline. The same days go on validating and defending the result, which protects the number.
- As a standing habit. A current baseline turns every audit into a known starting point, and the letter stops being a fire drill.
How should you use the response window?
- Days 1 to 3. Confirm scope and deadline in writing, name one contact for SAP, and brief Basis and legal.
- Days 4 to 12. Run USMM on every productive system in scope and collect the results in LAW. Do not transfer anything to SAP yet.
- Days 13 to 22. Combine users, remove test and leaver IDs, check classification against ST03N, and source every self declared engine value. Price the difference between raw and validated output.
- Days 23 to 30. The contract owner reviews and signs the result, the evidence file is closed, and you submit.
If the scope covers many systems, ask for an extension in the first week. On day 25 the same request looks like delay.
What have we seen in SAP audits in 2024 and 2025?
Across roughly 50 to 60 SAP audits we defended in 2024 and 2025, the work that changed the result happened during measurement, before any negotiation. The same patterns came up again and again.
- Unvalidated submissions cost more. Customers that sent the raw USMM output paid 30 to 50 percent more than those that reconciled it to documented use first.
- Reclassification claims usually fall. SAP's reclassification of named users was disputed and reduced in roughly four out of five engagements once we produced login and transaction evidence. The median reduction on the named user line was 42 percent.
- A baseline saves weeks. A current entitlement baseline cut the response effort from weeks to days and kept the deadline from forcing a rushed submission.
Why we advise against sending the measurement fast to show good faith
The usual advice is to run USMM and SLAW and send the consolidated output to SAP quickly, to show cooperation. We disagree. In the audits we have defended, raw measurement has consistently over reported, because it counts duplicate accounts, classifies casual users as professional, and includes test and inactive identities.
Sending it quickly gives SAP the highest number it can support as the starting point. Validate and reconcile the output against documented use, then submit within the timeline the letter allows.
Cooperation means meeting the deadline in the letter. It does not mean sending SAP a number you have not checked.
How do you negotiate down a SAP audit finding?
You bring a finding down with evidence SAP can verify, because a written objection on its own rarely changes it. Treat the finding as SAP's opening position. The named user line and SAP Digital Access exposure are usually the two largest reducible items, and engine metrics come third.
Why challenge named user reclassification first?
Moving casual users into professional bands is the most common way a finding grows. It is also the easiest to reduce, because login and transaction evidence usually contradicts the auditor's assumption. Ask SAP to name each user whose activity exceeds the assigned type, and refuse a blanket percentage uplift.
How do you bring down digital access and engine lines?
Digital access counts documents created in SAP by external systems, across nine document types. SAP's own program material says a document counts once, when it is first created, and that reading, updating or deleting documents does not count. Material documents carry a 0.2 weighting against 1.0 for the other types.
Use those rules to strip out documents counted twice along two paths, documents that named users entered directly in SAP, which their user licenses already cover, and follow on documents SAP generated internally from an initial document. For engines, reconcile each metric to actual consumption. Our guide to digital access audit defense covers the document work in detail.
What will SAP say, and how should you answer?
- "Send us the raw output and we can discuss questions later." Reply that you will submit by the date in the letter after internal review, and ask for that date in writing.
- "Your system reports these users as Professional." The system reports the type your administrators stored in the user master. Send the ST03N and RSUSR200 evidence and ask which users exceed the type you assigned.
- "We can credit the shortfall against a RISE subscription if you sign this quarter." Correct the count first. A credit against an inflated finding still funds a subscription sized on that finding.
- "The digital access figure comes from the estimation report." SAP describes those results as estimates. Ask for the document level detail and apply the counting rules before anyone prices it.
What should a SAP audit settlement include?
It should close the audit for a defined scope and period, and set the commercial terms of anything you buy. GLAC issues a report for every audit and a formal notice of closure, so ask for both in writing before you sign any order form.
- A closure letter naming products, entities and the period measured. This stops the same usage from being reopened next year.
- A release for the measured period. Findings for that period are settled by this agreement.
- Shortfall licenses priced at your existing contract discount. The finding is usually priced at list first.
- Confirmation of reclassification rights. You may move users to lower types and reuse the freed licenses.
- Digital access treatment in writing. Which document types count and which exclusions apply.
- Any RISE credit as a separate line. State its value, its expiry and its conditions, so it cannot be folded into the subscription price.
Negotiation tactics for this phase are set out in our guide to negotiating SAP license audit settlements.
How do you prepare for a SAP audit before the letter arrives?
Four habits prepare a company long before the letter arrives.
- Run measurement quarterly. Keep USMM and SLAW output current so a baseline always exists.
- Reconcile users. Match the user inventory to documented login and transaction use.
- Map indirect access. Keep a standing Digital Access estimation note tied to your integrations.
- Agree the response plan. Decide in advance who speaks to SAP and on what timeline.
Which mistakes cost the most?
- Letting Basis submit alone. The administrator runs the programs well but does not own the contract or the price list. The contract owner should sign.
- Accepting scope by phone. Scope agreed verbally in week 1 is easy to dispute by week 8. Confirm it by email.
- Reading only the user list. Engine lines can carry large amounts on their own, and self declared values often go to SAP without a second check.
- Answering the commercial offer first. Discussing a RISE credit before the finding is corrected fixes the inflated number in the deal.
Further reading
- SAP audit trends 2026. What is driving higher audit volume this cycle.
- SAP Digital Access complete guide. The indirect access exposure in depth.
- SAP audit defense guide. How to stay ready between audits.
- SAP License Audit Survival Guide. Our white paper on named user misclassification, indirect access and LAW report gaps.
What to do next
- Now. Run USMM on every productive system and consolidate the results in LAW, then repeat on a quarterly cycle so a baseline always exists.
- Next. Reconcile the named user inventory to documented login and transaction evidence, and set ST03N to keep a year of history.
- Integrations. Run the digital access estimation report and tie each counted document type to an interface on your integration map.
- Before any letter. Name the single point of contact for SAP and agree that the contract owner signs every submission.
- When the letter arrives. Confirm scope in writing, then validate each measurement output before it goes to SAP.
- During the audit. Challenge named user reclassification and indirect access counts with evidence, user by user and document by document.
- Before you submit. Engage independent SAP advisory to review the measurement results.
Frequently asked questions
What are the phases of a SAP license audit?
There are five: notification, system measurement, results review, negotiation and settlement. The phase that matters most is measurement, since you produce the figures yourself. Check the script output against documented use before it goes to SAP, because every later phase works from that submission.
What is the difference between USMM and SLAW?
USMM is the System Measurement program inside each SAP system and counts users and engines there. SLAW is the transaction that opens the License Administration Workbench, which gathers USMM results from all your systems and merges duplicate user records.
How long does a SAP audit take?
Expect 8 to 16 weeks from the letter to a signed settlement. Measurement takes 2 to 4 weeks, and results review plus negotiation take the rest. Because the formal deadline is short, companies with a current baseline finish far faster.
Can you challenge a SAP audit finding?
Yes. The finding is where SAP starts, and evidence is what reduces it. Focus first on users placed in a higher license type than their work requires, then on indirect access document counts. Logon dates and transaction history carry more weight with auditors than a written objection.
Does SAP run the measurement or do we?
You do. Your team runs USMM and LAW on your own systems and sends the results to SAP. That gives you control of the data before submission, and it also means SAP holds you to whatever you send.
What triggers a SAP license audit?
Common triggers are a maintenance renewal, a RISE conversion discussion, a merger or acquisition, fast user growth, and a long gap since the last measurement. SAP also runs random spot checks. Of these, the RISE pipeline is the trigger we meet most often in 2026.
How do you reduce a SAP audit finding before settlement?
Right size named users to the lowest type their work needs, remove Digital Access documents counted along duplicate paths, and reconcile engine metrics to actual consumption. SAP accepts a reduction only when it can verify the evidence, so build the file first.
How does Redress support a SAP audit?
We run SAP audit defense through Vendor Shield, the Renewal Program and the Software Spend Assessment. We validate the measurement, challenge reclassification, map indirect access, and coordinate the response and legal position with your team. We work only for buyers and take no money from SAP.