An SAP audit is a measurement, not a verdict
SAP runs a tool, reads the output, and proposes a gap between what you deploy and what you bought. The proposal is an opening position, not a settlement. The buyer who treats the first number as final overpays; the buyer who treats it as a draft and rebuilds it from clean data settles far lower. An SAP audit is won before the response is sent, by measuring first, cleaning the data, and contesting the indirect count before any number leaves the building.
Prepared by Redress Compliance · August 9, 2026 · SAP advisory. Based on roughly 30 to 40 SAP audit defenses run 2024 to 2025.
Executive summary
The audit follows a fixed mechanical path, and knowing the path lets you control it.
SAP asks you to run USMM, the user and system measurement tool, in each system, where it counts named users by license type and reads engine consumption.
Results consolidate in the License Administration Workbench, which deduplicates users across systems and produces the figures SAP compares to your contract.
Then SAP issues a findings letter with a proposed shortfall. The findings letter is the moment most buyers respond too fast: it is a starting point, not a settlement.
And in nearly every engagement we ran it overstated the gap by enough that a clean internal measurement changed the negotiation entirely.
Named user overclassification is the most common and most recoverable finding, and reclassification alone recovered 15 to 35 percent.
Most estates carry the wrong mix: many users hold a Professional license while only performing Employee or Productivity tasks, so reclassifying them to the correct lower type removes cost the audit assumed.
Remove the dormant accounts with no logon in the measured period, the duplicate users counted across systems, and the technical and test service accounts that should not carry a named license.
Then map real activity to the correct type using SAP's software use rights material and document the basis for each change.
Named user reclassification alone recovered 15 to 35 percent of the proposed shortfall across our defenses.
Indirect access is the highest-value exposure, 40 to 70 percent of the total in order-driven businesses, and the most contestable line.
Third-party systems that read from or write to SAP create indirect use, with ecommerce, CRM and automation tools the usual sources, a risk the Diageo judgment made concrete.
Under digital access, SAP counts documents created by outside systems, but the count is contestable, because duplicates and follow-on records inflate the vendor number, so the indirect question becomes a document count you can reconcile and strip.
It is the largest dollar line and the one where a clean internal reconciliation moves the settlement most, so contest it before any number leaves the building.
A controlled response protocol beats a fast response every time, and buyers who measured first settled 25 to 45 percent below the opening claim.
The common advice is to respond quickly, cooperate fully, and hand SAP the raw USMM output to show good faith; we disagree, because raw output handed over without review locked buyers into an inflated baseline that took months to unwind.
The buyer-side move is to run USMM internally first, clean the data, reclassify users, and contest the indirect count before responding, then route all communication through one owner so no informal admission can be held against you.
Cooperation is right; speed without preparation is not, and it favors the vendor. The audit clock favors the buyer who prepared a baseline before the letter arrived.
The named user types, and where buyers overclassify
| User type | Typical scope | Common overcount |
|---|---|---|
| Professional | Full operational use | Assigned to view-only staff |
| Limited Professional | Restricted operational use | Used where Employee fits |
| Employee | Self-service tasks | The reclassification target |
| Productivity | Light reporting and lookup | Rarely assigned, often correct |
Named user classification is the most recoverable area in any SAP audit, because most estates carry the wrong mix.
Many users hold a Professional license, the most expensive type, while only performing Employee self-service or Productivity lookup tasks, so reclassifying them to the correct lower type removes cost the audit assumed.
Before reclassifying, strip the accounts that should not carry a named license at all: inactive users with no logon in the measured period, the same person counted as a duplicate across systems, and technical and test service accounts.
SAP defines each user type in the software use rights material, so map real activity to the correct type and document the basis for each change, because a documented reclassification survives challenge where an undocumented one does not.
The digital access model behind the largest audit line sits in the digital access complete guide, and the pricing in the indirect access pricing guide.
The response protocol
- Measure internally first: run USMM in a controlled internal pass before you share anything, and read the output the way SAP will read it, because the raw output handed over without review locks you into an inflated baseline.
- Clean before you send: reclassify users to the correct type, remove dormant, duplicate and technical accounts, and reconcile the indirect document count, so you send a position you have already defended.
- Contest the indirect count: strip duplicates and follow-on records that inflate the vendor number, because indirect access is the largest dollar line and the most contestable, converting the exposure into a document count you control.
- Control the channel: route all vendor communication through one owner, because a single voice prevents informal admissions that the vendor can hold you to later.
- Prepare the baseline before the letter: the audit clock favors the buyer who already has a clean internal measurement, because every disputed number then has to be rebuilt under pressure, and a prepared buyer closes the audit in a few months. The response framework sits in the SAP audit defense framework.
The SAP license audit survival guide
The USMM and LAW process, named user reclassification, the digital access math, and the response protocol that protects the buyer.
Get the white paper →How indirect access drives the exposure
Indirect access is the largest dollar line in most SAP audits, 40 to 70 percent of the total exposure in order-driven businesses, and it is also the most contestable.
It comes from third-party systems that read from or write to SAP: ecommerce, CRM and automation tools are the usual sources, and the Diageo judgment made the risk concrete by establishing that a connected system generating SAP documents creates licensable use.
Under the digital access model SAP counts documents created by outside systems rather than the users behind them, which is exactly why the count is contestable, because the raw document count is inflated by duplicates and follow-on records that a clean reconciliation strips out.
The buyer-side move is to reconcile the indirect document count and remove the non-chargeable records before any number leaves the building, converting an open-ended indirect-use argument into a specific, defensible document total.
Getting this line right matters more than any named user work in an order-driven business, because it is where the majority of the dollars sit, and because SAP's opening number is built on the un-reconciled raw count.
The buyer who measures first, cleans the data, and contests the indirect count never negotiates from the vendor number, and in our defenses the findings letter overstated the gap by enough that a clean internal measurement changed the negotiation entirely.
The document model and the liability math sit in the indirect access pillar, and the RISE conversion context in the RISE negotiation tactics.
- Percentile standing for your exact deal size and industry, from real closed transactions
- Scenario simulation before the call: test alternative terms and see the financial impact of each
- A negotiation playbook, talking points, and a two page executive brief on day one
What we saw across SAP audit defenses, 2024 to 2025
Across roughly 30 to 40 SAP audit defenses we ran between 2024 and 2025, the first findings letter overstated the gap in nearly every case, and the common advice makes it worse. The common advice is to respond quickly, cooperate fully, and hand SAP the raw USMM output to show good faith.
We disagree:
Median user shortfall recovered by reclassifying users to the correct type and stripping dormant, duplicate and technical accounts before responding.
Median settlement below the first claim where the buyer ran USMM internally, cleaned the data, and contested the indirect count.
In our defenses, the raw output handed over without review locked buyers into an inflated baseline that took months to unwind, so cooperation is right but speed without preparation is not, and it favors the vendor.
The buyer-side move is to run USMM internally first, clean the data, reclassify users, and contest the indirect count before any number leaves the building.
Named user reclassification alone recovered 15 to 35 percent of the proposed shortfall, indirect access accounted for 40 to 70 percent of the total dollar exposure in order-driven businesses.
And buyers who ran USMM internally before responding closed the audit 25 to 45 percent below the opening claim.
The sequence is seven moves: run USMM internally in every system before responding, consolidate and read the results the way the vendor will, reclassify users to the correct type and document the basis for each change, remove dormant, duplicate and technical accounts.
Reconcile the indirect document count and strip non-chargeable records, route all vendor communication through a single owner, and engage independent SAP audit defense before sending a response.
An SAP audit is won before the response is sent: the buyer who measures first, cleans the data, and contests the indirect count never negotiates from the vendor number. The wider library sits in the SAP practice.
Your first five moves
- Run USMM internally in every system before responding, and read the output the way SAP will, because a raw export handed over first locks you into an inflated baseline.
- Reclassify users to the correct type and document each change, and strip dormant, duplicate and technical accounts, the most recoverable line at 15 to 35 percent.
- Reconcile the indirect document count and strip non-chargeable records, because indirect access is 40 to 70 percent of the exposure and the raw count is inflated by duplicates.
- Route all vendor communication through a single owner, so no informal admission can be held against you during the engagement.
- Engage independent SAP audit defense before you send a response, because the audit is won before the response is sent and a prepared buyer closes it in months. The SAP practice runs the defense with you.
Frequently asked questions
What triggers an SAP license audit?
SAP audits run on an annual measurement cycle and on event triggers such as a renewal, an S/4HANA conversion, or a major new integration. The annual USMM measurement is the most common starting point.
Because the measurement is scheduled, the audit clock favors the buyer who prepared a clean internal baseline before the letter arrived, since every disputed number otherwise has to be rebuilt under time pressure once the findings letter lands.
What is USMM and the License Administration Workbench?
USMM is the SAP user and system measurement tool, which counts named users by license type and reads engine consumption in each system.
Its output feeds the License Administration Workbench, often called LAW, which consolidates USMM results across systems, deduplicates users, and produces the figures SAP compares against your contracted entitlement.
Running USMM internally first, before SAP does, is the single most important move, because it lets you read and clean the numbers before they become the baseline.
What is the most common SAP audit finding?
Named user overclassification. Many users hold a Professional license, the most expensive type, while performing only Employee self-service or Productivity lookup tasks, so reclassifying them to the correct lower type removes cost the audit assumed.
It is the most common and most recoverable finding, worth 15 to 35 percent of the proposed shortfall on its own, provided you map real activity to the correct type and document the basis for each change so it survives challenge.
Why is indirect access so important in an SAP audit?
Because it is usually the largest dollar line, 40 to 70 percent of the total exposure in order-driven businesses, and the most contestable. Third-party systems that read from or write to SAP, ecommerce, CRM and automation tools, create indirect use, a risk the Diageo judgment made concrete.
Under digital access SAP counts documents created by outside systems, but the raw count is inflated by duplicates and follow-on records, so reconciling and stripping the non-chargeable records moves the settlement more than any other single line.
Should you send SAP the raw USMM output?
Not before you review it. Handing over raw output without cleaning the data locks you into an inflated baseline that takes months to unwind, because SAP builds its opening number on whatever you send.
Run the measurement internally first, reclassify users, remove dormant, duplicate and technical accounts, and reconcile the indirect document count, then send a position you have already defended. Cooperation is right; speed without preparation favors the vendor.
How long does an SAP audit take?
A prepared buyer closes an SAP audit in a few months. The timeline stretches when buyers respond without a baseline, because every disputed number then has to be rebuilt under pressure while the clock runs.
The findings letter is an opening position, not a settlement, so the buyers who measure first, clean the data, and contest the indirect count both settle lower, 25 to 45 percent below the opening claim, and close faster than those who respond fast and unwind an inflated baseline afterward.