Contents
Key takeawaysHow the audit worksNamed user overclassificationIndirect access exposureResponse protocolWhat we have seenWhat to do nextFAQAn SAP license audit starts with a measurement you can run yourself. The findings letter is SAP's opening position, and buyers who measure first, clean their user data and contest the indirect document count settle well below it.
- The audit is a measurement. USMM counts users and engines in each system, LAW consolidates them, and SAP's findings letter proposes a gap you can rebuild from your own data.
- User classification is the most recoverable finding. Reclassifying users and removing dormant, duplicate and technical accounts recovered 15 to 35 percent of the proposed shortfall in our defenses.
- A lock does not reduce the count. USMM still measures locked users, so end the validity period or delete dormant accounts before the measurement runs.
- Indirect access carries most of the dollars. It made up 40 to 70 percent of the exposure in order driven businesses, and SAP's raw document count includes records that should come out.
- Measure before you respond. Buyers who ran USMM internally before replying settled 25 to 45 percent below SAP's opening claim.
- One voice to SAP. Route every exchange with the audit team through a single owner so informal remarks cannot be used against you.
Every SAP license audit ends in a findings letter that proposes a shortfall. That letter is SAP's opening position, and the work you do before you answer it decides most of the final number.
How does an SAP license audit work, from measurement request to findings letter?
It follows a fixed, mechanical sequence. You run USMM, SAP's user and system measurement tool, in each system in scope. The results are consolidated in the License Administration Workbench (LAW), SAP compares the consolidated figures with your contract, and it issues a findings letter with a proposed shortfall.
| Stage | What happens | What you control |
|---|---|---|
| Measurement request | SAP asks for USMM results from the systems in scope, with a deadline | Written agreement on which systems and entities are in scope |
| USMM run | Named users are counted by license type and engine consumption is read in each system | User classification, validity dates and technical accounts |
| LAW consolidation | Results from all systems are merged and duplicate users removed | Whether each person's accounts can be matched across systems |
| Findings letter | SAP proposes a gap between what you deploy and what you bought | Whether you accept the figure or rebuild it from clean data |
| Settlement | The agreed gap is settled commercially | The evidence behind every line and the wording of the release |
What does USMM count in each system?
USMM counts dialog users by the license type recorded on the License Data tab of the user master record in SU01. It also reads engine consumption for the packages you license on business metrics instead of users. A few counting rules decide how clean that number is.
- Unclassified users. A dialog user with no license type assigned is measured at the most expensive type, so every gap in classification inflates the count.
- Locked users. Locking an account does not take it out of the measurement. Deleted users, and users whose validity period has ended, are not counted.
- Background users. System and service users that run batch jobs or SAP to SAP connections are normally classified as technical users. Look hard at the ones that post data on behalf of outside systems, because that is where indirect use sits.
- Engines. Engine results sit beside the user count and are compared with the engine metrics in your order form.
What does LAW add to the USMM results?
LAW, delivered as transaction SLAW or SLAW2 in current releases, consolidates the USMM results from every system and counts each person once. It can only merge accounts it can match to the same person, so inconsistent user IDs or names across systems appear as separate people. The consolidated LAW figures are what SAP compares with your entitlement.
Our guide to USMM, LAW, SLAW and STAR covers the tooling and its settings in more detail.
Optimize the Estate First: The SAP Work That Pays for the Negotiation
Which SAP named user types get overclassified in an audit?
Professional users are the most common overcount. Many people hold a Professional license, the most expensive type, while they only perform Employee self service tasks or Productivity lookups. Reclassifying them to the correct lower type removes cost the audit assumed, which makes this both the most common finding and the most recoverable one.
| User type | Typical scope | Common overcount | What to check before you reclassify |
|---|---|---|---|
| Professional | Full operational use | Assigned to view only staff | The transactions each user actually ran in the measured period |
| Limited Professional | Restricted operational use | Used where Employee fits | Whether any activity goes beyond self service |
| Employee | Self service tasks | The reclassification target | That the tasks match the self service definition in your contract |
| Productivity | Light reporting and lookup | Rarely assigned, often correct | Whether any create or change activity exists |
SAP defines each user type in its software use rights material, and your order form may carry its own definitions that override them. Map what each person did in the measured period to those definitions and write down the basis for each change. A documented reclassification survives SAP's challenge, while an undocumented one tends to be reversed.
Our guide to SAP named user license types sets out the definitions in full.
Which accounts should not carry a named license at all?
Remove these before you reclassify anyone. Each one is a full license the audit has assumed.
- Dormant accounts. Users with no logon in the measured period. End their validity period or delete them.
- Duplicates across systems. One person with separate accounts in ECC, BW and other systems. Align user IDs or names so LAW merges them into one.
- Technical and test service accounts. Batch, interface and test users that no person logs on with. Classify them under the technical or test type your contract provides.
- Leavers still marked valid. Staff who left before the measurement date but whose accounts were never closed. HR exit dates are your evidence.
Worked example: cleaning a hypothetical 600 user shortfall
Say you hold 2,000 Professional and 500 Employee licenses. The raw measurement shows 2,600 Professional users and 400 Employee users, so the findings letter claims a shortfall of 600 Professional users.
| Step | Accounts affected | Professional users counted | Shortfall |
|---|---|---|---|
| Raw measurement | None | 2,600 | 600 |
| Remove dormant accounts | 70 | 2,530 | 530 |
| Merge duplicates across systems | 40 | 2,490 | 490 |
| Move technical and test accounts off named licenses | 30 | 2,460 | 460 |
| Reclassify Professional users to Employee | 40 | 2,420 | 420 |
The Employee count rises to 440, still inside the 500 you own, so the reclassification costs nothing. The shortfall falls from 600 to 420 users, a 30 percent reduction, before anyone has discussed price. Every step rests on evidence you produced yourself: logon dates, LAW matching, account purposes and activity records.
SAP License Audit Survival Guide
The measurement process, user cleanup, indirect access reconciliation and response protocol in one white paper.
Get the white paper →How does indirect access drive the SAP audit exposure?
Indirect access is usually the largest dollar line in an SAP audit, 40 to 70 percent of the total exposure in order driven businesses. It is also the most contestable line. The exposure comes from third party systems that read from or write to SAP, and ecommerce platforms, CRM and automation tools are the usual sources.
The Diageo judgment made the risk concrete. In 2017 the UK High Court held that people using Diageo's Salesforce based systems connected to SAP needed named user licenses. Digital access now counts the documents outside systems create instead of the users behind them, so the indirect question becomes a document count you can reconcile.
What should you strip from the raw document count?
SAP's opening number rests on the raw count, which duplicates and follow on records inflate. Only the initial creation of a document by an outside system counts; reading, changing or deleting one does not. SAP's adoption program material concedes that its estimation report counts follow on documents created by the same technical users, which you must adjust out by hand.
The counting rules are set out in our digital access complete guide, and current prices in the SAP indirect access pricing guide for 2026.
| What inflates the count | Why it should come out | Where the evidence sits |
|---|---|---|
| Follow on documents | SAP created them in its own processing after the first external document, such as a delivery and invoice after a web order | The document flow of the originating order |
| Documents counted twice | The same document appears in more than one extract or system | Your own document numbers, reconciled across the extracts |
| Documents entered by licensed users | A named user created them directly in SAP | The created by user and transaction on each document |
| Reads, changes and deletions | Only initial creation counts | Interface direction and change logs |
| Financial and material documents at full weight | They carry a 0.2 multiplier | SAP's document type definitions |
SAP publishes digital access estimation reports for ECC and S/4HANA through SAP Notes 2992090 and 2999672. Run them yourself before SAP's team asks, then reconcile the output against your integration inventory. The liability arithmetic is worked through in our indirect access pillar, and the digital access document guide explains each document type.
How does a RISE conversation change the indirect access finding?
SAP account teams may offer to fold the indirect finding into a RISE with SAP conversion while the audit is still open. Agree the document count on its own evidence first, then judge the RISE offer on its own price and terms. The conversion side is covered in our RISE negotiation tactics.
What should your SAP audit response protocol look like?
Measure, clean and contest before you send anything, and send it through one person. These are the five rules we run in every defense, and the fuller method sits in our SAP audit defense guide.
- Measure internally first. Run USMM in a controlled internal pass before you share anything, and read the output the way SAP will read it.
- Clean before you send. Reclassify users, remove dormant, duplicate and technical accounts, and reconcile the indirect document count, so what reaches SAP is a position you have already tested.
- Contest the indirect count. Strip duplicates and follow on records, which converts an open ended argument about indirect use into a specific document total.
- Control the channel. Route all communication with SAP through one owner. An offhand remark from a basis administrator or a project lead can be held against you later.
- Prepare the baseline before the letter. Without one, every disputed number has to be rebuilt under time pressure. A prepared buyer closes the audit in a few months.
What should you do at each stage of the audit?
| Stage | Your action | Owner |
|---|---|---|
| Before any letter | Run USMM and the digital access estimation report internally, fix classifications and validity dates | SAP basis team with the license manager |
| Measurement request arrives | Confirm scope in writing (systems, clients, legal entities) and name the single contact | Audit owner |
| Before you submit | Review the consolidated LAW result, document each reclassification, keep an evidence file | Audit owner and advisor |
| Findings letter arrives | Rebuild the gap from your clean data and answer SAP line by line | Audit owner and advisor |
| Settlement | Negotiate the commercial settlement of the agreed gap and get the release terms in writing | Procurement with the audit owner |
What will SAP's audit team say, and what should you say back?
- "Please send the measurement results as they are." Classifying users in the measurement is the customer's task. Tell SAP you will submit after your review, with the basis for each classification documented.
- "The tool counted these users, so they stay in." Send the logon records showing no activity in the measured period and ask for those accounts to be removed from the count.
- "Every order from your web shop needs a license." Ask SAP to name the interfaces and document types behind its figure and to show how it counted them. Then reconcile against your own extract.
- "We can make the finding go away inside a larger deal." Keep the two apart. Agree the gap first, then price any new purchase on its own order form.
What should the settlement paperwork say?
- Scope. The systems, products and measurement period the settlement covers, so the same period cannot be reopened.
- Release. SAP's confirmation that the settlement resolves all compliance claims for that scope and period.
- Accepted user mix. The agreed classification, so the next measurement starts from it and not from the raw count.
- Document count method. Which documents were excluded and why, so the next indirect measurement uses the same rules.
What have we seen in SAP audit defenses in 2024 and 2025?
Across roughly 30 to 40 SAP audit defenses we ran between 2024 and 2025, the first findings letter overstated the gap in nearly every case. The overstatement was large enough that a clean internal measurement changed the negotiation entirely.
- 28 percent. Median user shortfall recovered by reclassifying users and stripping dormant, duplicate and technical accounts before responding. Across the defenses, this work alone recovered 15 to 35 percent of the proposed shortfall.
- 38 percent. Median settlement below the first claim where the buyer ran USMM internally, cleaned the data and contested the indirect count. Those buyers settled 25 to 45 percent below the opening claim.
Why we advise against handing SAP the raw USMM output early
The usual advice is to respond quickly, cooperate fully and hand SAP the raw USMM output to show good faith. We disagree with both the speed and the raw output. In our defenses, output sent without review locked buyers into an inflated baseline that took months to unwind. Cooperate on your own timetable, because speed without preparation favors the vendor.
SAP builds its opening number on whatever you send it, so the first thing you send should already be clean.
Which mistakes push the settlement up?
- Leaving scope open. If the measurement request does not list the systems, clients and legal entities, users from systems outside your contract can end up in the count. Fix the scope in writing before the first run.
- Reclassifying in bulk by role. Moving hundreds of users to Employee because of their job title, with no per user activity record, invites SAP to reject the whole batch and return to the raw count.
- Accepting the estimation report total. The report counts follow on documents created by the same technical users, so its raw figure sits above your chargeable count until you adjust it.
How does the work differ for a single system and a multi system SAP customer?
A company with one ECC or S/4HANA system and a few hundred users can often finish the internal pass with its own basis team. Its exposure usually sits in a handful of misclassified users and one or two integrations, and one person can own the whole response.
A group with many production systems, several legal entities and a busy integration layer has more work to do. It needs LAW matching rules agreed early and an owner for each system. Indirect access usually dominates there, so start the document reconciliation first.
What to do next
- Before any letter arrives. Run USMM internally in every system in scope, and read the output the way SAP will.
- Consolidate. Run LAW over the results, check that each person counts once, and fix user IDs that fail to match.
- Reclassify. Move users to the correct type and document the basis for each change against SAP's user definitions.
- Clean the account list. End validity or delete dormant accounts, merge duplicates, and move technical and test accounts off named licenses.
- Reconcile indirect use. Run the digital access estimation report and strip non chargeable records from the document count.
- Name one owner. Route all communication with SAP through a single person for the whole audit.
- Get independent help before you respond. Engage independent SAP audit defense before your response goes out. Our SAP practice runs the defense with you, and the SAP audit readiness plan covers the year before a letter.
Frequently asked questions
What triggers an SAP license audit?
SAP audits run on an annual measurement cycle and on event triggers such as a renewal, an S/4HANA conversion or a major new integration. The annual USMM measurement request is the most common starting point. Because that request is scheduled, you can have a clean internal baseline ready before it arrives instead of building one under a deadline.
What is USMM and the License Administration Workbench?
USMM is the measurement transaction that runs inside each SAP system and counts users by license type, plus engine use. The License Administration Workbench, usually called LAW, takes the USMM results from all systems, counts each person once and produces the figures SAP checks against your entitlement. Running both yourself, before SAP sees anything, is the single most useful step in an audit.
What is the most common SAP audit finding?
Named user overclassification: people licensed as Professional users who only perform Employee self service or Productivity lookup tasks. It is also the finding you can most readily reverse, provided each change is mapped to SAP's user definitions and backed by activity records from the measured period.
Why is indirect access so important in an SAP audit?
It is usually the largest dollar line and the one with the most room to contest. It also carries forward: the document count you accept becomes the starting point for the next measurement and for any digital access license you buy, so an inflated number costs you more than once.
Should you send SAP the raw USMM output?
Not before a review. Unreviewed output carries unclassified users at the top price, dormant accounts and duplicates, and a baseline set that way took months to unwind in our defenses. Clean and document the result first, then send a measurement you are prepared to explain line by line.
How long does an SAP audit take?
A prepared buyer closes an SAP audit in a few months. Running USMM and LAW takes little of that time. Most of it goes into disputing the findings letter line by line, so a clean, documented submission leaves fewer lines to argue and brings the signed release forward.
Do locked users count in an SAP license measurement?
Yes. USMM counts locked users, while deleted users and users whose validity period has ended drop out. The standard report RSUSR_LOCK_USERS selects accounts by last logon date and can set the end of their validity period, so schedule it to run before each measurement.