SoftwareOne logo

5 min to readPublisher Advisory Services

The changing face of audits: SAP Premium Engagement explained

Wendie Balzano
Wendie BalzanoSAP Lead Consultant – Contract Advisory & Software Licensing
A mountain range with a pink sky in the background.

Over recent months, SAP has launched a new "SAP Premium Engagement" programme, transforming the way audits are conducted.

What does this mean for you and your organisation?

Many organisations are now receiving notifications about upcoming SAP audits under this new Premium Engagement framework while in the middle of crucial projects. These new audits appear to be enhanced audits that operate differently from previous approaches.

Enhanced audits involve multiple detailed requests for a long list of authorisations, deeper data extractions, all performed by SAP auditors, on-site, directly accessing your systems. To understand the new Premium Engagement, you would first need to understand the previous enhanced services.

Legacy audits

While SAP has the right to ensure compliance with their software usage, end-users will also need transparency regarding the data extraction process, how it's being obtained and how all that data is combined and analysed to ensure licence compliance. This transparency is required to allow you to replicate all the steps needed to verify any compliance findings, as well as use the same procedures and analysis to ensure future compliance.

Key questions about the new Premium Engagement audits

With the introduction of SAP's new audit process, you might be wondering:

  • What exactly is SAP asking for?
  • What data are they looking for?
  • What processes are they using?
  • How will the data be analysed?

SAP's communication around these new processes appears limited. While the company has specified that extractions will be performed by SAP professionals,  there are reports about organisations receiving minimal information concerning:

  • What data they will be extracting
  • What the data is for
  • How it's analysed
  • How organisations can review or verify the data

How to navigate the new SAP audits

Despite this, there are several practical steps and strategies you can take to make sure you‘re well-placed for the audit:

  1. Review your agreements
    Check your SAP agreements for any audit clauses and understand what your rights and obligations are in terms of scope and methodology to follow.
  2. Cooperate strategically with the SAP audit team
    While you must cooperate with the SAP audit team, remember that the standard SAP Software Use Rights only require "reasonable cooperation". This means you can refuse direct access to the systems, whether onsite or remote. Refusing the audit isn't an option, but there are ways to manage it effectively.
  3. Minimise the scope of the audit with SAP
    Ensure you agree on the scale and scope of the data extracts to be delivered. Expect the following data to be requested:
    • The standard USMM and LAW consolidation
    • Additional user data extracts
    • Digital documents estimation notes extracts
    • Standard SAP HANA DB measurements (GB counts)
    • Any relevant self-declaration products, such as Revenue, GRC monitored users, CPU counts, etc.

Within these requirements, you can decline to provide any additional extracts that are covered by the standard USMM outputs, unless the USMM indicates a need for further information. For example:

  • Multiple log ons (USR41_MLD)
  • Activity checks (TUL_ACRES)

When dealing with requests outside such standard measurements, you might find it helpful to discuss the specific purpose with your SAP representative. This collaborative approach helps ensure that additional data requests are properly scoped and directly relevant to specific compliance considerations identified through initial measurements. It offers SAP the opportunity to explain why the extra data is required.

New audit measurement details

It’s also important to be aware that SAP has recently introduced two new measurements as part of their audit requests:

  • Developer users (V_E071EU)

This measurement counts developer users over 12 months, helping to classify users accurately

  • SAP HANA DB

This is a new request, currently in a pilot phase, and aims to measure database usage

Our review indicates that the SAP HANA DB data outputs currently do not provide meaningful insights to verify compliance

Informed customer consent and communication

To structure your expectations around these changes, it’s also worth noting that none of the customers we have supported were:

  • Informed the extraction was a pilot
  • Asked if they wanted to participate
  • Given any information about the data
  • Told what outputs constitute compliance

Conclusion

The introduction of SAP Premium Engagement represents a significant shift in audit methodology that organisations are still adapting to. As with any evolving process, there are opportunities to improve communication and transparency, particularly regarding data requirements and verification procedures. We look forward to seeing how SAP develops this programme in partnership with its customers, creating a balance between robust compliance verification and practical implementation.

Are you about to undertake an SAP Premium Engagement audit and don't know what to do? Reach out to your SoftwareOne representative and schedule a call. Our SAP experts can help you understand the implications of these new audit processes and develop appropriate strategies for managing them effectively.

An image of a dark room with neon lights.

Contact us today

SoftwareOne has solved many of the SAP challenges you may face. Tell us about your business challenge, and we’ll get right back to you.

Contact us today

SoftwareOne has solved many of the SAP challenges you may face. Tell us about your business challenge, and we’ll get right back to you.

Author

Wendie Balzano

Wendie Balzano
SAP Lead Consultant – Contract Advisory & Software Licensing