Persona Guide — IT Director

The IT Director's Guide to SAP Landscape Compliance

System copies, test environments, and user classification decisions made by IT teams create the compliance exposure that SAP auditors exploit. This is the technical leader's guide to understanding and controlling your SAP licence compliance position before SAP does it for you.

IT Landscape Compliance Risks
SYS
System Copy Classification
Dev, QA, and training systems misclassified as non-production can trigger audit findings
USR
User Type Misalignment
Developers and basis admins assigned lower licence types than their actual usage requires
INT
Third-Party Integration
Middleware, ETL tools, and automation platforms accessing SAP without digital access coverage
RFC
RFC/API Connections
Background RFC calls counted as named user access in SAP measurement tools
73%
of SAP audit findings relate to technical landscape decisions made by IT teams
6–12
typical number of non-production systems in an enterprise SAP landscape
€2M+
average back-licence claim generated by uncontrolled system copy proliferation
48hrs
typical time IT teams get to respond to SAP's measurement data request
System Landscape Risk

The SAP System Copy Compliance Trap

SAP's licensing model distinguishes between production and non-production systems — but the classification rules are far more specific than most IT teams realise. Misclassifying a system, even unintentionally, can create a back-licence exposure that SAP will identify during an audit measurement.

Production Systems

What SAP Counts as Production

In SAP's licensing framework, a production system is any system where live business transactions are processed — regardless of what your IT team calls it. This includes:

  • Systems used for live financial postings, even in a limited capacity
  • Systems processing real customer orders or inventory movements
  • Disaster recovery systems that are ever activated
  • Systems used for period-end close, even quarterly
  • Parallel run systems during migration phases

SAP's standard licence agreement ties named user counts to the production system landscape. Any system that touches live data may be counted.

Non-Production Systems

What Qualifies as Non-Production

SAP's licence agreement typically permits a limited number of non-production systems for development, testing, and training at no additional named user licence cost — subject to strict conditions:

  • No live business transactions processed
  • Only used by employees who hold licences in production
  • Not accessible by third parties without separate licence coverage
  • Clearly separated from the production system data
  • Subject to the same named user count as production

The last point catches most organisations. Non-production systems do not give you additional user capacity — the same users must be licensed in production.

⚠ The Sandbox and Training System Problem

Many IT teams create sandbox or training environments using a system copy of production, then give access to users who are not in the production licence count — typically for onboarding, testing, or temporary project access. SAP will count these users as requiring licences. If your training or sandbox system has 200 users and your production count covers 150, you have a 50-user shortfall that becomes an audit finding. Get this reviewed as part of your licence compliance assessment.

User Type Risk

User Classification: Where IT Decisions Create Liability

SAP's named user licence types are based on what a user can do, not what they typically do. IT teams that assign lower licence types to reduce cost — or inherit configurations from a previous team — are the most common source of user type audit findings.

Developer Risk

SAP Developer Licences

Developers with access to SE80, ABAP workbench, transport management, or any Basis administration function typically require a Professional User licence — the highest tier. IT teams frequently assign Developer User licences (a separate SKU), which is often insufficient for users who also perform configuration or system administration tasks.

The measurement: SUIM and USMM will identify authorisation objects associated with development activities. If a user has S_DEVELOP at a level that permits modification, SAP will classify them accordingly.

Basis Admin Risk

Basis and System Admin Users

System administrators performing Basis activities — transport management, user administration, system monitoring via SM50/SM66, profile maintenance — typically require Professional User licences. Assigning them Limited Professional or Employee type licences because "they don't do business transactions" is a common miscalculation.

SAP's measurement tools identify the authorisation profiles assigned, not the tasks actually performed. Broad Basis profiles almost always trigger Professional User classification regardless of actual usage patterns.

Test User Risk

Test and Integration Users

Automated test users, integration users for middleware systems, and service accounts used by third-party tools connected via RFC or BAPI are frequently left unclassified or assigned minimal licence types. SAP's position is that any system user accessing the SAP application layer requires a named user licence unless covered under the Digital Access model.

Review all technical users and RFC connections as a priority before any SAP measurement exercise.

Integration Risk

Third-Party Integrations and Indirect Access Exposure

When non-SAP systems connect to SAP — whether via RFC, BAPI, OData APIs, IDocs, or flat-file interfaces — the licensing question is not whether a human user is involved but whether SAP data is being read or written. IT teams managing integration architecture carry direct responsibility for indirect access exposure.

What Triggers an Indirect Access Claim

Any third-party system that reads or writes SAP data through the application layer — not via direct database access — may trigger named user licence requirements or Digital Access document charges. The most common triggers IT teams encounter:

  • CRM systems (Salesforce, HubSpot, etc.) writing orders into SAP SD
  • MES/SCADA systems pushing production confirmations into PP
  • HR platforms synchronising employee data with SAP HCM
  • BI tools pulling live data via SAP BAPI or OData connections
  • iPaaS platforms (MuleSoft, Dell Boomi, Azure Logic Apps) orchestrating SAP workflows
  • RPA bots (UIPath, Automation Anywhere) performing SAP transactions
  • Custom-built portals allowing suppliers or customers to interact with SAP data
Digital Access Model

How Digital Access Changes the Calculation

SAP's Digital Access licensing model (introduced formally in 2018) converts indirect access from named user exposure to document-based pricing. Instead of counting the users behind a third-party system, SAP counts the number of specific document types created — purchase orders, sales orders, goods receipts, journal entries, and five others.

For IT architects, the implication is significant: every integration that creates one of the nine document types in SAP is potentially billable. The volume can be very high in high-throughput environments.

Our Digital Access guide explains exactly which document types are charged, how to measure your exposure, and how to negotiate Digital Access into your contract structure.

Review Your Integration Risk →
Measurement Preparation

Preparing for SAP's USMM Measurement

SAP uses two primary tools to measure your licence position: the User and System Measurement (USMM) and the License Administration Workbench (LAW). Understanding what these tools measure — and how to influence the output — is one of the most valuable capabilities an IT Director can develop. Our USMM guide covers this in depth.

1

Audit Your User Master Records

Before any measurement, export your complete user list from SU01 and cross-reference against your contractual named user entitlements. Identify users who haven't logged in for 90+ days — these can often be locked or deleted to reduce the live user count. SAP counts valid users, not just active ones, so locked users typically do not count. Document your methodology.

2

Review Authorisation Profiles

USMM classifies users based on their authorisation profiles, not their actual logged transactions. If a user has a composite profile that includes development or administrative authorisation objects, USMM will classify them at the highest matching licence type. Run a pre-measurement classification report and remediate misassigned profiles before the formal measurement window.

3

Document System Classifications

Ensure every system in your landscape is correctly classified in the System Landscape Directory (SLD) and in LAW before measurement. Production, development, test, and quality systems must be accurately tagged. If SAP disputes a system's classification during audit, you need written documentation of your rationale — ideally contemporaneous with the system's creation.

Pro Tip: Run a Self-Assessment Before SAP Does

Running your own USMM measurement 3–6 months before the annual licence review gives you time to remediate findings on your terms. You can lock inactive users, adjust profiles, and address integration exposure without the pressure of a live SAP audit. If the self-assessment reveals a material shortfall, it also gives you time to engage commercial teams and consider remediation options rather than receiving a back-licence demand. Our team can help with a licence optimisation review before your next measurement cycle.

Migration Licensing Risk

S/4HANA and RISE Migration: Landscape Decisions That Bind You

SAP migrations — whether to S/4HANA on-premise, SAP Cloud ERP Private (formerly RISE), or GROW with SAP — create a unique licensing window. Decisions made during migration planning define your licence position for the next 5–10 years. IT Directors involved in migration architecture need to understand the commercial implications alongside the technical ones.

S/4HANA Migration

What Changes in S/4HANA Licensing

S/4HANA changes the licensing model in several ways that affect IT architecture:

  • User types are reassigned and some legacy types are deprecated
  • Fiori-based access creates new licence classification questions
  • Embedded analytics may require additional licence entitlements
  • Custom code that previously ran in ECC may require ABAP Cloud Developer licences in S/4HANA
  • SAP BTP extensions require separate BTP service plan entitlements

Our S/4HANA migration licensing advisory ensures your migration is commercially structured before you sign.

RISE / Cloud ERP Private

Cloud ERP Private Landscape Implications

RISE with SAP (now Cloud ERP Private) shifts infrastructure responsibility to SAP but creates new licence complexity for IT teams:

  • Non-production system count and configuration is defined by contract — negotiate it before signing
  • BTP credits are bundled but often insufficient for real integration workloads
  • Custom code migration to "clean core" creates developer licence questions
  • The hyperscaler choice (AWS/Azure/GCP) affects data residency and exit optionality
  • SLA definitions are weaker than traditional on-premise service expectations

Review our RISE with SAP advisory to understand the technical and commercial trade-offs.

Action Framework

The IT Director's SAP Compliance Action Plan

Immediate Actions (30 Days)

  • Export full user master and lock all users inactive for 90+ days
  • Map all RFC and API connections into SAP — document source system, interface type, and data written
  • Review system landscape against contractual non-production entitlement
  • Run USMM self-assessment and review classification output
  • Identify any training or sandbox systems with users not in the production licence count
  • Flag all third-party integrations that write the nine Digital Access document types

Structural Changes (90 Days)

  • Remediate authorisation profile misassignments identified in USMM review
  • Classify all systems formally in SLD with documented rationale
  • Implement technical user governance — one account per integration, clearly named and documented
  • Establish a process for reviewing user classifications when roles change
  • Create a register of all third-party systems with SAP access and their licence coverage
  • Engage commercial team before the next SAP true-up or contract renewal
Related Guides

Technical Guides for SAP IT Teams

Expert Advisory

Your SAP Landscape Has Compliance Risk. Find It Before SAP Does.

We work with IT Directors to identify and remediate SAP licence exposure before the audit letter arrives. Our technical landscape reviews cover system classification, user type analysis, integration mapping, and USMM preparation — giving you a defensible position before SAP's measurement window opens.