SAP Business Technology Platform SOC 1 (ISAE 3402) Audit Report 2023 H1
SAP Business Technology Platform (SAP BTP) is a technology platform that brings together application development, data and analytics, integration, automation, and AI capabilities in one unified environment. The platform offers users the ability to turn data into business value, compose end-to-end business processes, and build and extend SAP applications.
The services and solutions of SAP BTP are available on multiple cloud infrastructure providers. The multi-cloud foundation supports different environments, such as Cloud Foundry, ABAP, Kyma, and Neo, as well as multiple different regions and a broad choice of programming languages.
SAP BTP SOC1 Type 2 report covers within audit period the following services:
SAP BTP, Neo runtime | SAP BTP, Cloud Foundry runtime | SAP BTP, Kyma runtime |
SAP BTP, ABAP environment | SAP BTP, Kubernetes environment (internal only) | SAP AI Core |
SAP AI Launchpad | SAP Alert Notification service for SAP BTP | SAP Analytics Cloud including SAP Digital Boardroom and SAP Analytics Hub |
SAP Application Logging Service for SAP BTP | SAP ASE service | SAP Audit Log Service |
SAP Authorization and Trust Management service | SAP Automation Pilot | SAP Batch Release Hub for Life Sciences |
SAP Build Work Zone, advanced edition (called «SAP Work Zone» until November 2022) | SAP Build Work Zone, standard edition (called «SAP Launchpad service» until January 2023) | SAP Business Accelerator Hub (called« SAP API Business Hub» until April 2023) |
SAP Business Application Studio | SAP Business Network Asset Collaboration | SAP Business Network for Logistics, offered as a bundle and as single services:
|
SAP Cloud Appliance Library | SAP Cloud for Energy | SAP Cloud Identity Access Governance |
SAP Cloud Identity Services - Identity Authentication | SAP Cloud Identity Services - Identity Provisioning | SAP Cloud Integration for data services |
SAP Cloud Management service for SAP BTP | SAP Cloud Portal service | SAP Cloud Transport Management |
SAP Connectivity service | SAP Content Agent service | SAP Continuous Integration and Delivery |
SAP Conversational AI | SAP Credential Store | SAP Custom Domain service |
SAP Data Custodian | SAP Data Intelligence | SAP Data Privacy Integration |
SAP Data Quality Management | SAP Data Retention Manager | SAP Datasphere (called until March 2023 « SAP Data Warehouse Cloud »), incl. SAP BW Bridge |
SAP Destination service | SAP Digital Manufacturing Cloud | SAP Document Center |
SAP Document Management service offered as a bundle and as single services:
| SAP Document service | SAP Entitlement Management |
SAP Event Mesh | SAP Feature Flags service | SAP Fiori Cloud |
SAP Forms service by Adobe | SAP Git service | SAP Graph |
SAP HANA Cloud, offered as a bundle and as single services:
| SAP HANA service for SAP BTP | SAP HANA spatial services |
SAP HTML5 Application Repository service for SAP BTP | SAP Information Collaboration Hub (Excluding Russia MDLP domestic reporting and Saudi Arabia Reporting) | SAP Integration Suite, offered as a bundle and as single services:
|
SAP Intelligent Robotic Process Automation | SAP Job Scheduling service | SAP Keystore service |
SAP Landscape Management Cloud | SAP Leonardo Machine Learning Foundation | SAP Malware Scanning service |
SAP Market Communication for Utilities | SAP Market Rates Management:
| SAP Master Data Governance, cloud edition |
SAP Master Data Integration | SAP Mobile Services (incl. Agentry) | SAP Monitoring service for SAP BTP |
SAP Multi-Bank Connectivity
| SAP OData Provisioning | SAP Personal Data Manager |
SAP Platform Identity Provider service for SAP BTP | SAP Private Link service | SAP Service Manager |
SAP Software-as-a-Service Provisioning service | SAP Solutions Lifecycle Management service for SAP BTP | SAP Sports One |
SAP Subscription Billing | SAP Task Center | SAP Usage Data Management service for SAP BTP |
SAP Virtual Machine service | SAP Web IDE | SAP Workflow Management offered as a bundle and as single services:
|
Application Autoscaler | Business Entity Recognition | Commercial Infrastructure Service (internal only) |
Data Attribute Recommendation | Document Classification | Document Information Extraction |
Invoice Object Recommendation | Java Application Lifecycle Management for SAP BTP | Java Debugging for SAP BTP |
Java Profiling for SAP BTP | MongoDB on SAP BTP | OAuth 2.0 on SAP BTP |
Object Store on SAP BTP | PostgreSQL on SAP BTP / PostgreSQL on SAP BTP, hyperscaler option | RabbitMQ on SAP BTP |
Redis on SAP BTP / Redis on BTP, hyperscaler option | Service Ticket Intelligence | UI Theme Designer |
UI5 flexibility for key users | Unified Gateway (internal only) |
|
The following regions and their IaaS provider are covered:
SAP BTP Region Name | Infrastructure Provider |
UAE (Dubai) | SAP |
Australia (Sydney) | SAP |
China (Shanghai) | SAP |
Japan (Tokyo) | SAP |
Japan (Osaka) | SAP |
KSA (Riyadh) | SAP |
KSA (Dammam) | SAP |
Europe (Rot) | SAP |
Europe (Frankfurt) | SAP |
Europe (Amsterdam) | SAP |
Brazil (Sao Paulo) | SAP |
Canada (Toronto) | SAP |
US East (Ashburn) | SAP |
US East (Sterling) | SAP |
US West (Colorado Springs) | SAP |
US West (Chandler) | SAP |
US East (VA) | Amazon Web Services (AWS) |
Canada (Montreal) | Amazon Web Services (AWS) |
Singapore | Amazon Web Services (AWS) |
South Korea (Seoul) | Amazon Web Services (AWS) |
Europe (Frankfurt) | Amazon Web Services (AWS) |
India (Mumbai) | Amazon Web Services (AWS) |
Brazil (São Paulo) | Amazon Web Services (AWS) |
Australia (Sydney) | Amazon Web Services (AWS) |
Japan (Tokyo) | Amazon Web Services (AWS) |
US West (Oregon) | Amazon Web Services (AWS) |
US East (VA) | Microsoft Azure (Azure) |
US West (WA) | Microsoft Azure (Azure) |
Canada (Toronto) | Microsoft Azure (Azure) |
Europe (Netherlands) | Microsoft Azure (Azure) |
Singapore | Microsoft Azure (Azure) |
Australia (Sydney) | Microsoft Azure (Azure) |
Japan (Tokyo) | Microsoft Azure (Azure) |
UAE North (Dubai) | Microsoft Azure (Azure) |
Switzerland (Zurich) | Microsoft Azure (Azure) |
US Central (IA) | Google Cloud Platform (GCP) |
Europe (Frankfurt) | Google Cloud Platform (GCP) |
India (Mumbai) | Google Cloud Platform (GCP) |
SOC 1 reports are prepared in accordance with AT-C section 320, Reporting on an Examination of Controls at a Service Organization Relevant to User Entities’ Internal Control Over Financial Reporting, and evaluate the effect of the controls at the service organization on the user entities’ financial statements. SOC 1 reports are specifically intended to meet the needs of the entities that use service organizations (user entities) and the CPAs that audit the user entities’ financial statements (user auditors). SOC 1 Type 1 report on the fairness of the presentation of management’s description of the service organization’s system and the suitability of the design of controls to achieve the related control objectives as of a specified date, whereas a SOC 1 Type 2 also includes the operating effectiveness of controls to achieve the related control objectives throughout a specified period.
SAP Business Technology Platform has regularly prepared SOC 1 Type 2 audit reports by an independent 3rd party accountant. This version of the report covers the audit period October 1, 2022 to March 31, 2023.
The use of these reports is restricted to the management of the service organization, user entities, and user auditors. A copy of this report is available for all SAP Business Technology Platform customers who had productive and had financially-relevant systems during the audit period covered by the report.