SAP Enterprise Management SOC 1 (ISAE 3402) Audit Report 2023 H1

The scope of this SOC 1 report includes SAP Enterprise Management, SAP Asset Performance Management, SAP S/4HANA Cloud, public edition, SAP Marketing Cloud, and SAP Integrated Business Planning.

SAP Product Engineering (PE) department consists of product management, engineering, cloud operations and infrastructure. PE supports teams to consolidate and operate the organization with the objective to be able to respond to changes, challenges and trends in the cloud industry and to customer expectations. The portfolio includes the SAP S/4 HANA Cloud suite, SAP Digital Supply Chain, Small and Mid-Sized Enterprises (SME), and industry solutions as well as cloud offerings. Cross-functions in the Product Engineering (PE) include Architecture, global SAP Labs Network, SAP Knowledge & Education, Globalization Services, and SAP User Experience teams with the responsibility for the overall quality of SAP software products.

SOC 1 reports are prepared in accordance with AT-C section 320, Reporting on an Examination of Controls at a Service Organization Relevant to User Entities’ Internal Control Over Financial Reporting, and evaluate the effect of the controls at the service organization on the user entities’ financial statements. SOC 1 reports are specifically intended to meet the needs of the entities that use service organizations (user entities) and the CPAs that audit the user entities’ financial statements (user auditors).  SOC 1 Type 1 report on the fairness of the presentation of management’s description of the service organization’s system and the suitability of the design of controls to achieve the related control objectives as of a specified date, whereas a SOC 1 Type 2 also includes the operating effectiveness of controls to achieve the related control objectives throughout a specified period.

SAP Enterprise Management has regularly prepared SOC 1 Type 2 audit reports by an independent 3rd party accountant. This version of the report covers the audit period 1. October 2022 to 31. March 2023, in the data center locations, Ashburn (US), Amsterdam, (The Netherlands), Colorado Springs (US), Sydney (Australia), Toronto (Canada), Dubai (UAE), Frankfurt (Germany), Newtown Square (US), Riyadh (Saudi Arabia), St. Leon-Rot (Germany), Shanghai (China), Sterling (US), Tokyo (Japan), Council Bluffs (US), Mumbai (India), Eemshaven (Netherlands), Washington (USA), and Sao Paulo (Brazil).

The use of these reports is restricted to the management of the service organization, user entities, and user auditors. A copy of this report is available for all SAP Enterprise Management customers who had productive and had financially-relevant systems during the audit period covered by the report.