SAP Ariba and SAP Business Network SOC 2 Audit Report 2024 H1

SAP Ariba and SAP Business Network is a leading provider of on-demand spend management solutions. SAP Ariba and SAP Business Network ’s mission is to transform the way companies of all sizes, across all industries, and geographies operate by delivering technology, service, and network solutions that enable them to holistically source, contract, procure, pay, manage and analyze their spend and supplier relationships. Delivered on demand, SAP Ariba and SAP Business Network’s enterprise-class offerings empower companies to achieve greater control of their spend and drive continuous improvements in financial and supply-chain performance.

 

This report covers the following data center locations:

DC Locations

DC Providers

Council Bluffs, Iowa

Google Cloud Platform

Sydney, Australia

Google Cloud Platform

Frankfurt, Germany

Google Cloud Platform

Tokyo, Japan

Google Cloud Platform

Shanghai, China

SAP Cloud Infrastructure

Riyadh, Kingdom of Saudi Arabia

SAP Cloud Infrastructure

Dubai, United Arab Emirates

SAP Cloud Infrastructure

SOC 2 reports are prepared in accordance with AT-C Section 205 and the International Standard on Assurance Engagements No. 3000. SOC 2 reports fulfill various information and assurance needs of customers and aim to place trust in SAP’s service organization systems, processes, and controls.  These reports are intended to meet the needs of a broad range of users that need detailed information and assurance about the controls at a service organization relevant to Security, Availability, and Processing Integrity of the systems that are used to process users’ data and the Confidentiality and Privacy of the information processed by these systems (AICPA, Trust Services Criteria).  Additionally, they can play an important role in the oversight of the organization, vendor management programs, and regulatory oversight.  Please note that this examination's scope does not include the controls of any subservice organizations.  SOC 2 Type 1 covers management’s description of a service organization’s system and the suitability of the design of controls at a specific point in time, whereas a SOC 2 Type 2 also includes the operating effectiveness of controls for a dedicated period of time.

 

SAP Ariba and SAP Business Network has prepared SOC 2 Type 2 audit report by an independent 3rd party accountant. This version of the report covers as of the audit period 1. April 2023 to 31. March 2024, and the trust principles Security, Availability, Processing Integrity, and Confidentiality.

 

The use of these reports is restricted. A copy of this report is available for all SAP customers and prospects with non-disclosure agreement in place.

SAP Ariba and SAP Business Network is a leading provider of on-demand spend management solutions. SAP Ariba and SAP Business Network ’s mission is to transform the way companies of all sizes, across all industries, and geographies operate by delivering technology, service, and network solutions that enable them to holistically source, contract, procure, pay, manage and analyze their spend and supplier relationships. Delivered on demand, SAP Ariba and SAP Business Network’s enterprise-class offerings empower companies to achieve greater control of their spend and drive continuous improvements in financial and supply-chain performance.

 

This report covers the following data center locations:

DC Locations

DC Providers

Council Bluffs, Iowa

Google Cloud Platform

Sydney, Australia

Google Cloud Platform

Frankfurt, Germany

Google Cloud Platform

Tokyo, Japan

Google Cloud Platform

Shanghai, China

SAP Cloud Infrastructure

Riyadh, Kingdom of Saudi Arabia

SAP Cloud Infrastructure

Dubai, United Arab Emirates

SAP Cloud Infrastructure

SOC 2 reports are prepared in accordance with AT-C Section 205 and the International Standard on Assurance Engagements No. 3000. SOC 2 reports fulfill various information and assurance needs of customers and aim to place trust in SAP’s service organization systems, processes, and controls.  These reports are intended to meet the needs of a broad range of users that need detailed information and assurance about the controls at a service organization relevant to Security, Availability, and Processing Integrity of the systems that are used to process users’ data and the Confidentiality and Privacy of the information processed by these systems (AICPA, Trust Services Criteria).  Additionally, they can play an important role in the oversight of the organization, vendor management programs, and regulatory oversight.  Please note that this examination's scope does not include the controls of any subservice organizations.  SOC 2 Type 1 covers management’s description of a service organization’s system and the suitability of the design of controls at a specific point in time, whereas a SOC 2 Type 2 also includes the operating effectiveness of controls for a dedicated period of time.

 

SAP Ariba and SAP Business Network has prepared SOC 2 Type 2 audit report by an independent 3rd party accountant. This version of the report covers as of the audit period 1. April 2023 to 31. March 2024, and the trust principles Security, Availability, Processing Integrity, and Confidentiality.

 

The use of these reports is restricted. A copy of this report is available for all SAP customers and prospects with non-disclosure agreement in place.