SAP Concur SOC 2 (ISAE 3000) Audit Report 2023 H1

SAP Concur’s travel and expense management solutions (SAP Concur solutions) in scope for this SOC 2 Audit are:

  •  Concur Standard/Professional/Premium Editions, including Travel, Expense, and Invoice

  • Concur Small Business Edition

  • SAP Concur mobile app (including both Standard/Professional/Premium and Small Business)

  • SAP Concur Supporting Services (Imaging, Analytics, etc.)

The SOC 2 reports fulfill various information and assurance needs of customers and aim to place trust in SAP’s service organization systems, processes, and controls.  These reports are intended to meet the needs of a broad range of users that need detailed information and assurance about the controls at a service organization relevant to security, availability, and processing integrity of the systems that are used to process users’ data and the confidentiality and privacy of the information processed by these systems.  Additionally, they can play an important role in the oversight of the organization, vendor management programs, and regulatory oversight.  SOC 2 Type 1 covers management’s description of a service organization’s system and the suitability of the design of controls at a specific point in time, whereas a SOC 2 Type 2 also includes the operating effectiveness of controls for a dedicated period of time.

SAP Concur Solutions has prepared SOC 2 Type 2 audit report by an independent 3rd party accountant. This version of the report covers the audit period 1. October 2022 to 31. March 2023 in the primary data center locations, Lynwood, Washington (USA), and Paris (France).  The following AWS regions are also covered: EU2, Fabian EMEA, Fabian US, and US2, and the trust principles Security, Availability and Confidentiality.

The use of these reports is restricted. A copy of this report is available for all SAP customers and prospects with non-disclosure agreement in place.