SAP Sales Performance Management SOC 1 (ISAE 3402) Audit Report 2022 H1

Callidus Software Inc., doing business as SAP Sales Performance Management (SPM), was acquired by SAP SE in April 2018 and is part of SAP’s SuccessFactors business segment providing cloud-based sales, marketing, learning, and customer experience solutions. SAP SPM enables organizations to accelerate and maximize their lead to money process with a complete suite of solutions that identify the right leads, ensure proper territory and quota distribution, enable salesforce, automate bid configuration pricing and quoting, manage contracts, streamline sales compensation, and capture customer feedback for competitive advantage. Over 6,700 leading organizations, across all industries, rely on SAP SPM to optimize the lead to money process and close more deals, faster. 

"Lead to Money" is a process designed to enable companies to respond to the changing role of sales and marketing in the redefined buying cycle. In the last decade, the ubiquity of social networks, mobile devices, and e-commerce has transformed the traditional sales cycle into a buyer-lead journey. The core mission of SAP SPM is to accelerate and maximize effectiveness along this “Lead to Money” process. SAP SPM provides a suite of Software-as-a-Service (SaaS) solutions which generate revenue from cloud subscriptions, sales operation services, and term licenses. SaaS customers typically purchase annual subscriptions but can also purchase multi-year subscriptions.

SOC 1 reports specifically address service organizations internal control over financial reporting and controls specified by the service provider. The SOC 1 reports are intended solely for the information and use of existing user entities (for ex. Exiting customers of the service organization), their financial statement auditors and management of the service organization. SOC 1 reports are prepared in accordance with Statement on Standards for Attestation Engagements (SSAE) No.16, a new guidance that the auditors use to conduct a SOC 1 engagement. SOC 1 Type 1 covers management’s description of a service organization’s system and the suitability of the design of controls at a specific point in time, whereas a SOC 1 Type 2 also includes the operating effectiveness of controls for a dedicated period.

SAP SPM has regularly prepared SOC 1 Type 2 audit reports by an independent 3rd party accountant. This version of the report covers the audit period 1, November 2021 to 31. March 2022, the locations San Ramon (California), Birmingham (Alabama), Belgrade (Serbia), Hyderabad (India), as well as in co-locations Sacrament, CA and Ashburn, VA (USA), Frankfurt (Germany), Selangor (Malaysia), Kuala Lumpur (Malaysia), Singapore, and Dublin (Ireland). The use of these reports is restricted. A copy of this report is available for all SAP SPM customers who had productive and had financially-relevant systems during the audit period covered by the report.