SAP Business ByDesign SOC 1 (ISAE 3402) Audit Report 2022 H1

The scope of this SOC report includes the SAP Business ByDesign solution as offered for the live productive customer systems that are hosted in SAP SE's data centers in St. Leon–Rot (Germany), and Newtown Square (USA) as well as in the co-location Frankfurt (Germany), Sydney (Australia), and Shanghai (China).

SAP Business ByDesign is a cloud-based Software-as-a-Service (SaaS) ERP offering for mid-market companies and subsidiaries, powered by SAP HANA®. With SAP Business ByDesign (ByD), organizations can manage their entire business with a single cloud ERP solution. It is suited for mid-market companies and subsidiaries of large corporations This complete and integrated Software-as-a-Service (SaaS) suite supports financials, human resources, sales, procurement, customer service, supply chain management and more. Additionally, ByD has integration capabilities with a variety of SAP’s LoB based cloud solutions like SuccessFactors, Concur etc

SOC1 reports specifically address service organizations internal control over financial reporting and controls specified by the service provider. The SOC1 reports are intended solely for the information and use of existing user entities (for ex. Existing customers of the service organization), their financial statement auditors and management of the service organization. SOC 1 reports are prepared in accordance with Statement on Standards for Attestation Engagements (SSAE) No.18, a new guidance that the auditors use to conduct a SOC1 engagement. SOC1 Type 1 covers management’s description of a service organization’s system and the suitability of the design of controls at a specific point in time, whereas a SOC1 Type 2 also includes the operating effectiveness of controls for a dedicated period of time.

SAP Business ByDesign has regularly prepared SOC1 Type 2 audit reports by an independent 3rd party accountant. This version of the report covers the audit period 1. November 2021 to 31. March 2022, the locations St. Leon–Rot (Germany), and Newtown Square (USA) as well as in the co-location Frankfurt (Germany), Sydney (Australia), and Shanghai (China).

The use of these reports is restricted. A copy of this report is available for all SAP Business ByDesign customers who had productive and had financially-relevant systems during the audit period covered by the report.