Summary
The corporate criminal resolution is a DPA, not a guilty plea. SAP admitted the DPA's statement of facts and accepted responsibility for the described acts, while prosecution of the two-count information was deferred subject to the agreement. That boundary must survive any short account of the case.
The SEC order has its own findings and scope. It addressed South Africa and six other countries, found anti-bribery, books-and-records and internal-control violations, and imposed disgorgement, interest and a cease-and-desist remedy. Its accounting and entity-level-control findings should not be silently replaced by the DPA's criminal admissions.
South African remedies are distinct. The NPA's corporate process, SIU investigations, Special Tribunal orders, contract invalidation and repayments operated under South African law. A recovery or settlement order does not itself convert every investigative statement into a criminal conviction.
The operational failure joined opportunity, intermediary and payment data too late. Sales teams could pursue valuable public business while ownership, qualifications, service evidence, commission economics, public-official connections and accounting classification were not subjected to one independent gate.
Public software is operational infrastructure. Electricity, transport, water and municipal institutions depend on functioning systems, but continuity cannot justify a bypass. Urgency should trigger earlier planning, stronger evidence and controlled alternatives, not retrospective paperwork.
Repair must be transaction-replayable. A reviewer should be able to reconstruct demand, competition, approvals, intermediary necessity, beneficial ownership, service, invoice, beneficiary, ledger entry, acceptance and post-payment monitoring from immutable records.
Remediation claims remain bounded. Cooperation, discipline, elimination of certain commission models, compliance investment and analytics are material evidence of design. They do not prove that every later public contract operated effectively; independent sampling and exception outcomes are still required.
Start with the legal map
The Justice Department's SAP case page identifies the Eastern District of Virginia matter and links the information and deferred prosecution agreement. That compact map matters because the instruments do different work. The information states the charged conspiracies. The DPA defines SAP's admissions, payments, cooperation, compliance obligations and the conditions under which the government agreed to defer prosecution. A defensible case register should preserve the docket, instrument, date, defendant, status and legal consequence rather than label the entire package a conviction.
The criminal information charged SAP with one conspiracy concerning South Africa that included anti-bribery and books-and-records entities and a second conspiracy concerning Indonesia focused on anti-bribery. It described SAP Africa, SAP South Africa and related employees and intermediaries, and it identified multiple South African public bodies. A charge is not by itself an admission. Here the admissions arise because SAP agreed to the DPA and stipulated to its attached statement of facts. That procedural sequence should be stated, not compressed.
The deferred prosecution agreement and statement of facts provide the central corporate admission. SAP agreed that the stipulated facts were true and accurate and accepted responsibility for the acts described. The record discusses public-sector opportunities involving municipalities, the Department of Water and Sanitation and Eskom, as well as the use of intermediaries, commission arrangements, things of value and false records. It also sets a three-year term, cooperation duties, compliance reporting and consequences for breach.
A DPA is therefore neither a non-event nor a guilty plea; it is a conditional criminal resolution with express admissions and enforceable duties.
The Justice Department's resolution announcement reconciles the criminal penalty, forfeiture, coordination credits, cooperation and remediation. It reports that SAP did not voluntarily self-disclose, but received substantial cooperation credit and a reduction based on the government's assessment. It also describes elimination of the third-party sales-commission model globally and a prohibition on sales commissions for public-sector contracts in high-risk markets. Those are significant remediation statements attributed to the Department's resolution analysis; they are not a permanent certificate of effectiveness.
The SEC order is parallel, not interchangeable
The SEC's settled administrative order made findings concerning SAP's conduct in South Africa, Greater Africa, Indonesia and Azerbaijan. SAP submitted an offer of settlement, and the Commission found violations of anti-bribery, books-and-records and internal-accounting-control provisions. The order describes third-party intermediaries, deficient service evidence, expense recording and limited public evidence entity-level controls. It is the controlling source for what the Commission found; the criminal information should not be cited as though it were the SEC's instrument.
The SEC's January 2024 announcement provides a concise reconciliation of disgorgement, prejudgment interest and offsets for South African payments. It also notes that the Commission had brought an earlier 2016 accounting-controls matter involving Panama. Offsets are accounting coordination, not proof that every authority entered the same judgment. A board dashboard should display gross amount, credited amount, recipient authority, remedy type and covered conduct so that a global headline does not create double counting or erase local recovery.
The earlier 2016 SEC SAP order is relevant as enforcement history, not as proof of the South African facts. That order concerned conduct connected with Panama and books-and-records and internal-controls provisions. The 2024 resolution considered prior history, but governance analysis should resist the shortcut of treating recurrence as identical conduct. The proper question is which control theme recurred: third-party justification, entity-level oversight, accurate recording, escalation or testing—and whether remediation after the earlier matter reached the later risk population.
South Africa's public record has several lanes
The National Prosecuting Authority's SAP corporate alternative-dispute-resolution summary records the South African corporate process and its economic-harm component. That mechanism should be described on its own terms. It was not the United States DPA, the SEC administrative order or a Special Tribunal contract judgment. Corporate settlement architecture can coordinate facts and payments while each authority retains its statute, standard and remedy.
The SIU's March 2024 Eskom statement reports a settlement made an order of the Special Tribunal, the setting aside of two contracts and a R500 million payment. It states that the agreements were declared constitutionally invalid and that the settlement did not absolve SAP or an implicated party from possible prosecution. That last sentence is a boundary: civil contract consequences and potential criminal process are not the same. The article therefore does not infer an individual conviction from the order.
The SIU's 2023/24 annual report supplies institutional context for the Eskom litigation and recovery. Annual reports aggregate case outcomes and public value, but their totals require care. A payment can be described inclusive of tax or in a rounded media amount; a contract can be reviewed and set aside while a separate just-and-equitable remedy determines repayment. The evidence pack should preserve the precise source for each number rather than harmonize differences by assumption.
An earlier SIU 2020/21 annual report shows that SAP-related litigation already appeared in the Special Tribunal pipeline before the 2024 Eskom order. That chronology helps distinguish investigation and filing from final resolution. It also shows why a board cannot wait for a final judgment to examine control design. Once credible allegations, preservation activity or civil proceedings identify a recurring intermediary pattern, prospective public opportunities should receive enhanced review without treating unsettled allegations as established guilt.
The official archive of the Judicial Commission's state-capture report section covering SAP contracts with Transnet and Eskom is a broad investigative record. Its role is to document the Commission's evidence and conclusions within South Africa's state-capture inquiry. It is not a substitute for SAP's DPA admission, the SEC's findings or a criminal verdict against a named person. Used carefully, it illuminates how enterprise-software contracts, public procurement and intermediary relationships sat within a wider institutional environment.
The South African Parliament's 2025 asset-recovery annex separately reports recovery information supplied by the SIU and Asset Forfeiture Unit, including Transnet-SAP and Eskom-SAP entries. Recovery tables are accountability records, but they are not self-explanatory verdicts. They should be reconciled by matter, authority, payment date and remedy. Aggregating a Transnet settlement, Eskom repayment and another SAP-related asset entry without identifiers can overstate recovery or misattribute it.
Opportunity approval must begin with public need
The control chain should start before a reseller, adviser or implementation partner is selected. The public customer should have a documented operational need, approved budget, procurement route, scope, delivery timetable and accountable owner. On the vendor side, SAP's opportunity record should capture the customer entity, tender or exception authority, anticipated products and services, competitors, decision points, officials involved and all third parties expected to influence or support the sale.
Enterprise-software opportunities are often described as combinations of licence, maintenance, cloud access, migration and professional services. That complexity can conceal where value is created. The approval record should separate each component, identify who performs it and compare direct sale, partner sale and subcontracting alternatives. A reseller margin or commission must have an economic explanation tied to real capability and assumed risk, not merely access to decision-makers.
Public need also protects continuity. An electricity utility or municipal service cannot casually replace core systems, and a delayed implementation may carry real costs. But urgency is foreseeable in many renewal and capacity cycles. The company should maintain an advance calendar of public renewals and expiring agreements, with sufficient time for competitive process and control review. If an emergency route is genuinely required, the file should state the legal basis, duration, price benchmark, interim safeguards and plan to return to ordinary procurement.
No sales forecast should be recognized as control evidence. Pipeline probability, executive attention and quarter-end timing can explain commercial pressure, but they cannot establish customer authority, intermediary legitimacy or service. Those facts need independent sources. A stage gate should prevent an opportunity from advancing when the sales team has entered only narrative assurances or when required customer documents remain absent.
Intermediary ownership and capability need independent proof
An intermediary file should identify legal and beneficial owners, directors, controllers, politically exposed persons, relatives, employees, subcontractors, bank accounts, tax status, office, experience and conflicts. Verification should use reliable registries and corroborating records rather than a questionnaire alone. Ownership changes, dormant-company history, newly opened accounts and connections to officials should trigger enhanced review.
Capability is transaction-specific. A firm may be a legitimate software reseller yet lack staff to deliver technical implementation, public-procurement advice or change management. The sponsor should define the service before onboarding and specify named personnel, hours, location, work product, milestones and acceptance criteria. Compliance should test whether the proposed role duplicates work already performed by SAP or another contractor.
The intermediary must disclose all subcontractors and informal entities. Introducers, advisers and politically connected persons may operate without signing the main agreement. The commercial team should certify that no undisclosed person expects compensation or influence credit. Communications, calendars, expenses and customer contacts should be sampled to test the certification. A denial from the sponsor is evidence, not final resolution.
Approval should expire. Beneficial ownership, political links, bank details and capability can change during a multiyear sales cycle. Re-screening should occur before contract, before the first payment, after a material change and at scheduled intervals. A prior green status cannot be copied into a new public opportunity without showing that the entity, role and risk remained the same.
Commission economics must survive an adversarial test
High commissions are not automatically unlawful. A partner may assume marketing cost, credit risk, local support, configuration work or implementation responsibility. The accountability obligation is to show why the rate is proportionate to that value. The file should compare the proposed commission with similar deals by market, product, role and risk, while explaining any deviation.
The reviewer needs gross and net economics. A discount to a reseller can function like a commission if the resale price and retained margin are opaque. Rebates, marketing funds, free licences, credits and post-contract amendments also transfer value. One control should aggregate all benefits to the intermediary and connected parties across legal entities and opportunities.
Success-based compensation attached to a public decision deserves special challenge. If the intermediary is paid only when a tender, extension or exception is approved, the company must show a legitimate service that is not merely influence. In high-risk public markets, the safer design may prohibit such commissions, as the DOJ announcement says SAP did for specified categories. Any residual exception needs an independent approver, legal basis and documented alternative analysis.
Payment timing can expose substance. A large invoice immediately after an award, round-sum billing, a beneficiary in an unrelated jurisdiction or accelerated payment without accepted deliverables should stop release. Treasury must validate that the account belongs to the contracted party and that no split instructions or personal accounts appear. Commercial executives should not be able to override a treasury hold through email.
Service evidence must exist before invoice approval
A contract is only the start of proof. Each deliverable should have a dated work product, identified author, receiving owner and acceptance record. Meeting attendance without minutes, a generic market report or a copied presentation is not enough to support a substantial fee. The evidence should demonstrate how the service advanced the defined business need without substituting for an improper payment.
Reviewers should test metadata and chronology. A document created after an invoice or copied from another engagement can look complete while being retrospective. Systems should retain original creation time, version history and reviewers. Late-created evidence should trigger investigation, not quiet normalization. Where privacy or privilege limits access, an authorized reviewer can record a bounded verification without making the material disappear.
The customer's acceptance cannot be the sole proof if the customer contact may have influenced the award. SAP should designate a technical or commercial owner independent of the relationship sponsor to validate delivery. Procurement and compliance should sample high-risk engagements, contact appropriate counterparties under controlled procedures and compare the claimed service with communications and project outputs.
Invoices should use structured fields: opportunity identifier, contract, milestone, service period, deliverable, rate, tax, beneficiary and approvers. Free text such as “consulting services” prevents analysis. Accounts payable should block invoices that do not match an approved purchase order and accepted milestone, with exceptions routed outside the sales hierarchy.
Tender and contract compliance belong in the same record
Vendor compliance and public-customer compliance are connected. The company should retain the tender, bid, clarifications, evaluation result, award notice, exception authority, contract and amendments. It should identify what representations SAP and each partner made about ownership, local participation, subcontracting and price. A later side agreement must be compared with those representations.
Contract amendments are a major risk window. Scope, licence quantities, cloud terms or service hours can change after competition. Each amendment should explain need, price and procurement authority, and should be reviewed for effects on intermediary compensation. Cumulative changes may transform the economics even if each amendment appears modest.
The World Bank's South Africa suspension and debarment directory provides comparative background on exclusion mechanisms and procurement-integrity consequences. It is not evidence of a sanction against SAP in this matter. Its value is architectural: supplier declarations, subcontracting, prior conduct and exclusion eligibility should be captured in a form that public purchasers and vendors can test consistently.
Where the public entity relies on a sole-source or emergency provision, SAP should not simply accept the customer's characterization. Local counsel or a qualified procurement specialist should assess the provision and document limitations. The company need not assume the public body's legal duty, but it must understand whether its own proposal, partner structure or requested terms conflict with the procurement route it is using.
Subsidiary accounting must connect to group visibility
The SEC emphasized entity-level controls. A global policy cannot operate if a subsidiary can approve a third party, book an expense and release payment without the parent seeing the risk. Each high-risk public opportunity should have a group-visible identifier linking the local customer, SAP entity, partner, contract, invoice, beneficiary and consolidated ledger account.
Accounting classifications should follow economic purpose. A commission must not become generic marketing, sponsorship or professional services because one label receives less scrutiny. The chart of accounts should contain controlled categories for third-party sales support and require the opportunity identifier. Reclassification after an alert should preserve the original entry and reason rather than overwrite history.
Consolidation is a control point, not a clerical endpoint. Group finance should test unusual margins, round-dollar payments, manual journals, rapid credits, payments near quarter end and expense categories inconsistent with partner type. Compliance should receive the exceptions with enough context to investigate. A dashboard that shows only total spend cannot reveal a politically connected intermediary attached to one public contract.
Local and parent responsibilities must be explicit. The subsidiary owns accurate records and lawful execution. Regional compliance owns independent challenge and escalation. Group functions own minimum standards, cross-entity aggregation and resources. If approvals are delegated, the system should identify the person, threshold and basis. “Approved locally” cannot be an orphan status.
Escalation must beat the contract signature
Warnings lose value when they arrive after award or payment. The workflow should define triggers that automatically pause the opportunity: unresolved ownership, official connections, excessive commission, missing service scope, inconsistent procurement documents, unusual payment destination, retrospective contract, sponsor resistance or a prior adverse record. A hold should be technically enforced across CRM, contracting, ordering and accounts payable.
Escalation needs a named recipient, response deadline and decision authority. The case record should preserve the original concern, source, confidence, investigation steps, interim safeguards and final reason. If legal advice is privileged, the record can show that advice was obtained and the decision made without exposing privileged content broadly.
Cross-border data rules require designed routing. Relevant information can remain in jurisdiction while stable identifiers and risk flags tell an authorized group reviewer that evidence exists. Access denials should be logged and escalated. Data locality is not a rationale for a headquarters committee to remain unaware that a proposed intermediary was linked to another concern.
Whistleblower and internal-investigation records should connect at the entity and person level under appropriate permissions. A concern closed as unsubstantiated may become material when a new opportunity supplies corroboration. The system must allow reopening without treating the earlier closure as proof that the underlying relationship is permanently safe.
Public-service continuity changes the impact, not the standard
Software used by electricity, transport, water and municipal institutions can affect essential service. Failed procurement can waste funds, entrench unsuitable systems or delay modernization. That public impact explains why both supplier and customer need auditable decisions. It does not establish that every disputed contract caused an outage, nor does it make a technology vendor responsible for all institutional performance.
Continuity planning should reduce the leverage of urgency. Public customers and vendors can maintain renewal calendars, documented system dependencies, data-portability plans, tested backups and phased procurement. When only one vendor appears operationally feasible, the file should explain interoperability constraints and pricing safeguards. Technical lock-in should be treated as a governance risk that requires evidence, not as an automatic waiver.
Contract invalidation and repayment can themselves affect service. A settlement plan should identify licences, support, migration and transition obligations so that fiscal recovery does not create an avoidable operational gap. Those arrangements should be transparent enough for oversight without compromising security or confidential system details.
Stakeholder reporting should distinguish financial recovery, contract status, service status and criminal process. Citizens should not have to infer that a repayment means systems stopped working, or that continued software use means the procurement was validated. Clear categories protect both accountability and continuity.
Remediation evidence must show operation under pressure
SAP's company statement on the 2024 resolutions says it investigated, cooperated, separated from responsible parties and enhanced compliance and controls. That is relevant corporate self-reporting. Authority records determine the legal disposition; independent testing determines whether the redesigned system operates. The company statement should therefore be retained with its attribution and limitation.
SAP's 2024 Form 20-F reports the settlements and describes compliance activity within an issuer filing. A securities filing carries formal disclosure responsibilities, but descriptions of programme strength remain management representations unless supported by disclosed independent assurance. Reviewers should extract concrete changes, dates, scope and metrics rather than repeat adjectives.
The prior-year events-after-reporting-period disclosure shows how SAP described the January 2024 settlements as a subsequent event. That accounting disclosure is useful for timing and corporate financial treatment. It does not expand the admissions in the DPA or replace South African instruments. Legal, financial and operational closure can occur on different dates.
The Justice Department's later policy speech discussing SAP explains how prosecutors viewed cooperation, prior history, compensation incentives and analytics. Speeches are not operative agreements. Their value is to clarify the Department's stated reasoning and expectations. Boards should trace those expectations to controls and tests rather than treat a favorable cooperation description as assurance.
Testing should replay complete transactions
Independent testers should select public-sector opportunities by risk, value and exception status, including wins, losses and abandoned deals. For each, they should reconstruct customer need, procurement route, intermediary ownership, qualifications, service scope, commission benchmark, communications, contract, deliverables, invoice, beneficiary, ledger entry and approval. The sample should include quarter-end pressure and senior-sponsored opportunities.
Testing must inspect source evidence, not screenshots of green workflow statuses. A completed field may contain a generic phrase; an attached document may have been created late; an approval may have followed payment. Testers need creation timestamps, audit logs and system joins. Failures should be classified by design, execution, data quality, supervision or deliberate circumvention.
Analytics should search across customers, intermediaries, owners, accounts, employees and addresses. Repeated commissions just below thresholds, related vendors, shared bank accounts, excessive discounts, rapid amendments and payments to unrelated jurisdictions deserve review. Models produce leads, not findings. Every alert should have an owner, disposition and preserved rationale, with false positives used to improve rules without suppressing uncomfortable patterns.
The central outcome metric is stop capacity. How often did independent functions delay, condition or reject an opportunity? How many exceptions were requested and by whom? Were conditions closed before signature and payment? Did a senior sponsor's involvement change review time or result? A programme that reports only training and screenings cannot show that commercial pressure is governable.
Partner programmes need one risk standard across commercial labels
Technology groups often use several partner categories: reseller, distributor, systems integrator, referral source, implementation consultant and managed-service provider. Those labels describe commercial relationships, but they can create control gaps if each programme collects different evidence. A party able to influence a public award or receive value linked to it should enter the same risk graph regardless of its channel label.
The onboarding standard should ask what the partner will actually do on the named opportunity. A distributor that only handles logistics poses a different service question from an adviser expected to arrange meetings. Yet ownership, official connections, beneficiary accounts and subcontractors remain relevant to both. Risk scoring should combine role, geography, public-customer exposure, compensation, ownership and past conduct instead of declaring a whole partner category low risk.
Programme changes require continuity. A rejected intermediary should not reappear as a subcontractor under another partner or as a marketing vendor paid by another SAP entity. Stable identifiers should connect former names, owners, directors, addresses, bank accounts and sponsors. When the match is uncertain, compliance should resolve it before approval rather than let a new vendor number erase history.
Partner performance reviews should include compliance evidence alongside revenue and certifications. Metrics can test accepted deliverables, customer complaints, unusual discounts, late ownership updates, payment exceptions and undisclosed subcontracting. Renewal should be an active decision with a dated evidence snapshot. A partner that produces revenue but repeatedly needs exceptions is not a high-performing partner in a public-sector programme.
Incentives and forecasting can weaken independent challenge
Sales compensation often crystallizes at booking, while legal, delivery and collection risks mature later. That timing can reward an executive for closing a public contract before the consequences of a weak intermediary record appear. Compensation design should defer a risk-adjusted portion of reward, preserve malus and clawback authority and attach consequences to supervisors who approved avoidable exceptions.
Targets can also shape evidence indirectly. When a forecast has been communicated to senior management or investors, delay becomes institutionally costly. The control system should identify forecast-critical opportunities and raise—not lower—the level of independent review. Reviewers must be protected from performance ratings based on deal velocity, and their escalation statistics should not be treated as commercial obstruction.
Commission recipients have incentives too. A percentage tied to licence value may encourage scope inflation or unnecessary product. The company should compare customer demand, installed base, utilization and implementation capacity. Commercial benefit is legitimate only when supported by a real customer need and deliverable. A larger order should not automatically generate a proportionately larger fee if the intermediary's work did not increase.
Management should inspect incentive outcomes after the fact. Which employees received credit for contracts later disputed, repaid or investigated? Were awards deferred or recovered? Did control staff face adverse consequences for holds? Individual decisions require evidence and due process, but an institution that never revisits reward teaches employees that revenue is private while control failure is collective.
Investigation and preservation must protect the evidence chain
Once a concern appears, preservation should cover email, approved messaging, mobile applications used for business, contracts, invoices, CRM history, audit logs, bank instructions and work-product metadata. The DOJ resolution announcement credits early phone imaging and extensive cross-border production. That history illustrates a general rule: preservation quality affects whether an institution can reconstruct conduct rather than rely on memories and curated exports.
Legal holds need entity, person and transaction identifiers. A broad instruction to retain “SAP South Africa material” may be both overinclusive and ineffective. Custodian maps should identify sales, partner management, finance, legal, compliance, executives and relevant customer-facing staff. Collection should preserve native files and metadata, with chain of custody and documented exclusions.
Internal investigations must remain separate from commercial remediation. Suspending a partner, cancelling a commission or correcting an entry can reduce ongoing risk, but it can also change evidence. Investigators should capture the original record before operational teams edit systems. The case file should show what was known at each decision point and which facts emerged later.
Cooperation is not a substitute for self-detection. A company may receive credit for producing documents and making people available, but a board must ask why ordinary controls did not surface the issue earlier. The investigation closeout should therefore produce a root-cause map linked to control owners, deadlines and validation. Lessons should be applied across similar markets and partner models, not limited to the subsidiary where the public allegation arose.
Recovery and settlement need their own reconciliation ledger
Global resolutions often use credits to avoid duplicative recovery. South African settlements can also involve several public entities, contracts and legal routes. Finance and legal teams need a reconciliation ledger that records payer, payee, currency, gross amount, tax treatment, covered conduct, credit, due date, payment proof and remaining obligation. Public reporting should draw from that ledger.
The ledger must distinguish restitution, disgorgement, forfeiture, criminal penalty, civil penalty, interest, contract repayment and investigative cost. These categories answer different questions. A repayment linked to an invalid contract is not necessarily a calculation of profit; disgorgement is not a criminal fine; a coordination credit is not a new payment. Clear labels prevent stakeholders from adding overlapping figures or understating total obligations.
Operational ownership continues after payment. The company should verify that required funds reached the designated authority, that contract and licence consequences were implemented, and that any continuing service arrangement has a lawful basis. A settlement date does not by itself close migration, support, data-access or record-retention duties.
Boards should also track recoveries sought by public institutions and amounts actually received. Filed claims, settlement orders and cash receipts are separate milestones. Variances need explanation. This is not only financial housekeeping: a reproducible ledger demonstrates that commitments made across jurisdictions were executed and that local public institutions received the remedies attributed to them.
A board evidence pack should expose ownership
The board or delegated committee should see accountable owners for public-opportunity approval, intermediary due diligence, commission economics, procurement-law review, contracting, deliverable acceptance, invoice approval, accounting, escalation and independent testing. The same person may own related activities, but the sponsor cannot both create and independently clear the decisive evidence.
Leading indicators include incomplete ownership checks, late tenders, commission exceptions, sole-source routes, retrospective contracts, manual journals, payment holds and overdue investigations. Lagging indicators include contract disputes, recoveries, regulator contact, discipline and repeat findings. Data should be segmented by country, public entity, partner, sales leader and product so an improving global average does not hide concentration.
The pack should state limitations. Which systems are not integrated? Which local records could not be accessed? How many partner owners remain unverified? Which remediation tests cover only design? A candid gap with a funded deadline is better governance than an unqualified green status based on incomplete data.
Board challenge must be recorded. Minutes should identify the evidence requested, management's answer, dissent, conditions and person accepting residual risk. When management cites customer urgency, the board should ask what earlier planning failed and whether the proposed workaround preserves competition, price discipline, service proof and stop authority.
The committee should also receive a transaction-level exception appendix. Each entry should name the public customer, opportunity, partner, exception type, requestor, approver, value, compensating control, expiry and current status. Aggregated percentages can conceal that one executive repeatedly sponsors the highest-risk deviations. The appendix makes concentration visible and permits directors to ask why a supposedly temporary workaround became routine.
Assurance reports should separate design, implementation and sustained effectiveness. A policy may be well designed but not configured in every subsidiary. A workflow may be live but lack historical data or payment integration. A sample may pass for one quarter without covering a renewal cycle. Management should state the population, sampling method, exceptions and period, while internal audit explains whether it independently reproduced the evidence.
Board reporting should follow unresolved conditions to closure rather than disappear them at approval. Conditions accepted before contract must be technically linked to signature, ordering and payment gates. If a condition is waived, the record should identify the new decision-maker and reason. Ageing reports should show overdue evidence, business continuing under interim controls and repeat extensions. A condition that never blocks value is not a condition; it is commentary.
Finally, directors should see failed and abandoned opportunities. A control system cannot be assessed only from contracts that survived every gate. Rejections reveal whether adverse ownership, weak service or unlawful procurement can overcome commercial sponsorship. Abandoned deals may also show whether sales teams withdraw an opportunity to avoid review and later reintroduce it through another entity or partner.
Who owes what after a procurement-control failure
SAP SE's board owes group standards, resources, incentive alignment and evidence that subsidiary controls operate. Senior management owes implementation, accurate regulator reporting and consequences for circumvention. Subsidiary leaders owe lawful local execution and truthful books. Sales sponsors owe complete disclosure of entities, economics and communications. Compliance and legal owe independent judgment and enforceable holds.
Finance and treasury owe beneficiary verification and accurate classification. Procurement owes contracting discipline and service evidence. Internal audit owes end-to-end testing across systems and entities. Compensation committees owe a documented response when revenue was generated through serious misconduct or control failure, while respecting individual evidence and employment law.
South African public entities owe their own demand planning, lawful procurement, contract management and transparent recovery. Investigators, prosecutors and tribunals owe clear identification of authority, party, legal status and remedy. Journalists and reporting institutions owe the same precision. A civil recovery should not be written as an individual conviction; a corporate admission should not establish liability for unnamed people.
Taxpayers, electricity and transport users, employees, competitors and investors are entitled to evidence that public software demand is legitimate and value transfers are traceable. They are not served by a choice between overstatement and denial. The record supports a more useful conclusion: public-sector sales require a joined control architecture in which opportunity, intermediary, contract, service, payment and accounting evidence meet before commitment.
The accountability standard is evidence before value
The enduring lesson is not that enterprise-software companies must reject intermediaries or public customers. It is that they must be able to prove why each intermediary exists and what each payment buys. That proof must be independent of the sales narrative, complete before signature and payment, visible across subsidiary boundaries and reproducible years later.
Evidence before value means no unresolved owner, official connection or subcontractor; no commission without benchmark and service logic; no invoice without accepted deliverable; no payment without verified beneficiary; no ledger entry without opportunity identity; and no exception without a named accountable executive, expiry and review. High-risk public business should generate more traceability, not more discretion.
Durability is demonstrated when the system stops an attractive deal. Independent sampling should show that holds cannot be overridden informally, adverse records travel with people and entities, analytics produce investigated cases, and board metrics reveal exceptions. Remediation is complete only after sustained operation across a meaningful population, including periods of commercial pressure.
That standard preserves the legal boundaries of the SAP record. The DPA admissions, charged information, SEC findings, NPA corporate process, SIU investigations, Special Tribunal settlements, recoveries and company reports remain distinct. Together they establish a coherent procurement-accountability demand: public-sector software revenue must rest on independently challenged need, legitimate intermediaries, verified services, lawful contracting and an attributable evidence chain from opportunity to ledger.

