Skip to main content

      Data drives business processes, enables analysis and underpins digital business models. At the same time, data volumes in many SAP systems have grown unchecked over the years.  

      Data management does not become any easier with SAP S/4HANA: The HANA in-memory database and the revised data model increase complexity. Data volumes remain a key factor in costs and system performance, whilst regulatory requirements for traceability, transparency and compliance are on the rise.

      This brings one central question into focus:

      • Which data is actually required for day-to-day operations in SAP S/4HANA, and which data primarily increases complexity, costs and risks?

      Why SAP S/4HANA rarely fails due to technical issues

      The real challenges lie not in the technology, but in the structural handling of data – and SAP S/4HANA consistently lays this bare. Data stocks that have accumulated over the years often remain fully accessible, regardless of whether they are still relevant to the business. What older SAP architectures have long compensated for is now having an immediate impact.

      Without a clear strategy for data reduction and early archiving, data volumes continue to grow, hindering transparency and manageability – with direct consequences for system behaviour, project complexity and day-to-day operations.

      auto_stories

      Current insights into the technological transformation in companies - focus topic AI

      Regulatory requirements, system performance and cost-effectiveness are all interlinked

      At the same time, regulatory requirements are increasing. The General Data Protection Regulation (GDPR) requires clear purpose limitation, data retention and the compliant deletion of personal data; the German Commercial Code (HGB) and the German Fiscal Code (AO) require the audit-proof retention of business-relevant information for defined periods. As both are spread across all business processes, these requirements have an impact across systems and processes.

      In practice, however, it is evident that regulatory requirements, system performance and cost-effectiveness are often considered in isolation, even though they cannot be separated in day-to-day system operations. The result is a growing conflict:

      • Data remains operationally available even though its original purpose no longer applies.
      • Demonstrating compliance with data processing regulations becomes more complex and time-consuming.
      • Operating costs and migration efforts are rising

      It is at this point, at the very latest, that it becomes clear: data management is no longer a mere operational detail, but a strategic issue with direct implications for transformational capability, project risks and ongoing operating costs.

      Typical patterns recur time and again:

      Archiving as a workaround

      Archiving is often seen as a solution, but it merely moves data from one system to another. This does not provide end-to-end, audit-proof control over the entire data lifecycle. Clear responsibilities, targeted deletion and transparency remain unaddressed.

      Governance without technical enforcement

      Although technical and legal rules are defined, they are not technically enforced during system operation and are therefore implemented inconsistently. Without technical implementation, governance remains conceptual and dependent on manual processes – this leads to inconsistencies and can only be substantiated to a limited extent during an audit.

      The approach: managing data throughout its lifecycle

      It is not the sum of individual measures that is effective, but rather the consistent management of data throughout its entire lifecycle. Instead of permanently classifying data as ‘productive’, it is categorised according to its usage and legal context.

      Lifecycle-oriented data management thus lays the foundation for targeted control, cost efficiency and risk reduction. Technical solutions such as SAP Information Lifecycle Management enable this control at the system level: Retention periods, restrictions and deletions are implemented on a rule-based basis, tracked automatically and documented in an audit-proof manner. It is crucial, however, that these mechanisms are clearly embedded in both business processes and organisational structures.

      A structured lifecycle typically comprises four phases:

      • Active use (operational, high-performance, available)
      • Restriction/block (e.g. once the purpose no longer applies, whilst a retention obligation remains in force)
      • Audit-compliant storage (legally required, reduces operational burden)
      • Compliant data erasure (automated, auditable and repeatable)

      Above all, this distinction achieves one thing: the ability to make decisions. It highlights which data provides genuine added value and which merely generates costs and risks. It is only this transparency that enables data to be actively managed.

      This approach yields the following key benefits:


      Data management as part of corporate governance

      The way data is handled is no longer just a matter of regulatory compliance. It affects the performance of IT systems, operating costs and the success of strategic transformations. Data management thus becomes an integral part of corporate governance.

      Whether data lifecycle management delivers results or remains merely a concept depends on its implementation. Three key decisions are crucial here, and you should be taking active steps to address them now:

      • Specify scope

        Identify which data objects are relevant from a business and risk perspective: data volume, process criticality and legal requirements such as personal data and retention obligations. Make a conscious decision to start with a clearly defined scope in order to achieve visible results at an early stage.

      • Clarify rules and responsibilities

        Decide who is responsible for determining retention and deletion policies, and define clear processes for exceptions such as legal holds, audits or disputes. Only when responsibilities are clearly defined can data management be effectively enforced.

      • Designing the technical implementation

        Design data locking, archiving and deletion processes in such a way that they can be reproduced, are properly documented and meet audit requirements.

      Only when you have clearly made these three decisions and implemented them consistently will you be actively managing your data – with an immediate impact on costs, efficiency and compliance. A structured analysis of your data assets, regulatory requirements and technical implementation will highlight where action is needed.

      Talk to our experts now about how you can embed data management as an effective control tool within your SAP landscape.

      More KPMG Insights

      Your contact

      Andreas Steffens

      Director, Audit, Regulatory Advisory, Digital Process Compliance

      KPMG AG Wirtschaftsprüfungsgesellschaft