SAP customers in the DACH region are facing an architectural challenge in 2026 that has emerged over the last 18 months. Four key regulations each require their own audit trail structures, with different retention periods, content requirements, and reporting obligations. Those who treat them in isolation end up building four parallel logging silos and paying three times more than necessary. Those who integrate them need the architecture described in this article.
The four regulations are: SOX Sarbanes-Oxley Act (in effect since 2002 for publicly traded companies with US ties, Section 802 requires 7-year retention), EU DORA Digital Operational Resilience Act (in effect since January 17, 2025, for financial entities), NIS2 in Germany (NIS2 implementation act in effect since December 6, 2025, affecting approximately 29,500 companies across 18 sectors), EU AI Act Article 26 (effective from August 2, 2026, for deployers of high-risk AI systems).
This concentration of deadlines is new. While SOX has been around since 2002, DORA, NIS2, and Article 26 have all come into force within the last 16 months or will take effect in the next 90 days. Customers who last reviewed their audit architecture before 2024 will find gaps today that need to be closed.
The BaFin guidance from January 2026 explicitly clarified that AI systems must be embedded into DORA-compliant ICT risk management frameworks, rather than kept in a separate AI compliance silo. Customers need an audit trail architecture that reflects this integration.
Scope: Public companies with a US stock exchange listing and their auditors. Audit trail requirements: Section 802 requires 7 years of retention in tamper-proof storage. Section 404 requires annual internal control reports subject to external audit. Penalties: Prison sentences of up to 20 years for intentional manipulation. Material weakness findings in the annual report. SAP implementation: SAP Security Audit Log (SM19/SM20), BTP Audit Log Service, Cloud ALM Audit Log API. Annual reporting cycle.
Scope: 20 categories of financial entities (banks, insurance companies, investment firms, payment institutions, crypto-asset service providers) plus their critical ICT third-party providers. Audit trail requirements: Explicit logging program according to RTS, practically a 5-year retention period. Article 10 requires real-time anomaly detection. Article 17 requires incident reporting in three stages (24h/72h/1M). SAP implementation: FS-CD, insurance-specific SAP solutions, S/4HANA Finance components. Logging architecture must be real-time capable.
Scope: Around 29,500 companies across 18 sectors in Germany. Three categories: operators of critical infrastructure, essential entities, and important entities. Audit trail requirements: §30 new BSIG: 10 core risk management measures. §32: Reporting obligations in three stages (24h/72h/1M). §39: Proof of effectiveness within 3 years. Important: Registration deadline with the BSI ended on March 6, 2026. Relationship to DORA: DORA is lex specialis for financial entities. Penalties: Up to EUR 10 million or 2% of annual turnover, plus personal liability for management.
Scope: Deployers of high-risk AI systems from Annex III (8 sectors). Audit trail obligations: 6-month retention of automatically generated AI logs (paragraph 6). Document human oversight activities. SAP implementation: SuccessFactors Recruiting, FS-CD credit scoring, Joule agents. Digital Omnibus status: Trilogue failed on April 28, 2026; follow-up trilogue scheduled for May 13, 2026. Customers are planning based on the original deadline.
Pragmatic approach: Those subject to multiple regulations should adopt the longest period as the standard. SAP customers with SOX requirements retain their finance-related logs for 7 years. AI system logs: 7 years. ICT incident logs: 5 years. System operation logs: 2 years.
The GDPR conflict: SOX, DORA, NIS2, and the EU AI Act require long retention periods, while GDPR Article 5 requires storage limitation. Resolution: Pseudonymization during logging, separation of technical audit trails from personal tracking, and a clear legal basis under GDPR for long-term retention.
DORA requires EU data centers for critical data. Customers storing audit logs in US cloud services must explicitly select the EU region and secure this contractually. For customers with strict data sovereignty requirements, BSI-certified providers (C5:2026, published by the BSI in April 2026) are the natural choice: T-Systems Open Telekom Cloud, IONOS, Plus Server.
SOX Section 802 requires tamper-proof storage. DORA requires real-time detection. Solution: WORM (Write Once, Read Many) architecture with read optimization. AWS S3 Object Lock, Azure Blob Immutable Storage, and Google Cloud Storage Bucket Lock are the typical cloud implementations. For on-premises requirements: WORM NAS from NetApp, Dell EMC, or IBM.
SAP customers have logs from many sources with different formats and time zones. Solution: A two-tier architecture. First tier: Source-specific connectors that normalize data into a unified format (CEF, OCSF). Second tier: A central SIEM platform that aggregates the normalized data and makes it searchable.
Four regulations, four different versions of the truth, and high maintenance effort versus a single source of truth. Solution: A central data layer with regulatory-specific view filters. Raw data is stored once, and reports are generated from regulatory perspectives.
The architecture proven in practice consists of five layers.
Layer 1, Source Connector: Source-specific modules that extract data from SAP components and third-party systems and normalize it into a unified format. Options: SAP's own Splunk connectors, Microsoft Sentinel SAP Solution, Google Chronicle Forwarder, ELK Beats with custom parsers, Onapsis, SecurityBridge.
Layer 2, Central Aggregation Platform: A SIEM platform that collects, indexes, and correlates normalized data in real time. For DORA Article 10 anomaly detection and NIS2 §30 incident detection. Market standards: Splunk Enterprise Security, Microsoft Sentinel, Google Chronicle, Elastic Stack, IBM QRadar.
Layer 3, WORM Compliance Storage: Immutable storage for long retention periods. Tiered storage: Hot (0-90 days), Warm (90 days to 2 years), Cold (over 2 years up to 7 years).
Layer 4, Regulatory Views: SOX ITGC dashboard (Logical Access, Change Management, IT Operations), DORA incident reporting dashboard, NIS2 reporting dashboard with BSI portal interface, EU AI Act compliance dashboard.
Layer 5, Operational Processes: Compliance officer roles, escalation process, training plan, review cycles (monthly operational, quarterly compliance, annual strategy), incident response playbooks. No technical architecture works without this organizational layer.
Solutive AG is the initiator of the Change Orchestration Institute. The ratings in the table are self-reported by the providers and are not part of an independently validated editorial assessment.
SIEM platforms are strong in DORA and NIS2 (real-time detection) but weaker in the EU AI Act. GRC platforms are strong in the EU AI Act and SOX but weaker in real-time detection. A combination of SIEM and GRC is the standard architecture for large enterprises.
Customers starting with an integrated audit trail architecture today need a 12-to-18-month plan.
Phase 1 (60-90 days): Determine compliance scope, inventory data sources, map obligations per regulation, perform gap analysis, and make architectural decisions (SIEM, GRC, storage, EU hosting). Output: Architectural concept.
Phase 2 (90-180 days): Implement source connectors, tune data volume, define correlation rules, set up WORM storage, and build initial dashboards. Output: Functional aggregation.
Phase 3 (60-120 days): SOX ITGC dashboard, DORA incident reporting, NIS2 reporting with BSI portal interface, EU AI Act compliance tracking, and cross-regulatory master view. Output: Complete reporting suite.
Phase 4 (ongoing): Establish compliance operations, training, audit preparation, roadmap tracking, and cost optimization. Output: Mature compliance architecture.
PhaseTimeframeMain Result1Inventory and gap analysis60-90 daysArchitectural concept2Connector setup90-180 daysFunctional aggregation3Regulatory views60-120 daysReporting suite4Operational maturityongoingMature compliance architectureFirst key takeaway: The four regulations—SOX, DORA, NIS2, and the EU AI Act—each require their own audit trail structures, but they share a common data foundation. Treating them in isolation leads to triple the costs. Integrating them requires a single source of truth with regulation-specific view filters. The five-layer architecture described in this article (source connector, aggregation platform, WORM storage, regulatory views, and operational processes) is the proven solution in practice.
Concrete recommendation: Use the SAP data source mapping table from section 5 as the basis for your inventory. For each data source, check which regulations it covers and whether the connector already exists or needs to be built.
Second key takeaway: Retention periods must be handled hierarchically. The 7-year SOX requirement is the longest period and serves as the standard for all finance-related logs. The tension with GDPR (storage limitation) is resolved through pseudonymization and the separation of technical and personal audit trails. Tiered storage (hot/warm/cold) significantly reduces the costs of this long-term retention.
Actionable recommendation: Use a WORM architecture with a cold tier for data older than 2 years. Cold-tier storage costs are approximately one-tenth of hot-tier costs. This makes 7-year retention feasible for large enterprises at a low six-figure annual cost.
Third key takeaway: No single tool fully covers all four regulations. SIEM platforms (Splunk, Sentinel, Chronicle) are strong in real-time detection (DORA, NIS2) but weaker in AI-specific obligations. GRC tools (OneTrust, ServiceNow) are strong in SOX and the EU AI Act. SAP-specific platforms (Onapsis, SecurityBridge) are strong in ITGC but weak in AI. The typical architecture combines SIEM and GRC, with SAP-specific tools serving as data providers.
Actionable recommendation: Make toolchain decisions based on the three customer profiles in Section 7.3. Cost ranges: 300k to 700k EUR (Profile C, mid-market), 800k to 1.5M EUR (Profile A, publicly traded critical infrastructure), 2M to 5M EUR (Profile B, major bank).
EU Regulation 2024/1689 EU AI Act, Articles 12, 14, 26, 27, 99. Official Journal of the EU, July 12, 2024. EU Regulation 2022/2554 DORA. Official Journal of the EU, December 27, 2022. Articles 9, 10, 17, 25, 28. Regulatory Technical Standards (RTS) for Articles 15, 16, 17, 18, 19. NIS2 Implementation Act (NIS2UmsuCG). Federal Law Gazette of December 4, 2025. §30, §32, §38, §39, §65. Sarbanes-Oxley Act of 2002. Sections 302, 404, 802. BSI. "BSI-Portal MUK". muk.bsp.de. Active since January 6, 2026. BSI. "C5:2026". bsi.bund.de, April 2026. BaFin. "DORA-Guidance AI Systems in ICT Risk Management". bafin.de, January 2026. SAP Help Portal. "SAP Security Audit Log". help.sap.com. SAP Help Portal. "SAP Read Access Logging". help.sap.com. SAP BTP Audit Log Service Documentation. Splunk. "SAP Integration for Splunk". splunk.com. Microsoft. "Microsoft Sentinel SAP Solution". docs.microsoft.com. Onapsis. "SAP Security and Compliance Platform". onapsis.com. SecurityBridge. "SAP Security Platform". securitybridge.com. Pathlock. "SAP GRC and Security Platform". pathlock.com. OneTrust. "AI Governance and GRC Platform". onetrust.com. DSAG. "Investment Report 2026". February 2026. COI cross-reference: "SAP Cloud ALM and the gaps in change management", "EU AI Act Article 26: SAP deployer obligations", "MCP Server Governance for SAP", "SAP DevOps and CI/CD for ABAP".
"EU AI Act Article 26: What SAP customers must do as deployers starting August 2, 2026", "MCP Server Governance for SAP", "SAP Cloud ALM and the gaps in change management: Status 2026", "SAP DevOps and CI/CD for ABAP: gCTS and Project Piper in a 2026 reality check", "SAP Note 11599: Why transport imports are irreversible".
Christian Steiger is a co-founder and managing director of Solutive AG and has been working for over 15 years with SAP Application Lifecycle Management, change orchestration, and transport governance in complex landscapes. His focus is on bridging the gap between SAP Basis practice and modern governance architectures, as well as integrating regulatory requirements into operational SAP processes.
Sarah Connor (pseudonym) is a compliance specialist focusing on European digital regulation, the EU AI Act, GDPR, NIS2, and DORA. She supports the Change Orchestration Institute as a co-author on regulatory topics and brings operational experience from compliance programs in the financial and industrial sectors.
The Change Orchestration Institute is an independent knowledge resource for SAP ALM, change orchestration, and AI governance. Initiator and research partner: Solutive AG, solutive.ag/kontakt.