SAP QM Module: Where Audit Management Hits Its Limits in S/4HANA
You run S/4HANA. The QM module is live, inspection lots are created, usage decisions get posted, batches get released — and the annual audit programme still lives in a spreadsheet on a network drive. That combination is common enough that projects tend to write it off as inertia.
It isn’t. The usual explanation — “the functionality is there, people just don’t use it” — describes the symptom, not the cause. The real finding is more specific, and you can look all of it up in SAP’s own documentation. Every statement below about what SAP does and does not offer comes from help.sap.com or the SAP Fiori Apps Reference Library. Where the text goes past that, it is marked Assessment:.
What S/4HANA Actually Ships for Audits
The component is called Audit Management and carries the application component CA-AUD. You reach it through SAP Easy Access under Cross-Application Components → Audit Management, and Customizing sits in the same branch [1]. That layout is the origin of a claim you hear often — that audit management is not part of QM at all. Too blunt: SAP files CA-AUD in its own solution taxonomy under Manufacturing → Quality Management → Quality Improvement, and the Fiori library assigns “Manage Audits” to the business role Quality Auditor [4][5]. The accurate description is a cross-application component that SAP positions in the quality management solution area.
The documented scope is not a token. SAP names four objects — audit plan, question list, audit, and corrective and preventive actions — and structures the application into audit planning, question lists, audit execution, CAPA, audit documentation with the audit report, and audit evaluation through an audit monitor [1].
The question lists are the strongest part. SAP distinguishes two types: a master record serving as a copy template, and the audit question list with answer fields. Question lists are hierarchical and multilingual, the permitted valuation is planned per hierarchy level, and a CAPA can reference an entire question list or a single node within it [2]. Anyone who has maintained an audit question catalog under ISO 19011 across several cycles will recognize a considered data model here. Multilingual questions with level-dependent valuation logic are not a first draft.
Execution is modeled just as fully: questions are valuated from the replies, the system derives the audit result and a degree of fulfilment, and the audit gets an overall rating. The lead auditor determines CAPAs with a person responsible and a planned date, and an audit that comes out “Not Passed” sets “Subsequent Audit Required” [3]. On top of that: status management, a dedicated authorization concept, digital signature through the forms PLM_AUDIT and PLM_AUDITACTION, and the archiving object PLM_AUD [1]. Audit Management shares its data model with FMEA — both sit on PLMM_AUDIT [1].
And one point that gets asserted wrongly all the time: Audit Management has not been deprecated. SAP documents the component unchanged for SAP S/4HANA on-premise 2025 FPS01, delivered in February 2026 [1]. No deprecation statement exists.
Fiori or SAP GUI: Where the Interface Coverage Actually Ends
Here is the real finding, and it is sharper than the phrase people reach for — “Fiori coverage for audits is thin”.
In the SAP Fiori Apps Reference Library, Audit Management (CA-AUD) returns three apps — Manage Audits, Monitor Audits, Classify Audit Partners — all of application type “SAP GUI”, in every S/4HANA release from 1610 through 2025 FPS01 [5]. Across those releases that is 90 library rows, on-premise and private cloud, and not one of them is anything other than SAP GUI. The detail page for Manage Audits spells it out on its own: business role Quality Auditor, SAP S/4HANA (private cloud and on-premise), 2025 FPS01, application type SAP GUI, device types desktop and tablet [4].
Now compare the inspection side of the same system:
| Area | Fiori coverage | Example apps | Evidence |
|---|---|---|---|
| Audit Management (CA-AUD) | none — 90 of 90 rows, 1610 through 2025 FPS01, application type “SAP GUI” | Manage Audits, Monitor Audits, Classify Audit Partners | [4][5] |
| QM inspection processing (QM*) | extensive — 302 rows for 2025 FPS01, 39 of them non-GUI | Manage Inspection Lots (F2343), Record Inspection Results (F1685A), Manage Inspection Plans (F3788), Manage Quality Levels (F2914), Manage Control Charts (F2810), Record Defects (F2929) | [5] |
| Audit and Inspection Management (EHS-SUS-AIM) | Fiori-native, public cloud only | Manage Checklists (F9072), Manage Findings (F9073), My Inspections (F9071), Inspection Management Overview (F9414) | [5][6] |
| SAP Audit Management (GRC-AUD) | Fiori-native, separately licensed | Manage Audit Plans (F2980), Audit Universe (F5244), Prepare Audits (F3731), Approve Audit Reports (F3777) | [5] |
The inspection side is not merely better covered — SAP maintains dedicated Fiori sub-components for it: QM-FIO, QM-FIO-IM, QM-FIO-IM-RR and QM-FIO-PT. There is no audit equivalent anywhere under QM-* [5]. Four dedicated Fiori sub-components for inspection, none for audit: that is not an accidental gap, it is a priority.
Which is why the last two rows of the table are there. Writing “SAP has no Fiori audit application” would be false, and a reader could disprove it in five minutes. Two SAP products do audits in Fiori.
SAP Audit Management (GRC-AUD) ships around 43 Fiori apps, so it is the opposite of a GUI island. It is, however, a separately licensed product inside “SAP Assurance and Compliance Software for SAP S/4HANA” (1.7 SP00), and by design it is internal audit: audit universe, work packages, working papers [5]. Different tool, different discipline. An ISO 9001 process audit with a QM question list, hierarchical valuation and a degree of fulfilment is not what it is built for.
Audit and Inspection Management (EHS-SUS-AIM) is Fiori-native and available in public cloud. SAP describes it as carrying out inspections, identifying nonconformity, addressing root causes and implementing CAPAs [6] — which reads at first like exactly what a quality manager wants. Three qualifications belong with it: it sits in EHS, not QM; its five apps appear in public cloud, not in on-premise 2025 FPS01; and it is oriented towards inspection and compliance rather than running a QMS audit programme under ISO 9001 clause 9.2.2 [5][6].
On deployment: SAP documents Audit Management only for on-premise and private cloud. In the Fiori library, CA-AUD under the public cloud release identifier returns no rows, while QM* returns 149 there, 52 of them non-GUI; and no CA-AUD documentation exists under SAP_S4HANA_CLOUD [5]. If your target architecture is public cloud, that absence is a planning constraint.
Why the Module Still Rarely Gets Used to Its Full Depth
Assessment: what follows is project experience, not a sourced SAP statement. SAP documents functional scope, not adoption.
In the S/4HANA rollouts I have worked on, the pattern is nearly always the same. Quality gets scoped down to whatever blocks material flow: incoming goods inspection, batch release, blocked stock, certificates. Those are the topics where missing Customizing stops a shipment, which is precisely why they stay in scope. The audit side stops no shipment. It moves to “phase two”, and phase two rarely arrives with a budget.
Then there is timing. Quality often joins after scope freeze — at a point where an additional component with its own authorization concept, master data and forms is a change request rather than standard scope.
That is a more honest explanation than “SAP can’t do it”. SAP can do it. It simply never wins a prioritization argument, because its payoff shows up in a management review rather than in a delivery backlog.
The Part of the Audit Lifecycle That Stays Open
Here is the detail that makes the interface debate secondary. SAP’s own Audit Execution documentation describes the on-site sequence like this: the auditors print out the audit question list. The lead auditor prints out the questions with the replies. He then prints out the audit report, which is signed by all participants [3].
That is not an interpretation. It is SAP’s documented field workflow, in the present tense, in the help text for 2025 FPS01.
It fits the only device statement CA-AUD carries: “Desktop, Tablet” [4]. In practice that means SAP GUI for HTML in a tablet browser — no native app, no offline capability. Walk a plant floor with patchy Wi-Fi and you are working on paper. Not because the organization is behind the times, but because the documented process says so.
That is where the lifecycle breaks relative to what ISO 9001 asks you to prove. Clause 9.2.2 f) requires documented information retained as evidence of both the implementation of the audit programme and the audit results — two things inside one subclause, and most organizations hold only the second [7]. Clause 10.2.1 d) requires a review of the effectiveness of any corrective action taken [7]. A media break between shop floor and system does not cost you convenience, it costs you evidence: a note on a pad, transcribed from memory three days later, says nothing about when the finding was actually made. The mechanics are covered in the article on findings and CAPA management, and the programme layer in the guide to audit programme planning.
Assessment: the missing Fiori interface is therefore not an aesthetics problem. It is the reason capture gets deferred out of the audit and into rework — and rework is where findings quietly disappear. The same seam, without an ERP in the picture, is the subject of the article on Excel in quality management.
Extend Rather Than Replace: The Question Worth Asking
If you have already paid for licenses, master data and the integration into materials management and plant maintenance, you do not rip SAP out over a user interface. The useful question is: which part of the audit lifecycle has to run where the auditor is standing, and which part belongs in the system that owns the master data?
Audit plans, question list master records, status logic, archiving and signature are well placed in the SAP standard. On-site capture and the tracking of open actions, measured against the documented workflow, are not.
That is where qportal fits — as a complement, not a replacement. It runs on SAP BTP and connects to existing user and role concepts through SAP Cloud Identity Services, with its focus on mobile capture of audits and findings and on unbroken tracking through to the effectiveness review. A feature-level comparison sits in the comparison with SAP S/4HANA Audit Management, the technical integration on the SAP BTP overview, and the functional scope under audit management. How audit programmes and audits are structured there is set out in the audit programme documentation and the audits overview.
Five Questions for Your Own SAP QM Setup
- Is CA-AUD activated and configured at all — or did audit management get pushed to “later” during the project?
- Is your target architecture private cloud or on-premise? Audit Management is not documented for public cloud.
- How do findings reach the system: directly, or via a notepad and later transcription?
- Can you evidence the implementation of the audit programme — including dates moved, merged or dropped — or only the audits you actually ran?
- Does every corrective action carry a documented effectiveness review, or does the trail end at “closed”?
Conclusion
The common story about SAP QM and audits is wrong at both ends. It is too negative where it claims SAP offers nothing for audits, or something deprecated: Audit Management is functionally complete — hierarchical multilingual question lists, degree of fulfilment, follow-up audit logic, digital signature, archiving — documented for 2025 FPS01. And it is too generous where it calls the interface situation “thin”. It is not thin. It is zero, across nine years of release history, while SAP maintains four dedicated Fiori sub-components on the inspection side.
Neither of those decides the matter, though. One sentence from SAP’s own help text does: print the question list, print the replies, print the report and have it signed. As long as that is the documented field workflow, adding a complementary tool is not a question of taste. It is a question of evidence.
Sources
SAP product documentation (help.sap.com) — SAP S/4HANA on-premise 2025 FPS01
- SAP SE: Audit Management. SAP S/4HANA on-premise, version 2025.001. https://help.sap.com/docs/SAP_S4HANA_ON-PREMISE/fe141d99d84f4bebaa714ebc382210f0/ab02e1532104414de10000000a174cb4.html?version=2025.001 (accessed 2026-08-27)
- SAP SE: Question List. SAP S/4HANA on-premise, version 2025.001. https://help.sap.com/docs/SAP_S4HANA_ON-PREMISE/fe141d99d84f4bebaa714ebc382210f0/d802e1532104414de10000000a174cb4.html?version=2025.001 (accessed 2026-08-27)
- SAP SE: Audit Execution. SAP S/4HANA on-premise, version 2025.001. https://help.sap.com/docs/SAP_S4HANA_ON-PREMISE/fe141d99d84f4bebaa714ebc382210f0/f802e1532104414de10000000a174cb4.html?version=2025.001 (accessed 2026-08-27)
SAP Fiori Apps Reference Library
- SAP SE: Manage Audits (PLMD_AUDIT). SAP Fiori Apps Reference Library, release identifier S32OP (SAP S/4HANA 2025 FPS01, private cloud and on-premise). https://fioriappslibrary.hana.ondemand.com/sap/fix/externalViewer/#/detail/Apps('PLMD_AUDIT')/S32OP (accessed 2026-08-27)
- SAP SE: SAP Fiori Apps Reference Library. Evaluated by filtering on application components CA-AUD, QM*, GRC-AUD and EHS-SUS-AIM across releases 1610 through 2025 FPS01 and SAP S/4HANA Cloud 2608; the figures given for application type, device types, business role and row counts come from that evaluation. https://fioriappslibrary.hana.ondemand.com/ (accessed 2026-08-27)
Note on citation durability: the classic Fiori Apps Reference Library at fioriappslibrary.hana.ondemand.com is being retired in favor of fal.cloud.sap, and the new interface requires sign-in. Sources [4] and [5] therefore point at the classic addresses, which redirect.
SAP product documentation (help.sap.com) — SAP S/4HANA Cloud
- SAP SE: Audit and Inspection Management. SAP S/4HANA Cloud, version 2608.500. https://help.sap.com/docs/SAP_S4HANA_CLOUD/323bd3f1dc8248bc8647c62f1baa6a3a/c69612e40e5d49eb9a2d20d8d21ff1a1.html?version=2608.500 (accessed 2026-08-27)
Normative text
- DIN EN ISO 9001:2015-11, Qualitätsmanagementsysteme – Anforderungen (ISO 9001:2015); German and English version EN ISO 9001:2015. Beuth Verlag, Berlin. English text: ISO 9001:2015, Quality management systems — Requirements. Clause numbers are cited and requirements paraphrased; the normative wording is under copyright. Clauses used: 9.2.2 f), 10.2.1 d).
Consultancy, certification-body and content-marketing pages are not cited. Every statement about SAP functionality rests on SAP’s own documentation. Where this text goes beyond the sources — in particular on adoption in projects — it is marked as an assessment.
Frequently asked questions
- Does SAP S/4HANA include audit management out of the box?
- Yes. The component is Audit Management (CA-AUD), reached through SAP Easy Access under Cross-Application Components. It covers audit plans, question lists, audits and corrective and preventive actions, plus the audit report, an audit monitor, status management, an authorization concept and digital signature. SAP documents it for SAP S/4HANA on-premise 2025 FPS01 — the February 2026 delivery.
- Are there Fiori apps for SAP Audit Management?
- Not for CA-AUD. In the SAP Fiori Apps Reference Library the component returns three apps — Manage Audits, Monitor Audits and Classify Audit Partners — all of application type "SAP GUI", in every release from 1610 through 2025 FPS01. Fiori interfaces for auditing exist in two other SAP products instead: GRC-AUD and EHS-SUS-AIM.
- Is Audit Management (CA-AUD) available in SAP S/4HANA public cloud?
- SAP documents Audit Management only for on-premise and private cloud. Filtering the Fiori library for the public cloud release identifier returns no CA-AUD rows, and no CA-AUD documentation exists under SAP_S4HANA_CLOUD. The QM inspection components do appear there. For a public cloud target architecture that absence is a planning constraint, not a detail.
- Has SAP deprecated Audit Management?
- No. There is no deprecation statement. SAP documents Audit Management unchanged for SAP S/4HANA on-premise 2025 FPS01, shipped in February 2026. The component is maintained and functionally complete — the constraint is the user interface and the deployment options, not the product status.
- Can auditors run an audit on a mobile device with SAP QM?
- Only in a limited sense. The single device statement for the audit apps is "Desktop, Tablet", which means SAP GUI for HTML in a tablet browser, not a native or offline-capable app. SAP's own Audit Execution documentation describes the on-site sequence in print: print the question list, print the questions with replies, print the audit report and have all participants sign it.