コンテンツへスキップ

SAP × AI Agents: A Practical Implementation Checklist

Practical Implementation Checklist

— SAP × AI: A Deep-Dive Version of the Big Picture —

A practical diagnostic tool covering all phases of judgment, design, risk, and governance

July 2026 Paddy&Water Inc.

Chapter 1: How to Use This Document and Scoring

1.1 Target Readers and Use Cases

This document is intended for CIOs, DX promotion departments, ERP project managers, and business transformation leaders at manufacturing, distribution, and high-tech companies that operate SAP as their core system, who are examining, designing, and driving “how to incorporate AI agents into SAP operations.” It covers the entire implementation lifecycle, from adding AI value to an existing SAP environment through to building an autonomous AI agent execution platform via BTP.

Phase Checklist Chapter Purpose / Question
Phase 0: Adoption Decision Chapter 2 A management and field-level diagnosis of “Should we even adopt AI now?”
Phase 1: Use Case Selection Chapter 3 Prioritization assessment of “Which operations/modules should we start AI with?”
Phase 2: Technical Architecture Design Chapter 4 Design diagnosis of “How should we combine SAP BTP, Joule, and external AI?”
Phase 3: Data & Security Chapter 5 “Is governance in place for the SAP data that AI will handle?”
Phase 4: Change Management & Talent Development Chapter 6 “Are the organization and people ready to work with AI?”
Phase 5: Governance & Risk Chapter 7 “Are there control mechanisms in place for when AI makes a wrong judgment?”
Phase 6: Go-Live & KPI Management Chapter 8 “Does a cycle exist for measuring AI’s effect and driving continuous improvement?”

1.2 Scoring Method

How to Read the Importance Badges

H (Red) = High importance: If this check is “No,” the implementation risk is significant. Do not proceed while leaving it unaddressed

M (Orange) = Medium importance: If this check is “No,” quality and effectiveness will be affected. Addressing it at the planning stage is recommended

L (Green) = Low importance: If this check is “No,” there is room for optimization. It can be improved after operations begin

[Score Aggregation Method]

Step 1: For each phase, count the number of H-importance items marked “Unconfirmed / NG” → H score

Step 2: Cross-reference the total H score across all phases against the matrix below to make an overall determination

H Score 0–3: Green Light → Proceed to full-scale AI agent consideration phase H Score 4–7: Yellow → Re-diagnose after prioritizing resolution of problem areas H Score 8+: Red Line → Adopting AI without foundational readiness is high-risk

Chapter 2: Phase 0 — Adoption Decision Check (Should We Do AI Now?)

2.1 Management & Strategy Layer

The first gate for AI agent adoption is “whether management commitment and a business hypothesis exist.” Technology-first, trend-following adoption is the area with the highest failure rate. Check the following items against your OKRs, mid-term management plan, and DX strategy.

Check Management & Strategy Layer Importance
The purpose of adopting AI agents is concretely tied to at least one of “cost reduction,” “revenue growth,” or “improved operational quality” H
An executive sponsor such as a CIO / CDO / business unit head has been explicitly appointed and holds budget authority H
“What we want to achieve with AI” is documented as a quantitative hypothesis (e.g., reduce order-entry effort by 50 hours/month) H
The timing of the AI adoption plan is aligned with SAP’s roadmap (S/4HANA migration, ECC maintenance end-of-life response) M
The decision reflects awareness of competitors’ AI adoption trends and industry standards (not merely following a trend) M
An ROI estimate for the implementation has been made, at least at a rough-order level, giving a sense of the payback period M
A dedicated AI agent budget (covering PoC, production, and continuous improvement over three years) is secured or expected to be secured H

2.2 Field / Operations Layer

Even if management alignment is in place, the investment will be wasted if there is no “room for AI to fit in” within field operations. Check the degree of process standardization, data quality, and the field’s sense of the problem.

Check Field / Operations Layer Importance
The target operation that AI is meant to automate or assist is standardized and routinized as an SAP transaction H
The quality (accuracy, completeness, freshness) of the data entered into SAP for the target operation is at or above an acceptable level H
The people responsible for the target operation (field users) are positive, or at least neutral, toward AI adoption M
There is a voice from the field saying things like “we want this kind of work automated” or “we want this data retrieved automatically” M
The rate of errors/exception handling occurring in the target process is under 20% (processes full of exceptions are difficult to make AI-ready) M
The business flow is designed so that a “final human confirmation” step can be built in when the process is AI-enabled H
The authority and procedure for a human to reject or correct AI output (proposals / automated processing) after go-live are defined H

Chapter 3: Phase 1 — Use Case Selection Check (Where to Start?)

3.1 Overall Map of SAP × AI Use Case Candidates

Operations where AI agents can be leveraged in an SAP environment fall broadly into five categories: “automation of data entry and reconciliation,” “anomaly detection and alerting,” “planning optimization,” “natural language interface (NLI),” and “multi-step autonomous execution.”

AI Category Representative Use Cases Target SAP Module Maturity
Automation of Data Entry & Reconciliation Supplier invoice OCR matching (AI-Invoice) Bank statement matching (AI-Bank) Automatic posting of EDI orders FI-AP / MM-IV FI-BL SD / MM ★★★★★ Abundant production track record
Anomaly Detection & Alerting Early warning for payment delays / credit limit overruns Inventory anomaly (spike/drop) alerts Outlier detection in QM inspection results FI-AR / FI-AP MM-IM QM ★★★★☆ Practical stage
Planning Optimization AI demand forecasting (IBP for Demand) Automatic MRP parameter tuning Transportation route optimization (TM) IBP / PP PP-MRP TM ★★★★☆ Practical stage
Natural Language Interface (NLI / SAP Joule) Natural-language queries such as “What was AR balance last month?” AI guidance on business screens Automatic generation of reports and email text S/4HANA (all areas) Fiori / BTP SuccessFactors ★★★☆☆ Expanding
Multi-Step Autonomous Agents Automatically executing Order → ATP check → Delivery instruction Automatically issuing a maintenance order → parts ordering → schedule adjustment Month-end closing assistant (journal entry proposal → review → posting) SD+EWM+TM PM+MM FI-GL+CO ★★☆☆☆ Mostly at PoC stage

3.2 Use Case Priority Assessment Check

When there are multiple use case candidates, score them from the following perspectives to narrow down the target for the first PoC (proof of concept). The golden rule is to start with operations where “the effect is large, the risk is small, and the data is in place.”

Check Use Case Priority Assessment Importance
A quantitative estimate of the effect of automating/AI-enabling the target use case (effort reduction in h/month, error-rate reduction in %, etc.) has been calculated H
SAP transaction data for the target operation (two years or more of history) has been accumulated and can be used for AI training and validation H
It has been confirmed whether the selected use case can be covered by the standard features of “SAP Joule” or “SAP BTP AI Services” M
The scope has been narrowed to a use case whose effect can be fully validated within the PoC period (roughly within 3 months) M
From the standpoint of “showing an early win,” the business unit selected is one with the strongest sense of the problem and the most cooperative attitude in the organization M
The starting use case is one where, even if AI produces a wrong result, it will not cause serious impact on human life, legal compliance, or finances H
The success criteria (KPIs, thresholds, timing of evaluation) for the selected use case have been agreed upon before the PoC begins H
Reference has been made to AI adoption case studies and benchmark data from peer companies or similar businesses L

Chapter 4: Phase 2 — Technical Architecture Design Check (How to Build?)

4.1 Designing SAP BTP and the AI Foundation

There are three main technical paths for incorporating AI agents into an SAP environment: (1) SAP Joule (SAP’s standard AI), (2) BTP AI Services (SAP’s own microservices), and (3) external AI (OpenAI / Azure / Google) connected to SAP via the BTP Integration Suite. Check the rationale for each method’s selection and its architectural consistency.

AI Integration Method Overview / Characteristics Benefits Points of Caution
① SAP Joule (Standard AI) An AI assistant provided as standard by SAP within S/4HANA, BTP, SuccessFactors, etc., complementing natural-language queries, AI recommendations, and automation Operates without loose coupling to SAP AI Units included in RISE/GROW Data does not leave SAP Functional scope is defined by SAP Constraints on applying custom business logic Japanese-language support depends on the module
② BTP AI Services (SAP’s Own Microservices) A group of APIs such as Document Information Extraction (DIE), business entity matching, anomaly detection, and recommendation engines, with direct access to SAP data on BTP Custom AI processing can be added while retaining SAP context Can be configured with no-code/low-code BTP Credit consumption must be managed Models are limited to those provided by SAP Incorporating proprietary ML models requires separate development
③ External AI + BTP Integration (OpenAI / Azure / Google, etc.) External LLM/ML models connected to SAP via BTP AI answers questions by referencing SAP data through RAG (Retrieval-Augmented Generation) Can leverage the latest, highest-performing AI models Free to train on custom domain knowledge Easy integration with non-SAP data Since SAP data is sent to an external AI, scrutiny of data residency and privacy requirements is essential Costs are incurred for both BTP and the external AI

4.2 Architecture Design Check

Check Architecture Design Importance
The rationale for selecting the AI integration method (Joule / BTP AI Services / external AI) has been documented from technical, security, and cost perspectives H
An SAP BTP Global Account has been set up, and an estimate of the BTP Credit consumption required for AI processing has been completed H
The authentication method (OAuth 2.0 / confirmation of Basic Auth deprecation) for when the AI agent calls the SAPIE API/OData has been designed H
It has been confirmed that, when AI agent output (journal entry proposals, purchase order proposals, etc.) is written to SAP, it is designed to pass through an approval workflow H
API rate limiting, monitoring, and log collection have been configured via BTP’s Integration Suite (API Management) M
Among SAP’s CDS Views / OData APIs, the scope of permissions (principle of least privilege) for data referenced by AI has been designed M
AI model version control and rollback procedures are defined across the three environments of production, QA, and development M
AI processing latency requirements (e.g., ATP confirmation on the order screen within 2 seconds) have been measured and meet the passing criteria M
When using an external AI model, it has been confirmed that settings prevent SAP data from being incorporated into the external model as training data (Zero Data Retention) H
Extensions are thoroughly aligned with SAP’s Clean Core policy (implementing AI functionality on the BTP side), and direct custom development on the S/4HANA core itself is minimized L

Chapter 5: Phase 3 — Data, Security & Privacy Check

5.1 Quality and Access Control of SAP Data Handled by AI

Because AI agents “view, judge, and write” SAP data, if data quality, access permissions, and personal-data protection design are incomplete, there is a risk that AI’s incorrect judgments will contaminate SAP data in a chain reaction. The principle of “Garbage in, Garbage out” becomes even more critical with AI adoption.

Check Data, Security & Privacy Importance
Data quality standards have been defined and an MDM process established for the SAP master data (material master, customer master, vendor master, etc.) that AI references H
It has been confirmed that missing values and outliers in the historical transaction data (purchase orders, sales orders, journal entries, etc.) used for AI training/inference are below an acceptable threshold H
When SAP data used for AI processing includes personal information (name, address, bank account number, etc.), anonymization/pseudonymization compliant with personal information protection laws and the GDPR has been implemented H
When an AI agent has write access to SAP, the permissions of that RFC user/technical user are designed on the principle of least privilege H
SAP documents generated by AI (journal entries, purchase orders, sales order changes, etc.) carry an “AI-generated flag” that allows identification during audits H
All of the AI agent’s SAP access history is recorded and retained in SAP’s Audit Log (SM19/SM20) M
The freshness of the SAP data referenced by the AI model (real-time vs. delay from batch updates) meets business requirements M
When production data is used in test/PoC environments, data masking and anonymization have been completed H
The contract with the AI vendor (SAP or external) clearly states clauses on data handling, storage location, and prohibition of third-party disclosure H

5.2 SAP Joule-Specific Security Checks

Additional Items to Confirm When Using SAP Joule in an SAP Environment

① Confirm the scope of SAP objects and sensitive fields that Joule can access (control over salary, credit limit, cost information, etc.)

② Confirm in the contract the retention period and deletion policy for how long Joule session data is stored in SAP Cloud

③ Understand the AI Units cap included in the RISE / GROW subscription and the mechanism for overage charges

④ Confirm that access control to Joule (MFA / SSO) via BTP Identity Authentication (IdP) has been configured

⑤ Confirm whether a “human confirmation” step is built into the business flow when using Joule’s answers as the basis for major decisions (large purchase orders, closing entries, etc.)

Chapter 6: Phase 4 — Change Management & Talent Development Check

6.1 Managing the Impact on the Organization and People

Many AI agent failures are not “technical problems” but “change-management failures.” If field users do not trust AI’s judgment, cannot use it correctly, or fail to notice when AI makes a mistake, no ROI will be generated.

Check Change Management & Talent Development Importance
The scope of impact of business-flow changes from AI adoption (changed procedures, discontinued tasks, newly established confirmation steps) is documented by department H
The boundary is clearly defined between operations where “AI proposes and a human makes the final decision” and operations where “AI executes automatically and a human confirms afterward” H
Training has been conducted for field users on “how to reject, correct, and give feedback when AI’s proposal is incorrect” H
For staff whose workload decreases or changes due to AI adoption, a reskilling/reassignment plan has been prepared in coordination with HR M
A “manual fallback procedure (SOP)” for when the AI system is down or its accuracy degrades has been established and trained on H
There are plans to reflect the post-AI-adoption business process changes (As-Is → To-Be) in SAP business procedure manuals and operating manuals M
At least one “AI Promotion Leader (Change Agent)” who can leverage AI in the field has been appointed in each department M
Explanatory sessions on AI’s limitations, failure cases, and the risk of over-reliance have been held for management and executives M
A channel for collecting employee Q&A and concerns about AI adoption has been established, with regular responses and feedback provided L

6.2 SAP Joule × User Education Check

Check SAP Joule User Education Importance
Field users understand what Joule “can and cannot do,” and no excessive trust (automation bias) has arisen H
Prompts to Joule are designed in line with SAP’s standard guidelines, and an operational rule thoroughly prohibiting confidential information (passwords, personal data) from being included in prompts is enforced H
There is a procedure allowing staff to verify the basis of Joule’s analyses and recommendations (which SAP data was referenced) M
Guidelines and prohibitions are clarified for cases where Joule and other AI tools (such as ChatGPT) are used together in business operations M

Chapter 7: Phase 5 — AI Governance & Risk Management Check

7.1 Classifying and Controlling AI Risk

The risks of AI agents connected to SAP fall into four quadrants: “AI model risk (misjudgment),” “system risk (failure/security breach),” “compliance risk (regulatory violation),” and “operational risk (drift/degradation).” Designing control mechanisms for each quadrant in advance is essential.

Risk Quadrant Representative Risk Scenario Impact on the SAP Environment Main Control Measures
AI Model Risk (Misjudgment / Hallucination) Demand-forecasting AI is wrong, leading to a large excess-inventory order Credit AI misjudges and blocks a good customer’s sales order Joule presents incorrect accounting standards MM-IM inventory bloat / FI loss SD lost sales opportunity FI mis-posting risk Mandatory human-confirmation gate Requiring AI proposals to be accompanied by supporting data Mandatory human approval when a threshold is exceeded
System Risk (Failure / Unauthorized Access) BTP AI services go down, halting SAP operations The integration API with external AI is compromised, leaking SAP data Core business operations halted Leakage of confidential data (cost, credit information) Confirming the AI service’s SLA (99.9% or higher) Rate limiting / WAF at the API gateway Establishing fallback procedures
Compliance Risk (Regulatory / Internal Controls) AI’s automatic journal entries violate accounting standards AI uses personal information as training data, violating the GDPR Restatement of accounts / audit findings Fines from regulatory authorities Flagging and audit trails for AI-generated documents Data anonymization / Zero Data Retention contracts Regular internal-audit review of AI processing
Operational Risk (Model Drift / Degradation) AI forecast accuracy declines due to changing demand patterns SAP configuration changes break a CDS View referenced by AI AI model updates affect operations Increased stockouts/shortages Continued undetected AI errors Monthly accuracy-monitoring KPI Impact assessment on AI before SAP upgrades Model version control / rollback

7.2 Governance Structure Check

Check AI Governance Structure Importance
An AI ethics policy (Responsible AI principles) has been formulated and approved internally, and it also applies to SAP × AI usage H
A clear reporting structure and escalation path is defined for major AI system incidents (damage from misjudgment, data leaks, etc.) H
Limits on the processing an AI agent can execute (maximum order amount, types of journal entries, threshold for approval exemption, etc.) are implemented as system settings H
Explainability is ensured so that the basis for AI’s decisions (what data was used, why that recommendation was made) can be audited after the fact H
A regular meeting is set up for the AI governance owner (AI Risk Owner) and the SAP-side owner (SAP ERP Owner) to coordinate M
Release of new AI features into the SAP production environment is mandated to go through the change-management process (CAB / RFC) M
Legal and compliance have completed a review of the scope to which the high-risk AI system requirements of the EU AI Act (phased application from 2026 onward) apply to the company M
A contingency plan is prepared for the case of a third-party AI vendor (such as OpenAI) discontinuing service or changing its terms of use M
A mechanism is designed to report the business impact of AI adoption (both positive and negative) to management on a quarterly basis L

Chapter 8: Phase 6 — Go-Live & KPI Monitoring Check

8.1 Final Gate Before Go-Live

Check Pre-Go-Live Gate Importance
Before the production cutover, AI’s proposal accuracy and error rate in UAT (user acceptance testing) clear the pre-agreed thresholds H
The fallback (switching to manual processing) that keeps SAP operations from stopping in the event of an AI system failure has actually been drilled and confirmed H
A phased rollout (Shadowing Mode) is adopted for the first 30 days after go-live, in which “AI’s proposals are displayed but execution remains with humans” M
The go-live rollout plan follows a phased approach of “pilot → expansion → company-wide,” rather than a single big-bang rollout M
Connection testing and load testing of the AI service in the SAP production environment have been completed, and response performance at peak times has been confirmed H
It has been confirmed that the SAP permissions used by AI (RFC function modules / OData API) work correctly in the final production environment H
An operational monitoring structure (AI error alerts, BTP monitoring, SAP system logs) is active after go-live H

8.2 KPI Monitoring Design Check

Continuous measurement of an AI agent’s effectiveness requires designing indicators across three layers: “AI accuracy KPIs,” “operational effectiveness KPIs,” and “system health KPIs.” Adoption without KPIs falls into a state of “using it without really knowing why,” making it impossible to decide whether to continue investing.

KPI Layer Main Indicators (Examples) Measurement Method in SAP Evaluation Frequency
AI Accuracy KPI Forecast accuracy (MAPE / F1 score) Misjudgment rate / mis-recommendation rate Number of hallucination occurrences IBP analysis reports BTP AI Services dashboard Custom log analysis Weekly / Monthly
Operational Effectiveness KPI Effort reduction (h/month) Error-count reduction rate Shortened processing lead time Improved inventory accuracy / reduced stockout rate S/4HANA transaction volume comparison Number of QM notifications MM inventory turnover / service rate Monthly / Quarterly
System Health KPI AI service uptime (SLA compliance) BTP Credit consumption vs. budget API response time (P95/P99) Number of AI errors / abnormal terminations BTP ALM / Cloud Health Monitor BTP cost management dashboard API Management monitoring Daily / Weekly
Governance KPI Rate at which humans reject AI proposals Post-hoc correction rate of AI-generated documents Number of audit findings (AI-caused) Number of AI-related security incidents SAP change document analysis Internal audit reports SM21 / SWI2_FREQ Monthly / Quarterly
Check KPI Monitoring Design Importance
All four layers of KPIs above are defined, with agreed measurement criteria, measurement methods, and evaluation frequency H
The thresholds and procedures for actions to take when KPIs worsen (AI model retraining, parameter adjustment, temporary suspension) are defined H
The results of AI accuracy KPI measurement are visualized for business staff as well, so the field can grasp AI accuracy M
There is a quarterly review meeting that measures AI adoption ROI and makes decisions on continuing, expanding, or scaling back investment M
An alert is set up to automatically detect AI model accuracy degradation (drift), notifying when it falls below a threshold M
A schedule and approval flow for periodic model retraining using SAP production data are defined L

Chapter 9: Diagnostic Results — Severity Matrix and Next Actions

9.1 Phase-by-Phase H Score Aggregation Table

Once you have completed the checks for each phase, count the “Unconfirmed / NG” H (high-importance) items and enter them into the aggregation table below.

Phase Number of H Items (Total in This Document) Number of NG H Items Phase Rating
Phase 0: Adoption Decision (Chapter 2) 7 items ______ items 0=GO / 1-2=CAUTION / 3+=STOP
Phase 1: Use Case Selection (Chapter 3) 4 items ______ items 0=GO / 1-2=CAUTION / 3+=STOP
Phase 2: Architecture Design (Chapter 4) 5 items ______ items 0=GO / 1-2=CAUTION / 3+=STOP
Phase 3: Data & Security (Chapter 5) 6 items ______ items 0=GO / 1-2=CAUTION / 3+=STOP
Phase 4: Change Management (Chapter 6) 5 items ______ items 0=GO / 1-2=CAUTION / 3+=STOP
Phase 5: Governance (Chapter 7) 4 items ______ items 0=GO / 1-2=CAUTION / 3+=STOP
Phase 6: Go-Live & KPI (Chapter 8) 8 items ______ items 0=GO / 1-2=CAUTION / 3+=STOP
[Total Across All Phases] 39 items ______ items Overall H Score
H Score 0–3: Green Light → Proceed to full-scale AI agent consideration phase H Score 4–7: Yellow → Re-diagnose after prioritizing resolution of problem areas H Score 8+: Red Line → Adopting AI without foundational readiness is high-risk

9.2 Recommended Actions by Severity

Overall Rating H Score Recommended Actions (in Priority Order)
Green Light ★★★ 0–3 items The foundation is in place. Approve the start of a PoC and begin a proof-of-concept trial with the first use case → Formulate a 90-day PoC plan and hold a project kickoff → Proceed in parallel with setting up the BTP environment and configuring AI for the target modules
Yellow, Caution Needed ⚠ 4–7 items Prioritize addressing the NG H items before moving to the next phase. A rushed rollout carries high risk → Create an issue-management table defining an “issue owner, resolution deadline, and resolution method” for each NG item → Re-diagnose after a 2–3 month foundation-building sprint → Do not underestimate NG items in “data quality” and “change management” in particular
Red Line ? 8+ items The prerequisites for AI adoption (SAP standardization, data quality, governance structure) are not in place → First prioritize SAP Clean Core conversion, master data cleanup, and organizational structure building → Reconsider the purpose of AI adoption (re-verify the ROI rationale) at the CIO level → Request an assessment from an external expert (SI partner / SAP) to obtain an objective evaluation

9.3 SAP × AI Maturity Roadmap

Four-Stage AI Maturity Roadmap (SAP Environment)

Level 1: Automation — Approximate duration: Up to 6 months

Automation of routine tasks. AI-driven automation of data entry and reconciliation (FI-AP invoice OCR, MM order/EDI, etc.)

Benchmark for graduating from PoC: Confirm at least 20 hours/month of manual work reduced and at least a 50% drop in error rate

Level 2: Intelligent Support (Augmentation) — Approximate duration: 6 months to 1 year

Hybrid operations in which AI “proposes” and humans “judge and approve”

Example: Humans finalize the MPS with reference to IBP demand forecasts; AI proposes BOP reallocation candidates for aATP

Benchmark for maturity: AI proposal adoption rate of 70% or higher, with the reasons for human rejection recorded in the system

Level 3: Autonomous Execution — Approximate duration: 1–2 years

AI executes autonomously under certain conditions; humans specialize in exception handling and monitoring

Example: AI automatically executes orders below a threshold; AI automatically links a firmed PO from the IBP plan to PP

Prerequisite: A track record of trust built up at Level 2, along with an established governance structure and audit trail

Level 4: Predictive Enterprise — Approximate duration: 2+ years

AI integrating S/4HANA, IBP, SAC, and external data autonomously generates management scenarios

Management shifts to being decision-makers who “select and approve AI-presented scenarios”

As of 2026, only a small number of manufacturers worldwide have reached Level 4

End of document.

About the author — Minami (Technology & Platform)

Covers SAP platform, cloud adoption and add-on architecture, from platform selection through migration and operational support.

Have a question about this article?

Ask the author directly — no sales pitch, just an answer.

Ask about this article →