§ Guide

ERP Evidence SAP Oracle

This guide, 'ERP Evidence: SAP, Oracle and Enterprise Systems', covers Purchase-to-Pay, Change Documents and the System of Record at Enterprise Scale.

Ref · E-D · 2026 · §LIBClass · ConfidentialJuris · England & WalesStatus · Active

Guide · 17 pages · 23 min read · Published 2026-08-30

This guide, 'ERP Evidence: SAP, Oracle and Enterprise Systems', covers Purchase-to-Pay, Change Documents and the System of Record at Enterprise Scale. It is prepared by Computer Forensics Lab's e-discovery team for UK lawyers, in-house counsel and investigators. The guide explains the machine that runs the company, its anatomy, modules, documents and flow. It details change documents, audit logs, and the history layer, alongside approvals, workflows and author is at i on evidence. It addresses scoping and extraction at enterprise scale, patterns like procurement fraud, warranty and supply-chain disputes, and source architecture. It includes worked examples, common mistakes, technical limitations, and questions to ask. A checklist, red flags, and when to involve a digital forensic expert are provided, along with frequently asked questions and a glossary. This guide is essential for those dealing with ERP evidence in legal disputes.

Read this guide on your phone, browse guides by topic or go back to the full PDF library.

§ Credit and source

Published by Computer Forensics Lab on 2026-08-30. Original material of the practice, free to read, cite and download. See every guide's author and source.

§ Full text of ERP Evidence SAP Oracle

Download the PDF

Prefer a PDF that matches this page exactly? Download the current text as a PDF, generated from the wording shown here, including any later corrections.

Page 1

ERPEVIDENCE · A GUIDE FOR UK LAWYERS ERP Evidence: SAP, Oracle and Enterprise Systems Purchase-to-Pay, Change Documents and the System of Record at Enterprise Scale COMPUTER FORENSICS LAB

§ ABOUT THE AUTHOR PREPARED BY COMPUTER FORENSICS LAB E-DISCOVERY TEAM CHANGE-DOCUMENT & WORKFLOW ANALYSIS CPR PART 35 EXPERT REPORT S FULL CHAIN-OF-CUSTODY DOCUMENTATION

§ CONTENTS In this guide 01 Executive summary 02 The problem in plain English: the machine that runs the company 03 Anatomy: modules, documents and the flow 04 Change documents, audit logs and the history layer 05 Approvals, workflows and author is at i on evidence 06 Scoping and extraction at enterprise scale 07 Patterns: procurement fraud, warranty and supply-chain disputes 08 Source architecture: where else the evidence lives 09 Worked examples 10 Common mistakes and technical limitations 11 Questions to ask · Suggested wording 12 Checklist and red flags · When to involve a digital forensic expert 13 Frequently asked questions 14 Glossary · References · Disclaimer · How a specialist laboratory can assist

§ 01 · ORIENTATION Executive summary THE HEADLINE POINT: THEERPLINKSEVERYDISPUTEDTRANSACTIONINTOA DOCUMENTEDFLOWWITHACHANGEHISTORY: FOLLOWTHEFLOW, READTHECHANGES, TESTTHEAPPROVALS

§ 02 · FIRST PRINCIPLES The problem in plain English: the machine that runs the company

§ 03 · ANATOMY Anatomy: modules, documents and the flow

Page 2

§ 04 · THEHISTORYLAYER Change documents, audit logs and the history layer

§ 05 · WHO COULD, WHODID Approvals, workflows and author is at i on evidence

§ 06 · SCALE Scoping and extraction at enterprise scale

§ 07 · THEPATTERNS Patterns: procurement fraud, warranty and supply-chain disputes

§ 08 · THEWIDERMAP Source architecture: where else the evidence lives EVIDENCE TEST PRODUCTION ARCHIVE S / WAREHOUSE / BANKS & DELETED / SYSTEM BACKUPS REPORTING COUNTERPARTIES RECOVERABLE COPIES

§ 09 · IN THE WILD Worked examples EXAMPLE1 · THEBANKDETAILSTHATCHANGEDFORNINEDAYS EXAMPLE2 · THE THREE - WAYMATCHTHATNEVERHAPPENED EXAMPLE3 · THETWOERPSTHATAGREEDAGAINSTTHEPLEADING

Page 3

§ 10 · WHEREITGOESWRONG Common mistakes and technical limitations Common mistakes Technical limitations

§ 11 · INTERROGATORIES & DRAFTING AIDS Questions to ask · Suggested wording Ask your client Ask your opponent Ask your e Discovery / forensic provider SUGGESTED WORDING · ERPLIMBFORTHEPRESER VAT I ON LETTER

§ 12 · QUICK CONTROL Checklist and red flags · When to involve a digital forensic expert The ERP checklist Red flags When to involve a digital forensic expert

§ 13 · COMMON QUESTIONS Frequently asked questions Can we really get evidence out of something as vast as SAP? What is a change document, in one paragraph? The opponent says extraction would cost a fortune and disrupt production. Genuine? Who actually did it, when the system only shows a user ID? The relevant years have been archived off the live system. Problem? Our supply dispute is really about what physically shipped. Can the ERP say?

§ 14 · REFERENCE Glossary Sources and authoritative references DISCLAIMER

§ HOW A SPECIALIST LABORATORY CAN ASSIST Working with Computer Forensics Lab Speak to a forensic examiner, not a salesperson. INSTRUCTTHELAB NEWENQUIRIESEMAILE - DISCOVERY

§ Common questions

Frequently asked questions

Can we really get evidence out of something as vast as SAP?
Routinely: vastness is the storage, not the request: a well-scoped ERP demand (named flows, document types, vendors, periods, change objects) produces bounded, structured, verifiable extracts faster than most email exercises: the system's own discipline works for you. What fails is vagueness: §2's point: and the cure is drafting with someone who speaks the platform, which is a scoping call, not a project.
What is a change document, in one paragraph?
The ERP's field-level history record: when a tracked field on a tracked object changes, the system writes who changed it, when, from what value to what value: automatically, as part of the transaction. It is guide 72's entry- date discipline built into the platform's bones: and it is why enterprise-system backdating and master-data fraud cases so often reduce to a four-row exhibit, per Example 1.
The opponent says extraction would cost a fortune and disrupt production. Genuine?
Sometimes: wholesale demands genuinely burden these systems: which is why the answer is precision plus protocol: the named-scope request, standard reports and table extracts, runs from copies or quiet windows, agreed queries between specialists with control totals: guide 71 §7 scaled. Offer the protocol in terms; a burden objection that survives a precise, cooperative, verifiable proposal is rare, and its rarity is visible to the court.
Who actually did it, when the system only shows a user ID?
The ID is the first rung: behind it run sign-on logs (terminals, IPs, times), session and transaction usage records, delegation and substitution data, emergency-access grants, and: for the human join: the device and presence layers of guides 61 and 78 plus the correspondence. Shared and service accounts widen the pool honestly; the finding is pleaded to the rung reached, per the series' standing attribution method: and Example 1's out-of-hours terminal sessions show how far the rungs can climb.
The relevant years have been archived off the live system. Problem?
A retrieval, not a wall: archive files preserve documents with their linkage and are read back by the platform's own retrieval facilities; backups bracket what archiving predates; and the warehouse layer often holds the period in reporting form meanwhile. Cost and time are real and scoped honestly: and prospectively, the preservation letter's suspension of archiving runs (§11's wording) exists precisely so the dispute's period stops moving while you argue about it.
Our supply dispute is really about what physically shipped. Can the ERP say?
It says what was recorded: orders, deliveries, receipts, quality postings: which becomes what shipped when converged with the outside: the counterparty's mirror flow, the carrier's manifests, the bank's payments: Example 3's three-way agreement. The ERP is the best witness to the paper reality and a strong proxy for the physical one; the convergence protocol is how the proxy becomes proof: and it settles supply cases with a regularity witness evidence never matches. cflab. u k · e-disc ove r y. u k ©2026 Computer Forensics Lab Ltd ·cflab.uk ·e-discovery.uk ·info@cflab.uk ·+44 (0)20 7164 6915 Page 15 of 17
§ Related documents
Instruct the practice

Bring us in early. Defensibility is built, not retrofitted.

Whether you are responding to a regulator, preparing for disclosure, or scoping an internal investigation, start the chain of custody with a short, confidential conversation.

WhatsApp