INDEPENDENT SERVICE AUDITOR'S REPORT ON A DESCRIPTION OF A SERVICE ORGANIZATION'S SYSTEM AND THE SUITABILITY OF THE DESIGN AND OPERATING EFFECTIVENESS OF CONTROLS (SOC 1 Type II — extract) To the Management of SAP SE — RISE with SAP S/4HANA Cloud, Private Edition Scope We have examined SAP SE's description of its RISE with SAP S/4HANA Cloud, Private Edition system throughout the period 1 January 2025 to 31 December 2025. Service auditor: Harlow Quinn LLP, Walldorf Opinion In our opinion, in all material respects, the description presents the system that was designed and implemented throughout the period, and the controls operated effectively throughout the period 1 January 2025 to 31 December 2025. The opinion is unqualified. Subservice organisations SAP uses Microsoft Azure as a subservice organisation for infrastructure hosting. The carve-out method has been used; controls at Microsoft Azure are not included in the scope of this examination. Results of tests of controls — exceptions noted Exception 1. Control LA-04 (quarterly privileged access review). For 2 of the 4 quarters in the period, the review evidence was retained but not signed by the reviewing manager. Management response: the review workflow now blocks closure until an approver signature is captured. Exception 2. Control CM-07 (emergency change post-approval). For 3 of 44 emergency changes sampled, post-implementation approval was recorded more than 5 business days after the change. Management response: an automated escalation was added at day 2. Exception 3. Control BK-02 (backup restoration test). The annual restoration test for the DR region was performed 6 weeks after the scheduled date. Management response: the test has been moved into the change calendar. Complementary User Entity Controls (CUECs) CUEC 1. User entities are responsible for provisioning, modifying and removing their own end-user accounts in the productive system. CUEC 2. User entities are responsible for defining and maintaining their own segregation-of-duties ruleset and for remediating conflicts. CUEC 3. User entities are responsible for reviewing security audit logs made available to them through the SAP Cloud ALM interface. CUEC 4. User entities are responsible for approving transports into the productive system. CUEC 5. User entities are responsible for the configuration of their own password policy parameters within the profile parameters exposed to them. CUEC 6. User entities are responsible for notifying SAP of terminated administrator personnel within one business day. CUEC 7. User entities are responsible for maintaining their own data backup of any data extracted from the productive system. CUEC 8. User entities are responsible for testing their own custom code. CUEC 9. User entities are responsible for their own business continuity plan. There are 9 complementary user entity controls in total.