SAP's AI ethics policy in delivery
As of 2026-09-25
What is SAP's AI ethics policy in delivery?
SAP's Global AI Ethics Policy is a named, versioned document — ten principles grounded in the UNESCO Recommendation on the Ethics of AI, applied through a five-stage checklist (Ideation, Validation, Realization, Productization, Operation) that classifies every AI use case as red line, high risk or standard. A consultant who reuses this checklist on a client engagement gets a defensible governance trail for free — most of it doubles as EU AI Act documentation.
The policy behind the word "responsible"
Every SAP AI slide says "responsible AI." The substance behind the word is a named, versioned document: the SAP Global AI Ethics Policy, first published in 2021 and rewritten as version 3.0 in September 2024 after deep-dive interviews with more than 50 international experts. The rewrite did one thing that matters for delivery: it re-grounded the policy explicitly in the UNESCO Recommendation on the Ethics of Artificial Intelligence, adopted by all 193 UNESCO member states in 2021. SAP's own framing is that UNESCO "reaches beyond current legal adherence and creates ethical safeguards in the absence of national or global standards" — in plain terms, the policy is meant to hold even where no AI Act or local law yet applies. The companion document consultants actually use is the AI Ethics Handbook, which translates the ten principles into checklists for people building and delivering AI solutions, not just SAP's own product teams.
Why it matters
- The Ideation classification (red line / high risk / standard) is the one artifact from SAP's own ethics framework that a consultant can hand a client's AI Act compliance team almost unchanged — running it at kickoff turns a governance obligation into a reusable deliverable instead of a rediscovered emergency at go-live.
- ISO/IEC 42001 certifies SAP's management system for Joule, AI Core and AI Launchpad, not any specific customer use case built on them — citing it as proof that a client's own AI feature is compliant is a category error that will not survive an audit.
- SAP's own governance bodies (the Steering Committee and the Advisory Panel) govern what SAP ships, not what a client deploys — someone at the client has to own that role after go-live, and naming them is a delivery task, not an afterthought.
Key points
- SAP Global AI Ethics Policy v3.0 (Sep 2024): ten principles grounded in the UNESCO Recommendation on the Ethics of AI (2021).
- The AI Ethics Handbook splits the ten principles: 1-7 for builders, 8-10 for the operating organization's governance.
- Five-stage checklist: Ideation, Validation, Realization, Productization, Operation — not a one-time gate.
- Ideation classifies every use case: red line (refused), high risk (routed to the AI Ethics organization, escalated to the Steering Committee for the most sensitive cases), or standard.
- Two governance bodies: the internal AI Ethics Steering Committee and the external AI Ethics Advisory Panel — both govern SAP's own AI, not a customer's use case.
- ISO/IEC 42001:2023 certification (trust-center materials name Joule, SAP AI Core, SAP AI Launchpad) certifies a management system, not any specific deployed use case.
- The classification artifact, produced in writing at kickoff, doubles as input to the client's own EU AI Act Annex III risk classification and Annex IV technical documentation.
- The client, not SAP, is usually the AI Act "deployer" for a built solution — SAP's certification does not discharge the client's own human-oversight and logging duties.
Terms used on this page
- SAP Global AI Ethics Policy
- SAP's named, versioned governance document (v3.0, Sep 2024) setting ten AI ethics principles grounded in the UNESCO Recommendation on the Ethics of AI.
- AI Ethics Handbook
- The applied companion to the policy: translates the ten principles into a five-stage checklist (Ideation to Operation) and a red-line/high-risk/standard classification.
- Red line
- A use-case classification that refuses the build outright, regardless of business case.
- AI Ethics Steering Committee
- SAP's internal body that reviews high-risk classified use cases and can require changes or halt a build.
- AI Ethics Advisory Panel
- An external body giving outside guidance on SAP's AI ethics policy itself.
- ISO/IEC 42001
- The first international standard for AI management systems; certifies an organization's process for managing AI risk, not any specific model or use case.
- Deployer (AI Act)
- The organization that puts an AI system into service under its own authority — usually the client, not the system integrator, for a built solution.
Sources
- SAP News — Why SAP's Updated AI Ethics Policy Is Based on the Human Rights-Oriented UNESCO Recommendation (Sep 2024): ten principles, governance bodies, UNESCO grounding
- SAP News — How the Newly Updated SAP AI Ethics Handbook Helps Create Ethical AI at SAP (Sep 2024): five-stage checklist, red line/high-risk/standard classification, Steering Committee escalation
- SAP News — The AI Governance Gap: Why Responsible AI Drives Adoption (23 Sep 2026): three-pillar approach (ethics, security, compliance), mandatory impact assessments, human-oversight survey data
- SAP Community — Building Trust in AI: SAP Business AI Earns ISO/IEC 42001 Certification (scope: Joule, SAP AI Core, SAP AI Launchpad)
- SAP Trust Center — Certifications and Compliance (ISO/IEC 42001 listing)
- UNESCO — Recommendation on the Ethics of Artificial Intelligence (2021, adopted by 193 member states)
Full card available to members. What the full card adds: the full decision framework · the common pitfalls and their fix · the cheat sheet · the code blocks · the facts worth quoting.