Autonomous SAP ALM Control Fabric (ASACF): A Practitioner-Grounded AI Governance Architecture for Change, Compliance, and Release Management Across Hybrid Enterprise Landscapes

Authors

  • Karthik Paramasivam

DOI:

https://doi.org/10.22399/ijcesen.5504

Keywords:

SAP ALM, SAP ChaRM, Autonomous ALM, SAP Solution Manager, Central ATC, BPCA

Abstract

Enterprise SAP landscapes have shifted from the rather centralized ERP landscape to a hybrid enterprise landscape that integrates SAP S/4HANA, SAP Solution Manager, SAP Cloud ALM, SAP Business Technology Platform extensions, custom ABAP and CDS developments, Fiori applications, integration middleware, analytics services, identity controls and third-party service management platforms. In such contexts, Application Lifecycle Management (ALM) transcends mere coordination between development and transport releasing tasks. It's a governance issue where there is a need to consider the change evidence, technical quality, business-process impact, authorization integrity, testing assurance, audit requirements and operational telemetry in tandem, before a decision can be deemed safe to release. There are various existing SAP ALM practices that create a considerable amount of evidence, such as Change Request Management (ChaRM), Central ATC, Business Process Change Analyzer (BPCA), SCMON, UPL, Test Suite, Cross System Object Lock (CSOL), Downgrade Protection, Retrofit and Focused Insights and incident management. These evidence sources can, however, be dispersed throughout workflows, repositories and governance roles. This fragmentation hampers release explainability and leaves behind long-lasting gaps in change classification, routing for approval, conflict prevention and compliance proof for retrofits. This paper suggests a literature inspired and practitioner-driven governance structure for AI-assisted SAP change, compliance and release management, called the Autonomous SAP ALM Control Fabric (ASACF). The framework is developed using design-science reasoning by synthesizing research on ERP governance, continuous auditing, process mining, DevOps, software analytics, explainable AI, MLOps, and self-adaptive systems, together with anonymized practitioner design evidence from enterprise SAP ChaRM landscapes. ASACF comprises seven layers: Change Evidence Collection, SAP Dependency Knowledge Graph, AI Risk Intelligence, Governance Policy Engine, Release Decision Layer, Audit Evidence Layer and Continuous Learning Layer. The paper also introduces four AI governance services built on ChaRM: a change type classification engine, a risk adaptive approval routing engine, a predictive retrofit conflict engine and a continuous compliance evidence assembler. The core idea is a bounded-autonomy model in which AI complements, rather than takes the place of, SAP governance authority, making recommendations, providing evidence completeness checks, routing according to the policy and enabling auditable human override. The framework provides a reference architecture and an evaluation roadmap for future empirical study of autonomous SAP ALM that can be reused.

References

[1] Feldman, G., Shah, H., Chapman, C., & Amini, A. (2016). Enterprise systems: The upgrade process model. Journal of Enterprise Information Management, 29(6), 822–840. doi:10.1108/JEIM-12-2014-0122

[2] Oseni, T., Foster, S., Rahim, M., & Smith, S. P. (2017). A framework for ERP post-implementation amendments: A literature analysis. Australasian Journal of Information Systems, 21, 1–21. doi:10.3127/ajis.v21i0.1268

[3] Barth, C., & Koch, S. (2019). Critical success factors in ERP upgrade projects. Industrial Management & Data Systems, 119(3), 656–675. doi:10.1108/IMDS-01-2018-0016

[4] Lee, N. C. A., & Chang, J. Y. T. (2020). Adapting ERP systems in the post-implementation stage: Dynamic IT capabilities for ERP. Pacific Asia Journal of the Association for Information Systems, 12(1), 28–59. doi:10.17705/1pais.12102

[5] Domagała, A., Grobler-Dębska, K., Wąs, J., & Kucharska, E. (2021). Post-implementation ERP software development: Upgrade or reimplementation. Applied Sciences, 11(11), Article 4937. doi:10.3390/app11114937

[6] Lee, C., Kim, H. F., & Lee, B. G. (2024). A systematic literature review on the strategic shift to cloud ERP: Leveraging microservice architecture and MSPs for resilience and agility. Electronics, 13(14), Article 2885. doi:10.3390/electronics13142885

[7] Priyadarsini, A., & Kumar, A. (2022). A literature review on IT governance using systematicity and transparency framework. Digital Policy, Regulation and Governance, 24(3), 309–328. doi:10.1108/DPRG-09-2021-0114

[8] Őri, D., & Szabó, Z. (2024). A systematic literature review on business-IT misalignment research. Information Systems and e-Business Management, 22(1), 139–169. doi:10.1007/s10257-023-00664-w

[9] Dutta, A., Roy, R., & Seetharaman, P. (2022). An assimilation maturity model for IT governance and auditing. Information & Management, 59(1), Article 103569. doi:10.1016/j.im.2021.103569

[10] Aftab, M. U., Qin, Z., Hundera, N. W., Ariyo, O., Zakria, Son, N. T., & Dinh, T. V. (2019). Permission-based separation of duty in dynamic role-based access control model. Symmetry, 11(5), Article 669. doi:10.3390/sym11050669

[11] Atlam, H. F., Azad, M. A., Alassafi, M. O., Alshdadi, A. A., & Alenezi, A. (2020). Risk-based access control model: A systematic literature review. Future Internet, 12(6), Article 103. doi:10.3390/fi12060103

[12] Jans, M., & Hosseinpour, M. (2019). How active learning and process mining can act as continuous auditing catalyst. International Journal of Accounting Information Systems, 32, 44–58. doi:10.1016/j.accinf.2018.11.002

[13] Augusto, A., Conforti, R., Dumas, M., La Rosa, M., Maggi, F. M., Marrella, A., Mecella, M., & Soo, A. (2019). Automated discovery of process models from event logs: Review and benchmark. IEEE Transactions on Knowledge and Data Engineering, 31(4), 686–705. doi:10.1109/TKDE.2018.2841877

[14] Rinderle-Ma, S., Winter, K., & Benzin, J. V. (2023). Predictive compliance monitoring in process-aware information systems: State of the art, functionalities, research directions. Information Systems, 115, Article 102210. doi:10.1016/j.is.2023.102210

[15] van Beest, N., Groefsema, H., Cryer, A., Governatori, G., Tosatto, S. C., & Burke, H. (2023). Cross-instance regulatory compliance checking of business process event logs. IEEE Transactions on Software Engineering, 49(11), 4917–4931. doi:10.1109/TSE.2023.3319086

[16] Shahin, M., Babar, M. A., & Zhu, L. (2017). Continuous integration, delivery and deployment: A systematic review on approaches, tools, challenges and practices. IEEE Access, 5, 3909–3943. doi:10.1109/ACCESS.2017.2685629

[17] Waseem, M., Liang, P., & Shahin, M. (2020). A systematic mapping study on microservices architecture in DevOps. Journal of Systems and Software, 170, Article 110798. doi:10.1016/j.jss.2020.110798

[18] Kazmi, R., Jawawi, D. N. A., Mohamad, R., & Ghani, I. (2017). Effective regression test case selection: A systematic literature review. ACM Computing Surveys, 50(2), Article 29, 1–32. doi:10.1145/3057269

[19] Li, N., Shepperd, M., & Guo, Y. (2020). A systematic review of unsupervised learning techniques for software defect prediction. Information and Software Technology, 122, Article 106287. doi:10.1016/j.infsof.2020.106287

[20] Barredo Arrieta, A., Díaz-Rodríguez, N., Del Ser, J., Bennetot, A., Tabik, S., Barbado, A., García, S., Gil-Lopez, S., Molina, D., Benjamins, R., Chatila, R., & Herrera, F. (2020). Explainable artificial intelligence (XAI): Concepts, taxonomies, opportunities and challenges toward responsible AI. Information Fusion, 58, 82–115. doi:10.1016/j.inffus.2019.12.012

[21] Mittelstadt, B. (2019). Principles alone cannot guarantee ethical AI. Nature Machine Intelligence, 1(11), 501–507. doi:10.1038/s42256-019-0114-4

[22] Kreuzberger, D., Kühl, N., & Hirschl, S. (2023). Machine learning operations (MLOps): Overview, definition, and architecture. IEEE Access, 11, 31866–31879. doi:10.1109/ACCESS.2023.3262138

[23] Batool, A., Zowghi, D., & Bano, M. (2025). AI governance: A systematic literature review. AI and Ethics. doi:10.1007/s43681-024-00653-w

[24] Hogan, A., Blomqvist, E., Cochez, M., d’Amato, C., de Melo, G., Gutierrez, C., Kirrane, S., Gayo, J. E. L., Navigli, R., Neumaier, S., Ngonga Ngomo, A.-C., Polleres, A., Rashid, S. M., Rula, A., Schmelzeisen, L., Sequeda, J., Staab, S., & Zimmermann, A. (2021). Knowledge graphs. ACM Computing Surveys, 54(4), Article 71. doi:10.1145/3447772

[25] Ji, S., Pan, S., Cambria, E., Marttinen, P., & Yu, P. S. (2022). A survey on knowledge graphs: Representation, acquisition, and applications. IEEE Transactions on Neural Networks and Learning Systems, 33(2), 494–514. doi:10.1109/TNNLS.2021.3070843

[26] Charalampidou, S., Ampatzoglou, A., Karountzos, E., & Avgeriou, P. (2020). Empirical studies on software traceability: A mapping study. Journal of Software: Evolution and Process, 32(12), Article e2294. doi:10.1002/smr.2294

[27] Mucha, J., Kaufmann, A., & Riehle, D. (2024). A systematic literature review of pre-requirements specification traceability. Requirements Engineering, 29, 119–141. doi:10.1007/s00766-023-00412-z

[28] Gheibi, O., Weyns, D., & Quin, F. (2021). Applying machine learning in self-adaptive systems: A systematic literature review. ACM Transactions on Autonomous and Adaptive Systems, 15(3), 1–37. doi:10.1145/3469440

[29] Weyns, D., Gerostathopoulos, I., Abbas, N., Andersson, J., Biffl, S., Brada, P., Bures, T., Di Salle, A., Galster, M., Lago, P., Lewis, G., Litoiu, M., Musil, A., Musil, J., Patros, P., & Pelliccione, P. (2023). Self-adaptation in industry: A survey. ACM Transactions on Autonomous and Adaptive Systems, 18(2), Article 5, 1–44. doi:10.1145/3589227

[30] Baskerville, R., Baiyere, A., Gregor, S., Hevner, A., & Rossi, M. (2018). Design science research contributions: Finding a balance between artifact and theory. Journal of the Association for Information Systems, 19(5), 358–376. doi:10.17705/1jais.00495

[31] Hasan, N., Miah, S. J., Bao, Y., & Hoque, M. R. (2019). Factors affecting post-implementation success of enterprise resource planning systems: A perspective of business process performance. Enterprise Information Systems, 13(9), 1217–1244. doi:10.1080/17517575.2019.1612099

[32] Butarbutar, Z. T., Handayani, P. W., Suryono, R. R., & Wibowo, F. W. (2023). Systematic literature review of critical success factors on enterprise resource planning post implementation. Cogent Business & Management, 10(3), Article 2264001. doi:10.1080/23311975.2023.2264001

[33] Mahmood, F., Khan, A. Z., Shah, S. A., & Adil, M. (2024). Post ERP implementation issues and challenges: Exploratory case studies in the context of Saudi Arabia. Kybernetes, 53(12), 5749–5774. doi:10.1108/K-06-2022-0914

[34] Salih, A. A., Zeebaree, S. R. M., Abdulraheem, A. S., Zebari, R. R., Sadeeq, M. A. M., & Ahmed, O. M. (2022). Evolution of enterprise resource planning. IEEE Access, 10, 108004–108020. doi:10.1109/ACCESS.2022.3202954

[35] Kirmizi, M., & Kocaoglu, B. (2022). The influencing factors of enterprise resource planning readiness stage on enterprise resource planning project success: A project manager’s perspective. Kybernetes, 51(3), 1089–1113. doi:10.1108/K-11-2020-0812

[36] Jans, M., Soffer, P., & Jouck, T. (2019). Building a valuable event log for process mining: An experimental exploration of a guided process. Enterprise Information Systems, 13(5), 601–630. doi:10.1080/17517575.2019.1587788

[37] Martin, N., Fischer, D. A., Kerpedzhiev, G. D., Goel, K., Leemans, S. J. J., Röglinger, M., van der Aalst, W. M. P., Dumas, M., La Rosa, M., & Wynn, M. T. (2021). Opportunities and challenges for process mining in organizations: Results of a Delphi study. Business & Information Systems Engineering, 63(5), 511–527. doi:10.1007/s12599-021-00720-0

[38] El-Gharib, N. M., & Amyot, D. (2023). Robotic process automation using process mining: A systematic literature review. Data & Knowledge Engineering, 148, Article 102229. doi:10.1016/j.datak.2023.102229

[39] Azad, N., & Hyrynsalmi, S. (2023). DevOps critical success factors and organizational practices: A systematic literature review. Information and Software Technology, 157, Article 107150. doi:10.1016/j.infsof.2023.107150

[40] Kumar, R., Nadeem, M., & Shameem, M. (2025). DevOps metrics: A systematic literature review. Journal of Software: Evolution and Process, 37(1), Article e2733. doi:10.1002/smr.2733

[41] Lwakatare, L. E., Kuvaja, P., & Oivo, M. (2019). Dimensions of DevOps. Information and Software Technology, 114, 217–230. doi:10.1016/j.infsof.2019.06.010

[42] Laukkanen, E., Itkonen, J., & Lassenius, C. (2017). Problems, causes and solutions when adopting continuous delivery: A systematic literature review. Information and Software Technology, 82, 55–79. doi:10.1016/j.infsof.2016.10.001

[43] Grattan, F., da Costa, D. A., & Stanger, N. (2024). The need for more informative defect prediction. Information and Software Technology, 171, Article 107456. doi:10.1016/j.infsof.2024.107456

[44] Stradowski, D., & Madeyski, L. (2023). The state of the art in software defect prediction. Information and Software Technology, 159, Article 107192. doi:10.1016/j.infsof.2023.107192

[45] Ali, S., Abuhmed, T., El-Sappagh, S., Muhammad, K., Alonso-Moral, J. M., Confalonieri, R., Guidotti, R., Del Ser, J., Díaz-Rodríguez, N., & Herrera, F. (2023). Explainable artificial intelligence (XAI): What we know and what is left to attain trustworthy artificial intelligence. Information Fusion, 99, Article 101805. doi:10.1016/j.inffus.2023.101805

[46] Hassija, V., Chamola, V., Mahapatra, A., Singal, A., Goel, D., Huang, K., Scardapane, S., Spinelli, I., Mahmud, M., & Hussain, A. (2024). Interpreting black-box models: A review on explainable artificial intelligence. Cognitive Computation, 16(1), 45–74. doi:10.1007/s12559-023-10179-8

[47] Werder, K., Ramesh, B., & Zhang, S. (2022). Establishing data provenance for responsible artificial intelligence systems. ACM Transactions on Management Information Systems, 13(2), Article 22, 1–23. doi:10.1145/3503488

[48] Birkstedt, T., Minkkinen, M., Tandon, A., & Mäntymäki, M. (2023). AI governance: Themes, knowledge gaps and future agendas. Internet Research, 33(7), 133–167. doi:10.1108/INTR-01-2022-0042

[49] Mäntymäki, M., Minkkinen, M., Birkstedt, T., & Viljanen, M. (2022). Defining organizational AI governance. AI and Ethics, 2, 603–609. doi:10.1007/s43681-022-00143-x

[50] Mehrabi, N., Morstatter, F., Saxena, N., Lerman, K., & Galstyan, A. (2021). A survey on bias and fairness in machine learning. ACM Computing Surveys, 54(6), Article 115, 1–35. doi:10.1145/3457607

[51] Paulheim, H. (2017). Knowledge graph refinement: A survey of approaches and evaluation methods. Semantic Web, 8(3), 489–508. doi:10.3233/SW-160218

[52] Wang, L., Sun, Z., Zhang, Y., Nie, L., & Huang, Y. (2023). Application of knowledge graph in software engineering field: A systematic literature review. Information and Software Technology, 164, Article 107327. doi:10.1016/j.infsof.2023.107327

[53] Tamašauskaitė, G., & Groth, P. (2023). Defining a knowledge graph development process through a systematic review. ACM Transactions on Software Engineering and Methodology, 32(1), Article 27, 1–40. doi:10.1145/3522586

[54] Lyu, Y., Cho, H., Jung, P., & Lee, S. (2023). A systematic literature review of issue-based requirement traceability. IEEE Access, 11, 13334–13348. doi:10.1109/ACCESS.2023.3242294

[55] Wong, T., Wagner, M., & Treude, C. (2022). Self-adaptive systems: A systematic literature review across categories and domains. Information and Software Technology, 148, Article 106934. doi:10.1016/j.infsof.2022.106934

Downloads

Published

2025-03-29

How to Cite

Karthik Paramasivam. (2025). Autonomous SAP ALM Control Fabric (ASACF): A Practitioner-Grounded AI Governance Architecture for Change, Compliance, and Release Management Across Hybrid Enterprise Landscapes. International Journal of Computational and Experimental Science and Engineering, 11(1). https://doi.org/10.22399/ijcesen.5504

Issue

Section

Research Article