This seems simple enough, however there are some significant talking points hidden in that sentence. This is not boxed software that is purchased at some retail outlet, in fact this means the only way to purchase this software at all is through whatever sales channel the SaaS organization has set up. In most instances this means directly from the organization that has produced the software.
Another challenge is licensing and pricing. Unlike boxed software that can be controlled with required serial numbers it is not possible to limit. This poses challenges to an organization to secure their IP. There is also additional risk assumed by the organization in terms of having confidential information for users.
The primary means of limiting use/controlling access to features, etc is through the application of roles and privileges. This requires users to log into the application which now necessitates the need for the application to store that information in some way. This also means that it is possible for the application to track usage and behavior patterns which boxed software companies would normally not have access to. What additional legal / moral / ethical obligations does that entail?
Another factor around delivery over the internet and that is around performance. As a company cannot be responsible for performance of any of the vat network that makes up the total access to the application it is impossible for an organization to truly control any performance related issues and end user may have.
The final thought is around security. Any application that is delivered via the internet must contend with all the security issues that entails.