Top class compliance: How University of Virginia strengthens security with Kainos Smart

Discover how this leading educational institute uses Kainos automation to transform Workday operations, maintain agility, and support ongoing compliance obligations.
Date posted
13 January 2025
Reading time
6 minutes

The goals

image
Reduce
bi-annual update testing effort
image
Empower
decentralised self-service Workday use
image
Minimise
manual activity monitoring and access reviews
image
Streamline
audit evidence gathering process

Results

75%

reduction in testing effort and costs

80K

SoD, access and security checks completed annually

89%

decrease in security and compliance effort

12

fewer FTE required for testing

When we turned on Smart Audit, parts of our configuration were instantly flagged as security risks. We could see risks, remediate them more quickly and record evidence of the issue and resolution. Smart Audit has been phenomenal in terms of that quick ROI.

Augie Maurelli
CFO
University of Virginia

About University of Virginia

University of Virginia (UVA) offers world-class education across a diverse range of programs and faculties. One of North America’s top higher education institutions, University of Virginia’s campuses, university hospital and research institutions are home to nearly 21,000 students and over 29,000 staff.   

Retiring disparate legacy systems with Workday   

In 2019, UVA began a strategic initiative to upgrade a range of disconnected, ageing software systems. With nearly 29,000 staff and a financial landscape ranging from procurement to grant management, any solution needed both powerful HR and finance governance abilities.  

UVA chose Workday as the most viable solution to streamline operations because its unified, scalable platform could meet current needs and support the institution's growth ambitions. 

image

Adapting to ongoing change   

Following a successful HCM implementation and with Workday providing university-wide benefits, attention turned to ongoing maintenance and optimisation. The scale and complexity of UVA’s configuration meant manually validating change was challenging for the institution’s lean Workday operations team. 

A solution was required that would allow UVA to seamlessly implement hundreds of change requests per month, manage business-as-usual maintenance, and efficiently test during Workday’s bi-annual feature releases.   

image

Automated testing drives agility   

The university began the search for a solution that could facilitate growth and adaptability. With these requirements in mind, UVA selected Kainos Smart Test. Combining automation with Kainos’ experienced Workday experts, Workday’s preferred test solution would allow UVA to expand and streamline its testing processes.  

Seamless automation has empowered the university’s Workday team to test more quickly, more accurately, and with greater coverage.   

As a dynamic institution, Smart Test has enabled UVA to keep pace with change and deliver results with more cost-effective processes. Augie Maurelli, VP of Finance at UVA explains, “During our first bi-annual release we couldn’t implement lots of new features. Smart Test has allowed us to get to a point of maturation. We're really maximising the benefits and we’re more agile, because Smart Test helps us to change our configuration so easily.”  

As UVA’s Workday footprint expands, Smart Test is carrying out testing that would typically require a full time team of 12, increasing test coverage and decreasing manual effort by 75%.   

Smart Test has allowed us to get to a point of maturation. We're really maximising the benefits and we’re more agile, because Smart Test helps us to change our configuration so easily.

Augie Maurelli
CFO
University of Virginia

Decentralised finance with centralised compliance  

With Smart Test’s Built on Workday automation in use, the team was able to understand and test the impact of changes but UVA’s structure also brought requirements for a highly decentralised approach to managing Workday Financials. “On the finance side, we have a lot of decentral users and this required a lot of custom security groups and roles. This meant lots of opportunities for both Segregation of Duties and potential high-risk behaviour,” Augie notes.   

With a lean security and compliance team, manually monitoring user activity, reviewing access and reconciling Segregation of Duties conflicts wasn’t feasible.  

In addition to security, as a higher education institute, UVA faces a unique regulatory landscape. Christine Kennedy-Tyburski, Senior Financial Controls Coordinator at UVA adds, “As a publicly-funded institute, we have unique requirements. These include state and federal audits, strict reporting obligations, and the need to maintain a system of record. It is nearly impossible to effectively monitor all these elements without a tool that can work with you based on your business needs.”

image

Smart Audit highlights risks  

Kainos Smart Audit, Workday’s preferred audit solution, is the only tool that matched UVA’s complex needs, offering the university the ability to minimise risk, reduce audit preparation effort, and maintain compliance without increasing budgets.   

Immediately after implementation, Smart Audit provided value to the team at UVA, highlighting a range of risks and potential conflicts that may have gone undetected.  

Augie explains, “When we turned on Smart Audit, parts of our configuration were instantly flagged as security risks. We could see risks, remediate them more quickly, and record evidence of the issue and resolution. Smart Audit has been phenomenal in terms of that quick ROI.”  

Smart Audit carries out over 80,000 individual access, configuration change and SoD checks annually for UVA, completing work equivalent to 28 full time employees (FTE). This has allowed the university to expand security coverage to a level that was unachievable with manual processes and to reduce the overall cost of managing controls.

image

Graduating to simplified compliance with Built on Workday automation 

In addition to identifying potential risks, Smart Audit has provided a single, simplified system of reporting to streamline UVA’s auditing processes. Christine notes, “Speaking as a former auditor, Smart Audit is a phenomenal tool. The level of record retention, reporting and auditability is fantastic. It not only shows what we are monitoring but how we manage cases and everything that is going on within our tenant. Being able to give that to auditors without manual evidence gathering is so valuable.”   

Augie adds, “Everything we need is there, we can give auditors access. So, they can review the ledger account and pick samples. It makes their job as easy as possible”  

image

World-class knowledge for a world-class institution    

Beyond Smart Audit’s powerful features, UVA has found that the support and expertise provided by Kainos has been invaluable in building the institution’s Workday security and compliance strategy.  

“It's not just the technology when it comes to Kainos. When we implemented Smart Audit, we were overwhelmed with red flags and Kainos helped us to clear up which were genuine risks or false positives,” Augie notes, “Between Kainos’ extended knowledge and Smart Audit’s functionality, that is a powerful combination, especially when you’re on that adoption curve.”  

Securing UVA’s Workday future   

With automated SoD detection, user activity monitoring and user access reviews, UVA now has a consolidated, accessible source of security, compliance and truth. This confidence in security has enabled the university to scale Workday operations.   

Christine shares, “Looking back, my one tip to anyone thinking of implementing Workday for their organisation, please explore how Smart Audit can help before you go any further. The ability to proactively identify and fix issues is a lot easier than fixing them on the back end.”  

Augie adds, “If there are people contemplating Smart Audit, I would just echo how powerful it is, it was absolutely worth the investment. When you combine it with Smart Test, you have really valuable tools to scale your day-to-day Workday operations.”  

Want to learn more about how automated testing, security and compliance can help your organisation?