Citizen Portal
Sign In

Get Full Government Meeting Transcripts, Videos, & Alerts Forever!

Get email alerts on the School District Accounting Systems topic

No spam. Unsubscribe anytime.

Audit: Many Kansas school districts lack basic accounting-system access controls and written policies

5783771 · September 17, 2025
AI-Generated Content: All content on this page was generated by AI to highlight key points from the meeting. For complete details and context, we recommend watching the full video. so we can fix them.

Summary

A Legislative Division of Post Audit review found that among 20 Kansas school districts examined, most lacked at least one basic access control for accounting systems and very few had written policies covering account management, identity management and user limits.

Maury, an auditor with the Legislative Division of Post Audit, told the Legislative Post Audit Committee that his office evaluated accounting-system access controls at 20 school districts to answer whether the districts “have adequate access security controls.” He summarized the audit’s short answer: “Of the 20 districts that we reviewed, only some had adequate access controls for their accounting systems and very few had adequate written policies.”

The audit team compiled 12 access controls drawn from guidance by the Kansas Information Technology Executive Council (ITEC), the National Institute of Standards and Technology (NIST) and accounting-control practices the Kansas Department of Administration makes available. The controls were grouped into three categories: account management, identity management, and user limits.

Why it matters: district accounting systems record payroll, benefits and other K‑12 expenditures; weak access controls can increase risk of unauthorized access, ransomware and fraud. The auditor said school districts are not required by state law to have specific accounting-system access controls; the audit therefore evaluated basic controls the team considered fundamental regardless of the age or vendor of a district’s accounting software.

Key findings

- Overall: None of the 20 reviewed districts had adequate practices across all three control categories.

- Account management: Only one district demonstrated adequate practices for all three account‑management controls the audit reviewed. Fourteen districts had a formally designated account manager; six reported that account‑management responsibilities were handled informally and lacked documentation. Three of 20 districts had documented change‑request processes; only one district could show both a timeline and documentation practice for making access changes in a timely manner.

- Identity management: Four districts met all four identity‑management controls the audit measured. Most districts (19 of 20) used unique user IDs and had acceptable‑use rules to prohibit password sharing; 13 of 20 had automatic account lockouts after repeated failed logins. Fewer than half (8 of 20) required multifactor authentication (MFA) to sign into accounting systems; several districts allowed staff to bypass MFA on trusted devices or for extended periods.

- User limits and segregation of duties: Eleven districts had adequate controls across the five user‑limit checks the audit reviewed. All 20 districts maintained an automated list of authorized system users. Most had additional approval for high‑dollar purchases (commonly set at $20,000, with some districts using $10,000–$15,000 thresholds). Thirteen districts had adequate segregation of duties; seven — typically smaller districts with only one to three administrative users — did not, meaning one person could both enter and approve transactions in some cases.

- Written policies: Very few districts had formal written policies covering all three categories; no district had policies for every category. The audit emphasized that undocumented practices can disappear when staff turn over.

Recommendations and responses

The audit included two recommendations: one for the Kansas Department of Education to provide clearer guidance on basic accounting‑system access controls, and one for the selected school districts to adopt and document practices and policies covering account management, identity management and user limits. Maury said the agency and the reviewed districts generally agreed with the recommendations and that some districts acknowledged controls existed in practice but were not documented.

What committee members asked

Senator Thompson asked the auditor to clarify that “change requests” referred to adding, modifying or disabling people’s access when staff change jobs or leave; Maury confirmed it included new accounts, role changes and timely termination of access. Senator Holster asked whether timing of the audit (conducted in June) limited district responses; Maury said one district mentioned timing as an issue and that was not a widespread concern. Dr. Harwood, an agency representative, told the committee that districts subscribe to policy guidance from groups such as the Kansas Association of School Boards and that the Department of Education focuses on procedures and practice rather than imposing detailed accounting rules.

Ending

The audit report urges clearer, documented practices and stronger technical settings such as MFA so districts do not rely on informal arrangements or a single employee. The committee accepted the audit as part of the meeting’s consent calendar later in the session.