Citizen Portal
Sign In

Get Full Government Meeting Transcripts, Videos, & Alerts Forever!

Get email alerts on the School It Security topic

No spam. Unsubscribe anytime.

LPA audit: most school districts lack full accounting‑system access controls

Joint Committee on Information Technology (JCIT) · October 29, 2025
AI-Generated Content: All content on this page was generated by AI to highlight key points from the meeting. For complete details and context, we recommend watching the full video. so we can fix them.

Summary

A Legislative Post Audit review found none of 20 sampled Kansas school districts had adequate accounting system access controls across account management, identity management, and user limits.

A Legislative Post Audit examination of 20 Kansas school districts' accounting systems found pervasive weaknesses in access controls and security practices.

The audit team, led by senior auditor Amori Exline, assessed 12 control elements grouped in three categories: account management (who creates/modifies accounts and how change requests are documented), identity management (unique IDs, password controls, failed‑login handling, multifactor authentication) and user limits (authorized user lists, high‑dollar approval workflows, adjustment rights and segregation of duties).

Exline told the committee that none of the 20 districts reviewed had adequate controls across all three categories. Common findings included informal or undocumented change request practices, limited use of formal multifactor authentication (12 of 20 districts did not require MFA for accounting system access), and segregation of duties gaps in smaller districts where one staff member performed multiple roles.

"None of the 20 districts that we reviewed had adequate IT security access control practices in all three categories that we evaluated," Exline said, summarizing the primary audit finding.

The audit urged districts to formalize written policies, document change‑request and account‑management workflows, require multifactor authentication for access to accounting systems, and consider compensating controls where fully segregating duties is impractical in smaller districts. State Department of Education (KSDE) deputy commissioner Frank Harwood told the committee KSDE provides accounting guidance and will work to issue recommended best practices for districts; he acknowledged KSDE relies on district CPAs for many accounting determinations but said the agency will circulate guidance and coordinate with the State Board of Education.

Why it matters: Inadequate access controls increase the risk of fraud, ransomware and unauthorized changes to financial records. The audit highlights a policy gap: districts are locally controlled and not required by statute to adopt specific access control standards. Absent statewide minimums or shared services, small districts with limited staffing are particularly vulnerable.

What remains open: LPA recommended districts adopt formal written policies and KSDE produce guidance on best practices. KSDE agreed to work on recommended controls and to share guidance; the committee asked KSDE and LPA to follow up on guidance dissemination and implementation.