Creating opportunity through risk remediation

Resilience redefined: A health tech giant transforms security risk into operational readiness with Workday

hero image
  • October 07, 2025

What would you do if your external auditor told you your security and controls framework wouldn’t pass review?


When a health tech leader's Workday system faced audit failure risks, it turned to PwC. With limited resources and urgent gaps in access reviews, change management and duties segregation, PwC helped the company address controls and reimagine its Workday security.


The result: stronger automation, clearer procedures and a resilient, future-ready control environment.

CLIENT

Leading health tech organization

INDUSTRY

Healthcare

FEATURING

Workday

7

IT general controls brought into audit standards

12

months of supported system changes and access reviews

24%

fewer security groups to review — streamlining access oversight

PwC helped design and implement a more streamlined security model so the client can safeguard its Workday system

Ready for what’s next — with stronger controls and compliance

What sparked the need for change?

When a large health tech company expanded its Workday footprint to include financials, it faced new scrutiny from auditors — putting new pressure on its security and controls. With limited resources, the organization had to embed new financial controls and streamline existing ones without slowing down the business. Staying compliant meant moving fast and getting it right the first time.

What solution did the teams unlock by working together?

PwC worked alongside the client to reimagine core IT controls, policies and procedures — strengthening oversight across financial systems. Along the way, we streamlined Workday security, creating a more intuitive structure that’s easier to manage and scale. Together, we simplified access reviews and improved how configuration changes can be monitored.

Using Enterprise Control a PwC product we automated segregation of duties (SoD) reviews — shifting focus to high-risk access points and unlocking time savings and better insights. We assessed the client’s security environment and uncovered opportunities to help reduce duplication, like consolidating overlapping security groups and removing outdated elements. The takeaway? A cleaner security model that’s easier to manage, faster to navigate and built for better oversight.

Where did tech innovation meet human ingenuity?

Balancing compliance priorities with the company’s resource capacity was one of the keys to sustaining momentum. We automated wherever we could. And where manual controls were necessary, we redesigned them for speed and simplicity — helping reduce friction without sacrificing oversight. To integrate changes without disrupting operations, the company had PwC engage stakeholders across the organization and create control documentation to help support long-term operation. We also remained involved after the redesign to help with ongoing adoption and a smooth handoff.

What was the real-world impact of approaching things differently?

With PwC’s help, the company met audit milestones with confidence and strengthened its control environment. Seven key IT general control gaps previously flagged by auditors were resolved. Security groups assessed in access reviews were reduced by 24% — streamlining the process and making it easier to manage. Momentum gained: less risk, more control and a stronger position ahead of future audits.

PwC AND WORKDAY

PwC is a select Industry Accelerator for Healthcare from Workday.

Learn more

HEALTH INDUSTRIES

Lead the future of healthcare — today.

Learn more

CASE STUDIES. REAL IMPACT.

Expertise. Technology. Results. Powered by collaboration. Explore our case studies to see what’s possible.

Learn more

Contact us

Nicole Pledger

Principal, PwC US

Win Fisher

Principal, PwC US

Follow us