Grant Thornton Australia, a longtime iManage customer, maintains a repository of roughly 50 TB, comprising about 20 million documents and emails. As client expectations for confidentiality rose across professional services, the firm evolved its security to meet the moment. This meant moving from a flexible, collaboration-first model to a self-service but tightly controlled model built for today’s risk and compliance environment. The technology team rolled out iManage Security Policy Manager with the latest version of iManage Work 10 in the Cloud, applying a need-to-know security posture across its roughly 170,000 workspaces. Engagement teams now manage their own access. Every change is auditable. And the firm has reached 100% adoption across all of its service lines.
The business challenge
Getting ahead of a shifting security landscape
Grant Thornton Australia’s Enterprise Risk Committee, a subcommittee of the board, identified an opportunity to proactively strengthen the firm’s approach to security and privacy and to remain a vanguard in the industry. Chief Technology Officer Ben Swindale was tasked with leading the initiative.
Like many firms, Grant Thornton Australia had built its original model around collaboration, applying extra security to confidential engagements as required — but it was a manual process. It meant engagement teams adding and removing access at the document and workspace levels, and again in the firm’s CRM. That level of individual effort was not practical at scale. And any departure from the standard could cause a discrepancy in the outcome, which, in an accountancy, creates unacceptable risk.
“Having to put the same things in different places made things inconsistent and hard to manage,” Swindale says. “And every access question a team couldn’t resolve on its own became a ticket for IT.” This added a steady stream of manual work for a small admin team to manage.
Headquarters
Sydney, Australia
Industry
Accountancy
Products
iManage Security Policy Manager
Benefits
Auditable, need-to-know security
Self-service access management
Client confidence in confidentiality
Reduced IT ticket volume
About partner
Founded in 2015, Morae Global Corporation is trusted around the world for the delivery of digital and business solutions for the ever-changing legal sector. It collaborates closely with clients to develop strategies, implement meaningful change, and achieve their business objectives.
"Grant Thornton wasn’t looking to change document management systems or where we were storing our content. We were looking for a security solution that was natively integrated with iManage and was simple to use. Everyone knows how to get into the iManage Security Policy Manager access portal, see who has access, and run their own reports. It has significantly reduced the workload on our iManage admins."
Ben Swindale, Chief Technology Officer, Grant Thornton Australia
The solution
A native fit, rolled out corporate-wide
Swindale identified iManage Security Policy Manager as a natural fit for the problem, informed by his firsthand experience with the product in a previous role. “Grant Thornton wasn’t looking to change document management systems or where we were storing our content,” he recalls. “We were looking for a security solution that was natively integrated with iManage and was simple to use. Introducing a third-party tool or changing to a different platform would have been a much bigger project.”
After working with implementation partner Morae on an early discovery session, Grant Thornton Australia rolled out Security Policy Manager over roughly six months, by service line (audit, tax, advisory, and consulting). Each rollout paired training with a network of internal “Change Champions”: power users who could field colleagues’ questions directly, in the moment, preventing them from becoming IT support tickets. The resulting system is secure by default, with the need-to-know principle applied consistently across every Opportunity and Project workspace that contains client materials. People were guided carefully through the training to dispel any resistance they might feel to changing their day-to-day workflows.
50 TB
of data
170,000
workspaces
100% adoption
adoption
The business outcomes
Security that runs itself
Every live engagement at Grant Thornton Australia is now secured under Security Policy Manager across roughly 170,000 workspaces. From the partner leading the work to the executive assistants, the engagement teams manage their access lists without waiting on IT. Client-facing teams manage access to their client workspaces through a controlled, auditable, self-service process. This has freed IT admins to spend more time on strategic platform work.
“Everyone knows how to get into the iManage Security Policy Manager access portal, see who has access, and run their own reports. It has significantly reduced the workload on our iManage admins,” says Swindale, Chief Technology Officer, Grant Thornton Australia.
Alongside the success of Security Policy Manager, strong adoption of Microsoft co-authoring in iManage has enabled engagement teams to work together on documents in real time, producing a clear audit trail of who worked on which section and when.
Audit trails are vital to Grant Thornton’s ability to reassure clients on matters of confidentiality — a high-profile topic for professional services firms in Australia. Swindale reports that integrating Security Policy Manager with the iManage platform, allows the firm’s professionals to consistently explain to its clients exactly how engagement materials are controlled and audited.
“Clients want assurance that we’re looking after their data, keeping it safe, keeping it secure. We’re in a good position to say we are, because we’ve got these iManage tools in place.”
Looking ahead
Grant Thornton Australia recently joined the Grant Thornton Advisors multinational platform of nearly 20 aligned firms across the Americas, Europe, the Middle East, and the Asia-Pacific region, accelerating its ambitions to become the nation’s most modern, cross-border professional services firm. As it extends security coverage to parts of its iManage environment outside of engagements, Swindale is evaluating iManage Threat Manager as a next step in the firm’s security journey.