Kean University Procurement Policy


Kean University Procurement Policy

Table of Contents

About This Policy

Kean University uses a transparent and structured process when buying goods, services, and technology. This ensures that purchases support academic and operational needs, reduce risk, and comply with laws, regulations, and grant requirements.

Back to top

Scope

This policy applies to anyone who requests, recommends, approves, or manages purchases, including:

  • Academic departments
  • Administrative offices
  • Research groups
  • Grant-funded projects
  • Information Technology and operational units

It applies to purchases such as:

  • Software and information technology systems
  • Laboratory and research equipment
  • Professional services
  • Cloud platforms
  • Capital equipment and infrastructure
  • Grant-funded assets

Back to top

Key Principles

Plan for the Entire Lifecycle

Departments must plan for how a product or service will be supported, upgraded, maintained, and eventually retired. This reduces the risk of outdated or unsupported systems.

  • Maintenance needs
  • Upgrade requirements
  • Vendor support timelines
  • End-of-life considerations
Include Risk in Every Purchase

Departments must assess and document risks such as:

  • Vendor cybersecurity maturity
  • System upgrade paths
  • Data protection risks
  • Accessibility and compliance issues

Significant risks must be escalated based on the approval path defined in this policy.

Follow Laws, Policies, and Standards

Purchases must comply with all relevant requirements, including:

  • Family Educational Rights and Privacy Act (FERPA)
  • Accessibility standards, including the Web Content Accessibility Guidelines (WCAG) and Section 508
  • Grant conditions and federal regulations
  • Internal Kean University policies such as Asset Management and Risk Management
Transparency and Documentation

All purchases must be logged in Kean’s official procurement or ticketing system and remain fully traceable.

Back to top

What You Must Do Before Buying

Conduct a Risk Assessment
  • Review vendor support lifecycles
  • Verify upgrade and patching plans
  • Assess compliance and data protection risks
  • Log material risks in the University Risk Register

Example: A vendor unable to provide security updates may require escalation to Risk Management.

Plan for Support and Maintenance
  • Budget for maintenance
  • Plan for upgrades
  • Account for renewal fees
  • Prepare for end-of-life and disposal

Example: Laboratory equipment must include firmware update support for at least five years.

Vendor Assurance Requirements

Departments must collect relevant assurance documentation, such as:

  • System and Organization Controls (SOC) 2 report
  • Higher Education Community Vendor Assessment Toolkit (HECVAT)
  • Voluntary Product Accessibility Template (VPAT)
  • Cloud architecture and security documentation
  • Data protection agreements
Follow the Proper Approval Path
  • Low-risk: Department-level approval
  • Medium-risk: Review by the University Risk Manager
  • High/Critical-risk: Review by the Risk Management Committee or Executive Leadership Team

Example: Any unsupported or legacy system requires high-level review.

Special Considerations for Grant-Funded Purchases
  • Sustainability planning after grant expiration
  • Alignment with grant terms
  • Escalation of risk when vendor support is insufficient
Emergency Purchases

Emergency purchases must include:

  • Written justification
  • Follow-up risk assessment
  • Approval from both Procurement and Risk Management

Back to top

How Procurement Supports University Strategy

Procurement ensures that purchasing decisions align with Kean’s long‑term academic and operational goals through:

  • Alignment with strategic planning cycles
  • Risk‑informed decision‑making
  • Support for scalable, modern, and innovative solutions
  • Collaboration with Information Technology, Academic Affairs, Finance, and other partners

Back to top

Documentation Requirements

All Purchases Must Be Logged
  • Requestor name
  • Purpose and justification
  • Risk assessment summary
  • Sustainment plan
  • Approval record
Record Retention

Kean must retain procurement documentation for at least seven years, including:

  • Purchase orders
  • Contracts
  • Vendor documentation
  • Risk assessments
  • Sustainment plans
Audit Readiness

Auditors may review items such as:

  • Risk assessments
  • Approval workflows
  • Vendor assurance evidence
  • Sustainment planning
Link to Risk Register

Any procurement involving material risk must be documented in the University Risk Register.

Back to top

Roles and Responsibilities

Department Heads

  • Initiate purchase requests
  • Provide sustainment plans
  • Complete risk assessments for high‑impact purchases

Procurement Office

  • Manages vendor selection and negotiation
  • Validates vendor documentation such as SOC 2 and HECVAT
  • Maintains audit logs

Risk Manager

  • Reviews risk assessments
  • Ensures proper escalation and logging
  • Advises on long‑term risk considerations

Chief Risk Officer / Risk Management Committee

  • Reviews high‑risk purchases
  • Approves critical procurement decisions
  • Ensures alignment with the Enterprise Risk Management (ERM) framework

Back to top

Training Requirements

Procurement staff must complete annual training in:

  • Risk assessment methodologies
  • Sustainment and lifecycle planning
  • Escalation guidelines for unsupported or high‑risk systems

Back to top

``

Was this answer helpful? Yes No

Sorry we couldn't be helpful. Help us improve this article with your feedback.