Kean University Supplier Risk Management Policy
Table of Contents
- About This Policy
- Purpose
- Scope
- Authority & Governance
- Definitions
- Policy Statements
- Roles & Responsibilities (RACI)
- Compliance Mapping
- Enforcement
- Exceptions
- Related Documents
- Review & Maintenance
- Version History
About This Policy
The KU SRM 01 – Supplier Risk Management Policy establishes a structured, repeatable, and auditable risk management program for all third‑party suppliers providing goods, services, systems, or infrastructure to Kean University. It ensures all suppliers are evaluated, monitored, and governed under the Enterprise Risk Management (ERM) framework and cybersecurity requirements.
Back to topPurpose
The purpose of this policy is to establish a consistent lifecycle for supplier risk management; protect the University from cybersecurity, operational, financial, and compliance risks; mandate required assurance artifacts (SOC 2, HECVAT); and ensure continuous risk monitoring, reporting, and integration with ERM processes.
Back to topScope
Suppliers Covered
- IT and cloud service providers (IaaS, PaaS, SaaS)
- Outsourced business process vendors
- Research and operational technology suppliers
- Contractors, consultants, strategic partners
- Hardware and software providers
- Any vendor with logical or physical access to University systems or data
Lifecycle Stages
- Onboarding
- Active service
- Contract renewal
- Offboarding
- Reassessment following incidents or material changes
Mandatory Vendor Assurance Requirements
- Current SOC 2 Type II (issued within 12 months)
- Completed Higher Education Community Vendor Assessment Toolkit (HECVAT)
- Annual updates of all assurance artifacts
Failure to provide these documents results in automatic High‑Risk classification.
Back to topAuthority & Governance
This policy inherits authority from RC01 – Policy Standard and KU SEC 10 – Policy Precedence. It is subordinate only to Federal and State law, RC01 governance hierarchy, and University‑level policies governing procurement, asset management, risk management, and cybersecurity.
Back to topDefinitions
View Definitions
Lifecycle Sustainment – Long-term viability, support, and upgrade planning.
Vendor Assurance – Required documentation ensuring compliance (SOC 2, HECVAT, VPAT).
Risk Register – The University’s official record of institutional risks.
Critical Vulnerability – High-impact security flaw requiring urgent remediation.
Governance Thresholds – Defined escalation tiers for risk decisions.
Policy Statements
Risk Identification
- Biannual and ad‑hoc risk identification activities
- Use of questionnaires, financial reviews, threat intelligence, and performance KPIs
Risk Assessment
- Evaluate likelihood, impact, control strength, and vendor maturity
- Automatic High‑Risk classification for missing SOC 2 / HECVAT
- All risks recorded in the Risk Register
Risk Response
- Accept
- Mitigate
- Transfer
- Terminate
High and Critical risks require a formal Risk Action Plan.
Ongoing Monitoring
- Monthly control and performance monitoring
- Quarterly dashboards
- Annual supplier risk report
Mandatory SOC 2 / HECVAT Requirements
Required at onboarding, annually, and upon significant changes.
Non‑compliance may trigger escalation, contract holds, or termination.
Contractual Requirements
- Security and privacy clauses
- SOC 2 / HECVAT obligations
- Breach notification
- Right to audit and corrective action requirements
Escalation Requirements
- Critical risks
- SLA violations
- Security incidents
- Missing documentation
- Repeated non-compliance
Continuous Improvement
- Post‑Incident Review (PIR)
- Root Cause Analysis (RCA)
- Lessons learned sessions
- Periodic updates to this policy
Documentation & Recordkeeping
Required documentation includes risk assessments, contracts, KPIs, incident logs, due diligence packages, and training records. Minimum retention: 7 years.
Back to topRoles & Responsibilities (RACI)
View RACI Table
| Role | Responsible | Accountable | Consulted | Informed |
|---|---|---|---|---|
| Chief Risk Officer | Program oversight | ✔ | Executive Leadership Team | President |
| Risk Manager | Risk scoring, register updates | ✔ | Chief Risk Officer | Business Units |
| Procurement Lead | Onboarding, SOC 2 / HECVAT verification | ✔ | Risk Manager | Departments |
| Business Owners | SLA management & remediation | CRO, Procurement | Kean IT | |
| Kean IT Security | Technical review, cyber assessments | Risk Manager | CIO | |
| Internal Audit | Independent assurance | ✔ | CRO | Board / Audit Committee |
| Vendors | Provide SOC 2 / HECVAT, remediation | Procurement Lead | Kean IT |
Compliance Mapping
| Framework | Requirements |
|---|---|
| NIST Cybersecurity Framework (CSF) 2.0 | ID.RM1–3, ID.SC1–2, DE.CM1–8, RS.CO1, RS.CO4, RS.IM1, RS.MI3 |
| CIS Controls v8 | Controls 1, 4, 6, 8, 10, 15, 17, 18 |
| FERPA, HIPAA, GLBA, GDPR | Vendor privacy, security, and data handling obligations |
Enforcement
Violations may result in High or Critical risk classification, contract suspension or termination, mandatory remediation plans, escalation to leadership, or revocation of departmental procurement privileges.
Back to topExceptions
All exceptions must comply with KU SEC 05 – Exception Management Policy. Exceptions require documented risk analysis, compensating controls, approval from the Chief Risk Officer and Compliance Officer, entry into the Exception Register, and may not exceed 12 months in duration.
Back to topRelated Documents
- RC01 – Policy Standard
- KU SEC 10 – Policy Precedence
- Procurement Policy (KU SRM 02)
- Asset Management Policy (KU IT 01)
- Risk Management Policy
- Contract Language Templates (Appendix D)
Version History
| Version | Date | Author | Approvers | Summary |
|---|---|---|---|---|
| 1.0 | 02‑13‑2026 | Andrew Mayorga | CIO, CISO, CRO, UPC | Initial RC01‑aligned release |