Kean University SOP 01 – Supplier Onboarding & Due Diligence
Table of Contents
- About
- Scope
- Definitions
- Roles & Responsibilities
- Procedure
- Records & Retention
- Metrics & KPIs
- Related Policies
About
This Standard Operating Procedure (SOP) defines the required steps for onboarding new suppliers and performing due diligence in alignment with the Supplier Risk Management Policy and Procurement Policy.
Scope
This SOP applies to all suppliers who:
- Provide information technology systems, software, or cloud services
- Access, store, transmit, or process University data
- Provide consulting or professional services
- Have physical or logical access to University systems
Definitions
- Supplier: Any third party providing goods or services.
- Vendor Assurance: Documentation such as SOC 2 Type II, HECVAT, and VPAT.
- Risk Register: System of record for supplier risk.
- Risk Tier: Classification of supplier risk (Low, Medium, High, Critical).
Roles & Responsibilities
View roles
- Procurement Lead: Initiates onboarding and collects documentation.
- Risk Manager: Performs risk scoring and updates the Risk Register.
- IT Security: Conducts cybersecurity reviews.
- Business Owner: Confirms business need and data access.
- Chief Information Security Officer (CISO): Approves High and Critical risk suppliers.
Procedure
- Business Owner submits a Supplier Onboarding Request in Freshservice.
- Procurement Lead validates request completeness.
- Required assurance documents are collected from the supplier.
- IT Security performs cybersecurity and technical review.
- Risk Manager assigns a risk tier and records it in the Risk Register.
- High or Critical risk suppliers are escalated to the CISO for approval.
- Approved suppliers are activated and scheduled for annual review.
Records & Retention
All onboarding documentation, approvals, and risk assessments must be retained for a minimum of seven (7) years in approved systems of record.
Metrics & KPIs
- Percentage of suppliers onboarded with complete documentation
- Average onboarding completion time
- Number of High or Critical risk escalations
Related Policies
- KU SRM 01 – Supplier Risk Management Policy
- KU SRM 02 – Procurement Policy
- KU SEC 05 – Exception Management Policy
``