Kean University SOP 03 – Vendor Assurance Documentation
Table of Contents
- About
- Scope
- Definitions
- Roles & Responsibilities
- Procedure
- Deficiencies & Escalation
- Annual Refresh
- Records & Retention
- Metrics & KPIs
- Related Policies
About
This Standard Operating Procedure (SOP) defines how vendor assurance documentation is requested, validated, reviewed, escalated, and retained for suppliers providing information technology, data‑handling, or accessibility‑impacting services.
Vendor assurance documentation is used to evaluate cybersecurity, privacy, operational, and accessibility risk in support of procurement and supplier risk management decisions.
Scope
This SOP applies to suppliers that:
- Provide software, cloud services, or information technology systems
- Access, store, transmit, or process University data
- Integrate with University systems or identity services
- Impact regulatory, cybersecurity, or accessibility obligations
This procedure applies during supplier onboarding, annual documentation refresh, and contract renewal activities.
Definitions
- Vendor Assurance Documentation: Evidence demonstrating a supplier’s security, compliance, and accessibility controls.
- SOC 2 Type II: An independent audit report evaluating security controls over time (must be less than 12 months old).
- HECVAT: Higher Education Community Vendor Assessment Toolkit.
- VPAT / ACR: Voluntary Product Accessibility Template / Accessibility Conformance Report.
- Documentation Deficiency: Missing, expired, incomplete, or insufficient assurance documentation.
- Risk Tier: Supplier classification (Low, Medium, High, Critical).
Roles & Responsibilities
View roles
- Procurement Lead: Requests documentation, validates completeness, routes materials for review, and ensures proper storage.
- Risk Manager: Evaluates documentation and records risk determinations in the Risk Register.
- IT Security: Reviews cybersecurity posture using assurance artifacts.
- Accessibility Reviewer: Reviews VPAT / ACR documentation.
- Chief Information Security Officer (CISO): Approves High and Critical risk suppliers.
Procedure
- Procurement requests SOC 2 Type II, HECVAT, and VPAT / ACR documentation.
- Documentation is reviewed for validity, scope, and expiration.
- IT Security and Accessibility reviewers evaluate submitted materials.
- Risk Manager assigns a risk tier and records results.
Deficiencies & Escalation
- Missing or insufficient documentation is reported to the supplier.
- High or Critical risk deficiencies are escalated to the CISO.
- The CISO may approve, approve with conditions, require remediation, or deny the supplier.
Annual Refresh
Vendors must submit updated SOC 2, HECVAT, and VPAT / ACR documentation annually. Procurement ensures reminders are issued and records are updated.
Records & Retention
Assurance documentation and review records must be retained in approved systems of record for a minimum of seven (7) years.
Metrics & KPIs
- Percentage of suppliers submitting complete documentation on first request
- Number of documentation deficiencies per quarter
- Annual documentation refresh compliance rate
Related Policies
- KU SRM 01 – Supplier Risk Management Policy
- KU SRM 02 – Procurement Policy
- KU SEC 05 – Exception Management Policy
- KU SEC 10 – Policy Precedence & Governance
- KU IT 01 – Asset Management Policy
``