Kean University SRM SOP 05 – Supplier Risk Assessment & Scoring

Skip to main content


Kean University SOP 05 – Supplier Risk Assessment & Scoring

Table of Contents

About

This Standard Operating Procedure (SOP) defines the standardized method for evaluating, scoring, and classifying supplier risk. It ensures all suppliers are assessed consistently, objectively, and in an auditable manner prior to onboarding, renewal, or significant service changes.

Back to top

Scope

This SOP applies to suppliers that:

  • Provide information technology systems, software, infrastructure, or cloud services
  • Access, store, process, or transmit University data
  • Integrate with University systems or identity services
  • Provide professional or consulting services introducing operational or compliance risk

This procedure applies to both initial risk assessments and ongoing reassessments.

Back to top

Definitions

  • Risk Assessment: A structured evaluation of supplier risk based on likelihood, impact, and control maturity.
  • Risk Tier: Supplier classification (Low, Medium, High, Critical).
  • Risk Scoring Model: A weighted framework evaluating cybersecurity, operational, financial, compliance, accessibility, and lifecycle risks.
  • Documentation Deficiency: Missing or inadequate assurance documentation such as SOC 2 Type II, HECVAT, or VPAT / ACR.
  • Risk Register: The University system of record for supplier risk.

Back to top

Roles & Responsibilities

View roles
  • Procurement Lead: Initiates the risk assessment workflow and ensures required documentation is collected.
  • Risk Manager: Performs risk scoring, assigns risk tier, and updates the Risk Register.
  • Information Technology (IT) Security: Provides cybersecurity assessment input.
  • Business Owner: Provides operational context and confirms business requirements.
  • Accessibility Reviewer: Assesses accessibility compliance risks.
  • Chief Information Security Officer (CISO): Reviews and approves High and Critical risk suppliers.

Back to top

Procedure

1. Confirm Required Documentation

Procurement verifies that required vendor assurance documentation has been collected, including SOC 2 Type II, HECVAT, and VPAT / ACR.

2. Preliminary Review

The Risk Manager reviews documentation completeness, supplier scope, and data sensitivity. Any deficiencies are returned for remediation.

3. Detailed Risk Assessment

The Risk Manager applies the standardized scoring model across cybersecurity, operational, financial, compliance, accessibility, and lifecycle sustainment domains.

4. Risk Tier Determination

Weighted scores are summed and a risk tier (Low, Medium, High, or Critical) is assigned with documented justification.


Back to top

Escalation & Approval

  • Low / Medium Risk: Approved by Risk Manager
  • High / Critical Risk: Escalated to the CISO
  • The CISO may approve, approve with conditions, require remediation, or deny the supplier

Back to top

Records & Retention

Risk assessments, scoring documentation, approvals, and remediation plans must be retained in the Risk Register and approved repositories for a minimum of seven (7) years.

Back to top

Metrics & KPIs

  • Percentage of suppliers assessed within required service‑level targets
  • Number of High and Critical risk suppliers per quarter
  • Average risk assessment cycle time
  • Percentage of suppliers with documentation deficiencies

Back to top

  • KU SRM 01 – Supplier Risk Management Policy
  • KU SRM 02 – Procurement Policy
  • KU SEC 05 – Exception Management Policy
  • KU SEC 10 – Policy Precedence & Governance
  • KU IT 01 – Asset Management Policy

Back to top

Was this answer helpful? Yes No

Sorry we couldn't be helpful. Help us improve this article with your feedback.