Kean University SRM SOP 08 – Supplier Offboarding & Contract Termination

Skip to main content


Kean University SOP 08 – Supplier Offboarding & Contract Termination

Table of Contents

About

This Standard Operating Procedure (SOP) defines the required process for securely offboarding suppliers whose contracts have expired, been terminated, or will no longer provide services to the University.

Proper offboarding ensures residual cybersecurity, privacy, accessibility, operational, and compliance risks are mitigated and auditable records are maintained.

Back to top

Scope

This SOP applies to suppliers that:

  • Had access to University systems, data, networks, or facilities
  • Provided IT systems, software, cloud services, or integrations
  • Maintained credentials, application programming interfaces (APIs), or single sign‑on (SSO)
  • Were subject to cybersecurity, privacy, accessibility, or operational controls

Offboarding applies to contract expiration, termination, non‑renewal, or transition to a new supplier.

Back to top

Definitions

  • Supplier Offboarding: Structured process to terminate access and close out obligations.
  • Data Return & Sanitization: Return of University data and verified destruction of copies.
  • Access Revocation: Removal of accounts, credentials, integrations, and physical access.
  • Offboarding Checklist: Document confirming completion of all termination steps.
  • Exit Review: Final assessment of performance, risks, and lessons learned.

Back to top

Roles & Responsibilities

View roles
  • Procurement Lead: Coordinates offboarding workflow and documentation.
  • Risk Manager: Reviews residual risks and closes risk records.
  • Information Technology (IT) Security: Revokes access and validates data destruction.
  • Business Owner: Confirms service transition and dependency removal.
  • Accessibility Reviewer: Verifies closure of accessibility obligations.
  • Chief Information Security Officer (CISO): Approves offboarding for High or Critical‑risk suppliers.

Back to top

Procedure

1. Initiate Offboarding

Procurement identifies contract termination or expiration and opens a Supplier Offboarding ticket in Freshservice. An Offboarding Checklist is distributed to all responsible teams.

2. Contract Closeout Review

Procurement reviews contract exit obligations, including data return, destruction, transition support, and notice requirements, and notifies the supplier.

3. Revoke Access & Disable Integrations

IT Security revokes all supplier access, including user accounts, SSO, APIs, virtual private network (VPN) access, and system integrations. Completion is documented in Freshservice.

4. Data Return or Destruction

The supplier must provide written confirmation of data return and secure destruction. IT Security validates evidence. Failure to provide documentation is escalated.

5. Exit Review & Risk Closure

Procurement, Risk Management, IT Security, and the Business Owner conduct an exit review to document unresolved issues, incidents, and lessons learned. The Risk Register is updated.


Back to top

Approval & Escalation

  • Suppliers previously classified as Low or Medium risk require Procurement and Risk approval.
  • Suppliers classified as High or Critical risk must be escalated to the CISO for approval.
  • Unresolved data, access, or compliance issues require escalation before closure.

Back to top

Records & Retention

Offboarding tickets, checklists, data destruction confirmations, exit reviews, and final contracts must be stored in approved systems of record.

Records are retained for a minimum of seven (7) years.

Back to top

Metrics & KPIs

  • Percentage of suppliers offboarded with completed checklists
  • Number of delayed or incomplete access revocations
  • Percentage of suppliers providing timely data destruction confirmation
  • Average time from offboarding initiation to closure

Back to top

  • KU SRM 01 – Supplier Risk Management Policy
  • KU SRM 02 – Procurement Policy
  • KU SEC 05 – Exception Management Policy
  • KU SEC 10 – Policy Precedence & Governance
  • KU IT 01 – Asset Management Policy

Back to top

``

Was this answer helpful? Yes No

Sorry we couldn't be helpful. Help us improve this article with your feedback.