Kean University SOP 12 – Records Management & Retention
Table of Contents
- About
- Scope
- Definitions
- Roles & Responsibilities
- Procedure
- Retention & Disposition
- Records & Storage Locations
- Metrics & KPIs
- Related Policies
About
This Standard Operating Procedure (SOP) establishes standardized processes for creating, storing, managing, and retaining records associated with Procurement and Supplier Risk Management activities.
Proper records management ensures documentation is complete, accessible, audit‑ready, and retained in alignment with University governance requirements and external regulations.
Scope
This SOP applies to records generated during:
- Procurement intake, triage, and approvals
- Supplier onboarding and due diligence
- Vendor assurance documentation
- Risk assessments, escalation, and remediation
- Contract review, execution, and amendments
- Supplier monitoring, offboarding, and termination
- Emergency and grant‑funded procurement activities
This SOP applies to all departments, business units, principal investigators (PIs), and staff involved in procurement or supplier risk processes.
Definitions
- Record: Any document, file, data entry, or communication generated during procurement or supplier risk activities.
- Official Repository: University‑designated system used to store official records.
- Retention Period: Minimum timeframe records must be preserved.
- Controlled Document: A record requiring version control and restricted access.
- Audit‑Ready: Documentation that is complete, organized, and accessible for review.
Roles & Responsibilities
View roles
- Procurement Lead: Ensures procurement records are complete, stored correctly, and version‑controlled.
- Risk Manager: Maintains supplier risk records and the Risk Register.
- Information Technology (IT) Security: Stores technical reviews and security‑related vendor artifacts.
- Business Owner / PI: Provides and maintains operational documentation.
- Accessibility Reviewer: Maintains accessibility reviews and remediation records.
- Chief Information Security Officer (CISO): Oversees recordkeeping for High and Critical‑risk suppliers.
Procedure
1. Identify Required Records
Procurement determines required records based on procurement category and supplier risk, including requests, due diligence packets, risk assessments, contracts, reviews, and approvals.
2. Create and Capture Records
Records must be created during the workflow, dated, complete, and attributable to a role. Records must not include unnecessary personal identifiers.
3. Store Records in Official Repositories
- Freshservice: Requests, approvals, escalations, and workflow records
- Scrut.io: Vendor assurance documentation
- SharePoint (Read‑Only): Executed contracts and audit archives
- Risk Register: Risk assessments, scoring, and remediation tracking
- IT Security Repositories: Technical assessments and incident records
Retention & Disposition
All procurement and supplier risk records must be retained for a minimum of seven (7) years, unless sponsor or regulatory requirements mandate longer retention.
At the end of the retention period, records may be securely disposed of only if no audit, litigation, or legal hold is in effect. Disposition must follow University data destruction standards and be documented.
Records & Storage Locations
- Procurement Requests & Approvals – Freshservice
- Vendor Assurance Documents – Scrut.io / SharePoint (Read‑Only)
- Risk Assessments & Scoring – Risk Register
- Security & Accessibility Reviews – IT Security / Accessibility Repositories
- Contracts & Amendments – SharePoint (Read‑Only)
- Monitoring & Remediation Records – Freshservice / Risk Register
Metrics & KPIs
- Percentage of records stored in official repositories
- Number of missing or incomplete procurement files
- Percentage of suppliers with complete risk documentation
- Number of audit findings related to recordkeeping
Related Policies
- KU SRM 01 – Supplier Risk Management Policy
- KU SRM 02 – Procurement Policy
- KU SEC 05 – Exception Management Policy
- KU SEC 10 – Policy Precedence & Governance
- KU IT 01 – Asset Management Policy
- University Records Retention Schedule
``