Kean University SRM SOP 11 – Supplier Risk Escalation & Remediation

Skip to main content


Kean University SOP 11 – Supplier Risk Escalation & Remediation 

Table of Contents

About

This Standard Operating Procedure (SOP) defines the formal process for escalating supplier risks and implementing remediation actions when suppliers fail to meet required security, compliance, operational, accessibility, or contractual obligations.

The escalation and remediation process ensures timely resolution of high‑impact supplier risks and supports continuous oversight throughout the supplier lifecycle.

Back to top

Scope

This SOP applies to:

  • All suppliers classified as Medium, High, or Critical risk
  • Suppliers with documented deficiencies (e.g., missing SOC 2, HECVAT, VPAT)
  • Suppliers with SLA violations, security incidents, or accessibility failures
  • All lifecycle phases: onboarding, active engagement, renewal, and offboarding

This SOP complements incident response procedures but does not replace them.

Back to top

Definitions

  • Risk Escalation: Formal elevation of supplier risk requiring governance review.
  • Remediation Plan (RP): Documented corrective actions required of a supplier.
  • Critical Risk Event: A major issue posing immediate security, compliance, or operational threat.
  • Risk Thresholds: Criteria determining escalation and approval requirements.

Back to top

Roles & Responsibilities

View roles
  • Procurement Lead: Identifies escalation triggers and coordinates supplier communication.
  • Risk Manager: Evaluates severity, develops remediation plans, and tracks closure.
  • IT Security: Reviews and validates security‑related remediation actions.
  • Business Owner: Provides operational impact context and ensures supplier cooperation.
  • Accessibility Reviewer: Defines and validates accessibility remediation requirements.
  • Chief Information Security Officer (CISO): Approves escalations and closure for High and Critical risks.

Back to top

Procedure

1. Identify Escalation Triggers

Escalation is initiated when predefined triggers occur, such as missing assurance documents, repeated SLA breaches, security incidents, accessibility violations, or non‑responsiveness.

2. Evaluate Risk Severity

The Risk Manager evaluates severity and classifies the issue as Medium, High, or Critical risk, documenting justification in the Risk Register.

3. Initiate Escalation

Procurement opens a Risk Escalation ticket in Freshservice and notifies required stakeholders. High and Critical risks are immediately escalated to the CISO.

4. Develop Remediation Plan

The Risk Manager creates a Remediation Plan outlining corrective actions, responsible parties, documentation requirements, and completion timelines.


Back to top

Remediation & Closure

Supplier remediation progress is tracked against defined checkpoints. IT Security and Accessibility reviewers validate completion of their respective controls.

Final verification is performed by the Risk Manager. Closure of High or Critical risks requires CISO approval. Failure to remediate may result in contract modification, suspension, or offboarding.

Back to top

Records & Retention

Escalation tickets, remediation plans, approvals, and verification evidence must be stored in approved systems of record.

Records are retained for a minimum of seven (7) years.

Back to top

Metrics & KPIs

  • Number of supplier risk escalations per quarter
  • Percentage requiring CISO involvement
  • Percentage of remediation plans completed on time
  • Reduction in unresolved supplier risks over time

Back to top

  • KU SRM 01 – Supplier Risk Management Policy
  • KU SRM 02 – Procurement Policy
  • KU SEC 05 – Exception Management Policy
  • KU SEC 10 – Policy Precedence & Governance
  • KU IT 01 – Asset Management Policy

Back to top

Was this answer helpful? Yes No

Sorry we couldn't be helpful. Help us improve this article with your feedback.