Kean University SOP 13 – Exception Management
Table of Contents
- About
- Scope
- Definitions
- Roles & Responsibilities
- Procedure
- Approval & Duration
- Records & Retention
- Metrics & KPIs
- Related Policies
About
This Standard Operating Procedure (SOP) defines the formal process for requesting, reviewing, approving, implementing, and tracking exceptions to standard procurement and supplier risk management requirements.
Exception Management ensures deviations are risk‑assessed, time‑bound, formally approved, and monitored in alignment with University governance and risk tolerance.
Scope
This SOP applies when mandatory requirements cannot be met, including:
- Vendor assurance documentation (SOC 2, HECVAT, VPAT)
- Risk, technical, legal, or accessibility reviews
- Contractual security or accessibility clauses
- Procurement routing, approvals, or sustainment requirements
Exceptions may occur during onboarding, procurement, renewal, remediation, or offboarding.
Definitions
- Exception: A documented, time‑limited approval to deviate from a required control or process.
- Exception Request: A formal submission explaining the unmet requirement and justification.
- Compensating Control: A temporary measure that reduces risk during an exception period.
- Exception Register: The system of record for all active and closed exceptions.
- Time‑Bound Exception: An exception approved for a maximum of twelve (12) months.
Roles & Responsibilities
View roles
- Procurement Lead: Initiates and coordinates the exception workflow.
- Risk Manager: Performs risk analysis and maintains the Exception Register.
- Information Technology (IT) Security: Reviews security‑related exceptions.
- Accessibility Reviewer: Reviews accessibility‑related exceptions.
- Business Owner: Provides justification and implements compensating controls.
- Chief Information Security Officer (CISO): Approves all exceptions and renewals.
Procedure
1. Identify Need for Exception
An exception is required when a mandatory control or requirement cannot be met. Procurement instructs the Business Owner to submit an Exception Request.
2. Submit Exception Request
The Business Owner submits an Exception Request in Freshservice, including justification, requested duration, and proposed compensating controls.
3. Risk Assessment
The Risk Manager evaluates security, compliance, operational, and accessibility impacts and assigns a risk level.
4. Consolidated Review
Technical and accessibility reviews are completed as applicable. Procurement compiles the exception package for approval.
Approval & Duration
- All exceptions require CISO approval
- Exceptions must not exceed 12 months
- Compensating controls are mandatory
- Renewals require full reassessment and approval
Records & Retention
Exception requests, approvals, risk analyses, and closure documentation must be stored in Freshservice and the Exception Register.
Records are retained for a minimum of seven (7) years.
Metrics & KPIs
- Number of exceptions requested per quarter
- Percentage approved versus denied
- Number of expired or overdue exceptions
- Average exception duration
Related Policies
- KU SRM 01 – Supplier Risk Management Policy
- KU SRM 02 – Procurement Policy
- KU SEC 05 – Exception Management Policy
- KU SEC 10 – Policy Precedence & Governance
- KU IT 01 – Asset Management Policy
``