KU SRM 02 - Procurement Policy


Kean University SRM‑02 Procurement Policy (User‑Facing)

Table of Contents

1. About This Policy

This policy explains how Kean University purchases goods and services—including software, information technology systems, equipment, consulting services, cloud services, and any acquisition funded by University or grant resources.

The purpose of this policy is to ensure that purchasing is:

  • Clear and consistent
  • Safe and secure
  • Aligned with University strategy and risk standards
  • Accessible and compliant with regulations

It also ensures the University evaluates vendor security, privacy practices, support lifecycles, and full long‑term costs before approving any purchase.

Back to top

2. Who Must Follow This Policy

This policy applies to:

  • All Kean University departments and units
  • Faculty, staff, and administrators
  • Kean Information Technology (IT)
  • The Procurement Office
  • Third‑party vendors
  • Anyone making purchases using grant or sponsor funds

It covers all acquisitions, including systems, cloud‑based services, software, consulting, infrastructure, equipment, and any purchases funded by University or grant budgets.

Back to top

3. Requirements Before Any Purchase

A. Pre‑Procurement Risk Assessment

Departments must evaluate the following before submitting a purchase request:

  • Vendor support lifecycle and duration
  • Availability of a secure and supported upgrade roadmap
  • Whether the system has known vulnerabilities
  • Data security, privacy, and accessibility risks
  • Any risks needing inclusion in the University’s Risk Register

B. Plan for Full Lifecycle Management

  • Budgeting for maintenance and support
  • Including service and support contracts
  • Planning upgrades (typically staying within two major versions)
  • End‑of‑life security handling and disposal planning

C. Vendor Assurance Documentation

Vendors providing IT‑related products or services must supply:

  • SOC 2 Type II report (within the last 12 months)
  • HECVAT (Higher Education Community Vendor Assessment Tool)
  • VPAT (Voluntary Product Accessibility Template)
  • Annual updates for all submitted documents

Missing SOC 2 or HECVAT automatically classifies a purchase as High Risk.

Back to top

4. Approval Levels

Purchases follow a tiered approval path based on risk level:

  • Low Risk: Department Head
  • Medium Risk: Risk Manager or Procurement Lead
  • High Risk: Risk Management Committee
  • Critical Risk: Executive Leadership Team (ELT)

Back to top

5. Special Procurement Types

A. Grant‑Funded Purchases

Grant purchases must include:

  • A full sustainment plan
  • Compliance with sponsor rules
  • Evidence that the purchase is viable beyond the grant period

B. Emergency Purchases

Emergency purchases require:

  • Written justification describing the emergency
  • Post‑purchase risk assessment
  • Approval from both the Chief Risk Officer (CRO) and Procurement

Back to top

6. Strategic Requirements

  • Purchases must support the University’s long‑term strategy
  • Procurements should align with multi‑year planning
  • Enterprise‑wide impacts must be evaluated
  • Innovation is encouraged—but must be balanced with responsible risk management

The policy also encourages the use of diverse suppliers, including minority‑owned, women‑owned, veteran‑owned, and disability‑owned businesses.

Back to top

7. Documentation Requirements

Departments must keep the following records for at least seven years:

  • Purchase request details
  • Risk assessment summary
  • Sustainment plan
  • Vendor security and accessibility documents
  • The full approval path (including escalations)

Back to top

8. Roles and Responsibilities

  • Department Heads: Initiate requests and provide sustainment plans.
  • Procurement Office: Manages vendors, contracts, bidding, and documentation.
  • Risk Manager: Performs risk assessments and escalates concerns.
  • Chief Risk Officer (CRO): Provides governance and oversight.
  • Kean IT: Conducts technical and security reviews.
  • Internal Audit: Verifies compliance and effectiveness of controls.

Back to top

9. Compliance Requirements

This policy aligns with the following standards and regulations:

  • NIST Cybersecurity Framework (CSF) 2.0
  • CIS Controls v8
  • FERPA, HIPAA, GLBA, GDPR
  • New Jersey State procurement regulations

Back to top

10. Consequences for Not Following the Policy

Non‑compliance may result in:

  • Purchase request denial
  • Escalation to the CRO or Executive Leadership Team
  • Contract suspension or cancellation
  • Budget restrictions
  • Disciplinary action for repeated violations

Back to top

11. Exceptions

Policy exceptions require:

  • A documented risk analysis
  • Compensating controls
  • Approval from the CRO and Compliance
  • Entry in the University’s Exception Register
  • A maximum duration of 12 months

Back to top

12. Policy Review Cycle

This policy is reviewed:

  • Annually
  • After major incidents
  • After regulatory changes
  • After changes to cybersecurity, enterprise risk management, or accessibility frameworks

Back to top

Was this answer helpful? Yes No

Sorry we couldn't be helpful. Help us improve this article with your feedback.