Kean University SRM SOP 03 – Vendor Assurance Documentation


Kean University SOP 03 – Vendor Assurance Documentation

Table of Contents

About

This Standard Operating Procedure (SOP) defines how vendor assurance documentation is requested, validated, reviewed, escalated, and retained for suppliers providing information technology, data‑handling, or accessibility‑impacting services.

Vendor assurance documentation is used to evaluate cybersecurity, privacy, operational, and accessibility risk in support of procurement and supplier risk management decisions.

Back to top

Scope

This SOP applies to suppliers that:

  • Provide software, cloud services, or information technology systems
  • Access, store, transmit, or process University data
  • Integrate with University systems or identity services
  • Impact regulatory, cybersecurity, or accessibility obligations

This procedure applies during supplier onboarding, annual documentation refresh, and contract renewal activities.

Back to top

Definitions

  • Vendor Assurance Documentation: Evidence demonstrating a supplier’s security, compliance, and accessibility controls.
  • SOC 2 Type II: An independent audit report evaluating security controls over time (must be less than 12 months old).
  • HECVAT: Higher Education Community Vendor Assessment Toolkit.
  • VPAT / ACR: Voluntary Product Accessibility Template / Accessibility Conformance Report.
  • Documentation Deficiency: Missing, expired, incomplete, or insufficient assurance documentation.
  • Risk Tier: Supplier classification (Low, Medium, High, Critical).

Back to top

Roles & Responsibilities

View roles
  • Procurement Lead: Requests documentation, validates completeness, routes materials for review, and ensures proper storage.
  • Risk Manager: Evaluates documentation and records risk determinations in the Risk Register.
  • IT Security: Reviews cybersecurity posture using assurance artifacts.
  • Accessibility Reviewer: Reviews VPAT / ACR documentation.
  • Chief Information Security Officer (CISO): Approves High and Critical risk suppliers.

Back to top

Procedure

  1. Procurement requests SOC 2 Type II, HECVAT, and VPAT / ACR documentation.
  2. Documentation is reviewed for validity, scope, and expiration.
  3. IT Security and Accessibility reviewers evaluate submitted materials.
  4. Risk Manager assigns a risk tier and records results.


Back to top

Deficiencies & Escalation

  • Missing or insufficient documentation is reported to the supplier.
  • High or Critical risk deficiencies are escalated to the CISO.
  • The CISO may approve, approve with conditions, require remediation, or deny the supplier.

Back to top

Annual Refresh

Vendors must submit updated SOC 2, HECVAT, and VPAT / ACR documentation annually. Procurement ensures reminders are issued and records are updated.

Back to top

Records & Retention

Assurance documentation and review records must be retained in approved systems of record for a minimum of seven (7) years.

Back to top

Metrics & KPIs

  • Percentage of suppliers submitting complete documentation on first request
  • Number of documentation deficiencies per quarter
  • Annual documentation refresh compliance rate

Back to top

  • KU SRM 01 – Supplier Risk Management Policy
  • KU SRM 02 – Procurement Policy
  • KU SEC 05 – Exception Management Policy
  • KU SEC 10 – Policy Precedence & Governance
  • KU IT 01 – Asset Management Policy

Back to top

``

Was this answer helpful? Yes No

Sorry we couldn't be helpful. Help us improve this article with your feedback.