Kean University SOP 07 – Supplier Performance Monitoring & KPI Reporting
Table of Contents
- About
- Scope
- Definitions
- Roles & Responsibilities
- Procedure
- Corrective Action Plans
- Records & Retention
- Metrics & KPIs
- Related Policies
About
This Standard Operating Procedure (SOP) defines the process for monitoring supplier performance, measuring service delivery and control effectiveness, and reporting key performance indicators (KPIs) throughout the supplier lifecycle.
Ongoing monitoring ensures supplier risks remain visible and managed in alignment with the Supplier Risk Management and Procurement Policies.
Scope
This SOP applies to suppliers that:
- Deliver information technology systems, software, cloud services, or infrastructure
- Have access to University data or systems
- Are classified as Medium, High, or Critical risk
- Provide essential operational or student‑facing services
- Are subject to service level agreements (SLAs) or performance obligations
Monitoring activities occur monthly, quarterly, and annually.
Definitions
- Supplier Monitoring: Ongoing review of supplier performance, security, and compliance activities.
- Key Performance Indicator (KPI): A measurable metric used to evaluate supplier performance and risk posture.
- Service Level Agreement (SLA): Contracted service commitments such as uptime, response, and resolution targets.
- Continuous Monitoring: Monthly review of performance and security events.
- Quarterly Review: Formal review of performance trends and risk indicators.
Roles & Responsibilities
View roles
- Procurement Lead: Coordinates monitoring activities and KPI reporting.
- Risk Manager: Reviews trends and updates supplier risk tiers.
- Information Technology (IT) Security: Monitors supplier‑related security events.
- Business Owner: Provides feedback on service quality and SLA performance.
- Accessibility Reviewer: Verifies ongoing accessibility compliance.
- Chief Information Security Officer (CISO): Reviews escalations and approves corrective actions for High and Critical‑risk suppliers.
Procedure
1. Establish Monitoring Requirements
Upon onboarding, Procurement identifies required KPIs, including SLA performance, incident response, security control effectiveness, and accessibility performance.
2. Monthly Monitoring
Procurement and IT Security review monthly performance data, security incidents, vulnerability disclosures, and reported service impacts. Deviations are documented as Monthly Performance Findings.
3. Quarterly Performance Review
Quarterly summaries consolidate trends, Business Owner feedback, security findings, and accessibility remediation progress. Summaries are reviewed by the Risk Manager.
4. Risk Re‑Scoring
The Risk Manager evaluates whether performance issues require risk tier changes, increased monitoring, or escalation to the CISO.
5. Annual Performance Report
An annual report summarizing KPIs, SLA compliance, security events, accessibility performance, and risk tier changes is distributed to stakeholders and informs renewal decisions.
Corrective Action Plans
A Corrective Action Plan (CAP) is initiated when KPIs fall below thresholds, SLA violations recur, or significant incidents occur.
CAPs must define deficiencies, remediation steps, deadlines, and monitoring checkpoints. CISO approval is required for High and Critical‑risk suppliers.
Records & Retention
Monitoring records, quarterly summaries, CAPs, and annual reports must be stored in approved systems of record and retained for a minimum of seven (7) years.
Metrics & KPIs
- Percentage of suppliers meeting SLA targets
- Number of recurring service disruptions
- Number of supplier‑attributed security incidents
- Percentage of Corrective Action Plans completed on time
- Quarterly and annual performance trend changes
Related Policies
- KU SRM 01 – Supplier Risk Management Policy
- KU SRM 02 – Procurement Policy
- KU SEC 05 – Exception Management Policy
- KU SEC 10 – Policy Precedence & Governance
- KU IT 01 – Asset Management Policy