Kean University SRM SOP 13 – Exception Management

Skip to main content


Kean University SOP 13 – Exception Management

Table of Contents

About

This Standard Operating Procedure (SOP) defines the formal process for requesting, reviewing, approving, implementing, and tracking exceptions to standard procurement and supplier risk management requirements.

Exception Management ensures deviations are risk‑assessed, time‑bound, formally approved, and monitored in alignment with University governance and risk tolerance.

Back to top

Scope

This SOP applies when mandatory requirements cannot be met, including:

  • Vendor assurance documentation (SOC 2, HECVAT, VPAT)
  • Risk, technical, legal, or accessibility reviews
  • Contractual security or accessibility clauses
  • Procurement routing, approvals, or sustainment requirements

Exceptions may occur during onboarding, procurement, renewal, remediation, or offboarding.

Back to top

Definitions

  • Exception: A documented, time‑limited approval to deviate from a required control or process.
  • Exception Request: A formal submission explaining the unmet requirement and justification.
  • Compensating Control: A temporary measure that reduces risk during an exception period.
  • Exception Register: The system of record for all active and closed exceptions.
  • Time‑Bound Exception: An exception approved for a maximum of twelve (12) months.

Back to top

Roles & Responsibilities

View roles
  • Procurement Lead: Initiates and coordinates the exception workflow.
  • Risk Manager: Performs risk analysis and maintains the Exception Register.
  • Information Technology (IT) Security: Reviews security‑related exceptions.
  • Accessibility Reviewer: Reviews accessibility‑related exceptions.
  • Business Owner: Provides justification and implements compensating controls.
  • Chief Information Security Officer (CISO): Approves all exceptions and renewals.

Back to top

Procedure

1. Identify Need for Exception

An exception is required when a mandatory control or requirement cannot be met. Procurement instructs the Business Owner to submit an Exception Request.

2. Submit Exception Request

The Business Owner submits an Exception Request in Freshservice, including justification, requested duration, and proposed compensating controls.

3. Risk Assessment

The Risk Manager evaluates security, compliance, operational, and accessibility impacts and assigns a risk level.

4. Consolidated Review

Technical and accessibility reviews are completed as applicable. Procurement compiles the exception package for approval.


Back to top

Approval & Duration

  • All exceptions require CISO approval
  • Exceptions must not exceed 12 months
  • Compensating controls are mandatory
  • Renewals require full reassessment and approval

Back to top

Records & Retention

Exception requests, approvals, risk analyses, and closure documentation must be stored in Freshservice and the Exception Register.

Records are retained for a minimum of seven (7) years.

Back to top

Metrics & KPIs

  • Number of exceptions requested per quarter
  • Percentage approved versus denied
  • Number of expired or overdue exceptions
  • Average exception duration

Back to top

  • KU SRM 01 – Supplier Risk Management Policy
  • KU SRM 02 – Procurement Policy
  • KU SEC 05 – Exception Management Policy
  • KU SEC 10 – Policy Precedence & Governance
  • KU IT 01 – Asset Management Policy

Back to top

``

Was this answer helpful? Yes No

Sorry we couldn't be helpful. Help us improve this article with your feedback.