Third Party Risk Manager - Technology Vendor Oversight
Role details
Job location
Tech stack
Job description
As the GT third Party Risk Manager you will be responsible for the oversight of the Global Technology supply chain ensuring identification, analysis and management of risks associated with outsourcing and third-party suppliers, vendors, and service providers. This role ensures that all Global Technology suppliers are subjected to appropriate pre-onboarding and ongoing due diligence, are fully compliant with regulatory obligations, policies, procedures and that Global Technology makes effective use of its' incumbent supply chain. You will also support decision making in the business through strong management information, governance, policies and procedures.
What you'll do
- Managing the existing Vendor due diligence processes, including financial crime, modern slavery, credit, information security, corporate responsibility etc.
- Collaborate with key stakeholders to align risk management practices with business goals, and to implement effective risk-based referral and acceptance thresholds in respect of key risk areas such as finance, financial crime, legal, business continuity and information security,
- Acting as the SME for regulatory requirements associated with Technology third parties including DORA, FCA and PRA regulations,
- Acting as the Global Technology control point to prevent the onboarding of supplier risk through data capture, review and assessment.
- Implementing and maintaining systems, controls, oversight and reporting relating to outsourcing, third party services and procurement;
- Provide support, advice for Supplier and Service Owners globally, maintaining oversight of supplier reviews, enabling supplier risk reporting capabilities ensuring policy compliance.
- Embedding supplier oversight reporting capabilities and continuously improving performance and risk assessment governance and metrics.
- Continually monitor the global regulatory landscape to ensure our procedures remain compliant and fit for purpose.
- Create and agree initial vendor risk register recording the services and Vendor for transition risk
- Support the completion of regular and meaningful criticality assessments with an awareness of changes to risk, nature or scale of services and regulatory, industry and market influences affecting the risk profile and suitability of a service or provider.
- Maintain a suite of supplier key risk indicators with appropriate metrics and risk acceptance thresholds to identify and track material third party risks and monitor trends
- Maintain centralised and accurate record keeping and data management and ensure alignment of information between business areas internally across Global Technology and with Group Legal, Compliance, Finance, Supplier Oversight and Procurement.
- Continuously monitor the vendor relationship to identify changes in risk status through
- Performance reviews (annual, strategic, tactical, operational)
- Benchmarking
- Stakeholder satisfaction
- Responsible for ensuring that each Vendor has a risk management profile, including:
- Identification, documentation, and assessment of risks including concentration risk and fourth party risk
- Business Continuity/disaster recovery oversight, including ensuring plans are ready and available to be tested at any point
- Governance Oversight - Ensures that formal risk governance is in place at a relevant level for each vendor
Requirements
You will have a solid understanding of the evolving due diligence expectations of managing risk in the supply chain, particularly in a globally regulated environment, considering the different types of assessment and risk that organisations face., * Experience of setting policy/best practice regarding managing third party relationships in a financial services/regulated environment including setting the strategy, developing a roadmap and executing.
- Experience working with 2nd line risk functions to ensure supplier due diligence is performed and monitored whilst supporting supplier owners to fulfil their obligations and remain compliant with policy.
- Development of reporting capabilities to enable effective supplier reporting across the many areas of supply chain risk.
- Excellent levels of communication, able to influence and persuade others, whilst building strong working relationships.
- Ability to consider wider business strategy.
- Contract review and data capture to enable reporting and oversight to Board level.
- Strong analytics experience to understand and interpret information, bringing insight.
- Excellent organisation, and problem-solving skills
- Ability to develop positive working relationships and strong rapport with support staff as well as senior leadership (both business and technical users)
- Broad spectrum cross-discipline knowledge, experience and understanding including financial and investment operations and regulatory environment
The knowledge, experience and qualifications that will help
- Demonstrable experience of delivering third party risk management within a supplier risk management framework
- Experience of utilising and managing procurement systems and tools.
- Ability and experience coordinating due diligence activities across technical specialists (e.g Operational Risk, Information Security, Credit Risk, Financial Crime, Legal) globally.
- Track record of global/regional delivery across complex matrix environments.
- Ability to influence decision making and make confident assessments and recommendations
What you'll be like
- You'll enjoy working collaboratively across a Global organisation
- Ability to influence decision making and make confident assessments and recommendations
- Flexible and able to adjust priorities quickly
- High-level of personal initiative; able to work independently as well as collaborate in teams
- Really well organised with a strong attention to detail.