Our Client works with an extensive network of third party organizations to perform a vast range of activities across the enterprise. Known internal risks that may impact our client such as privacy, information security, compliance, pricing, IT, etc. are amplified or compounded with the use of third parties. Today, third party oversight is decentralized. There are many functions working with third parties in some capacity including, but not limited to: Procurement, Third Party Management Organizations (TPMOs), Risk Domain Partners including Audit/Assessment Teams.
The TPRM organization is implementing a holistic program to support consistent, efficient, and effective decision making and determining potential inherent risk. The central team’s scope encompasses priority business and risk areas across all stages of the third party collaboration lifecycle.
Successful execution of this strategy will reduce third party risk, strengthen capabilities, drive consistency and efficiency, and reduce cost.
The scope of the TPRM Hub Team will include the following:
Create and maintain policies, procedures, and training to drive consistent TPRM for third party use. Liaise with Risk Domain Partners to create and maintain: Risk Definitions, Tolerances, and Required Training for TPMOs, Engagement Owners, and Third Parties. Construct and own the overall TPRM Program. Own the enterprise TPRM technology solution. Provide oversight of the TPRM initial and on-going monitoring due diligence processes. Report progress and results to Senior Leadership including, but not limited to, the CPO, the SVP of Ethics & Compliance, and the Compliance & Enterprise Risk Management Committee (CERMC).
The Risk Assessor will work in partnership internally, cross functionally and externally with third parties, and to assess and mitigate third party risk. Current risk domains in scope are Anti Corruption, Privacy, Information Security and Information Systems Quality, which will expand as we grow the programme.
· Determine, conduct and incorporate applicable risk domain screenings into due diligence activities and ongoing oversight plan
· Conduct assessments in a coordinated fashion with other risk domains. Assessment work includes but is not limited to scoping the assessment, testing controls, conducting interviews, reviewing evidence, determining final disposition of findings, written and verbal communication of findings, rating criticality of findings and evaluating action plans provided by the third party
· Set risk domain ongoing monitoring schedule and activities per inherent risk domain level
· Perform Ongoing Monitoring activities per the inherent risk domain level as a part of the TPRM Program
· Define and own risk domain assessment methodology for control assessments activities
· Provide risk domain requirements for termination and off-boarding activities, supporting these activities as required
· Maintain risk domain questions for Inherent Risk Questionnaire (IRQ) for the TPRM tool
· Work with risk domain partners to provide risk domain specific scoring thresholds for inherent risk domain levels per common TPRM risk tiering scale
· Provide feedback on centralized intake form
· Classify and consolidate report of findings using centralized TPRM tool whilst notifying appropriate stakeholders / partners
· Opine on / recommend risk domain specific controls to mitigate identified findings and determine residual risk domain level for respective risk domains
· Provide risk domain subject matter expertise and standard setting on findings tracking and mitigation
· Create and own standards for qualitative residual risk scoring that adhere to the overall scoring methodology set by the TPRM Program
· Issue approvals according to TPRM Approvals Matrix
· Provide guidance to business teams on Third Party Risk Management
· Support internal education and best practices sharing with peers and colleagues, as well as third party education & awareness
· In partnership with the Legal team, maintain inventory of risk domain specific contract principles, provide feedback on contract terms in contract negotiations and approve edits or adjustments to risk domain contractual principles
· Drive and deliver on risk domain IRQ and process metrics to measure control effectiveness and allow decision making
· Continually monitor and update assessments of the control environment, keeping abreast of significant control issues, trends and developments
· Integrate emerging risk control requirements into the existing risk assessment process
· Internal subject-matter expert of our TPRM risk procedures and standards, owning & updating as required
· Maintain list of third parties by risk domain in centralized TPRM tool
· Consult or provide risk domain input into our framework for third party governance
· Support the TPRM Team in the implementation and maintenance of an effective enterprise risk management framework
· Participate at forums including but not limited to TPRM Steer Committee (Risk Domain Partner Leadership), Assessment Coordination and TPRM Operations Committee
· Support TPRM Projects as required
· Partner with risk domain business functional areas to ensure TPRM activities are maintained and reflect current risks and expectations.
· Bachelor’s Degree or CIPP/CIPT/CTPRP/CRISC/CISA/CISM qualification
· Experience performing third party risk assessments in areas including but not limited to Anti-Corruption, Privacy, Information Systems and Information Systems Quality.
· Minimum of three or more years of audit, operational risk or other risk management experience or other proven related business experience
· Good understanding of risk management and internal control leading practices within specialized area of focus
· Demonstrated ability to work effectively in a complex, highly regulated environment
· Ability to plan, organize, prioritize and drive workload autonomously
· Effective influence management skills
· Evidence of strong analytical and data management skills
· Collaborate and builds partnerships across functions and regions, works well with others
· Ability to work in a matrix organization to influence outcomes
Our Client does not discriminate on the basis of age, race, color, religion, gender, sexual orientation, gender identity, gender expression, national origin, protected veteran status, disability or any other legally protected status.