Description
Operating within the Second Line of Defence, the Supplier Risk Lead provides independent oversight, challenge, and assurance over FCE Bank's third-party and supplier risk profile.
Responsibilities:
- Independently review and challenge supplier risk assessments and classifications completed by the First Line
- Conduct quality assurance reviews on supplier due diligence and risk mitigation plans
- Lead the design and enhancement of the global Third-Party Risk Management (TPRM) framework and policy
- Maintain supplier risk classification tools and support optimisation of the GRC/TPRM system
- Produce consolidated risk reporting, dashboards, and MI for senior leadership and Risk Committees
- Monitor Key Risk Indicators (KRIs), policy exceptions, and risk acceptances against risk appetite
- Oversee monitoring of third and fourth-party incidents, ensuring robust root-cause analysis and remediation
- Provide advisory support and guidance to business owners, contract managers, and Vendor Management
- Develop and deliver training to strengthen risk culture and assessment quality
- Facilitate risk-profiling workshops for high-risk or complex supplier projects
- Ensure TPRM compliance with regulatory standards (e.g., DORA, PRA SS2/21, BCBS/BIS)
- Support internal audits and regulatory inspections, evidencing 2LoD oversight
- Maintain the ICT Third-Party Register of Information under DORA
- Assess third and fourth-party concentration risk to safeguard operational resilience
Qualifications:
- Professional Qualifications: Relevant professional risk or security certifications (e.g., CRISC, CISA, or IRM credentials).
This listing is enriched and indexed by YubHub. To apply, use the employer's original posting:
https://efds.fa.em5.oraclecloud.com/hcmUI/CandidateExperience/en/sites/CX_1/job/63154