Third Party Risk Analyst

Third Party Risk Analyst

Full-Time No working from home possible
D

Third Party Risk Management Analyst


Location : Flexible on location in the UK with visits to our office in Wimbledon.


Contract: Permanent


Salary: Competitive


We have an exciting opportunity for our Third Party Risk Management Analyst to join our Third Party Risk Party team at Domestic & General. This role will operate core first-line third-party risk management controls across the third-party lifecycle. It will work with Procurement, Risk, Compliance, Information Security, Legal and business owners and challenges incomplete, inconsistent or unsupported assessment submission. The role performs and quality-assures third-party scope, service assessment, categorisation, risk assessment, due diligence, onboarding, reassessment, ongoing monitoring and offboarding activity in accordance with approved policies, methodologies and procedures.


It will also maintain accurate and auditable third-party risk records, assessment evidence, risk decisions, remediation actions and review dates within approved systems and inventories. It prepares governance and management information, monitors trigger events and overdue activity, and escalates material risks, control weaknesses, incidents, exceptions and breaches of TPRM requirements.


The role covers all in-scope third-party arrangements, including suppliers, outsourced services, ICT providers, client and distribution relationships, repair networks and intragroup service arrangements. The analyst does not own the commercial relationship, accept risk on behalf of the business or replace specialist risk judgement. Accountability for the third-party relationship and associated risk remains with the designated Business or Service Owner and relevant delegated authority holder.


What you'll be doing:



  • Perform and support third party risk assessments for new and existing supplier engagements, ensuring required due diligence is completed in line with policy and risk framework requirements.

  • Coordinate inputs from business owners, Procurement, Information Security, Data Privacy, Compliance, Risk and Legal to build a complete view of supplier risk.

  • Review supplier information, questionnaires, documentation and control evidence to identify gaps, issues or areas requiring further clarification.

  • Challenge incomplete, inconsistent or unsupported submissions and ensure mandatory evidence requirements are met before assessments are progressed or closed.

  • Maintain accurate third-party risk records, assessment outcomes, risk ratings, evidence and action status within relevant systems and trackers.

  • Maintain the central third-party inventory and Register of Information, ensuring records remain complete, accurate and updated following onboarding, changes, reassessments, renewals and termination events.

  • Monitor open findings, remediation actions and review dates, following up with accountable owners to support timely closure.

  • Monitor trigger events including material service changes, incidents, ownership changes, subcontractor changes, renewals and contract amendments, initiating reassessment where required.

  • Support ongoing monitoring of higher-risk or critical suppliers, including periodic reviews, issue tracking and evidence collection.

  • Coordinate risk-based ongoing due diligence and periodic reassessments in line with supplier tier, criticality, materiality and ongoing monitoring requirements.

  • Produce reporting, governance packs and management information on supplier risk status, assessment activity, overdue actions, key themes, exceptions and remediation progress.

  • Escalate incomplete assessments, material risk concerns, overdue actions or control weaknesses to the Third Party Risk Management Manager.

  • Support audit, assurance, regulatory or governance requests by collating evidence and providing accurate information on third party risk activity.

  • Contribute to the maintenance of third party risk procedures, guidance, templates and process documentation.

  • Identify opportunities to improve data quality, process consistency, reporting and stakeholder understanding of third party risk requirements.

  • Support controlled supplier offboarding by validating completion of required TPRM activities, including record updates, evidence retention and closure of outstanding actions.

  • Support third-party categorisation, materiality assessments and risk-tiering activities in accordance with approved TPRM methodologies.


What you'll bring:



  • Experience in third party risk, procurement, supplier management, operational risk, compliance, audit, controls or a regulated operational environment.

  • Good understanding of supplier lifecycle activity, due diligence, risk assessment, issue tracking and evidence management.

  • Awareness of key third party risk areas, including information security, data privacy, financial crime, operational resilience, business continuity, regulatory compliance and service performance.

  • Strong analytical skills, with the ability to review supplier information, identify gaps and summa

#J-18808-Ljbffr

D

Contact Details:

domesticandgeneral Recruitment Team