Third-Party Assurance Manager
Third-Party Assurance Manager

Third-Party Assurance Manager

Full-Time 60000 - 75000 £ / year (est.) No home office possible
Ocorian

At a Glance

  • Tasks: Lead client assurance and vendor due diligence across the supply chain lifecycle.
  • Company: Join a global leader in fund services with a culture of collaboration and support.
  • Benefits: Competitive salary, career growth opportunities, and a diverse work environment.
  • Why this job: Make a real impact by managing third-party risks and ensuring client trust.
  • Qualifications: 2+ years in risk management or compliance; strong communication skills required.
  • Other info: Be part of a team that values ambition, agility, and ethical practices.

The predicted salary is between 60000 - 75000 £ per year.

We help clients succeed by unlocking new value through expertise, trust and scale. We deliver solutions that solve complex challenges faced by asset managers, financial institutions, corporates, high net-worth individuals and family offices. With a curious mindset, we ask the right questions to get to the right solution, faster. We collaborate to win together, sharing successes and shaping the future of our global business. Our culture of support and recognition provides the tools and opportunities for you to grow, while unlocking the most value for our clients and making your mark with Ocorian.

Expertise: We deliver specialist, tech-enabled solutions for our clients grounded on deep industry expertise.

Trust: We’re a trusted partner to over 8,000 clients globally. We are proud to have long-lasting partnerships with our clients.

Scale: With more than 1,500 colleagues, we operate across 20+ countries, our scale enables us to support our clients globally and locally, providing a seamless client experience across borders and service lines.

Purpose of the job: We are seeking an experienced Third-Party Assurance Manager to lead our client assurance and vendor due diligence programme across the full end-to-end supply chain lifecycle. This role sits at the intersection of risk management, compliance, security, procurement, and customer trust, ensuring that third-party risks are effectively identified, assessed, and managed—while enabling the business to scale confidently. The successful candidate will also be responsible for the oversight and strategic ownership of the TrustCenter and VendorPortal, ensuring transparent, accurate, and timely assurance information for both clients and internal stakeholders. In addition, this role will have responsibility for the AI Management System and ensuring organisational readiness for ISO 42001, supporting compliance and best practice in artificial intelligence governance.

Main Responsibilities:

  • Client Assurance: Act as the primary point of contact for client assurance requests, including security, privacy, compliance, and supply-chain risk inquiries. Coordinate and manage responses to customer due diligence questionnaires, audits, and assurance reviews (e.g., SOC, ISO, regulatory requests). Partner with Security, Data Privacy, Legal, and Engineering teams to deliver clear, consistent, and high-quality assurance responses. Drive continuous improvement in client assurance processes to reduce friction and response time.
  • Vendor Due Diligence and Supply Chain Lifecycle: Own and manage the end-to-end third-party risk lifecycle, including onboarding, risk assessment, contracting, ongoing monitoring, and offboarding. Design and execute vendor due diligence reviews across security, privacy, operational resilience, and regulatory risk domains. Collaborate with Legal, Data Privacy, Security, and Business stakeholders to ensure risk-appropriate controls and remediation plans are in place. Maintain risk tiering, review cadences, and escalation paths aligned to business and regulatory requirements. Oversee procurement processes and licensing management to ensure all third-party solutions are sourced in compliance with company policy and regulatory standards. Work collaboratively with Technology, Legal and Finance to maintain accurate software inventories, manage renewals, and optimise cost-effectiveness while mitigating contractual and compliance risks. Develop and maintain third-party assurance frameworks, policies, and procedures. Track and report on third-party risk metrics, trends, and remediation status to senior stakeholders. Support internal and external audits related to third-party risk and supply chain assurance. Stay current on evolving regulatory expectations and industry best practices related to third-party and supply chain risk. Provide oversight of the AI Management System, ensuring robust governance, risk management, and compliance practices are in place throughout the third-party risk lifecycle. Coordinate ISO 42001 readiness activities, aligning internal controls and vendor due diligence processes to the requirements of the AI management standard. Monitor evolving best practices and regulatory developments in AI governance, supporting continued compliance and operational excellence.
  • TrustCenter & Vendor Portal Ownership: Lead and nurture teams, building a culture centred around user service, documentation, and proactive engagement. Recruit, mentor, and develop talented employees, defining clear career paths and performance expectations focused on service excellence. Encourage continuous improvement and innovation in support, training, and user communication. Provide strategic oversight of the TrustCenter, ensuring assurance materials are accurate, up to date, and aligned with company risk posture. Own and continuously improve the Vendor Portal, enabling transparency and efficient information sharing with clients and partners. Define content strategy, governance, and operating model for assurance artifacts published externally. Partner with Product, Security, and Communications teams to enhance usability and trust signals.

Qualifications: 2+ years of experience in third-party risk management, assurance, compliance, security, or audit. Strong understanding of vendor due diligence and supply chain risk management across the full lifecycle. Hands-on experience managing client assurance requests and customer-facing risk discussions. Familiarity with common assurance frameworks (e.g., SOC 2, ISO 27001, ISO 42001, NIST, GDPR, vendor risk standards). Proven ability to work cross-functionally and influence without authority. Excellent written and verbal communication skills, particularly in explaining risk to non-technical audiences.

Preferred Experience: Experience owning or contributing to a TrustCenter or external assurance portal. Background in SaaS, technology, or regulated environments. Experience implementing or optimizing third-party risk tools or workflows. Certifications such as CISA, CRISC, CISSP, or equivalent (nice to have).

Additional Information: All staff are expected to embody our core values that underpin everything that we do and that reflect the skills and behaviours we all need to be successful. These are: We are CLIENT CENTRIC – Clients are at the centre of our world, and we’re committed to providing expertise and specialist solutions to meet their most complex challenges. We are AMBITIOUS – We aim high. We think and act globally, seizing every opportunity to delight our clients and support our colleagues - wherever in the world they may be. We are AGILE – We act on our initiative to get things done for our clients. Our independence gives us the flexibility and freedom to keep things simple, efficient and effective. We are COLLABORATIVE – With a curious mindset, we ask the right questions to get to the right solution, for our clients faster. We collaborate to win together and share our successes. We are ETHICAL – We behave with integrity at all times and assume positive intent, building trust through responsible actions and honest relationships.

Equal Opportunities for Everyone: Please let us know if there’s anything we can do to make the process easier for you. You can reach us at careers@ocorian.com. We’re an equal opportunity employer. All applicants will be considered for employment without attention to age, ethnicity, religion, sex, sexual orientation, gender identity, family or parental status, national origin, or veteran, neurodiversity or disability status.

Third-Party Assurance Manager employer: Ocorian

Ocorian is an exceptional employer that fosters a culture of collaboration, support, and recognition, empowering employees to grow and make a meaningful impact in the financial services sector. With a commitment to client-centric solutions and a global presence, we offer unique opportunities for professional development and innovation, particularly in the dynamic field of third-party risk management. Our diverse and inclusive work environment ensures that every team member can thrive while contributing to our mission of delivering excellence to over 8,000 clients worldwide.
Ocorian

Contact Detail:

Ocorian Recruiting Team

StudySmarter Expert Advice 🤫

We think this is how you could land Third-Party Assurance Manager

✨Tip Number 1

Network like a pro! Reach out to your connections in the industry and let them know you're on the hunt for a Third-Party Assurance Manager role. You never know who might have the inside scoop on job openings or can put in a good word for you.

✨Tip Number 2

Prepare for interviews by researching the company and its culture. Understand their approach to client assurance and vendor due diligence. This will help you tailor your responses and show that you're genuinely interested in how you can contribute to their success.

✨Tip Number 3

Practice your pitch! Be ready to explain your experience in third-party risk management and how it aligns with the company's needs. Highlight your ability to collaborate across teams and drive continuous improvement—these are key traits they’re looking for.

✨Tip Number 4

Don’t forget to apply through our website! It’s the best way to ensure your application gets noticed. Plus, it shows you’re serious about joining the team and ready to make an impact in the world of client assurance.

We think you need these skills to ace Third-Party Assurance Manager

Third-Party Risk Management
Client Assurance
Vendor Due Diligence
Supply Chain Risk Management
ISO 42001 Compliance
Security and Privacy Knowledge
Regulatory Compliance
Audit Management
Cross-Functional Collaboration
Excellent Communication Skills
Continuous Improvement
Risk Assessment
Project Management
Technical Aptitude in SaaS and Technology

Some tips for your application 🫡

Tailor Your Application: Make sure to customise your CV and cover letter to highlight your experience in third-party risk management and compliance. We want to see how your skills align with the role, so don’t be shy about showcasing relevant projects or achievements!

Showcase Your Communication Skills: Since this role involves explaining complex risk concepts to non-technical audiences, it’s crucial to demonstrate your written communication skills. Use clear, concise language in your application to reflect your ability to convey important information effectively.

Highlight Collaborative Experiences: We value teamwork, so share examples of how you’ve worked cross-functionally in previous roles. Whether it’s partnering with legal teams or collaborating on vendor due diligence, showing your collaborative spirit will make your application stand out.

Apply Through Our Website: We encourage you to submit your application through our website for a smoother process. It helps us keep track of your application and ensures you’re considered for the role. Plus, it’s super easy to do!

How to prepare for a job interview at Ocorian

✨Know Your Stuff

Make sure you have a solid understanding of third-party risk management and the specific frameworks mentioned in the job description, like SOC 2 and ISO 27001. Brush up on your knowledge about compliance and security protocols, as you'll likely be asked to explain how these apply to the role.

✨Showcase Your Experience

Prepare to discuss your previous experience with client assurance requests and vendor due diligence. Use specific examples to illustrate how you've successfully managed risks and improved processes in past roles. This will demonstrate your hands-on expertise and ability to handle the responsibilities of the position.

✨Ask Insightful Questions

During the interview, don’t hesitate to ask questions that show your curiosity and understanding of the role. Inquire about the current challenges they face in third-party risk management or how they measure success in their assurance processes. This not only shows your interest but also helps you gauge if the company is the right fit for you.

✨Emphasise Collaboration

Since the role involves working cross-functionally, highlight your collaborative skills. Share examples of how you've worked with different teams, such as Legal or Data Privacy, to achieve common goals. This will reinforce your ability to thrive in a team-oriented environment, which is crucial for this position.

Third-Party Assurance Manager
Ocorian

Land your dream job quicker with Premium

You’re marked as a top applicant with our partner companies
Individual CV and cover letter feedback including tailoring to specific job roles
Be among the first applications for new jobs with our AI application
1:1 support and career advice from our career coaches
Go Premium

Money-back if you don't land a job in 6-months

>