Role & responsibilities
Conduct due diligence on third-party vendors, focusing on IT controls and risk management.
Review third-party documentation for compliance with outsourcing and regulatory requirements.
Identify IT control gaps and third-party risks and recommend mitigation actions.
Support implementation of TPRM frameworks, IT outsourcing, and third-party management policies.
Coordinate with internal stakeholders and vendors to ensure ongoing compliance.
Monitor regulatory updates and industry best practices related to TPRM and IT controls.
Prepare assessment reports, findings, and presentations for stakeholders.