Third-Party Risk Manager Lead
Listed on 2026-09-20
-
Management
Risk Manager/Analyst, Regulatory Compliance Specialist -
Business
Risk Manager/Analyst, Regulatory Compliance Specialist
Job Description
Are you looking for your next opportunity?
Sompo has a unique opportunity for a Third-Party Risk Manager Lead in our Operations team.
Sompo International is seeking a TPRM Lead to drive the operational execution of the global Third-Party Risk Management (TPRM) strategy standards in / across the UK Region. This role sits within the COO function, and the successful candidate will bring oversight of Third-Party Risk Management (external and intra-group) across the entire business by ensuring regulatory compliance, accurate data management, and stakeholder engagement.
Location: This position will be based out of our London office. This is a hybrid role, with 3 days being office based. We strive for collaboration which is why we offer a work environment where our employees thrive and develop long lasting careers.
Our business, your impact, our opportunity:
What you'll be doing:Third-Party Risk Management Oversight
- Lead the implementation and embedding of the Global Third-Party Risk Management (TPRM) target operating model across the UK Region, acting as the primary liaison with the Global TPRM team and ensuring effective local oversight, governance, and adoption of global frameworks and requirements.
- Partner with business contract owners / department leads across the organisation to monitor supplier performance, manage risk exposure, and reduce critical outsourcing and third-party dependencies (external and intra-group) through proactive contract reviews within CERTA, remediation actions and service improvements.
- Proactively work to uplift contracts and intragroup standards to mitigate business risk and mature operational resilience.
- Serve as the named oversight contact for key Operations and cross-functional Business Process Outsourcing (BPO) arrangements, including Genpact and EXL, ensuring appropriate governance, performance management and contractual oversight.
- Ensure third-party engagements within the UK are managed in line with regulatory requirements, including FCA and PRA (meeting Operational Resilience and upcoming Third-Party Oversight expectations), as well as internal policies and standards.
- Provide end-to-end governance and oversight of material outsourcing arrangements and critical third-party services (external and intra-group), ensuring supplier performance, risk exposure, and regulatory obligations are actively monitored and managed.
- Maintain the Material Third-Party and Intragroup Services Register, ensuring completeness, accuracy and compliance with regulatory and internal reporting requirements, including submissions to Internal Audit, senior committees, Board(s), and regulators.
- Chair regular governance forums with material outsourcing providers, acting as the primary point of contact between Sompo and key third-party stakeholders to drive effective communication, issue resolution, and delivery oversight.
- Lead the quarterly TPRM Portfolio Review, providing consolidated oversight of third-party risk, outsourcing arrangements, remediation activity and emerging concerns ahead of Operational Committee (OpCo) reporting.
- Maintain TPRM and outsourcing records, repositories and management information, ensuring data quality, accuracy and timely reporting.
- Provide risk insights, analysis and reporting to relevant stakeholders to support informed decision-making and effective risk management of Sompo's critical third parties.
- Build organisational awareness of TPRM requirements, roles and responsibilities, providing guidance and support to contract owners and business stakeholders.
- Support the delivery of training, communications and change initiatives to strengthen third-party risk management capability across the business.
- Foster strong relationships with global, regional and local stakeholders to ensure alignment with the broader third-party risk strategy and operating model.
- Monitor emerging third-party, outsourcing and operational resilience risks and industry trends, together with regulatory developments that may impact on the organisation's TPRM framework.
- Identify and drive opportunities to strengthen controls, improve processes and enhance the effectiveness of third-party risk management across Operations.
- Monitor and report on key performance indicators (KPIs), risk metrics and remediation plans to assess the effectiveness and maturity of the TPRM framework.
- Provide feedback and recommendations…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).