About the job
Oversee the risk assessment process for outsourced activities by:
- gathering and analyzing information from the First Line of Defense (1LOD) and suppliers;
- assessing supplier-related risks and the risk mitigation strategies in place.
Establish and maintain the control framework and monitoring indicators by:
- defining and reviewing risk controls associated with outsourced operations;
- creating and validating Key Performance Indicators (KPIs), Key Risk Indicators (KRIs), and their respective tolerance levels.
Supervise activities conducted by the 1LOD in the domain of Third-Party and ICT Risk by:
- reviewing documentation and due diligence processes;
- monitoring the compliance and performance of critical and non-critical ICT suppliers;
- swiftly identifying discrepancies and proposing corrective actions.
Assist in the enhancement and development of the governance framework for supplier-related risks, ensuring alignment with internal policies and applicable regulations (e.g., DORA, EBA Guidelines, local standards).
Facilitate effective communication with all stakeholders while providing expert advice and support to the 1LOD.

