← Takaisin työpaikkoihin

Outsourcing Manager / Third-Party Risk Processes Expert

  • Etätyö
  • Ruotsi
  • Englanti
  • Julkaistu 10.09.26 20:38

Job title: Outsourcing Manager / Third-Party Risk Processes ExpertDuration: 6 months (Possibility to be extended or made permanent) Allocation: Full timeLocation: Remote (EU hours is a must) Start: ASAPRate: Dependant on experience This is a delivery role. The task is to get the clients Payments’ outsourcing framework working in practice doing the pre-outsourcing analysis on existing and incoming arrangements, getting the outsourcing register populated and functional, and making sure new suppliers are onboarded through the right process. Once the foundations are in place, the role extends into improving and rolling out the execution framework on an ongoing basis. What You’ll Be DoingPre-Outsourcing Analysis:Run classification and criticality assessments for each arrangement — determining whether it falls under ICT, critical/important function, outsourcing, or a combinationComplete pre-outsourcing due diligence steps: sanctions screening, adverse media checks, GDPR preliminary assessment, conflict of interest checkDocument outputs clearly so each arrangement is assessed, recorded, and approvableFlag gaps or issues in existing arrangements and work with the relevant teams to resolve them Outsourcing Register:Populate the register with all current arrangements, applying the updated classification frameworkKeep entries current as new arrangements come in or existing ones changeChase down missing information from business owners and service providersMake sure the register is audit-ready at any point in time Supplier Onboarding Coordination:Own the process for getting new suppliers through governance steps before contracts are signedCoordinate inputs from Legal, IT, Compliance and the business, not doing their jobs, but making sure nothing falls through the gapsTrack where each supplier sits in the process and flag blockers early Process Improvement & Execution Rollout:Identify where the current process is slow, unclear or not being followed and propose practical fixesWork with the business to embed good habits, making the governance process easier to follow, not harderBuild simple tools, guides or templates that make it easier for teams to engage with the frameworkAs the initial backlog clears, shift focus to improving how the framework runs day-to-day and extending it to cover any gaps Contracting Support:Support Legal in reviewing incoming and existing contracts against the required clause standards (audit rights, incident notification, sub outsourcing controls, exit provisions)Flag contracts that need remediation and provide Legal with the governance context needed to action themAct as the operational bridge between Legal and the business during contract negotiations, making sure governance requirements are understood and reflectedMaintain a clear record of contract status across the register What You’ll NeedEssential:Experience running outsourcing or third-party risk processes in a regulated financial institution (payment institution, e-money institution, or bank)Comfortable working through a high volume of assessments methodically and to deadlinesStrong problem-solving instincts, able to find pragmatic solutions when the process hits real-world frictionExperience supporting Legal on contract governance, able to identify missing or inadequate governance clauses and provide the context Legal needs to actGood at driving process, chasing stakeholders, removing blockers, keeping things moving without much hand-holdingAble to spot where a process is broken and propose a fix that people will actually use HelpfulFamiliarity with DORA and EBA outsourcing requirements, the frameworks are in place, you’re executing against themExperience with third-party risk or GRC toolingBackground in financial services compliance, procurement, or operational risk

What This Role Isn’t:This is not a policy or strategy role. The procedure is written and the framework is set. The job is to work through the backlog, make the process functional, and then help build the muscle for doing this well going forward. Regulatory decision-making, risk acceptance, andsecond-line oversight remain with the permanent compliance and risk teams.