The opportunity
As a Senior Business Analyst, TPRM, you will support the assessment and ongoing oversight of third party relationships, including vendors and partners, throughout the third party risk management lifecycle.
What you'll do
Review and challenge Inherent Risk Questionnaires (IRQs), working with: business owners to understand vendor relationships, validate information, and determine appropriate inherent risk and criticality ratings.
Coordinate due diligence activities with cross-functional risk partners and: subject matter experts across areas such as Information Security, Privacy, Compliance, Enterprise Risk Management, and Legal.
Conduct business due diligence, including reviews of corporate registration,: reputational information, insurance coverage, and other relevant documentation, and coordinate additional activities such as background checks.
Manage assigned third party assessments through completion, coordinating with: business owners and cross-functional risk partners to address questions, follow up on outstanding requirements, and escalate concerns as appropriate.
Facilitate vendor approval processes with Chime’s bank partners, including: coordinating assessment information, responding to follow-up requests, and tracking approvals through completion.
Identify and document issues arising from TPRM assessments and partner with: relevant stakeholders to track third party risk issues and remediation activities through resolution.
What they're looking for
- Support ongoing monitoring and periodic reassessments of third party: relationships, including reviewing changes that may impact the inherent risk rating, criticality rating, or due diligence requirements.
- Clearly document TPRM assessments, risk decisions, and supporting rationale: in accordance with program requirements.
- Provide guidance to business owners and stakeholders on TPRM requirements, processes, and expectations.
- Contribute to the continued development and maturity of the TPRM program: through process improvements, tooling enhancements, reporting, and updates to policies, procedures, standards, and supporting documentation.