TPRM Analyst – Team Lead / Assistant Manager –Chennai
Location: Chennai
• Experience: Senior Level
• Openings: 2
Job description
Location – Chennai
Key Responsibilities:
5+ years of experience in TPRM activities and third-party due diligence.
Conversant with TPRM tools in the market Excellent attention to detail
and analytical skills.
Strong communication abilities. Experience with ERP and TPRM tools.
Legal or paralegal certification is a plus. Familiarity with
international contracts and regulatory requirements preferable
Third-Party Risk Assessment – Review
vendors and identify potential operational, cybersecurity, compliance,
financial, and reputational risks.
Impact Assessment – Assess the
potential business impact if a third party fails to deliver its services or
experiences a security/compliance incident.
Risk Classification – Classify third
parties as High, Medium, or Low risk based on factors such as data sensitivity,
criticality, system access, regulatory requirements, and business dependency.
Third-Party Due Diligence – Conduct
due diligence by reviewing security questionnaires, SOC reports, ISO
certifications, BCP/DR documents, privacy controls, financial information, and
other relevant evidence.
TPRM Tools – Use enterprise TPRM
platforms to manage vendor assessments, questionnaires, risk ratings,
documentation, workflows, findings, and remediation activities.
Risk Mitigation – Work with
Procurement, business owners, Information Security, Legal, Compliance, and
vendors to identify appropriate controls and develop risk mitigation plans.
Compliance & Policy Management –
Ensure third parties meet organizational TPRM requirements, contractual
obligations, regulatory requirements, and internal policies.
Risk & Remediation Tracking –
Maintain the third-party risk register/database and track open findings,
remediation actions, deadlines, risk acceptances, and reassessments.
Stakeholder Management – Act as a key
point of contact for Procurement and business stakeholders, gather
requirements, explain risks, and help resolve vendor-related issues.
Reporting & Audit Documentation –
Prepare management reports on vendor risk levels, due-diligence status,
outstanding findings, and remediation progress while maintaining accurate
records and audit trails.