Supplier Risk Lead
Summary
Oversees third-party and supplier risk management for Ford Credit’s ICT, information security, and operational resilience, ensuring compliance with DORA, PRA/FCA, and BCBS/BIS standards while leading risk assessments, reporting, and regulatory oversight.
Description
Operating within FCE Bank’s Second Line of Defence, the Supplier Risk Lead provides independent oversight, challenge and assurance across the Bank’s third-party and supplier risk profile.
The role helps ensure that outsourcing arrangements, particularly those involving ICT, information security and operational resilience, are identified, assessed and managed by the First Line in accordance with the Bank’s risk appetite.
The Supplier Risk Lead will support the continued development of FCE Bank’s global Third-Party Risk Management (TPRM) framework, policies and practices. This includes maintaining alignment with evolving regulatory requirements, such as the Digital Operational Resilience Act (DORA), PRA SS2/21 and wider PRA and FCA expectations.
Through robust review, constructive challenge and clear risk reporting, the role supports informed decision-making, protects customer outcomes and strengthens the Bank’s operational resilience and regulatory compliance.
Location: Dunton Campus, Basildon, Essex
Working model: Four days per week onsite
Department: Risk
Function: ICT Risk Office, Second Line of Defence
Reports to: ICT Risk and Information Security Manager
Responsibilities
- Independently review and challenge First Line supplier risk assessments, classifications and residual risk ratings.
- Conduct quality assurance reviews of supplier due diligence, controls and mitigation plans.
- Lead the development and ongoing enhancement of the global TPRM framework, policy and methodology.
- Maintain supplier risk classification tools, assessment templates and supporting GRC or TPRM workflows.
- Produce supplier risk reports, dashboards and management information for senior leadership and Risk Committees.
- Monitor Key Risk Indicators, policy exceptions, risk acceptances and remediation actions against risk appetite.
- Oversee material third-party and fourth-party incidents, including root-cause analysis and remediation.
- Advise business owners, contract managers and Vendor Management colleagues on supplier risk requirements.
- Deliver training and facilitate risk workshops for high-risk or complex supplier arrangements.
- Ensure the TPRM framework remains aligned with DORA, PRA SS2/21 and relevant regulatory expectations.
- Support internal audits and regulatory reviews by providing evidence of effective Second Line oversight.
- Oversee the DORA ICT Third-Party Register of Information.
- Assess third-party and fourth-party concentration risk to support operational resilience.
Essential Skills
- Strong understanding of third-party risk management, outsourcing risk and operational risk principles.
- Working knowledge of outsourcing and operational resilience requirements, particularly DORA, PRA SS2/21 and wider PRA and FCA expectations.
- Good understanding of risks associated with outsourced ICT, information security, business continuity, disaster recovery and data protection.
- Ability to assess risk throughout the supplier lifecycle, including supplier financial viability, performance, controls and operational vulnerabilities.
- Strong analytical skills, with the ability to interpret qualitative and quantitative supplier risk information.
- Ability to identify trends, concentration risks and enterprise-wide vulnerabilities across a supplier portfolio.
- Confidence to provide independent and constructive challenge to First Line business owners while maintaining collaborative professional relationships.
- Excellent written and verbal communication skills.
- Ability to translate complex technical and regulatory risks into clear executive summaries, management information and risk reports.
- Strong problem-solving, organisational and prioritisation skills.
- Ability to manage multiple overlapping reviews and maintain accurate governance records.
- Self-motivated, disciplined and capable of working with an appropriate level of independence.
Desired Experience
- At least three years of experience in operational risk, outsourcing risk or specialist Third-Party Risk Management.
- Experience working in a Second Line of Defence, independent risk oversight or assurance role.
- Experience within a highly regulated organisation, preferably financial services operating under PRA and FCA supervision or automotive finance.
- Practical experience reviewing supplier due diligence, risk assessments, control environments and risk mitigation plans.
- Experience producing supplier risk dashboards, management information and reports for senior stakeholders or governance committees.
- Experience monitoring Key Risk Indicators, policy exceptions, risk acceptances and remediation actions.
- Experience supporting the development or enhancement of a TPRM framework, policy or methodology.
- Experience advising business owners, contract managers, procurement teams or Vendor Management functions on third-party risk.
- Experience supporting supplier incident reviews, root-cause analysis and remediation oversight.
Nice-to-haves
- Familiarity with recognised information security and control frameworks, such as ISO 27001, NIST or COBIT.
- Experience using enterprise risk, GRC or TPRM platforms, such as ServiceNow, Archer, OneTrust or a comparable system.
- Experience assessing systemic supplier concentration risk.
- Experience mapping fourth-party or wider supply chain dependencies.
- Experience reviewing supplier exit, substitution or business continuity plans.
- Experience supporting internal or external audits.
- Experience participating in direct regulatory or supervisory engagements.
- Experience maintaining or overseeing the DORA ICT Third-Party Register of Information.
- Experience developing and delivering risk training or facilitating risk profiling workshops.
Qualifications
- A relevant professional qualification in risk, audit, information security or technology risk is desirable.
- Relevant certifications may include:
- Certified in Risk and Information Systems Control (CRISC)
- Certified Information Systems Auditor (CISA)
- Institute of Risk Management (IRM) qualification
- An equivalent recognised risk, audit or information security credential
- Equivalent practical experience will also be considered.
Additional Information
The Company is committed to diversity and equality of opportunity for all and is opposed to any form of less favorable treatment or harassment on the grounds of race, religion or belief, sex, marriage and civil partnership, pregnancy and maternity, age, sexual orientation, gender reassignment or disability.
As part of our pre-employment checks process, successful candidates will be required to undergo a criminal record check. This will be conducted in line with the Rehabilitation of Offenders Act 1974 and applied only to unspent convictions.
This position is based in Dunton, Essex and it is expected the successful candidate will be able to attend the Dunton Campus for typically 4 days a week and remain flexible on the days they are required to attend the office according to business requirements.
#LI-AC5 #LI-FordCredit #LI-Hybrid