Outsourcing and Third Party Risk Management Lead
Teya
| Company | Teya |
| Category | Legal & Compliance |
| Location | London |
| Remote | On-site (inferred) |
| Employment | Not stated |
| Level | Lead |
| Salary | Not stated by the employer |
| Posted | 11 Jun 2026 |
| Last verified | 11 Aug 2026 |
| Source | Employer ATS (ashby) |
Description
Hello. We’re Teya.
Teya was founded on a simple belief: local businesses deserve better.
They are the cafés, restaurants, salons, shops and entrepreneurs that bring character to our high streets, create jobs and keep communities moving. Yet for too long, financial services has made life harder for them - with clunky tools, poor support and complexity that gets in the way of running a business.
Teya exists to change that.
We’re building a financial platform for local businesses across Europe - one built around simple tools, thoughtful design and real human support. Our Members rely on us to help them run their business with confidence, and that responsibility shapes the way we work.
We move fast. We care about quality. We stay close to the detail. And we believe great performance and genuine hospitality should go hand in hand.
If you want to build meaningful products, solve real problems and make a genuine difference for local businesses, we’d love to hear from you
The Outsourcing and Third Party Risk Management (TPRM) Lead is responsible for running Teya’s day-to-day outsourcing and third party risk activities within the first line of defence, ensuring Teya meets its regulatory obligations and manages the risks arising from its use of external providers. The role owns the operational execution of the TPRM framework across the business, including due diligence, ongoing monitoring, contract risk review, and the maintenance of Teya’s outsourcing and ICT third party registers. You’ll be the go-to person for business owners managing third party arrangements, working closely with Procurement, Legal, Information Security, Compliance, and Operational Risk. You’ll be comfortable in a fast-paced environment and able to balance multiple competing priorities.
Key Objectives
- Drive the continuous improvement of TPRM and outsourcing processes, controls, and tooling, with a focus on risk-based prioritisation and proportionate due diligence.
- Own and maintain Teya’s outsourcing register and ICT third party register, ensuring all critical or important arrangements are correctly classified and recorded in line with EBA Guidelines on Outsourcing, DORA, and FCA/PRA expectations.
- Act as the first point of contact for business owners on third party risk matters, supporting them through onboarding, risk assessment, contract review, and ongoing monitoring.
- Coordinate due diligence across information security, data protection, financial crime, business continuity, and concentration risk, working with subject matter experts to produce a single view of third party risk.
- Run the ongoing monitoring programme, including performance reviews, control attestations, incident tracking, and periodic re-assessments of material third parties.
- Produce management information and reporting for senior governance forums, flagging emerging risks, control gaps, and remediation progress.
- Partner with Compliance and Operational Risk (2LOD) to ensure framework changes, regulatory updates, and findings are translated into operational practice.
- Support regulatory submissions, audits, and supervisory engagement on outsourcing and ICT third party matters.
Job Requirements
- A minimum of 3 years of experience in outsourcing or third party risk management within a regulated financial services environment (payments, e-money, banking, or similar).
- Working knowledge of the EBA Guidelines on Outsourcing Arrangements and DORA
- Experience running due diligence and ongoing monitoring across material third parties, including critical or important outsourcing arrangements and ICT services supporting critical or important functions.
- Highly organised, with strong attention to detail and the ability to manage a large portfolio of third parties simultaneously.
- A pragmatic, risk-based mindset. You see the role of 1LOD as enabling the business to move quickly and safely, not blocking it. You can hold the line on real risks