Tags: IRDAI Guidelines, Vendor Risk
Role Title: TPRM Manager
Employer: Leading Life Insurance Company
Required Experience: 5–8 Years
Location: Mumbai
Date published: 7 August 2026
A Leading Life Insurance Company is seeking a highly structured TPRM Manager to lead its Third-Party Risk Management practice in Mumbai. In this strategic governance role, you will own the end-to-end design, implementation, and continuous enhancement of the vendor risk framework across the entire vendor lifecycle. Furthermore, you will drive full compliance with statutory IRDAI guidelines, ensuring thorough risk evaluation across Information Security, Data Protection, and Business Continuity domains. Consequently, this position is essential for shielding the enterprise from supply chain vulnerabilities and supporting informed decision-making.
The TPRM Manager must combine deep regulatory knowledge with proven team leadership and stakeholder management capabilities. Operating across onboarding, due diligence, contracting, and exit phases, you will define vendor risk tiering methodologies and Turnaround Time matrices. Therefore, the organization is looking for a proactive leader who collaborates closely with Legal, Procurement, and Departmental Risk Officers to enforce contractual risk standards. If you want to steer a resilient, technology-enabled vendor risk program, this position offers an ideal path.
Key Responsibilities
- Own the end-to-end design, implementation, and enhancement of the TPRM framework, policy, and SOPs across the vendor lifecycle.
- Provide strategic oversight and supervisory review of third-party risk assessments across Information Security, Data Protection, and BCM.
- Define and maintain vendor risk tiering methodologies and volume/criticality-driven Turnaround Time (TAT) assessment matrices.
- Track, analyze, and report TPRM Key Risk Indicators (KRIs) and emerging vendor risk trends to senior leadership and the Risk Committee.
- Drive compliance with IRDAI ICS Guidelines 2026 and applicable outsourcing regulations, tracking remediation and clause traceability.
- Lead, mentor, and build technical capability within the TPRM team, reviewing assessment outputs and contractual reviews prior to closure.
- Partner with Legal and Procurement teams to strengthen third-party contractual risk clauses and align them with corporate risk appetite.
- Drive process improvements and technology enablement to enhance the efficiency and scalability of the TPRM lifecycle.
- Ensure framework alignment with global standards including ISO 27001, ISO 22301, ISO 31000, and data privacy regulations.
- Maintain strong working relationships with Departmental Risk Officers, Process Officers, and senior business stakeholders.
Requirements and Qualifications
- Postgraduate degree in Business Administration, Finance, Risk Management, Information Technology, or a related discipline.
- 5-8 Years of core experience in Third-Party Risk Management, Vendor Governance, Operational Risk, or Information Security Audit in BFSI.
- Strong working knowledge of IRDAI regulatory guidelines, ISO 27001, ISO 22301, ISO 31000, and data privacy frameworks.
- Proven ability to lead and mentor a team while managing a high-volume, multi-stakeholder vendor assessment portfolio.
- Strongly preferred certifications: CISA, CRISC, or ISO 27001/ISO 22301 Lead Auditor credentials.