We're seeking someone to join our team as a Risk Framework, Governance and Regulatory Engagement Lead to define and strengthen the third-party risk management framework, governance standards, policy alignment, and regulatory-ready execution across the third-party lifecycle.
In the Corporate Services division, we empower our businesses by creating collaborative workplace solutions and commercial services that enhance the employee and client experience, while optimizing the value of our sourcing and third-party lifecycle to enable the Firm to do-and-win business.
What you'll do in the role:
- Own and continuously improve the third-party risk management framework, including risk tiering, materiality, applicability criteria, inherent and residual risk methodology, due diligence standards, continuous monitoring expectations, control requirements, and emerging risk coverage.
- Design right-sized controls for operational resilience, critical services, and other emerging third-party risk areas, ensuring controls are proportionate, explainable, and aligned to regulatory expectations.
- Strengthen governance through clear decision rights, committee routines, escalation protocols, issue management expectations, policy and procedure alignment, regulatory response coordination, and senior management reporting.
- Use AI-enabled analytics and automation to identify risk patterns, supplier risk signals, policy gaps, control inconsistencies, duplicate requirements, manual process friction, and opportunities to simplify or right-size due diligence requirements.
- Partner with platform, data, reporting, analytics, technology, and operations teams to embed methodology, governance requirements, controls, and escalation rules into automated workflows, dashboards, reporting packs, and decision support tools.
- Oversee training, procedures, job aids, and knowledge materials to ensure they remain aligned to policy, methodology, governance decisions, platform changes, and regulatory expectations.
What you'll bring to the role:
- 12+ years of experience driving strategic programs, regulatory and governance initiatives, operational transformation, executive stakeholder engagement, and enterprise-wide project delivery.
- Strong understanding of third-party risk management, outsourcing and non-outsourcing risk, due diligence, continuous monitoring, control design, operational resilience, critical services, emerging risk, and regulatory expectations.
- Experience designing, implementing, or improving risk frameworks, governance routines, policy requirements, procedure standards, issue escalation models, and senior management reporting processes.
- Demonstrated ability to use AI, analytics, automation, and workflow tools to improve risk identification, process efficiency, assessment consistency, stakeholder experience, and management insight.
- Ability to translate regulatory expectations and risk requirements into practical controls, procedures, training content, platform requirements, and operational decision rules.
- Strong executive communication and influencing skills, including the ability to create governance-ready materials, explain complex risk concepts clearly, and drive adoption across regions, business units, control partners, and senior stakeholders.
- Ability to lead through ambiguity, simplify complex requirements, and balance regulatory expectations with practical execution for business users and control partners.
Expected base pay rates for the role will be between $130,000 and $182,500 per year at the commencement of employment. However, base pay if hired will be determined on an individualized basis and is only part of the total compensation package, which, depending on the position, may also include commission earnings, incentive compensation, discretionary bonuses, other short and long-term incentive packages, and other Morgan Stanley sponsored benefit programs.
To learn more about our offices across the globe, please copy and paste https://www.morganstanley.com/about-us/global-offices into your browser.