# Third Party Program Manager

> Clinigen · Shah Alam, Malaysia · Full-time · Posted 2026-08-07

**Workplace:** on_site

**Department:** Support Functions

## Description

Clinigen’s third‑party ecosystem is wide and includes suppliers, service partners, consultants, distributors, and other intermediaries who can create ABAC, fraud, sanctions, reputational and operational risk if not properly assessed and controlled. This role provides the organisation’s front‑door integrity control: ensuring that third parties are vetted and monitored, risk is visible, escalations are handled consistently, and decisions are documented and auditable.

The role is also accountable for ensuring that third‑party due diligence is not a one‑off event — but a lifecycle process with ongoing monitoring and clear remediation steps, consistent with modern regulatory expectations

**Key Responsibilities:**

**1) TPRM Operating Model Ownership (Global)**

-   Own and maintain Clinigen’s TPRM framework and operating standards (scope, risk tiers, minimum due diligence requirements, escalation thresholds, evidence expectations).
-   Ensure consistent application across regions and business units, partnering with Procurement, Legal, Finance, Quality and operations to align the “who/what/when” of onboarding and approvals.
-   Ensure the TPRM programme supports “adequate procedures” expectations under global anti‑bribery, sanctions, and financial crime frameworks.
-   Support remediation actions, conditions of engagement, and contractual controls where third‑party risks are identified, working with Legal and Procurement

**2) NAVEX RiskRate Platform Ownership (End‑to‑End)**

-   Run the third‑party compliance workflow in NAVEX RiskRate: initiation, duplicate checks, questionnaires, screening outputs, risk decisions, approvals, and documentation standards.
-   Maintain process discipline so third parties are not engaged prior to approval, and ensure stakeholders understand timelines and required inputs.
-   Drive continuous improvements to workflows, templates, and automation, and act as the business owner for enhancements needed to scale.
-   Ensure data quality, completeness, and consistency within the third‑party system of record to support reporting, audit readiness, and decision‑making
-   Apply independent judgement and appropriate challenge where business urgency conflicts with third‑party risk requirements

**3) Due Diligence & Risk Assessment (Proportionate, Risk‑Based)**

-   Oversee initial risk screening and due diligence, ensuring appropriate depth of review depending on risk tier (including standard/enhanced due diligence as triggered by risk tiering).
-   Ensure that third‑party onboarding includes robust review of identity, ownership, location risk, services risk, and reputational indicators, and that findings are documented in the system of record.
-   Manage “go / no‑go” escalation where red flags exist; ensure decisions are risk‑informed, consistent, and defensible.

**4) Sanctions & Trade Sanctions Controls**

-   Ensure third‑party sanctions screening is performed and maintained, including appropriate escalation where potential matches arise and alignment to Clinigen sanctions requirements.
-   Support the organisation’s trade/export sanctions controls (including appropriate routing and escalation for sanctioned jurisdictions and commodity/HS code issues where required by policy).
-   Maintain clear records and audit trails for sanctions decisions and escalations.

**5) Ongoing Monitoring & Lifecycle Management (Third‑Party Specific)**

-   Own the ongoing screening/monitoring approach for third parties, including how alerts are reviewed, triaged, resolved and evidenced (TPRM lifecycle management).
-   Ensure periodic refresh, re‑screening and re‑due diligence occurs where required (e.g., risk changes, contract renewals, market expansion, scope changes).
-   Support off‑boarding/termination and ensure controls prevent continued engagement with blocked or terminated third parties.

**6) Third‑Party Risk Intelligence, Reporting & Insight**

-   Produce third‑party risk reporting for senior stakeholders: pipeline volumes, aged cases, bottlenecks, high‑risk concentrations, recurring red flags, and remediation themes (TPRM only).
-   Provide actionable intelligence to enable better business decisions (e.g., procurement interventions, process controls, contract gating improvements).

**7) Stakeholder Enablement (Process Adoption Without Owning E&C Training)**

-   Provide targeted process enablement and practical guidance to business requestors and procurement/finance stakeholders on “how to onboard third parties correctly” and how to avoid retrospective onboarding.
-   Maintain clear user guidance and practical comms for third‑party onboarding expectations (TPRM communications only)

**8) GxP / Quality Interfaces (No Duplication of QA Vendor Qualification)**

-   Ensure appropriate hand‑offs to Quality for GxP vendor qualification steps, and ensure compliance approval is aligned with QA requirements (without duplicating QA’s technical assessments).

**Additional Duties:**

The above list is not exhaustive. Duties may evolve based on business needs, and the post‑holder is expected to work flexibly to support a scalable, defensible Third‑Party Risk Management capability aligned to Clinigen’s Ethics & Compliance programme

## Requirements

-   Experience in pharma, life sciences, healthcare services, or similarly regulated environments where third‑party risk (ABAC, fraud, sanctions, reputational risk) is material.
-   Experience using third‑party due diligence systems and structured workflows (RiskRate/NAVEX or comparable platforms).
-   Experience working with sanctions compliance expectations and controls (screening, escalation, record‑keeping, and programme components).
-   Familiarity with risk‑based “adequate procedures” expectations including due diligence and monitoring & review principles is beneficial

## Apply

[Apply at Clinigen](https://apply.workable.com/clinigen/j/8E80C00CC5/apply)

---
Powered by [Workable](https://www.workable.com)
