Job Req ID: 60975
Posting Date: 23 July 2026
Function: Procurement
Location: Gurugram
About the role
The Risk & Compliance Professional supports the effective operation of the Supply Management Group, Risk and Compliance (GRC) framework by coordinating risk management, control monitoring, assurance, reporting, and third-party risk activities across the procurement and supplier lifecycle.
Working within the Supply Management Risk team, the role helps ensure that supply management activities are aligned with BT's policies, standards, regulatory requirements, and risk framework. The role works closely with Process Teams, Category Teams, Control Owners, Subject Matter Experts, and other stakeholders to support risk assessments, control assurance, audit management, reporting, and continuous improvement initiatives.
What you will be doing (Role Accountabilities)
Risk Management & Third-Party Risk Oversight
- Support procurement and third-party risk management activities throughout the supplier lifecycle.
- Coordinate and implement processes and controls across various risk categories e.g.; Cyber Security, Data and AI, Business Continuity, Financial Risk, Sustainability, Health & Safety, Anti-Bribery & Corruption, Human Rights etc.
- Track risk mitigation actions and follow up with stakeholders to ensure timely closure.
- Support the identification, assessment, and reporting of enduring, point and emerging risks.
Governance, Controls & Assurance
- Coordinate periodic control self-assessments and attestations with control owners.
- Monitor control performance, deficiencies, remediation plans, and action tracking.
- Support assurance reviews, control testing activities, and deep-dive assessments.
- Maintain records of audit findings and actions, ensuring progress is tracked through to closure.
- Assist in preparing evidence and documentation for internal and external audits.
Risk Reporting & Data Management
- Support the preparation of risk reports, dashboards, and management information for governance forums and leadership reviews.
- Monitor risk metrics, key risk indicators, and control status reporting.
- Validate and maintain risk, control, audit, and action data within the Risk platform and other governance tools.
- Assist with preparation of risk reporting.
Stakeholder Engagement
- Work across the Process Teams, Procurement Category Teams and Subject Matter experts to obtain data and evidence required for risk assessments and reporting.
- Support engagement with Group Risk, Compliance, Legal, Internal Audit, and Business Unit stakeholders.
- Provide guidance and support to stakeholders on risk and compliance processes.
- Help promote risk awareness and good governance practices across the Supply Management function.
Continuous Improvement
- Identify opportunities to improve risk, reporting, governance, and control processes.
- Support implementation of process improvements and best practices.
- Contribute to policy, standard, and process reviews where required.
Assist with data collection, analysis, project activities, and governance initiatives.
What you’ll need to succeed (Skills & Experience)
- 5–10 years' experience in Risk Management, Compliance, Supplier Risk Management, Procurement, Governance, Audit, or related disciplines.
- Good understanding of third-party risk management and supplier lifecycle processes.
- Experience supporting risk assessments, controls, audits, and compliance activities.
- Knowledge of risk domains including Information Security, Privacy, Business Continuity, Financial Risk, Sustainability, and Regulatory Compliance.
- Strong analytical, reporting, and problem-solving skills.
- Experience working with risk data, dashboards, and governance reporting.
- Strong stakeholder engagement and communication skills.
- Proficiency in Microsoft Excel, PowerPoint, and other Microsoft Office applications.
- Experience using risk management systems is desirable.
Success Measures
- Timely completion of risk assessments, reporting, and governance activities.
- Accurate maintenance of risk, control, audit, and action data.
- Effective support of control assurance and audit activities.
- Timely tracking and closure of risk and audit actions.
- High-quality risk reporting and stakeholder engagement.
- Continuous improvement of Supply Management risk and compliance processes.
BT Group is the UK’s leading communications group and the holding company behind some of the country’s most recognised brands – including BT, EE, Openreach and Plusnet. Our purpose is as simple as it is ambitious: we connect for good. Our customers include consumers, small, medium and large businesses, public sector organisations and other communications providers.
BT Group’s role is about setting direction, unlocking value and creating the conditions for our brands and businesses to thrive.
Having come through the most capital-intensive phase of our fibre investment, our focus now is on what comes next – simplifying how we operate, using technology and AI to work smarter, and organising ourselves to serve customers better and grow sustainably. Group teams shape strategy, policy, brand, capital allocation and transformation, helping the whole organisation perform at its best.
We have a singular culture that unites all our people: we are customer-first challengers, who are committed, clear and connected. These behaviours unite us as one team to deliver for our colleagues, our customers, our stakeholders and the country. Joining BT Group means working at the heart of a business that matters to the UK, with the opportunity to shape decisions, influence outcomes and help set the future course of one of the country’s most important companies.