Jobs › Central Outsourcing Control Office (COCO)
Central Outsourcing Control Office (COCO)
Job at a glance
- Category
- GRC
- Work arrangement
- On-site
- Location
- Frankfurt, Germany
- Posted
- Aug 31, 2026
Free. One click to unsubscribe. We never share your address.
Morgan Stanley is hiring a Central Outsourcing Control Office (COCO) in Frankfurt, Germany. This is a GRC job in the governance, risk, and compliance field. Review the full details below and apply directly with Morgan Stanley.
About the Team The Central Outsourcing Control Office (COCO) is responsible for Morgan Stanley Europe SE's outsourcing governance framework and acts as the firm's independent second line of defense for outsourcing risk management. The team works closely with business units, support functions and legal entities across Europe to ensure compliance with internal policies and regulatory requirements, including EBA Outsourcing Guidelines, DORA and other applicable outsourcing regulations. Responsibilities Supporting the maintenance and development of the firm’s outsourcing framework and governance processes. Providing guidance to business units and support functions on outsourcing requirements and regulatory expectations. Performing reviews and testing of outsourcing controls, monitoring activities and regulatory compliance requirements. Coordinating outsourcing risk assessments and reviewing submissions from business and support functions. Maintaining and enhancing outsourcing inventories, data repositories and supporting documentation. Driving data quality initiatives and performing analyses to identify inconsistencies, gaps and improvement opportunities. Designing and implementing automation solutions to improve reporting, monitoring and inventory management processes. Developing dashboards, management information and reporting for senior management and governance forums. Delivering training and awareness sessions on outsourcing requirements and governance obligations. Supporting regulatory initiatives, audits and strategic projects related to outsourcing and third-party risk management. Skills and Experience Strong analytical and problem-solving skills. Excellent organizational skills and attention to detail. Strong written and verbal communication skills. Ability to manage multiple priorities in a fast-paced environment. Experience using Excel, Power BI, Power Query, Power Automate or similar tools, including AI tools such as Claude and ChatGPT, to support process automation. Interest in regulatory topics, operational risk and outsourcing governance. Ability to collaborate effectively with stakeholders across functions. Self-motivated, proactive and results-oriented. #LI-CM1 WHAT YOU CAN EXPECT FROM MORGAN STANLEY: At Morgan Stanley, we raise, manage and allocate capital for our clients – helping them reach their goals. We do it in a way that’s differentiated – and we’ve done that for 90 years. Our values - putting clients first, doing the right thing,
Full responsibilities and requirements are on Morgan Stanley's application page.
Apply for this job →Location and market context
This job is based in Frankfurt, Germany on-site. Local candidates benefit from being close to Morgan Stanley's teams and regional hiring market. Confirm the exact in-office expectation and any relocation support with the employer.
About third-party risk jobs
Third-party and vendor risk teams assess and monitor the security, privacy, and compliance posture of suppliers, an area under sharp regulatory and operational focus as AI vendors proliferate. Jobs like this one are typically evaluated against frameworks such as third-party risk frameworks, SOC 2, ISO/IEC 27001, and vendor due-diligence and monitoring practices.
How to position yourself for this third-party risk job
Strong candidates emphasize vendor due diligence and assessment, ongoing monitoring, contract and control requirements, and coordinating across security, privacy, and procurement. In your resume and outreach, tie your experience to how Morgan Stanley would apply third-party risk frameworks, SOC 2, ISO/IEC 27001, and vendor due-diligence and monitoring practices, and lead with concrete outcomes rather than duties.
Similar GRC jobs
More GRC jobs: All GRC jobs · Search by category & location