The pathway
How you actually get there, here
How you become one varies far more by country than what one does. This is the UK route. Most people take one of these ways in; the right one depends on where you're starting from.
- 1
Director of Quality & Compliance (L6)
3-5 years as a DirectorSkills to master
- Mastering business unit P&L impact, board reporting for specific functions, leading large teams (25-100+), and integrating compliance into business strategy. You'll need to demonstrate the ability to influence at a senior executive level and manage significant regulatory engagements.
You're ready to move on when
- Consistently achieving 100% first-time pass rates for certifications within your business unit.
- Successfully reducing regulatory fines or major non-conformances by >25% year-on-year.
- Positive feedback from the CEO/Board on your presentations and strategic insights.
- Proven ability to lead and develop a high-performing team of Directors and Managers.
- 2
General Counsel / Chief Legal Officer (with Compliance oversight)
5-7 years in a General Counsel roleSkills to master
- Developing deep expertise in corporate law, litigation management, and enterprise-wide legal risk. You'll need to expand your understanding of operational compliance beyond legal interpretation, focusing on practical implementation and cultural integration, often taking on direct responsibility for the compliance function.
You're ready to move on when
- Successfully advised the Board on complex legal and regulatory matters with significant business impact.
- Demonstrated ability to build and manage a robust legal and compliance framework.
- Proven leadership in navigating major legal challenges or regulatory investigations.
- Strong understanding of operational processes and the ability to translate legal requirements into practical compliance controls.
- 3
Chief Risk Officer (CRO)
4-6 years as a CRO in a mid-sized organisationSkills to master
- Broadening your risk management expertise beyond compliance to include financial, operational, strategic, and technological risks. You'll need to demonstrate the ability to design and oversee an integrated enterprise risk management framework across all risk domains, with compliance as a core component.
You're ready to move on when
- Successfully implemented an integrated ERM framework that demonstrably reduced overall enterprise risk exposure.
- Proven ability to present a holistic risk picture to the Board and influence strategic risk decisions.
- Strong analytical skills to quantify and prioritise diverse risk types.
- Experience in leading cross-functional risk mitigation initiatives.