The pathway
How you actually get there, here
How you become one varies far more by country than what one does. This is the UK route. Most people take one of these ways in; the right one depends on where you're starting from.
- 1
Senior Compliance Officer (L3) to Lead Compliance Officer (L4) to Manager (L5)
Roughly 4-7 years from Senior to ManagerSkills to master
- At the Senior level, it's about leading projects and advising. As a Lead, you're architecting solutions and becoming an SME. To make the jump to Manager, you need to prove you can lead people, own programmes, and influence senior stakeholders effectively, not just on a project-by-project basis.
You're ready to move on when
- Successfully led multiple complex, cross-functional compliance projects.
- Consistently provided high-quality, pragmatic compliance advice to business units.
- Demonstrated informal leadership or mentorship of junior colleagues.
- Taken initiative to improve compliance processes or controls within your area.
- Successfully managed a challenging regulatory interaction or audit finding.
- 2
Compliance Specialist (L4) from another regulated industry
Roughly 1-3 years in a Lead/Specialist role before ManagerSkills to master
- If you're coming from another regulated sector (e.g., insurance, asset management), you'll need to rapidly get up to speed on banking-specific regulations and nuances. The leadership and programme management skills are transferable, but the domain knowledge needs to be solid.
You're ready to move on when
- Quickly assimilated banking-specific regulatory frameworks (e.g., FCA, PRA).
- Successfully applied your specialist knowledge to banking contexts.
- Built credibility with banking stakeholders and demonstrated understanding of their unique challenges.
- Proven ability to lead a team or significant workstream in a new environment.
- 3
Internal Audit or Risk Manager (L4) to Compliance Manager (L5)
Roughly 2-4 years in Audit/Risk before ManagerSkills to master
- Your understanding of controls, risk assessment, and governance will be excellent. The gap to bridge is moving from independent assurance (Audit) or risk identification (Risk) to being the 'owner' of the 2nd Line of Defence – designing and implementing the controls, and advising the business directly.
You're ready to move on when
- Developed a deep understanding of the 2nd Line of Defence's role and responsibilities.
- Demonstrated a proactive, advisory mindset rather than purely assurance/oversight.
- Built strong relationships with compliance professionals and understood their day-to-day challenges.
- Taken on projects that involve designing or improving compliance controls, not just auditing them.