The pathway
How you actually get there, here
How you become one varies far more by country than what one does. This is the UK route. Most people take one of these ways in; the right one depends on where you're starting from.
- 1
Director/VP of Energy Compliance (Large Global Organisation)
5-10 years at this level before CCROSkills to master
- Mastering enterprise-level programme management, leading large-scale incident responses, managing multi-jurisdictional regulatory relationships, and consistently reporting to executive leadership. You'll need to demonstrate the ability to influence across diverse business units and geographies.
You're ready to move on when
- Successfully led a major regulatory enforcement action to a favourable outcome.
- Developed and implemented a new enterprise-wide compliance programme that significantly reduced risk.
- Consistently received positive feedback from the CEO and Board on strategic advice and reporting.
- Built and mentored a high-performing team that delivered measurable improvements in compliance performance.
- 2
General Counsel / Head of Legal & Compliance (Large Energy Company)
5-10 years at this level before CCROSkills to master
- Deepening legal expertise in corporate governance, regulatory law, and litigation, while also gaining significant experience in compliance programme design and implementation. You'll need to demonstrate the ability to integrate legal strategy with compliance objectives at an enterprise level.
You're ready to move on when
- Successfully managed complex legal disputes with significant compliance implications.
- Advised the Board on critical legal and regulatory risks impacting strategic decisions.
- Demonstrated leadership in integrating legal and compliance functions for greater effectiveness.
- Built a strong reputation as a trusted legal and compliance advisor to the executive team.
- 3
Head of Enterprise Risk Management (ERM) (Large Financial or Industrial Company)
7-12 years at this level before CCROSkills to master
- Developing deep expertise in all facets of enterprise risk management, including strategic, operational, financial, and reputational risks, across a complex organisation. You'll need to demonstrate the ability to build and embed a robust risk culture and framework that informs strategic decision-making, with a strong understanding of regulatory compliance.
You're ready to move on when
- Successfully designed and implemented a new ERM framework that demonstrably improved risk intelligence.
- Consistently presented comprehensive risk reports and strategic recommendations to the Board.
- Demonstrated ability to integrate diverse risk categories (including compliance) into a holistic view.
- Led significant risk mitigation initiatives that protected organisational value.