The pathway
How you actually get there, here
How you become one varies far more by country than what one does. This is the UK route. Most people take one of these ways in; the right one depends on where you're starting from.
- 1
Global Compliance Director / Head of Function
5-10 years to CCOSkills to master
- Leading multi-jurisdictional teams, managing significant programme budgets, developing and implementing enterprise-wide compliance programmes, regular executive reporting, and crisis management.
You're ready to move on when
- Successfully led a major global compliance programme (e.g., anti-corruption, data privacy) end-to-end.
- Consistently delivered impactful presentations and recommendations to executive leadership.
- Proven ability to build and motivate high-performing teams across different geographies.
- Demonstrated strategic thinking in anticipating and mitigating emerging risks.
- 2
General Counsel / Deputy General Counsel
7-12 years to CCO (often dual-hatted roles)Skills to master
- Deep legal expertise, managing external legal counsel, litigation management, corporate governance, and a strong understanding of regulatory enforcement actions. Often involves a transition to a more dedicated compliance focus.
You're ready to move on when
- Successfully managed complex legal matters with significant compliance implications.
- Provided strategic legal advice to the Board and executive team on regulatory risks.
- Demonstrated ability to build strong relationships with legal and regulatory stakeholders.
- Proven capacity to integrate legal risk management with broader compliance objectives.
- 3
Chief Audit Executive (CAE) / Head of Internal Audit
8-15 years to CCOSkills to master
- Expertise in internal controls, risk assessment methodologies, forensic auditing, and independent assurance. Requires developing a stronger focus on proactive programme design and regulatory engagement.
You're ready to move on when
- Successfully led a global internal audit function, providing independent assurance to the Audit Committee.
- Demonstrated ability to identify systemic control weaknesses and recommend effective remediation.
- Strong understanding of enterprise-wide risk management frameworks.
- Proven track record of influencing business leaders to improve control environments.