The pathway
How you actually get there, here
How you become one varies far more by country than what one does. This is the UK route. Most people take one of these ways in; the right one depends on where you're starting from.
- 1
Senior Manager, Compliance Monitoring & Testing (from a large firm)
3-5 years at Senior Manager levelSkills to master
- Enterprise-wide programme management, executive reporting and influence, leading multi-functional teams, strategic budget management, and proactive regulatory engagement.
You're ready to move on when
- Successfully led a significant, multi-year compliance monitoring programme from end-to-end.
- Demonstrated ability to present complex findings and recommendations to executive committees.
- Managed a team of at least 15-20 individuals, including other managers.
- Proven track record of influencing business unit heads to implement compliance improvements without direct authority.
- 2
Head of Compliance (from a smaller/mid-sized firm)
2-4 years as Head of ComplianceSkills to master
- Scaling compliance programmes for a larger, more complex organisation, navigating a more intricate internal stakeholder landscape, and managing a larger budget and team.
You're ready to move on when
- Successfully built and managed a full compliance function, including monitoring, for a smaller firm.
- Direct experience engaging with regulators and managing regulatory examinations.
- Developed strong strategic thinking and commercial acumen, balancing compliance with business growth.
- Demonstrated ability to adapt to a more matrixed and politically complex organisational structure.
- 3
Director, Internal Audit (with compliance specialism)
4-6 years at Director level in Internal AuditSkills to master
- Transitioning from a 'Third Line' assurance role to a 'Second Line' oversight and challenge function, developing a more proactive and preventative monitoring mindset, and building deeper relationships with business units.
You're ready to move on when
- Extensive experience leading complex internal audits with a strong focus on regulatory compliance.
- Proven ability to provide robust, independent challenge to senior management.
- Demonstrated understanding of control design and operating effectiveness across various business processes.
- A clear desire to move into a more proactive, risk-shaping role rather than purely retrospective assurance.