The pathway
How you actually get there, here
How you become one varies far more by country than what one does. This is the UK route. Most people take one of these ways in; the right one depends on where you're starting from.
- 1
Director/VP of Compliance or EHSQ (Large Multinational)
5-10 years at this level before CCOSkills to master
- Enterprise-wide programme management, global team leadership, direct Board reporting experience, navigating complex regulatory enforcement actions, and demonstrating strategic influence across business units.
You're ready to move on when
- Successfully led a major compliance programme transformation across multiple regions.
- Consistently delivered clean external audit results for a significant business unit.
- Proven ability to manage and resolve high-profile regulatory issues without significant penalties.
- Recognised internally and externally as a subject matter expert and ethical leader.
- 2
General Counsel / Chief Legal Officer (with strong compliance remit)
5-10 years at this level before CCOSkills to master
- Deep legal expertise in relevant regulatory areas, managing litigation and enforcement, strong understanding of corporate governance, and the ability to build effective partnerships with operational compliance teams.
You're ready to move on when
- Successfully advised the Board on complex legal and regulatory risks for major strategic initiatives.
- Managed significant legal disputes or regulatory inquiries with favourable outcomes.
- Demonstrated ability to translate legal theory into practical, business-focused compliance solutions.
- Possesses a strong network within regulatory and legal circles.
- 3
Chief Risk Officer (CRO)
3-7 years at this level before CCOSkills to master
- Holistic enterprise risk management, quantitative risk modelling, integrating compliance risk into the broader ERM framework, and strong financial acumen.
You're ready to move on when
- Successfully implemented or significantly enhanced an enterprise-wide risk management framework.
- Demonstrated ability to quantify and communicate complex risks to the Board and executive team.
- Proven track record of proactive risk mitigation that directly impacted business resilience.
- Deep understanding of how compliance risks intersect with financial, operational, and strategic risks.