The pathway
How you actually get there, here
How you become one varies far more by country than what one does. This is the UK route. Most people take one of these ways in; the right one depends on where you're starting from.
- 1
Director/VP of Global Compliance
You'd usually spend 5-10 years in this type of role, leading a significant part of the compliance function in a large multinational.Skills to master
- Mastering enterprise-wide risk assessments, managing complex regulatory investigations, building and leading large global teams, and developing robust compliance programmes for specific business units or regions.
You're ready to move on when
- Successfully navigated a major regulatory audit or investigation with a positive outcome.
- Consistently delivered measurable reductions in compliance risk for your area of responsibility.
- Built and retained a high-performing compliance team, with strong succession planning in place.
- Regularly presented to and influenced executive leadership on compliance matters.
- 2
General Counsel / Chief Legal Officer
Often 7-12 years in a senior legal leadership role, potentially as a Deputy GC or CLO of a smaller entity.Skills to master
- Deep legal expertise, particularly in corporate law, regulatory affairs, and litigation. Experience advising the board on legal risks, managing external counsel, and shaping legal strategy. Understanding how legal advice translates into practical business operations.
You're ready to move on when
- Successfully managed significant corporate litigation or regulatory enforcement actions.
- Provided critical legal advice during M&A activities or major business transformations.
- Demonstrated ability to balance legal risk with commercial objectives.
- Built strong relationships with external legal partners and regulatory bodies.
- 3
Chief Risk Officer (CRO) or Head of Enterprise Risk Management
Typically 5-10 years in a senior risk management role, overseeing a broad portfolio of risks.Skills to master
- Developing and implementing enterprise-wide risk frameworks, quantitative risk modelling, reporting to the board on aggregated risk exposure, and integrating diverse risk types (operational, financial, strategic, compliance).
You're ready to move on when
- Successfully implemented a new ERM framework across a complex organisation.
- Provided actionable insights to the board that led to significant risk mitigation.
- Proven ability to articulate complex risk scenarios in a clear, concise manner to non-experts.
- Built a strong reputation for proactive risk identification and management.