The pathway
How you actually get there, here
How you become one varies far more by country than what one does. This is the UK route. Most people take one of these ways in; the right one depends on where you're starting from.
- 1
Director/VP of Quality & Regulatory Affairs
5-10 years in this role before CCOSkills to master
- Deep expertise in specific industry regulations, managing large multi-site teams, P&L management for a significant function, strong executive presence, and a proven ability to influence business unit strategy.
You're ready to move on when
- Successfully led a major regulatory remediation project or achieved a critical certification for a business unit.
- Consistently delivered strong financial results for their function, demonstrating fiscal responsibility.
- Recognised internally as a trusted advisor to business unit heads and senior leadership.
- Developed and mentored a strong pipeline of talent within their department.
- 2
General Counsel / Head of Legal (with Compliance focus)
7-12 years in this role before CCOSkills to master
- Comprehensive understanding of corporate law, litigation management, enterprise-wide legal risk assessment, and experience in building and managing a robust compliance programme from a legal perspective. Requires a shift from purely legal advice to operational and strategic oversight.
You're ready to move on when
- Successfully navigated complex legal challenges with significant compliance components.
- Demonstrated ability to translate legal requirements into practical business processes.
- Built strong relationships with regulatory bodies and external legal counsel.
- Proactively identified and mitigated legal risks that had significant business implications.
- 3
Chief Risk Officer (CRO)
3-7 years in this role before CCO (often a lateral move, or CCO reports to CRO)Skills to master
- Expertise in enterprise risk management frameworks (operational, financial, strategic, compliance), quantitative risk modelling, and reporting to the Board on overall risk posture. The CCO role is often a specialisation within the broader CRO remit.
You're ready to move on when
- Successfully implemented or significantly improved an enterprise-wide risk management framework.
- Provided clear, actionable risk insights to the Board and executive team.
- Demonstrated the ability to integrate different risk types (e.g., financial, operational, compliance) into a holistic view.
- Proven track record of influencing strategic decisions based on robust risk analysis.