The pathway
How you actually get there, here
How you become one varies far more by country than what one does. This is the UK route. Most people take one of these ways in; the right one depends on where you're starting from.
- 1
Director/VP, Global Integrated Management Systems
5-8 years at this levelSkills to master
- Mastering the strategic integration of multiple ISO standards, leading large global teams, and consistently delivering measurable improvements in compliance and quality performance across diverse business units. You'll need to prove you can manage complexity at scale.
You're ready to move on when
- Successfully led a major enterprise-wide certification programme (e.g., ISO 27001 across all sites).
- Consistently achieved zero major non-conformances in external audits for your remit.
- Built and developed a high-performing team of senior compliance and quality professionals.
- Regularly presented to and influenced the Executive Leadership Team on strategic compliance matters.
- 2
General Counsel / Head of Legal & Compliance
7-10 years at this levelSkills to master
- Developing a deep understanding of regulatory enforcement, legal risk management, and corporate governance from a legal perspective. You'll need to broaden your expertise beyond legal compliance to encompass operational quality and safety systems.
You're ready to move on when
- Successfully navigated complex regulatory investigations or legal challenges.
- Established robust legal compliance frameworks across multiple jurisdictions.
- Demonstrated strong commercial acumen alongside legal expertise.
- Built a reputation for pragmatic, solution-oriented legal advice that enables business growth responsibly.
- 3
Chief Risk Officer (CRO)
6-9 years at this levelSkills to master
- Developing and managing a holistic enterprise risk management framework that encompasses financial, operational, strategic, and reputational risks. You'll need to deepen your specific knowledge of quality and safety management systems.
You're ready to move on when
- Successfully implemented an enterprise-wide risk appetite framework.
- Consistently provided actionable risk intelligence to the Board and Executive Team.
- Demonstrated ability to integrate diverse risk types into a single, cohesive view.
- Led crisis management efforts for significant business risks.