The pathway
How you actually get there, here
How you become one varies far more by country than what one does. This is the UK route. Most people take one of these ways in; the right one depends on where you're starting from.
- 1
Principal Systems Auditor (CQHS) or Senior Manager, GRC
You'd typically spend 3-5 years at the Principal/Senior Manager level, demonstrating consistent leadership and strategic impact.Skills to master
- Mastering enterprise-level programme management, developing a strong executive presence, and building a track record of successful cross-functional GRC initiatives.
You're ready to move on when
- Successfully led a major GRC system implementation or upgrade.
- Consistently delivered high-impact strategic audit or risk assessments.
- Mentored and developed multiple junior leaders within your team.
- Presented strategic recommendations to executive committees with demonstrable buy-in.
- 2
Director of IT Audit or Enterprise Risk Management (from another large organisation)
Often, candidates come from similar Director-level roles in other complex, regulated environments, bringing a fresh perspective and proven leadership.Skills to master
- Adapting your leadership style to a new organisational culture, quickly understanding our specific industry risks, and building rapport with our executive team.
You're ready to move on when
- A strong track record of leading GRC functions in a comparable industry.
- Demonstrable experience in managing large budgets and teams.
- A clear understanding of the nuances of CQHS compliance and risk.
- A network of industry contacts and a reputation for thought leadership.