The pathway
How you actually get there, here
How you become one varies far more by country than what one does. This is the UK route. Most people take one of these ways in; the right one depends on where you're starting from.
- 1
Senior Risk Analyst (CQHS)
3-5 years as a Senior AnalystSkills to master
- Leading complex, multi-site risk assessments, facilitating Root Cause Analysis sessions, mentoring junior colleagues, and presenting findings to mid-level management. You'll need to be a recognised subject matter expert.
You're ready to move on when
- Consistently leads assessments with minimal supervision.
- Proactively identifies and proposes improvements to assessment methodologies.
- Successfully mentors 1-2 junior team members.
- Receives positive feedback from business stakeholders on assessment quality and usefulness.
- 2
Specialist in a Specific Risk Domain (e.g., Environmental Risk Lead, Process Safety Engineer)
5-8 years in a specialist roleSkills to master
- Deep expertise in a particular area of risk (e.g., environmental compliance, process safety engineering, supply chain risk), including relevant regulations and technical assessment methods. You'll need to broaden your scope to enterprise-wide thinking.
You're ready to move on when
- Recognised as the go-to expert for a specific risk domain.
- Successfully translated specialist risks into broader business implications.
- Demonstrated ability to influence cross-functional teams on domain-specific risk mitigation.
- Expressed interest in taking on broader risk programme management responsibilities.
- 3
Internal Audit Manager (with C_Q_H_S focus)
4-6 years as an Internal Audit ManagerSkills to master
- Strong understanding of internal controls, audit methodologies, and reporting to audit committees. You'll need to shift from an assurance mindset to a proactive risk identification and mitigation role, and develop a deeper understanding of operational processes.
You're ready to move on when
- Led complex operational or compliance audits.
- Successfully identified significant control weaknesses and recommended practical improvements.
- Strong understanding of the 'Three Lines of Defence' model from an assurance perspective.
- Demonstrated ability to communicate audit findings and recommendations to senior management.