The pathway
How you actually get there, here
How you become one varies far more by country than what one does. This is the UK route. Most people take one of these ways in; the right one depends on where you're starting from.
- 1
Senior Risk Governance Officer (Internal Promotion)
3-5 years as a Senior OfficerSkills to master
- Deep expertise in one or two specific risk domains, proven ability to lead complex risk assessments independently, strong stakeholder engagement skills, and informal mentorship experience.
You're ready to move on when
- Successfully led multiple end-to-end RCSA cycles for significant business units.
- Consistently provided high-quality challenges to first-line risk assessments.
- Developed and implemented new KRIs that proved effective.
- Acted as a go-to person for junior colleagues and provided effective guidance.
- 2
Risk Consultant (External Hire)
5-8 years in risk consultingSkills to master
- Experience across multiple industries, strong project management skills, ability to quickly understand new business contexts, and a track record of designing and implementing risk frameworks for clients.
You're ready to move on when
- Managed client engagements focused on ERM or GRC implementation.
- Presented strategic risk advice to C-suite level clients.
- Developed and delivered training on risk management principles.
- Proven ability to manage project teams and deliverables.
- 3
Senior Internal Auditor (External Hire)
7-10 years in internal auditSkills to master
- Deep understanding of control environments, experience in testing control effectiveness, strong analytical skills, and a good grasp of risk-based audit planning. You'll need to shift from assurance to framework design.
You're ready to move on when
- Led complex internal audit engagements, including risk-based audits.
- Demonstrated ability to identify and assess control weaknesses.
- Strong report writing skills for executive audiences.
- Experience in making recommendations for control improvements.