The pathway
How you actually get there, here
How you become one varies far more by country than what one does. This is the UK route. Most people take one of these ways in; the right one depends on where you're starting from.
- 1
Senior Systems Auditor (CQHS)
3-5 years as a SeniorSkills to master
- Deep expertise in a specific CQHS domain (e.g., Quality Management Systems, Environmental Reporting), proven ability to lead complex audits end-to-end, and demonstrable mentorship of junior colleagues.
You're ready to move on when
- Consistently delivers high-quality audit reports with minimal review.
- Proactively identifies and proposes solutions for systemic control weaknesses.
- Trusted by business stakeholders as a subject matter expert.
- Successfully mentored 1-2 junior auditors through their first independent audits.
- 2
IT Auditor (with CQHS focus)
5-7 years in IT AuditSkills to master
- Strong understanding of IT General Controls (ITGCs), experience auditing ERP systems (e.g., SAP, Oracle), and a demonstrated interest in applying IT audit principles to operational compliance, quality, or safety systems.
You're ready to move on when
- Has led audits of critical IT systems (e.g., access management, change control).
- Can clearly articulate the business impact of IT control weaknesses.
- Has worked on projects involving integration of IT systems with business processes.
- Expressed a clear desire to specialise in CQHS systems assurance.
- 3
Compliance/Quality/Safety Specialist (with Systems Experience)
6-8 years in a specialist roleSkills to master
- Deep practical experience managing compliance, quality, or safety programmes, combined with a strong understanding of the underlying systems and data. Needs to have developed an audit mindset and a drive for independent assurance.
You're ready to move on when
- Has been responsible for managing a specific CQHS system or process.
- Demonstrates a strong understanding of regulatory requirements and internal controls.
- Has participated in or supported external audits, understanding the auditor's perspective.
- Shows a proactive approach to identifying and mitigating compliance risks.