The pathway
How you actually get there, here
How you become one varies far more by country than what one does. This is the UK route. Most people take one of these ways in; the right one depends on where you're starting from.
- 1
Senior Risk Governance Officer (L3)
3-5 years as Senior OfficerSkills to master
- Mastering end-to-end project leadership for risk workstreams, developing strong stakeholder influencing skills, and informally mentoring junior colleagues. You'd be consistently delivering high-quality risk assessments and challenging the first line effectively.
You're ready to move on when
- Consistently exceeding expectations in your Senior Officer role, taking on the most complex projects.
- Demonstrable ability to influence senior business leaders and manage challenging conversations.
- Proactively taking on informal leadership roles, such as training new hires or leading cross-functional initiatives.
- Strong feedback from your manager and peers on your leadership potential and ability to drive outcomes.
- 2
Lead Risk Analyst/Manager from another function (e.g., Internal Audit, Compliance, Operations)
5-7 years in a lead role + specific risk experienceSkills to master
- Deepening your understanding of ERM frameworks, GRC platforms, and the 'Three Lines of Defence' model. You'd need to translate your audit/compliance experience into a proactive risk governance mindset, focusing on prevention rather than just detection.
You're ready to move on when
- Proven track record of managing complex projects and leading small teams in your previous role.
- Demonstrable experience in identifying and assessing operational risks, even if not in a formal 'risk' role.
- Strong understanding of control environments and how they operate, ideally from an audit perspective.
- A clear passion for proactive risk management and a desire to build robust frameworks.
- 3
Consultant (Risk & Compliance Advisory)
3-5 years as a Senior ConsultantSkills to master
- Translating theoretical frameworks into practical, implementable solutions within an organisational context. You'd need to adapt to our specific culture and systems, moving from advising to directly owning and managing a function. Building internal credibility is key.
You're ready to move on when
- Extensive experience in advising multiple clients on ERM, GRC, or compliance projects.
- Proven ability to manage client relationships and deliver complex projects on time and budget.
- A desire to move from external advisory to an in-house leadership role, building and owning a programme.
- Strong understanding of various industry best practices and how they can be applied.