The pathway
How you actually get there, here
How you become one varies far more by country than what one does. This is the UK route. Most people take one of these ways in; the right one depends on where you're starting from.
- 1
Head of Risk Governance (Large Business Unit)
Direct moveSkills to master
- Deepening strategic oversight, managing larger teams, enhancing executive committee engagement, and driving significant P&L impact through risk reduction. You're already doing most of this, but at a slightly smaller scale.
You're ready to move on when
- Proven track record of success in a similar role at a slightly smaller scale or scope.
- Strong references from previous C-suite or board-level interactions.
- Demonstrated ability to lead and develop a high-performing team.
- Clear vision for how to elevate risk governance within our business unit.
- 2
Senior Manager, Internal Audit (Large Organisation)
1-2 yearsSkills to master
- Transitioning from assurance (3rd line) to strategic oversight and framework ownership (2nd line). This means moving from identifying issues to designing the solutions and influencing their implementation. You'll need to develop a more proactive, forward-looking risk management mindset.
You're ready to move on when
- Extensive experience in auditing risk management processes and controls.
- Strong understanding of risk governance frameworks from an auditor's perspective.
- Demonstrated ability to influence and advise senior management on risk matters.
- A clear desire to move into a 'builder' role rather than purely 'assurer'.
- 3
Director of Compliance (Large Business Unit)
1-2 yearsSkills to master
- Broadening your scope beyond pure compliance to encompass operational, strategic, and financial risks. You'll need to develop a more holistic ERM perspective, integrating compliance into a wider risk framework.
You're ready to move on when
- Deep expertise in regulatory compliance within a relevant industry.
- Experience managing compliance teams and programmes for a significant business unit.
- Strong understanding of how compliance failures translate into broader business risks.
- A strategic mindset focused on risk prevention and resilience, not just rule adherence.