The pathway
How you actually get there, here
How you become one varies far more by country than what one does. This is the UK route. Most people take one of these ways in; the right one depends on where you're starting from.
- 1
Internal Audit (Mid-Level)
3-5 yearsSkills to master
- End-to-end execution of audit sections, drafting clear findings, basic data analysis, understanding of COSO and IIA standards.
You're ready to move on when
- Consistently delivering assigned audit tasks on time and with high quality.
- Proactively identifying control weaknesses and suggesting practical solutions.
- Building good working relationships with auditees and the audit team.
- Taking initiative to learn new systems and processes.
- 2
External Audit (Big Four / Mid-Tier Firm)
3-5 years (post-qualification)Skills to master
- Financial statement audit methodologies, SOX compliance testing, client relationship management, working under tight deadlines, managing junior teams.
You're ready to move on when
- Achieved professional qualification (e.g., ACA, ACCA).
- Led audit engagements as a Senior Associate or Assistant Manager.
- Strong understanding of financial reporting risks and controls.
- Ability to manage multiple client engagements simultaneously.
- 3
Risk & Compliance Specialist
4-6 yearsSkills to master
- Deep knowledge of specific regulatory frameworks, risk assessment methodologies, control design, policy development, and compliance monitoring.
You're ready to move on when
- Experience designing or implementing control frameworks.
- Strong understanding of a particular regulatory domain (e.g., GDPR, MiFID II).
- Ability to translate regulatory requirements into practical business controls.
- Experience working with business units to manage risk.