The pathway
How you actually get there, here
How you become one varies far more by country than what one does. This is the UK route. Most people take one of these ways in; the right one depends on where you're starting from.
- 1
Risk Control Manager (L5) in a large organisation
Typically 3-5 years at L5, demonstrating strong functional leadership and strategic influence.Skills to master
- Mastering functional P&L management, building and leading high-performing teams, developing and implementing divisional risk strategies, and confidently presenting to senior leadership.
You're ready to move on when
- Successfully led a significant operational risk transformation programme from end-to-end.
- Consistently received positive feedback from C-Suite stakeholders on your strategic insights and influence.
- Developed and mentored multiple team members into more senior roles.
- Owned and significantly improved the operational risk profile for a major business division.
- 2
Head of Internal Audit (Operational Focus)
Around 5-7 years as Head of Internal Audit, with a strong focus on operational audits.Skills to master
- Deep understanding of control effectiveness, governance frameworks, independent assurance, and influencing business leaders to remediate issues. Translating audit findings into proactive risk mitigation strategies.
You're ready to move on when
- Successfully managed relationships with the Audit Committee and external auditors.
- Demonstrated ability to drive significant improvements in control environments through audit recommendations.
- Built a reputation for objective, insightful, and commercially aware audit leadership.
- 3
Senior Operations Leader (with strong risk focus)
Roughly 5-7 years in a senior operational leadership role (e.g., Head of Logistics, Head of Manufacturing) where you've had direct accountability for risk management.Skills to master
- Hands-on experience managing complex operations, deep process knowledge, P&L responsibility, and a demonstrated ability to embed risk management directly into operational processes. You'll need to develop a more formal risk framework understanding.
You're ready to move on when
- Successfully managed significant operational risks within your own function, preventing major incidents.
- Implemented new operational processes that significantly improved control and reduced risk.
- Demonstrated a natural aptitude for identifying and mitigating systemic operational vulnerabilities.