The pathway
How you actually get there, here
How you become one varies far more by country than what one does. This is the UK route. Most people take one of these ways in; the right one depends on where you're starting from.
- 1
Lead Operational Risk Manager (Level 4)
3-5 years in roleSkills to master
- End-to-end ownership of a major operational risk programme for a business unit, leading complex incident investigations, and effectively influencing senior business stakeholders without direct authority.
You're ready to move on when
- Consistently exceeding targets for risk reduction and control effectiveness in your previous role.
- Demonstrable experience mentoring junior team members and taking on informal leadership responsibilities.
- Proactive identification and successful mitigation of significant, previously unknown risks.
- Strong positive feedback from senior business unit leaders on your ability to partner and deliver.
- 2
Head of Risk (Smaller Organisation/Start-up)
2-4 years in roleSkills to master
- Building a risk management function from the ground up, managing all aspects of enterprise risk, and presenting directly to executive leadership and boards.
You're ready to move on when
- Successfully scaled a risk function during a period of rapid growth.
- Proven ability to operate strategically with limited resources.
- Strong grasp of the full spectrum of enterprise risks, not just operational.
- Experience navigating regulatory scrutiny in a dynamic environment.
- 3
Senior Manager, Internal Audit (Operations Focus)
4-6 years in roleSkills to master
- Deep understanding of control testing, audit methodologies, and reporting to audit committees. Transitioning from identifying issues to owning their mitigation.
You're ready to move on when
- Consistently delivering 'green' audit reports for your areas of responsibility.
- Strong ability to identify systemic control weaknesses and recommend practical solutions.
- Demonstrable experience influencing business units to implement audit recommendations.
- A desire to move from assurance to direct risk ownership and management.