The assumption that compliance is a lawyer's job is the main reason people never look at it, and it is wrong most of the time. Legal teams interpret the rules. Compliance teams build the processes, controls, evidence and training that show the rules are being followed, then investigate what happens when they are not.
That is process design, evidence gathering and negotiation — closer to operations or audit than to litigation. The hiring pattern reflects it: walk into a large compliance function and you will find former auditors, analysts, operations managers and police officers alongside a minority of lawyers.
The five areas hiring hardest
Data protection and privacy
Driven by GDPR in the EU and UK, the patchwork of US state privacy laws, and equivalents across Asia-Pacific and Latin America. The work is data mapping, impact assessments, subject access requests, vendor review and breach response. Understanding how systems store data is worth more here than legal training.
Financial crime
Anti-money-laundering, sanctions screening, fraud and know-your-customer processes. The largest employer of compliance staff and the easiest to enter, because banks, payments firms and crypto businesses hire analysts in volume. The trade-off is repetitive alert review at entry level; the interesting work starts two or three years in.
AI governance
The newest area, and nobody has ten years of experience in it, which is the opportunity. The EU AI Act, sectoral regulators and internal model-risk policies have created demand for people who can inventory models, assess them against a framework and run an approval process. Data protection, model risk and product management transfer directly.
Supply-chain due diligence
Forced labour rules, modern slavery reporting, conflict minerals, sanctions exposure and the EU and German due diligence regimes. The work is supplier questionnaires, audit programmes and remediation. Procurement backgrounds transfer one for one.
Sustainability reporting
Gathering and reporting environmental and social data to an increasingly assurance-grade standard. This has shifted from a communications activity to a controls activity, which is why finance and audit people are being pulled into it.
Which backgrounds transfer
The filter is simple: compliance hires people who understand a process well enough to see where it breaks.
- Audit and accounting. The strongest transfer of all. You already think in controls, evidence and testing.
- Operations and process management. You know where the shortcuts are and who takes them, which is most of the job.
- Procurement and supply chain. A direct route into third-party risk and due diligence.
- Data, analytics and engineering. Increasingly sought for privacy, AI governance and transaction monitoring, where the bottleneck is understanding the data.
- Customer operations and complaints handling. An underrated entry into conduct compliance.
- Investigative backgrounds — policing, regulatory bodies, journalism — for financial crime and internal investigations.
The certifications that matter
Certifications here are a filter, not a qualification: they get you read, not hired. Choose one aligned to a specific area rather than collecting several.
- Privacy. The IAPP certifications, with separate European and US variants — pick the one matching your market.
- Financial crime. ACAMS is the most widely recognised anti-money-laundering credential internationally; ICA qualifications carry weight in the UK, the Middle East and parts of Asia.
- Audit and risk. The IIA's internal audit certification; ISACA's credentials for technology-adjacent roles.
- Security and AI. ISO 27001 lead implementer or auditor training; ISO 42001 has become the reference point for AI management systems.
- Sustainability reporting. Still unsettled, so demonstrable experience counts for more than any badge.
Most take one to six months part-time — a reasonable investment alongside a job, and a poor substitute for finding compliance-adjacent work inside your existing role.
The fastest realistic route
Do not start with a certification. Start by volunteering for the compliance-adjacent work already in your current job: the vendor questionnaire, the access review, the incident write-up, the audit response. Six months of that plus one targeted certification makes a credible internal move, and an internal move is by far the most common way people enter compliance.
What the work is actually like
Two things surprise people. The first is how much is persuasion. You will spend more time convincing a product team to change a design, or a sales director to accept slower onboarding, than reading regulation. Compliance staff who cannot negotiate get routed around, and a function that is routed around fails quietly until it fails loudly.
The second is how much is writing. Policies, procedures, assessments, board reports, regulator responses. If the record does not exist, the control did not happen — that is the operating assumption of every auditor you will meet. People who dislike writing find the job wearing.
There is also a pressure dynamic worth knowing. Compliance sits between commercial pressure and regulatory obligation, and there are moments where the answer has to be no. That takes a tolerance for being unpopular and an employer that backs the function — worth probing at interview.
The best compliance people are not the strictest. They are the ones who can find the version of the process that is both permitted and workable, and get the business to adopt it.
Progression and where the money is
Analyst to senior analyst to manager to head of function is the standard shape, typically eight to twelve years end to end. Pay rises steeply with regulatory exposure: roles carrying a personal regulatory responsibility, or sitting in a firm under supervision, pay well above generalist policy roles.
Specialisation separates the two halves of the market. A generalist compliance manager is replaceable; someone who understands sanctions screening, model governance or cross-border data transfers is not.