There is a moment every GRC leader knows. The deal is attractive, the client is significant, the front office is confident, and the room turns to you. What you say next will either be remembered as sound judgement or resented as obstruction — and often you will not know which for years. That moment, repeated hundreds of times across a career, is the real job. Everything else — the frameworks, the policies, the committee papers — exists to prepare you for it.
I want to write here about what actually makes a GRC leader effective, because I think the standard picture is incomplete. The standard picture emphasises technical knowledge: mastery of the regulations, fluency in FINMA circulars, deep understanding of AML typologies. All of that is necessary. None of it is sufficient. I have known brilliant technicians whose advice was never sought, and I have watched less encyclopaedic colleagues shape the risk culture of entire institutions. The difference between them was never knowledge. It was something harder to teach.
Credibility is earned in the business, not in the function
The single biggest determinant of a GRC leader's effectiveness is whether the business believes you understand their world. Not tolerates you. Not respects your title. Believes — genuinely — that you understand what it takes to win a client, build a book, hit a revenue target, and survive a difficult market.
This is where a path through C-level business roles changes everything about how one works. When you have carried commercial responsibility yourself — when you have been the one accountable for the number — you speak to the front office differently. You stop saying "the regulation requires" and start saying "here is how we get this done within the rules, and here is where the genuine line is." The first phrasing creates an opponent. The second creates a partner.
For GRC leaders who have grown up entirely within the function, my advice is simple and unfashionable: spend time in the business. Sit with relationship managers. Join client meetings as an observer. Understand the pipeline, the pressure, the economics of the desk. Every hour spent understanding the commercial reality of your institution pays back tenfold in the authority of your advice. Compliance officers who understand the business are listened to. Those who do not are routed around.
The art of the useful "no"
A GRC leader who says yes to everything is useless. A GRC leader who says no to everything is worse — because the business stops asking, and the risks go underground. The craft lies in the territory between.
Over the years I have developed a personal discipline around difficult answers: never deliver a "no" without a path. If a proposed structure does not work, what structure would? If this client cannot be onboarded as presented, what additional information or conditions would change the assessment? If the answer is genuinely and finally no — and sometimes it is — then explain the reasoning fully enough that the person across the table could explain it to their own team. People accept decisions they understand far more readily than verdicts they merely receive.
"The compliance function that only says no will eventually not be asked. The risks do not disappear — they simply stop being visible."
There is a deeper point here about what the "no" is for. Junior compliance officers sometimes believe their job is to prevent things. It is not. The job is to ensure the institution takes the risks it intends to take, with open eyes, within its stated appetite — and avoids the risks it never intended to accept. That framing changes the daily posture of the function from gatekeeping to navigation. Navigators are welcome on the bridge. Gatekeepers are avoided.
Managing upward: the board deserves your honesty, not your comfort
One of the least discussed skills in GRC leadership is the management of the relationship with the board and senior management. It is tempting — deeply, humanly tempting — to present the compliance picture in its best light. The programme is on track. The findings are being remediated. The metrics are green. Everyone in the room relaxes, and you are seen as someone who has things under control.
I learned early that this comfort is borrowed, and the interest rate is punishing. The moment a regulator, an auditor or an incident reveals a picture different from the one you painted, your credibility — the only real currency a GRC leader holds — is spent. And credibility, once spent with a board, is very hard to rebuild.
The alternative is a discipline of calibrated honesty. Tell the board what is working, what is not, what worries you, and what you are doing about it. Present the open items alongside the closed ones. When you do not know something, say so, and say when you will know. In my experience, boards do not lose confidence in leaders who bring them problems. They lose confidence in leaders whose problems arrive by surprise.
Your team is your legacy
A GRC function is only ever as strong as the people in it, and the people in it are shaped — more than any policy or training programme — by how they are led. The compliance officers who worked for you will carry your standards, your habits and your example into every institution they touch for the rest of their careers. That is a sobering thought, and it should be.
Three things matter most in building a strong GRC team. The first is protection: your people must know that when they raise an uncomfortable finding or hold a difficult line, you will stand behind them — visibly, and especially when it is costly. A team that has watched its leader absorb pressure on its behalf will do fearless work. A team that has watched its leader deflect that pressure downward will learn to soften its findings, and the function will quietly weaken.
The second is development. GRC work can become narrow if leaders let it — the same reviews, the same reports, year after year. The best people leave narrow roles. Rotate your team through different risk domains, put them in front of the board, send them into the business, give them the stretch project that frightens them slightly. The function becomes stronger and so do they.
The third is honesty about the work itself. GRC has difficult days: the finding nobody wants to hear, the escalation that strains relationships, the remediation that consumes a quarter. Pretending otherwise helps no one. What sustains people through those days is the conviction that the work matters — that a well-governed institution is genuinely safer for its clients, its employees and the financial system. I have found that conviction is not naïve. It is the truest thing about this profession, and leaders should say it out loud more often.
The quiet influence
If I had to compress two decades of GRC leadership into a single observation, it would be this: the most effective compliance and risk leaders I have known were rarely the loudest people in the institution. Their influence worked differently. It accumulated — through years of sound judgement, commercial understanding, honest reporting and protected teams — until their view carried weight not because of their title but because of their track record. When they expressed concern, projects paused. When they were comfortable, boards were comfortable.
That kind of authority cannot be demanded and cannot be delegated. It is built one decision, one honest conversation, one difficult moment at a time. It is slow work. It is also, I have come to believe, the real substance of leadership in this profession — and the reason that, all these years later, I still find the compliance department a far more interesting place than anyone dreams it will be.