The assumption that compliance is a lawyer's job is the main reason people never look at it, and it is wrong most of the time. Legal teams interpret the rules. Compliance teams build the processes, controls, evidence and training that show the rules are being followed, then investigate what happens when they are not.
That is process design, evidence gathering and negotiation, closer to operations or audit than to litigation. The hiring pattern reflects it: walk into a large compliance function and you will find former auditors, analysts, operations managers and police officers alongside a minority of lawyers.
The five areas hiring hardest
Data protection and privacy
Driven by the growing patchwork of state privacy laws, led by the California Consumer Privacy Act and followed by laws such as the Colorado Privacy Act, alongside sector rules in health care and finance. The work is data mapping, risk assessments, consumer requests to access, correct or delete their data, vendor review and breach response. Understanding how systems store data is worth more here than legal training.
Financial crime
Anti-money-laundering under the Bank Secrecy Act, sanctions screening, fraud and know-your-customer processes. Among the largest employers of compliance staff and the easiest to enter, because banks, payments firms and crypto businesses hire analysts in volume. The trade-off is repetitive alert review at entry level; the interesting work starts two or three years in.
AI governance
The newest area, and nobody has ten years of experience in it, which is the opportunity. Emerging state laws, sector regulators, voluntary frameworks such as the NIST AI Risk Management Framework and internal model-risk policies have created demand for people who can inventory models, assess them against a framework and run an approval process. Data protection, model risk and product management transfer directly.
Supply-chain due diligence
Forced labor rules, conflict minerals reporting, sanctions exposure and customer audit demands. Under the Uyghur Forced Labor Prevention Act, U.S. Customs and Border Protection presumes goods linked to the Xinjiang region are barred from import unless the importer proves otherwise, and SEC-reporting companies that use tin, tantalum, tungsten or gold necessary to their products must make a reasonable inquiry into where it came from. The work is supplier questionnaires, audit programs and remediation. Procurement backgrounds transfer one for one.
Sustainability reporting
Gathering and reporting environmental and social data to a standard an auditor could test. This has shifted from a communications activity to a controls activity, which is why finance and audit people are being pulled into it.
Which backgrounds transfer
The filter is simple: compliance hires people who understand a process well enough to see where it breaks.
- Audit and accounting. The strongest transfer of all. You already think in controls, evidence and testing.
- Operations and process management. You know where the shortcuts are and who takes them, which is most of the job.
- Procurement and supply chain. A direct route into third-party risk and due diligence.
- Data, analytics and engineering. Increasingly sought for privacy, AI governance and transaction monitoring, where the bottleneck is understanding the data.
- Customer operations and complaints handling. An underrated entry into consumer compliance.
- Investigative backgrounds (law enforcement, regulatory agencies, journalism) for financial crime and internal investigations.
The certifications that matter
Certifications here are a filter, not a qualification: they get you read, not hired. Choose one aligned to a specific area rather than collecting several.
- Privacy. The IAPP's CIPP/US, which covers US privacy laws and regulations, is the usual starting credential for American privacy roles.
- Financial crime. ACAMS's CAMS is an anti-money-laundering credential widely recognized by banks, fintechs and regulators.
- Audit and risk. The IIA's internal audit certification; ISACA's credentials for technology-adjacent roles.
- Security and AI. ISO/IEC 27001 lead implementer or auditor training; ISO/IEC 42001, the international standard for AI management systems, is an emerging reference point.
- Sustainability reporting. Still unsettled, so demonstrable experience counts for more than any badge.
Most take one to six months part-time: a reasonable investment alongside a job, and a poor substitute for finding compliance-adjacent work inside your existing role.
The fastest realistic route
Do not start with a certification. Start by volunteering for the compliance-adjacent work already in your current job: the vendor questionnaire, the access review, the incident write-up, the audit response. Six months of that plus one targeted certification makes a credible internal move, and an internal move is one of the most common ways people enter compliance.
What the work is actually like
Two things surprise people. The first is how much is persuasion. You will spend more time convincing a product team to change a design, or a sales director to accept slower onboarding, than reading regulation. Compliance staff who cannot negotiate get routed around, and a function that is routed around fails quietly until it fails loudly.
The second is how much is writing. Policies, procedures, assessments, board reports, regulator responses. If the record does not exist, the control did not happen. That is the operating assumption of every auditor you will meet. People who dislike writing find the job draining.
There is also a pressure dynamic worth knowing. Compliance sits between commercial pressure and regulatory obligation, and there are moments where the answer has to be no. That takes a tolerance for being unpopular and an employer that backs the function, which is worth probing in the interview.
The best compliance people are not the strictest. They are the ones who can find the version of the process that is both permitted and workable, and get the business to adopt it.
Progression and where the money is
Analyst to senior analyst to manager to head of function is the standard shape, typically eight to twelve years end to end. Pay rises steeply with regulatory exposure: roles with named accountability to regulators, such as the BSA compliance officer a bank's board must designate, or roles in a firm under close supervision, pay well above generalist policy roles.
Specialization separates the two halves of the market. A generalist compliance manager is replaceable; someone who understands sanctions screening, model governance or cross-border data transfers is not.