Guide Contents
UK Corporate Governance Code Provision 29: 2026 Guide
Guide Contents
In Summary
Provision 29 of the UK Corporate Governance Code 2024 requires boards of companies in the UK's commercial companies and closed-ended investment funds listing categories to make a formal declaration in their annual report on whether their material internal controls, covering financial, operational, reporting and compliance activity, were effective at the balance sheet date. The requirement applies to financial years beginning on or after 1 January 2026, so boards with a December year-end are already operating inside the first financial year it covers, even though the declaration itself will not reach an annual report until 2027. The evidence gets built this year; the disclosure follows next year, and the live question isn't whether the requirement applies. It's whether the evidence base being built right now will hold up when the board signs off.
- Provision 29 is already in force: It applies to financial years beginning on or after 1 January 2026, but the first declarations will not reach annual reports until 2027, so 2026 is the year the evidence gets built.
- Boards declare across four control categories: Financial, operational, reporting (including ESG) and compliance controls all need coverage, and the board decides what counts as material.
- There's no external audit sign-off required: Unlike US Sarbanes-Oxley, the board makes its own declaration from evidence it gathers itself.
- The Financial Reporting Council (FRC) has ruled out a template answer: It's confirmed it won't provide wording for the declaration, so boards can't lean on safe, generic phrasing.
- The evidence base has to be built across the year: Boards that leave it to Q4 run out of runway to close gaps before the balance sheet date.
Expert View
|
Matt Davies
Chief Product Officer, SureCloud |
What our experts say about evidence-based Provision 29 declarations
"Most boards can already write a page saying controls are effective. The real test is whether they could answer a follow-up question in the room: which controls, tested how, with what result. Boards that can't answer that in one meeting haven't finished the evidence, just the wording." |
What Provision 29 Requires
The FRC published the updated UK Corporate Governance Code in January 2024. It applies on a comply-or-explain basis: companies state annually how they've complied with the Code, and where they haven't, they explain why. Following the Financial Conduct Authority's (FCA) July 2024 Policy Statement PS24/6, which replaced the old premium and standard listing segments with a single commercial companies category, the Code's reach now extends to every company in the commercial companies and closed-ended investment funds listing categories, well beyond the former premium-listed tier.
The 2024 Code introduced a two-stage timeline. Principle O, which requires boards to maintain and review a risk management and internal control framework, applies to financial years beginning on or after 1 January 2025. Provision 29, the formal declaration requirement, follows a year later for financial years beginning on or after 1 January 2026. Companies already working to Principle O should have a framework in place before their first Provision 29 declaration falls due.
Provision 29 asks boards to do three things: describe how they monitored and reviewed the risk management and internal control framework throughout the year, declare formally whether material controls were effective at the balance sheet date, and disclose any material controls that weren't operating effectively, along with the action taken and progress against anything reported previously.
|
Control category |
What it covers |
|
Financial controls |
Accuracy and reliability of financial reporting |
|
Operational controls |
Key processes underpinning business operations |
|
Reporting controls |
Narrative reporting, including ESG (environmental, social and governance) and sustainability disclosures |
|
Compliance controls |
Adherence to applicable laws and regulations |
The board decides what counts as material, linked to the company's principal risks, business model and stakeholder impact. The FRC doesn't hand boards a checklist, so this is one of the most consequential judgement calls a board makes in 2026.
How This Differs From US SOX
Provision 29 gets compared to the US Sarbanes-Oxley Act (SOX) often enough that the comparison is worth correcting directly. Under SOX, management's assessment of internal controls over financial reporting must be attested by the external auditor. Provision 29 carries no such requirement: the board makes its own declaration from evidence it has gathered through its own monitoring and assurance work, and external auditors aren't required to opine on it. The practical effect is a standard of reasonable assurance, built on a documented evidence base the board compiles itself, which is why the ICAEW has published specific guidance for auditors on what the revised provision changes for their work.
Where Boards Are Struggling in 2026
Provision 29 is a board-level responsibility that boards can't delegate to the compliance team. But the parts that cause the most difficulty in a first declaration are rarely technical. They're judgement calls: what's material, what evidence is enough, and how to write a disclosure that says something real.
Defining "Material" Controls
The FRC doesn't supply a list of controls to cover. Boards decide for themselves, tied to the company's principal risks, business model and the interests of key stakeholders, and that scoping decision needs a documented rationale to survive scrutiny. Most companies engaging with the FRC on this have landed on somewhere between 30 and 50 material controls, with financial-sector firms often naming more, and there's no requirement to match that number or compare against peers. Many boards are scoping their first declaration without any published peer disclosures to benchmark against, since the earliest Provision 29 declarations won't appear until 2027.
Setting an Evidence Standard Before Q4
A board can't declare with confidence unless it's already agreed what counts as sufficient evidence: which controls get tested and how often, what exception thresholds trigger escalation, how issue closure gets verified, and who's accountable for attesting at each level. Skip this agreement and the year-end evidence pack turns out inconsistent, incomplete, or both. Boards that leave the question until the fourth quarter are the ones scrambling in December.
Reconciling the Three Lines of Assurance
The board's view of control effectiveness rests on three different sources of evidence. First-line management attestations come from control owners, second-line monitoring comes from risk and compliance functions, and third-line findings come from internal audit, each in a different format, at a different frequency, often sitting in a different system. Bringing the three together into one coherent picture is the real operational challenge behind Provision 29. Miss the reconciliation between internal audit findings and management attestations, and the board is working from a picture that isn't complete.
Avoiding Boilerplate Language
Generic language draws scrutiny. The FRC has confirmed it will not be providing any wording for declarations, specifically so boards don't default to safe, generic phrasing, and it expects reporting to stay proportionate rather than turn into a box-ticking script. Outcome-focused language, tied to the company's principal risks and risk appetite, is what separates a credible declaration from one that reads like a compliance formality.
Weak: "The board has reviewed the risk management and internal control framework and is satisfied that it is operating effectively."
Stronger: "During the year, the board reviewed the effectiveness of material controls across financial, operational, reporting and compliance categories, testing [X] key controls with [Y]% operating effectively throughout the year. Two controls relating to [specific risk area] needed improvement, with remediation complete by [date], and the board is satisfied that material controls were effective at the balance sheet date."
Specificity over sentiment.
The FRC expects boards to show their working: the process and reasoning behind the view, laid out in enough depth to reflect the evidence sitting behind it. A board that compresses real testing work into a single paragraph hasn't met the spirit of the requirement.
What a Credible Provision 29 Declaration Contains
Boards and governance, risk and compliance (GRC) teams are asking the same question right now: what does a good Provision 29 declaration actually look like? The FRC's guidance is clear on structure, but the quality of early disclosures will vary widely.
- A description of the monitoring and review process: How the board maintained oversight of the risk framework across the year, including reporting cadence, roles involved and assurance activity undertaken.
- A formal declaration on effectiveness: A positive assertion that material controls were, or weren't, effective at the balance sheet date.
- Disclosure of any ineffective controls: What the control was, the action taken or proposed, and progress against anything flagged previously.
- The process used to reach the conclusion: How the board got there: testing results, internal audit findings, management attestations, exception reports.
Provision 29 in Four Phases
Boards that treat Provision 29 as a year-end exercise run out of road. The evidence base for a credible declaration gets built across the full financial year, and the table below reflects emerging practice from FRC guidance and GRC advisers working with FTSE-listed companies.
|
Phase |
Timing |
Key activities |
|
Phase 1 |
Early year |
Define material controls; agree evidence standards and exception thresholds; map assurance lines across first, second and third line. |
|
Phase 2 |
Spring |
Targeted control testing; prioritise controls linked to principal risks; begin remediation of identified weaknesses. |
|
Phase 3 |
Mid-year |
Dry-run declaration with the audit committee; refine the evidence pack; identify gaps needing testing before year-end. |
|
Phase 4 |
Year-end |
Finalise disclosure language; close outstanding remediation; align investor messaging; board sign-off. |
The mid-year dry run in Phase 3 is the step boards skip most often, and it's the one that matters most. Advisers working with boards on Provision 29 readiness see the same pattern repeatedly: rehearsing the declaration with the audit committee while there's still time to test surfaces evidence gaps early. Boards that skip it tend to find those same gaps in the fourth quarter, when the options for fixing them have mostly closed.
Closing the Evidence Gap Across the Three Lines
Most boards already have controls in place. What they lack is reliable, current evidence that those controls are working, because point-in-time testing only ever gives a snapshot. Automated controls suit continuous monitoring; manual controls still need management attestations alongside targeted testing. SureCloud's Continuous Controls Monitoring provides full-population testing data across automated controls in place of sample-based testing, giving boards a continuously updated view of control performance and a 50 to 65% reduction in manual evidence collection.
The three-lines model is the right framework for Provision 29, but most organisations run each line through a separate system: management attestations sitting in email threads or spreadsheets, risk and compliance monitoring in one tool, Internal Audit findings recorded in another. Consolidating that picture manually takes weeks, so the board's assurance map is rarely current. SureCloud connects first-line attestations, second-line risk and compliance monitoring, and Internal Audit findings in a single system, so gaps between lines show up before they become blind spots in the annual declaration. Clients using the platform have cut board report preparation from two weeks to two days, because the underlying data doesn't need re-assembling every time.
Boards building the evidence for their first Provision 29 declaration face three judgement calls that no platform can make for them: which controls are material, what evidence standard is enough, and how to draft disclosure language that meets FRC expectations without overstating or understating the position. SureCloud's advisory team works alongside the platform on exactly these questions, scoping material controls against principal risks, designing evidence standards that are proportionate and defensible, and reviewing draft disclosure language before it reaches the audit committee. That support tends to matter most for boards that are ahead on technology but behind on the calls only the board itself can make.
- Risk-to-control mapping that keeps scope decisions documented and traceable.
- Continuous control testing for automated controls, replacing point-in-time sampling.
- Structured, auditable attestation workflows for first-line management input.
- Integrated Internal Audit findings, recorded in the same system as risk and compliance data so the assurance map stays current.
- Board-ready reporting, generated from live data and ready well ahead of year-end.
See Provision 29 Evidence in One Place
Provision 29 FAQ's
Who does Provision 29 apply to?
Provision 29 applies to companies in the UK's commercial companies and closed-ended investment funds listing categories, which now cover what used to be the premium and standard segments. Companies that opted into the transition category aren't required to comply with the Code. The declaration requirement itself applies to financial years beginning on or after 1 January 2026.
What does the annual declaration of effectiveness actually require?
The board has to describe how it monitored and reviewed the risk management and internal control framework across the year, make a formal declaration on whether material controls were effective at the balance sheet date, and disclose any controls that weren't, along with the action taken and progress against anything reported previously. All three elements need to appear in the annual report.
Can a board choose not to make a Provision 29 declaration?
The Code operates on a comply-or-explain basis under FCA Listing Rule 9.8.6R, and skipping the declaration is a breach of that Listing Rule, which can expose the company to FCA disciplinary action. In practice, the bigger cost is reputational: an unexplained gap on control effectiveness reads as a worse signal to investors than a declaration that discloses genuine weaknesses alongside a credible remediation plan.
How often do internal controls need reviewing?
At least once a year, though many boards review parts of the framework more frequently depending on how the business is changing. Ongoing monitoring throughout the year is what underpins a credible year-end declaration, well beyond a once-a-year check.
What happens if a board can't confirm a control was effective?
The board discloses it: the specific control, the action taken or proposed, and progress against anything reported previously. Investors and the FRC expect real detail here, and a vague or evasive disclosure draws more scrutiny than an honest one.
How does SureCloud support a Provision 29 declaration?
SureCloud connects Risk Management, Compliance Management, Continuous Controls Monitoring and Internal Audit in one system, so boards can map principal risks to material controls, monitor effectiveness continuously, and generate the evidence pack a Provision 29 declaration needs without stitching it together from spreadsheets. Gracie AI Agents with Personas and Skills handle the evidence chasing and control testing work that used to take teams weeks.
Platform +
Frameworks +
Products +
Industries +
Resources +
Company +
London Office
1 Sherwood Street, London, W1F 7BL, United Kingdom
US Headquarters
6010 W. Spring Creek Pkwy., Plano, TX 75024, United States of America
© SureCloud 2026. All rights reserved.
