UK Corporate Governance Code: Provision 29
The UK Corporate Governance Code has long emphasised the importance of effective internal controls and risk management. However, Provision 29 (introduced with the 2024 revision of the Code and applicable to accounting periods beginning on or after 1 January 2026) represents a significant evolution. It moves beyond high-level principles and requires Boards to formally attest to the effectiveness of their internal control framework.
This shift reflects increasing investor expectations, regulatory scrutiny, and lessons learned from high-profile corporate failures. For many organisations, Provision 29 is not simply an incremental update; it is a fundamental change in how Boards evidence and demonstrate control effectiveness.
What Provision 29 Requires
Provision 29 places explicit responsibility on the Board to:
- Monitor and Review Effectiveness
Boards must monitor and review the effectiveness of the company’s:
- Risk management framework
- Internal control systems (financial, operational, reporting, and compliance controls)
The monitoring must bee conducted on an ongoing basis, going beyond periodic review. It requires a structured, evidence-based approach throughout the year.
- Conduct an Annual Effectiveness Review
The annual review is the Board’s formal, holistic assessment that synthesises all monitoring, testing, and assurance activities into a single year‑end conclusion.
Provision 29 explicitly states that Boards must “conduct at least an annual review of effectiveness” of the internal control framework. This is a minimum requirement and applies regardless of how sophisticated or continuous the ongoing monitoring is. Continuous monitoring will strengthen the evidence base, but it does not replace the formal annual review and declaration.
- Declare Effectiveness in the Annual Report
A central requirement of Provision 29 is a formal Board declaration stating:
- Whether the internal control framework has been effective at the balance sheet date or throughout the reporting period, with the latter being the “gold standard”
- The basis for that assessment, including the evidence considered
This is a notable shift from the previous reliance on narrative to a requirement for explicit assurance.
- Disclose Material Weaknesses
If weaknesses are identified, companies must:
- Clearly describe the nature of the issues
- Explain their impact
- Set out remediation actions and timelines
This introduces a level of transparency more akin to regulated regimes such as Sarbanes-Oxley (SOX).
- Define What is Material
The Code explicitly states that it is the Board’s responsibility to determine what constitutes a material control, taking into account:
- the company’s principal risks
- potential impact on stakeholders
- long‑term business sustainability
This means that the Board needs to identify the controls that matter most to preventing serious harm, misstatement, or regulatory breach, and be prepared to stand behind their effectiveness in the annual report.
Why Provision 29 Differs from Previous Requirements
Provision 29 represents a clear departure from earlier expectations under the UK Corporate Governance Code, fundamentally reshaping how Boards engage with internal control.
One of the most significant changes is the move from review to accountability. Previously, Boards were required to review internal controls, with disclosures framed largely as high-level, principles-based narratives. Provision 29 shifts this position. Boards must now take ownership of the conclusion and support it through a formal attestation. This closes the gap between oversight and accountability, making it explicit that the Board stands behind the outcome.
Alongside this is a shift from qualitative commentary to evidence-based assurance. In the past, organisations could rely on describing their control environment without demonstrating how controls operated in practice. Under Provision 29, Boards must support their declaration with demonstrable, auditable evidence. This typically involves structured control frameworks linked to principal risks, targeted testing programmes, and documented assurance activities that answer a fundamental question: “How do we know?”
Transparency is also strengthened. Historically, organisations often limited disclosure of control weaknesses unless issues were unavoidable. Provision 29 requires explicit disclosure of material weaknesses and remediation actions, increasing investor visibility and reducing the scope for overly optimistic reporting. This strengthens market trust by making both strengths and weaknesses visible.
At a broader level, the UK is moving closer to international expectations, including regimes such as US Sarbanes-Oxley, where certification of internal controls is well established. However, the UK approach remains principles-based rather than prescriptive. Organisations retain flexibility in how they design their approach, but accountability for the outcome is significantly higher. Proportionality remains, but it must now be evidenced.
Perhaps the most important implication is the focus on the Board itself. Internal control effectiveness can no longer be treated primarily as a management responsibility. The Board owns the conclusion and must be satisfied that the supporting assurance is robust. This raises expectations of Board engagement, challenge, and understanding.
In this context, the Audit Committee’s role is also strengthened. It is expected not only to review but to challenge management’s conclusions and ensure that the evidence base is sufficient to support the Board’s declaration. In effect, it becomes a critical assurance gatekeeper, enabling the Board to stand behind its statement with a high degree of confidence.
Practical Implications for Organisations
For many companies, particularly those without a SOX-style framework, Provision 29 requires a step change in maturity.
Key capability gaps often include:
- Lack of a clearly defined controls framework aligned to principal risks
- Limited control documentation and ownership
- Inconsistent or informal testing and assurance processes
- Fragmented evidence across functions (risk, compliance, internal audit)
- Insufficient Board-level visibility and reporting
Why This Matters
Provision 29 is not just a governance update; it is a fundamental change.
It reflects:
- Investor demand for credible assurance over internal controls
- Recognition that weak controls underpin many corporate failures
- A shift toward accountability at the top of organisations
For Boards, this changes the conversation from “Do we have a framework?” to “Can we stand behind its effectiveness with evidence?”
Conclusion
Provision 29 represents a defining moment for UK corporate governance. It introduces:
- Formal board accountability
- Evidence-based assurance
- Transparent disclosure of weaknesses
While still principles-based, it requires a level of rigour that many organisations have not previously embedded. For companies transitioning toward compliance, the challenge is clear. They need to build a control environment that is not only well-designed, but also effective.
Resources
GRC Catalyst has developed a short, focused training course for Boards and Executives covering Provision 29. The course takes 10–15 minutes and uses scenario-based learning to challenge judgement, not just knowledge.
Click here to access the course – Provision 29: Board Accountability for Internal Controls in UK Governance
How GRC Catalyst Can Help
GRC Catalyst supports organisations in responding to Provision 29 through:
- Control framework design and alignment to principal risks
- Development of proportionate, right-sized assurance programmes
- Creation of evidence-based board reporting packs
- Independent effectiveness reviews and readiness assessments
Our approach ensures organisations meet regulatory expectations without over-engineering, enabling Boards to provide confident, defensible declarations grounded in robust evidence.
Disclosure
The concepts and ideas in this article are mine or have been referenced; I developed the body of the text and conducted the final editorial check. I used AI as a tool for research, to improve the flow and grammar of the article, and to check for factual inaccuracies.