GRC Catalyst
GRC Catalyst
  • Home
  • About Us
    • About Us
    • Our Founder
    • Our Mission
    • FAQ
  • Services
  • Sectors
  • Careers
  • Insights
  • Contacts
HomeNewsGovernanceUK Corporate Governance Code: Provision 29

UK Corporate Governance Code: Provision 29

A chart showing the requirements of Provision 29 of the UK Corporate Governance Code

UK Corporate Governance Code: Provision 29

The UK Corporate Governance Code has long emphasised the importance of effective internal controls and risk management. However, Provision 29 (introduced with the 2024 revision of the Code and applicable to accounting periods beginning on or after 1 January 2026) represents a significant evolution. It moves beyond high-level principles and requires Boards to formally attest to the effectiveness of their internal control framework.
This shift reflects increasing investor expectations, regulatory scrutiny, and lessons learned from high-profile corporate failures. For many organisations, Provision 29 is not simply an incremental update; it is a fundamental change in how Boards evidence and demonstrate control effectiveness.

What Provision 29 Requires

Provision 29 places explicit responsibility on the Board to:

  1. Monitor and Review Effectiveness

Boards must monitor and review the effectiveness of the company’s:

  • Risk management framework
  • Internal control systems (financial, operational, reporting, and compliance controls)

The monitoring must bee conducted on an ongoing basis, going beyond periodic review. It requires a structured, evidence-based approach throughout the year.

  1. Conduct an Annual Effectiveness Review

The annual review is the Board’s formal, holistic assessment that synthesises all monitoring, testing, and assurance activities into a single year‑end conclusion.

Provision 29 explicitly states that Boards must “conduct at least an annual review of effectiveness” of the internal control framework. This is a minimum requirement and applies regardless of how sophisticated or continuous the ongoing monitoring is. Continuous monitoring will strengthen the evidence base, but it does not replace the formal annual review and declaration.

  1. Declare Effectiveness in the Annual Report

A central requirement of Provision 29 is a formal Board declaration stating:

  • Whether the internal control framework has been effective at the balance sheet date or throughout the reporting period, with the latter being the “gold standard”
  • The basis for that assessment, including the evidence considered

This is a notable shift from the previous reliance on narrative to a requirement for explicit assurance.

  1. Disclose Material Weaknesses

If weaknesses are identified, companies must:

  • Clearly describe the nature of the issues
  • Explain their impact
  • Set out remediation actions and timelines

This introduces a level of transparency more akin to regulated regimes such as Sarbanes-Oxley (SOX).

  1. Define What is Material

The Code explicitly states that it is the Board’s responsibility to determine what constitutes a material control, taking into account:

  • the company’s principal risks
  • potential impact on stakeholders
  • long‑term business sustainability

This means that the Board needs to identify the controls that matter most to preventing serious harm, misstatement, or regulatory breach, and be prepared to stand behind their effectiveness in the annual report.

Why Provision 29 Differs from Previous Requirements

Provision 29 represents a clear departure from earlier expectations under the UK Corporate Governance Code, fundamentally reshaping how Boards engage with internal control.

One of the most significant changes is the move from review to accountability. Previously, Boards were required to review internal controls, with disclosures framed largely as high-level, principles-based narratives. Provision 29 shifts this position. Boards must now take ownership of the conclusion and support it through a formal attestation. This closes the gap between oversight and accountability, making it explicit that the Board stands behind the outcome.

Alongside this is a shift from qualitative commentary to evidence-based assurance. In the past, organisations could rely on describing their control environment without demonstrating how controls operated in practice. Under Provision 29, Boards must support their declaration with demonstrable, auditable evidence. This typically involves structured control frameworks linked to principal risks, targeted testing programmes, and documented assurance activities that answer a fundamental question: “How do we know?”

Transparency is also strengthened. Historically, organisations often limited disclosure of control weaknesses unless issues were unavoidable. Provision 29 requires explicit disclosure of material weaknesses and remediation actions, increasing investor visibility and reducing the scope for overly optimistic reporting. This strengthens market trust by making both strengths and weaknesses visible.

At a broader level, the UK is moving closer to international expectations, including regimes such as US Sarbanes-Oxley, where certification of internal controls is well established. However, the UK approach remains principles-based rather than prescriptive. Organisations retain flexibility in how they design their approach, but accountability for the outcome is significantly higher. Proportionality remains, but it must now be evidenced.

Perhaps the most important implication is the focus on the Board itself. Internal control effectiveness can no longer be treated primarily as a management responsibility. The Board owns the conclusion and must be satisfied that the supporting assurance is robust. This raises expectations of Board engagement, challenge, and understanding.

In this context, the Audit Committee’s role is also strengthened. It is expected not only to review but to challenge management’s conclusions and ensure that the evidence base is sufficient to support the Board’s declaration. In effect, it becomes a critical assurance gatekeeper, enabling the Board to stand behind its statement with a high degree of confidence.

Practical Implications for Organisations

For many companies, particularly those without a SOX-style framework, Provision 29 requires a step change in maturity.

Key capability gaps often include:

  • Lack of a clearly defined controls framework aligned to principal risks
  • Limited control documentation and ownership
  • Inconsistent or informal testing and assurance processes
  • Fragmented evidence across functions (risk, compliance, internal audit)
  • Insufficient Board-level visibility and reporting

Why This Matters

Provision 29 is not just a governance update; it is a fundamental change.

It reflects:

  • Investor demand for credible assurance over internal controls
  • Recognition that weak controls underpin many corporate failures
  • A shift toward accountability at the top of organisations

For Boards, this changes the conversation from “Do we have a framework?” to “Can we stand behind its effectiveness with evidence?”

Conclusion

Provision 29 represents a defining moment for UK corporate governance. It introduces:

  • Formal board accountability
  • Evidence-based assurance
  • Transparent disclosure of weaknesses

While still principles-based, it requires a level of rigour that many organisations have not previously embedded. For companies transitioning toward compliance, the challenge is clear. They need to build a control environment that is not only well-designed, but also effective.

Resources

GRC Catalyst has developed a short, focused training course for Boards and Executives covering Provision 29. The course takes 10–15 minutes and uses scenario-based learning to challenge judgement, not just knowledge.

Click here to access the course – Provision 29: Board Accountability for Internal Controls in UK Governance

How GRC Catalyst Can Help

GRC Catalyst supports organisations in responding to Provision 29 through:

  • Control framework design and alignment to principal risks
  • Development of proportionate, right-sized assurance programmes
  • Creation of evidence-based board reporting packs
  • Independent effectiveness reviews and readiness assessments

Our approach ensures organisations meet regulatory expectations without over-engineering, enabling Boards to provide confident, defensible declarations grounded in robust evidence.

Disclosure

The concepts and ideas in this article are mine or have been referenced; I developed the body of the text and conducted the final editorial check. I used AI as a tool for research, to improve the flow and grammar of the article, and to check for factual inaccuracies.

GRC Catalyst helps life sciences and healthcare organisations simplify governance and compliance to scale impact.

We offer flexible, outcome-driven support that adapts to your needs.

Useful Links

Home Page
About Us
Services
Sectors
Contact Us
Terms & Conditions
Privacy Notice
Our Mission

Insights

Read our latest Blogs
What is GRC ?
Risk Management

©2026 GRC Catalyst Ltd - All Rights Reserved