The provision that changes what a UK board actually has to sign is Provision 29. From financial years beginning on or after 1 January 2026, the board is asked to declare whether its material controls were effective at the balance sheet date, and to say so in the annual report. That is a positive statement about a defined set of controls, evidenced, dated and attributable, rather than a description of a process. This page sets out what the provision says, what the Financial Reporting Council's guidance does and does not settle, and the evidence an audit committee needs before the wording is drafted.
What does Provision 29 of the UK Corporate Governance Code require?
Provision 29 asks the board to monitor the company's risk management and internal control framework and to review its effectiveness at least annually, covering all material controls, including financial, operational, reporting and compliance controls. The annual report must then describe that monitoring, declare whether the material controls were effective at the balance sheet date, and explain any that were not.
The FRC's UK Corporate Governance Code 2024 sets it out in these terms:
"The board should monitor the company's risk management and internal control framework and, at least annually, carry out a review of its effectiveness. The monitoring and review should cover all material controls, including financial, operational, reporting and compliance controls."
The provision then asks for three things in the annual report: a description of how the board has monitored and reviewed the effectiveness of the framework; a declaration of effectiveness of the material controls as at the balance sheet date; and a description of any material controls which have not operated effectively as at that date, the action taken or proposed to improve them, and any action taken to address issues reported previously. Sources checked on 3 September 2026.
Two of those three are familiar work restated. The declaration is not. It moves the board from describing an approach to attesting to an outcome on a named date, which makes preparation an evidence question.
Who this applies to, and when
Provision 29 applies to companies with a UK premium listing that report against the UK Corporate Governance Code, on the same comply-or-explain basis as the rest of the Code. The 2024 Code has applied since financial years beginning on or after 1 January 2025; Provision 29 alone was deferred by a year and applies to financial years beginning on or after 1 January 2026.
A company with a 31 December year end is already inside the first financial year the provision covers, and its first declaration reaches print in the annual report published during 2027. A company with a 31 March year end enters its first covered year on 1 April 2026 and reports in 2027 as well. The reporting deadline feels distant; the evidence period does not, because a declaration made as at a balance sheet date rests on testing performed across the year that ends on it.
Organisations outside the Code's scope have no obligation here, though many are adopting the same discipline anyway. For the wider set of 2024 changes and the staggered timeline in one place, our company secretary's guide to the UK Corporate Governance Code 2024 covers the ground this page assumes.
What counts as a material control?
The FRC does not define a material control, and says so deliberately. Its Corporate Governance Code Guidance states that it is not the FRC's role or intention to prescribe or dictate what a material control is for a company, and that materiality will depend on the nature of the principal risks. The board determines the set, and must be able to explain how.
That is a transfer of judgement, not an absence of expectation. Read alongside the FRC's Provision 29 Mythbuster, published 29 January 2026 and checked on 3 September 2026, three points do most of the work in practice.
First, there is no prescribed number. The FRC notes that companies have tended to land somewhere in the region of 30 to 50 material controls, while being clear that the right number is the one a company can justify against its own principal risks rather than a target to hit.
Second, the disclosure is expected to be proportionate: the FRC says it would expect the report to be no longer than two pages in most cases, and would not expect anything commercially sensitive to be included.
Third, the declaration attaches to the controls, not to the framework as a whole. The board makes its own assessment of effectiveness using evidence obtained through monitoring and review of the risk and internal control framework, and the material controls that need to be disclosed are those supporting the most important risks, as determined by the board and management.
The workable definition that follows from all three: a control is material if its failure, at the balance sheet date, would leave a principal risk unmanaged in a way the board would have to tell shareholders about. Everything else is a control the company operates but does not declare on.
What the board needs to decide
Five decisions belong to the board or the audit committee, not to the finance function, and each should be minuted with its reasoning:
- The materiality threshold. The stated test by which a control enters the declared set, expressed against principal risks rather than a financial number alone.
- The control universe and its owner. Who maintains the schedule of material controls, how changes to it are approved mid-year, and where it lives.
- The evidence standard. What counts as sufficient evidence of effective operation: design assessment only, management self-certification, independent internal audit testing, or external assurance, and which controls get which.
- The deficiency escalation route. What triggers a control being reported as not effective, who decides, and by when in the reporting calendar that decision has to be made.
- The assurance posture. Whether external assurance is sought over the declaration. The FRC's Mythbuster states that this is a decision for the board and management, and that it may differ year on year or cover one element of the framework only.
A worked control universe
The table below is an illustrative extract for a mid-cap listed group, anonymised and simplified: the four categories named in Provision 29, one line per control, with the evidence a board would rely on. A real schedule carries the risk each control supports, its owner, the testing frequency and the last test date alongside.
| # | Category | Material control | Evidence the board relies on |
|---|---|---|---|
| 1 | Financial | Monthly balance sheet reconciliations reviewed and signed off by the financial controller | Reconciliation log with sign-off dates, internal audit sample testing of 25 reconciliations |
| 2 | Financial | Delegated authority matrix enforced in the purchase-to-pay system | System configuration report, exception report of overrides with approvals |
| 3 | Financial | Segregation of duties between vendor creation and payment release | Access-rights report, quarterly user-access review minutes |
| 4 | Financial | Board approval of capital expenditure above the stated threshold | Board minutes, capital expenditure register reconciled to approvals |
| 5 | Financial | Treasury counterparty and covenant compliance monitoring | Monthly treasury report to the audit committee, covenant certificates |
| 6 | Financial | Group consolidation review including intercompany elimination checks | Consolidation review checklist signed by the group financial controller |
| 7 | Operational | Change control over the core operating platform, including approval and rollback testing | Change advisory board records, sample of change tickets with test evidence |
| 8 | Operational | Business continuity and disaster recovery testing for tier-one systems | Annual test report, remediation tracker with closure dates |
| 9 | Operational | Supplier onboarding due diligence for critical suppliers | Due diligence files, critical supplier register with review dates |
| 10 | Operational | Health and safety incident reporting and root-cause review | Incident log, quarterly report to the board with trend analysis |
| 11 | Operational | Cyber security patching within stated service levels for internet-facing systems | Vulnerability management dashboard, exception approvals, penetration test report |
| 12 | Reporting | Review of significant accounting judgements and estimates by the audit committee | Audit committee papers and minutes recording the challenge |
| 13 | Reporting | Annual report disclosure checklist completed and reviewed | Completed checklist, evidence of second-person review |
| 14 | Reporting | Controls over data used in climate and sustainability disclosures | Data lineage documentation, sample recalculation of reported metrics |
| 15 | Reporting | Controls over price-sensitive information and the insider list | Insider list maintenance records, disclosure committee minutes |
| 16 | Compliance | Anti-bribery and corruption training completion and refresher cycle | Training completion report by population, escalation of non-completers |
| 17 | Compliance | Gifts, hospitality and conflicts of interest register review | Register with review sign-offs, exceptions escalated to the committee |
| 18 | Compliance | Data protection impact assessments for high-risk processing | Completed assessments, data protection officer sign-off |
| 19 | Compliance | Sanctions and know-your-customer screening at onboarding and periodically | Screening system logs, sample file review by compliance |
| 20 | Compliance | Whistleblowing channel operation and case triage | Case log, quarterly report to the audit committee on themes and outcomes |
Twenty lines sits deliberately in the middle of the range the FRC describes. The test to apply to each is the one above: if this control failed on the balance sheet date, would the board have to tell shareholders?
A twelve-month readiness timeline
For a 31 December 2026 year end, working back from the annual report published in 2027. Adjust the months, not the sequence.
| Month | Milestone | Owner | Output |
|---|---|---|---|
| Month 1 | Agree the materiality test and the scope of the exercise | Audit committee | Minuted definition of a material control for this company |
| Month 2 | Draft the control universe against principal risks | Risk and internal audit | Schedule of candidate material controls with risk mapping |
| Month 3 | Challenge and approve the control universe | Audit committee | Approved schedule, decisions on inclusions and exclusions recorded |
| Month 4 | Assess control design and identify gaps | Control owners, internal audit | Design assessment with gap list |
| Months 5 to 6 | Remediate design gaps; agree the testing plan | Executive, internal audit | Remediation tracker, testing plan by control |
| Months 7 to 9 | Operating effectiveness testing, first pass | Internal audit, control owners | Test results, exceptions logged |
| Month 10 | Interim report to the audit committee; remediate exceptions | Audit committee | Interim assessment, remediation deadlines |
| Month 11 | Retest failed controls; draft the declaration wording | Internal audit, company secretary | Retest evidence, first draft of disclosure |
| Month 12 | Year-end assessment as at the balance sheet date | Board | Board minute recording the effectiveness conclusion |
| Post year end | Finalise the disclosure with the auditor and legal review | Company secretary | Approved annual report section |
The step boards most often compress is the interim report at month 10. It exists so that a control found ineffective in the autumn can be fixed and retested before the balance sheet date, rather than becoming a disclosure the board discovers in February.
Evidence and wording: what the audit committee signs off
An evidence checklist
Before the committee recommends the declaration to the board, it should be able to answer yes to each of these, in writing:
- The materiality test is written down, and each included and excluded control traces to it.
- Every material control maps to at least one principal risk in the annual report.
- Each material control has a named owner who is accountable for its operation.
- Each control has a design assessment completed within the reporting year.
- Each control has operating effectiveness evidence covering the year to the balance sheet date, not a single point in time.
- The evidence standard applied to each control is recorded (self-certification, internal audit testing, external assurance).
- Every exception raised during the year is closed, retested, or carried forward with a disclosure decision recorded.
- Controls added or removed mid-year are documented with the approval that changed them.
- Reliance on service organisations is covered by a current assurance report or an alternative test.
- The board's conclusion is minuted with the date, the evidence relied on, and any dissent.
- The draft disclosure has been read against the actual evidence file, not against last year's wording.
- Prior-year issues previously reported have a status update ready for the annual report.
How the declaration might be worded
Illustrative only. This is not legal advice, and wording should be settled with the company's own advisers and auditor against its own facts.
The board has monitored the group's risk management and internal control framework throughout the year and carried out a review of its effectiveness covering the material financial, operational, reporting and compliance controls identified against the group's principal risks. The material controls were determined by the board on the basis that a failure of any of them would leave a principal risk unmanaged. Their operation was assessed using management certification and independent testing by internal audit, reported to the audit committee at its meetings in [month] and [month].
On the basis of that review, the board declares that the group's material controls were operating effectively as at 31 December 2026, with the exception of [named control], where [specific weakness] was identified in [month]. [Remedial action] has been implemented and the control was retested in [month]; the board will report on its operation in next year's annual report. The issue reported in the prior year concerning [control] was closed during the year following [action].
The second paragraph is the one to draft first. A declaration that reads as though nothing was ever found invites the question of how hard anyone looked, and the provision expressly contemplates reporting controls that did not operate effectively.
Common mistakes
The failure modes visible in early preparation work are consistent, and none are about the disclosure itself.
Treating this as a finance exercise. Provision 29 names operational, reporting and compliance controls alongside financial ones, so a universe that is almost entirely financial has not been scoped against the principal risks.
Building the universe bottom-up from an existing process catalogue. Starting with every control the company operates and filtering down produces hundreds of lines and no defensible threshold. Start from the principal risks in the annual report and work outwards.
Confusing design with operation. A control that is well designed and documented but tested once, in March, does not evidence effectiveness at a December balance sheet date.
Leaving the audit committee's own oversight untested. Several controls in the table above are committee activities, and the committee's capacity to run them is itself an evidence question. Our guide to committee effectiveness reviews for audit, remuneration and nomination committees covers how that is assessed, and the annual board effectiveness review is where the finding usually surfaces.
Discovering the answer in February. The declaration is made as at the balance sheet date. Testing that finishes after it cannot change what was true on it.
Next step
Most of the work above is record-keeping under pressure: a controls schedule that stays current, evidence attached to each control, exceptions tracked to closure, and a minute trail an auditor can follow a year later. BoardServe's governance platform holds that evidence in one place, alongside the board and committee assessments that sit next to it. This page is maintained as the FRC's guidance develops, including at the annual update.
FAQ
When does Provision 29 first apply?
Provision 29 applies to financial years beginning on or after 1 January 2026. A company with a 31 December year end is inside its first covered year now, and its first declaration appears in the annual report published in 2027. The rest of the 2024 Code applied a year earlier, from financial years beginning on or after 1 January 2025.
How many material controls should we declare on?
There is no prescribed number. The FRC's Provision 29 Mythbuster observes that companies have generally landed in the region of 30 to 50, while making clear that the right figure follows from a company's principal risks, not from a benchmark. A universe far outside that range is worth explaining internally before the auditor asks.
Does the declaration need external assurance?
No. The Code does not say that testing of material controls should be supported by external assurance; the FRC's Mythbuster describes it as a decision for the board and management, which may differ year on year. A board may also choose external assurance over one element of the framework only.
What happens if a material control was not effective?
The provision expects it to be disclosed. The annual report should describe the control that did not operate effectively at the balance sheet date, the action taken or proposed to improve it, and any action taken on issues reported in previous years. Disclosing a weakness with a credible remediation plan is the intended outcome, not a compliance failure.
Is Provision 29 the same as the Sarbanes-Oxley section 404 regime?
No. Section 404 in the United States is a statutory requirement with a mandated management assessment and, for larger filers, an auditor attestation on internal control over financial reporting. Provision 29 sits in a comply-or-explain code, covers operational, reporting and compliance controls as well as financial ones, and carries no mandatory external attestation.
Does Provision 29 apply to private companies or charities?
Not as a Code obligation. Provision 29 binds companies reporting against the UK Corporate Governance Code. Private companies, charities and housing providers may adopt the same discipline voluntarily, but the provision itself does not reach them.
