The UK Corporate Governance Code’s Provision 29 introduces a change that boards cannot delegate away. From financial years beginning on or after 1 January 2026, the board must declare whether the company’s material controls were effective at the balance sheet date. The declaration is new, yet the underlying expectation that boards monitor and review the risk management and internal control framework is not. It arrives with less prescription than many boards expect, and that is precisely why the preparation matters. This white paper sets out what the provision actually requires, where the practical difficulty tends to sit, and how a board can reach a supportable conclusion.
What Provision 29 Actually Requires
The wording of the Code is short. The choices left to the board are not. Provision 29 asks the board to monitor the framework and, at least annually, review its effectiveness across all material controls, including financial, operational, reporting and compliance controls. The reporting element is where companies feel the shift most, because reporting controls now sit expressly within scope. The white paper separates the requirements of the Code from the FRC guidance that supports it, and explains why that guidance is deliberately not prescriptive.
Who decides what counts as a material control
The FRC has not defined a material control, and has said it is not its role to decide which controls a company identifies. That leaves a real question for the board. The same control can be material in one company and immaterial in another, depending on business model, complexity, risk appetite and reliance. The paper walks through the factors a board may weigh, and the record it may wish to keep of why some controls were included and others were not.
Turning risk management information into a board level view
Most companies already hold risk, control, compliance and internal audit information. The harder question is whether, taken together, it gives the board a clear and sufficiently supported picture of the material controls and the framework around them. When relevant information sits across different functions, systems and reporting cycles, that does not signal weak controls, but it can make a coherent board view harder to assemble. The white paper looks at ownership and accountability, the evidence that supports an effectiveness conclusion, the sources of information and assurance available to a board, and how those sources can be coordinated without unnecessary duplication or gaps.
Where the external auditor fits, and where it does not
A common misunderstanding is that the statutory audit covers the Provision 29 statement. It does not. For audit purposes the statement is treated as other information, which the auditor reads for consistency rather than tests. The paper explains how this works in practice, why that work is not an assurance engagement over the declaration, and what it means for boards that lean on existing audit activity when forming their own view.
Who This White Paper Is For
This guide is written for board members and audit committee chairs who carry responsibility for the declaration, and for the risk, compliance, finance and internal audit teams who prepare the information behind it. Directors will gain a clear reading of what the Code and the FRC guidance ask of them. Assurance and control owners will find practical prompts for identifying material controls, gathering evidence and reporting proportionately.
The first reporting cycle under the UK Corporate Governance Code’s Provision 29 arrives in 2027 for companies with a 31 December 2026 year end, which leaves less time than it appears. A dry run now can reveal information gaps, unclear responsibilities and timetable pressure while there is still room to act. Download the white paper to see what a proportionate, board ready approach looks like.











