Share this article:

Key Takeaways

  • The UK Corporate Governance Code 2024, published by the FRC on 22 January 2024, applies to financial years beginning on or after 1 January 2025, with Provision 29 applying from 1 January 2026.
  • Provision 29 requires boards to declare the effectiveness of material controls covering financial, operational, reporting, and compliance controls. There is no external auditor attestation requirement. In-scope companies are in their first live Provision 29 cycle as of 2026, with first reports expected in early 2027.
  • The Code operates on a 'comply or explain' basis under the UK Listing Rules. Departure from a Provision is permitted provided the explanation is substantive and company-specific.
  • FTSE 350 companies must commission an externally facilitated board evaluation at least every three years under Provision 21 of the Code.

What is the UK Corporate Governance Code?

The UK Corporate Governance Code is a principles-based framework published by the Financial Reporting Council (FRC) that sets the standard for board leadership, accountability, and transparency among UK-listed companies.

As of 2026, the current version is the 2024 Code, which applies to financial years beginning on or after 1 January 2025, with Provision 29 on internal controls applying from 1 January 2026.

The Code works through a ‘comply or explain’ method, a principle established by the Cadbury Report in 1992 and embedded in the UK Listing Rules. It does not operate as law.

In-scope companies must apply its principles and either comply with its provisions or explain any departures clearly in their annual report. Our guide on the topic of what a code of governance is provides useful context on how the Code developed and why it matters.

Who does the Code apply to?

The Code applies to companies listed in the ‘equity shares (commercial companies)’ and ‘closed-ended investment funds’ categories on the UK Official List, as confirmed by the FRC.

AIM companies and those in other listing categories are not required to comply, though many choose to adopt the Code voluntarily.

Private companies are outside scope, but large private companies subject to The Companies (Miscellaneous Reporting) Regulations 2018 must report on their corporate governance arrangements, with the Wates Corporate Governance Principles for Large Private Companies providing the recognised framework.

How is the Code structured?

The 2024 Code is divided into five sections: Board Leadership and Company Purpose; Division of Responsibilities; Composition, Succession and Evaluation; Audit, Risk and Internal Control; and Remuneration.

Each section contains Principles, which all in-scope companies must apply, and Provisions, against which companies must comply or explain. Understanding board members’ roles and responsibilities within this structure is a practical starting point for company secretaries onboarding new directors.

What changed in the 2024 Code, and what applies when?

The FRC published the 2024 Code on 22 January 2024. Most provisions apply to financial years beginning on or after 1 January 2025. Provision 29, which introduces a board declaration on the effectiveness of material internal controls, was deferred and applies to financial years beginning on or after 1 January 2026. The FRC confirmed in its 2026 Provision 29 mythbuster that first mandatory reports under Provision 29 will appear in early 2027 for calendar-year companies.

2024 Code published — 22 January 2024

  • The FRC published the updated UK Corporate Governance Code, replacing the 2018 edition.

2024 Code applies — 1 January 2025

  • All provisions except Provision 29 apply to financial years beginning on or after this date.

Provision 29 applies — 1 January 2026

  • Boards must declare the effectiveness of their material internal controls for financial years beginning on or after this date.

First Provision 29 reports — Early 2027

  • The first mandatory declarations appear in annual reports for calendar-year companies, as confirmed by the FRC’s Provision 29 mythbuster.

Provision 29 and what it means in practice

Provision 29 is the most operationally significant change in the 2024 Code. The shift, as the FRC mythbuster makes clear, is from confirming that controls exist to evidencing that they operated effectively during the reporting period. The board carries the assurance responsibility directly; there is no requirement for external auditor attestation.

The FRC confirms that material controls extend beyond financial controls to cover operational, reporting, and compliance controls. As of 2026, in-scope companies are in their first live Provision 29 cycle.

Other changes in the 2024 Code

A new Principle C requires boards to report on governance decisions and their outcomes rather than processes. The Code also incorporated provisions from the FRC’s Audit Committees and the External Audit Minimum Standard, strengthened malus and clawback reporting requirements in the remuneration section, and revised diversity language to focus on outcomes. Culture reporting requirements were also tightened, with the FRC noting that board disclosures on culture under the 2018 Code had been broadly underwhelming.

What does the Code require for board evaluation?

Provision 21 of the 2024 Code requires a formal and rigorous annual evaluation of the board, its committees, the chair, and individual directors. For FTSE 350 companies, the chair must arrange an externally facilitated evaluation at least every three years, with the external reviewer named in the annual report. Our article on the importance of board evaluations explores what a rigorous process looks like, and our guide to what a board evaluation is covers the mechanics and frameworks in depth.

How does the Code apply to AI in the boardroom?

The UK Corporate Governance Code does not mention artificial intelligence by name, but AI oversight sits firmly within its existing framework. The FRC’s principles on risk management (Section 4), culture (Section 1), and board composition and skills (Section 3) all create governance obligations that extend to how boards manage AI use in their organisations.

The most immediate practical question in 2026 concerns Provision 29. The FRC confirms that material controls extend beyond financial controls to cover operational, reporting, and compliance controls. Any AI systems used in reporting processes or automated compliance functions therefore fall within the scope of the board’s effectiveness declaration. Boards should be asking whether those systems are covered by their assurance framework before making their Provision 29 declaration.

Research from ICAEW and the Chartered Governance Institute also suggests that director use of AI for board work has grown significantly, while formal governance of those tools at board level remains limited. The gap between adoption and oversight is itself a governance risk that sits within the culture and risk sections of the Code.

How the ‘comply or explain’ principle works in practice

Departing from a Provision is not a governance failure. The FRC is explicit that departure is acceptable provided the board gives a substantive explanation of why its approach is more appropriate for its circumstances. A boilerplate explanation is worse than none: the FRC monitors a sample of FTSE 350 and small-cap annual reports each year and flags inadequate explanations in its annual review of corporate governance reporting. The FRC published updated guidance on improving comply or explain quality in early 2026, which governance professionals should treat as current best practice.

What record-keeping obligations come with the Code?

Under section 248 of the Companies Act 2006, every UK company must record minutes of all board meetings and retain those records for at least ten years from the date of the meeting. In the context of Provision 29, minutes of board and audit committee discussions about internal controls form part of the evidence base for the effectiveness declaration. Our meeting minutes guide covers what accurate and compliant minutes look like in practice.

The UK Stewardship Code and how it connects to the Corporate Governance Code

The UK Corporate Governance Code does not sit alone. The FRC also publishes the UK Stewardship Code, which governs how institutional investors and asset managers engage with the companies in which they invest. The FRC published an updated UK Stewardship Code on 3 June 2026, with 2026 designated as a transition year for signatories. The two codes are designed to work in tandem: governance reporting by listed companies is read and assessed by investors who are themselves operating under a refreshed stewardship framework with its own reporting expectations. Boards whose governance disclosures are thin or process-heavy will face more scrutiny, not less, from Stewardship Code signatories.

How Convene supports effective board governance

Meeting the expectations of the UK Corporate Governance Code requires the right infrastructure. Secure document management, a clear audit trail, efficient board meeting processes, and tools that make accountability visible at every stage are all part of what a well-governed board needs.

Convene is an award-winning board portal designed to make governance smart, simple, and secure. From agenda building and board pack distribution to minute taking, voting, and post-meeting action tracking, Convene brings the entire board meeting lifecycle into one seamless platform.

Book a demo to discover how the right tools help your organisation meet the highest standards of governance with confidence.

Frequently Asked Questions

How does a board portal support compliance with the UK Corporate Governance Code?

A board portal supports Code compliance by creating a clear and searchable audit trail of board decisions, ensuring documents are distributed securely and on time, and making it easier for boards to evidence the kind of accountability and transparency the Code expects. For Provision 29 specifically, the audit trail generated by a board portal forms part of the evidence base a board can draw on when making its declaration on the effectiveness of material controls.

How secure is a board portal?

A well-built board portal uses enterprise-grade security including 256-bit AES encryption, role-based access controls, and remote wipe capability for lost or stolen devices. Board packs contain some of the most sensitive information a company holds, including unannounced financial results, M&A activity, and regulatory matters, so security is a core rather than an optional feature.

Do board portals work for committees as well as the full board?

Yes. Most board portals support multiple workspaces, allowing the audit committee, remuneration committee, nominations committee, and other sub-committees to each have their own secure environment within the same platform. This keeps sensitive committee papers separate from full board materials while maintaining a consistent governance workflow across the organisation.


Share this article:

Aika Cabales
Aika Cabales

  • Connect:
  • Email Account

Subscribe to the Convene blog

Get regular updates on Governance and Digital Transformation!

(+44) *
By submitting this form, I consent to the collection and processing of my personal data by Azeus for the purpose of fulfilling this request, as outlined in the Privacy Policy.

This site is protected by reCAPTCHA and the Google Privacy Policy and Terms of Service apply.