Key Takeaways
Provision 29 of the UK Corporate Governance Code 2024 requires listed company boards to declare, for the first time, whether their material internal controls were effective at the balance sheet date. The Financial Reporting Council published the revised Code on 22 January 2024, and the new declaration requirement takes effect for financial years beginning on or after 1 January 2026.
For company secretaries and board members, this is one of the most significant governance changes in years, because it moves internal control reporting from a description of process to a clear statement of outcome. This article explains what Provision 29 says, who it applies to, what boards need to disclose and how to prepare for the first reporting cycle in 2027.
What is Provision 29 of the UK Corporate Governance Code 2024?
Provision 29 requires the board to monitor the company’s risk management and internal control framework and to carry out a review of its effectiveness at least once a year.
This sits under Principle O of the Code, which covers the board’s responsibility for internal control and risk management. The provision extends beyond financial controls to cover operational, reporting and compliance controls, so it is broader than a standard internal audit exercise.
Where the 2018 Code asked boards to review effectiveness and report on that review, the 2024 Code asks boards to go a step further and state a clear conclusion on whether those controls actually worked.
When does Provision 29 take effect?
Provision 29 applies to financial years beginning on or after 1 January 2026. The remainder of the 2024 Code, including changes to audit committee provisions, applies to financial years beginning on or after 1 January 2025. The FRC deferred Provision 29 by a year after consultation feedback suggested the original proposal for continuous, whole year monitoring would be too burdensome.
For a company with a calendar year end, this means the first Provision 29 declaration will appear in the annual report published in 2027. Companies with a March year end will report slightly later again, so it is worth checking your own reporting calendar against the FRC’s effective date rather than assuming a single deadline applies to everyone.
Which companies does Provision 29 apply to?
The Code, and therefore Provision 29, applies on a comply or explain basis to all companies with a premium listing on the London Stock Exchange, whether incorporated in the UK or elsewhere. This covers the commercial companies category and the closed-ended investment funds category.
Compliance with the Code is not a legal requirement, but premium listed companies must either comply with each provision or publish a clear explanation of why they have not, under the Code’s comply or explain approach set out by the FRC. AIM listed and other non-premium companies are not bound by the Code directly, though some choose to follow elements of it as good practice.
What must a board do under Provision 29?
Provision 29 asks the board to monitor the risk management and internal control framework on an ongoing basis, then carry out at least one formal review of its effectiveness each year. The outcome of that review must then be reported clearly in the annual report. This applies to financial, operational, reporting and compliance controls, not only the controls that feed into the financial statements.
What does the annual report need to disclose?
Under Provision 29, the annual report must include a description of how the board monitored and reviewed the effectiveness of the risk management and internal control framework during the year.
It must also include a declaration on the effectiveness of the company’s material controls as at the balance sheet date, and a description of any material controls that had not operated effectively at that date, together with the action taken or proposed to address this. The FRC has confirmed it will not provide standard wording for the declaration, so each board needs to reach its own conclusion and express it clearly rather than relying on generic language.
How is this different from the old Provision 29 in the 2018 Code?
The key change is the addition of a formal declaration. The 2018 Code asked boards to describe how they had reviewed the effectiveness of their risk management and internal control systems, but it did not require a direct statement on whether those controls were actually effective.
The 2024 Code keeps the monitoring and review requirement and adds an outcome based conclusion, moving governance reporting away from process description and towards accountability for outcomes.
What counts as a material control?
A material control is one whose failure could have a significant effect on the company’s ability to achieve its objectives, safeguard its assets or produce reliable financial and non-financial reporting.
The FRC has deliberately avoided prescribing a fixed list or a required number of material controls, leaving this to each board’s judgement based on its own risk profile. This applies across financial, operational, reporting and compliance areas, so a material control might relate to cyber security or supply chain resilience as much as to financial reporting.
How should a board prepare for its first Provision 29 declaration?
Preparation starts with mapping the company’s risk management and internal control framework against Provision 29’s four disclosure requirements well before the relevant financial year begins. Boards should agree which controls are material and confirm who owns the annual effectiveness review.
Building an evidence trail that supports the eventual declaration should happen throughout the year, rather than being assembled retrospectively at year end. Many boards are also strengthening year round monitoring, using board management software to keep control evidence, risk registers and committee papers in one auditable record instead of scattered across email and shared drives.
How can a board avoid boilerplate reporting?
Avoid boilerplate by explaining how the board reached its conclusion rather than simply stating that controls were reviewed. A strong Provision 29 statement links the review process to specific evidence and names the committees or functions involved.
It also connects control outcomes to the company’s stated risk appetite. Generic language that could apply to any company in any sector signals to investors and analysts that the process behind the declaration may not be robust.
What happens if a board gets this wrong?
Getting Provision 29 reporting wrong creates reputational and investor confidence risk rather than a direct legal penalty, since the Code operates on a comply or explain basis. A vague or generic declaration, or one that is not well supported by evidence, invites challenge from shareholders and proxy advisers, particularly where a control failure later comes to light.
As the FRC’s Review of Corporate Governance Reporting already assesses how well companies report against the Code’s Provisions, boards that under prepare for Provision 29 risk being singled out in future FRC reviews as well as in their own investor engagement.
Provision 29 marks a shift from process to accountability
Provision 29 changes how UK boards talk about internal control, replacing a description of process with a clear declaration of outcome. Financial years beginning on or after 1 January 2026 are the first to fall within scope, which means most premium listed companies have limited time left to test their evidence gathering and agree how they will phrase their declaration.
Boards that start this work now, rather than waiting for the reporting deadline, are better placed to produce a credible, well evidenced statement rather than a generic one that invites scrutiny.
How Convene supports Provision 29 reporting
Provision 29 puts a premium on evidence, and Convene helps boards keep that evidence organised throughout the year rather than reconstructing it at reporting time. Board packs, committee minutes, risk registers and control review outcomes can sit in a single secure record, giving company secretaries and compliance teams a clear audit trail to support the board’s eventual declaration. This makes it easier to show how the board actually monitored and reviewed its internal control framework, rather than relying on a general statement at year end.
To see how Convene can support your board’s approach to Provision 29 reporting, book a demo.
FAQs
When does Provision 29 come into effect?
Provision 29 applies to financial years beginning on or after 1 January 2026. This means the first companies to report under the new requirement, those with a calendar year end, will publish their Provision 29 declaration in their 2027 annual report.
Does Provision 29 require external auditor sign-off?
No. The FRC has confirmed that a company’s external auditor does not give an opinion on the Provision 29 statement itself. The statement falls within the other information the auditor considers under auditing standard ISA (UK) 720, rather than within the scope of the audit opinion on the financial statements.
What should a Provision 29 declaration include?
A Provision 29 declaration should describe how the board monitored and reviewed the risk management and internal control framework during the year. It should state whether material controls were effective as at the balance sheet date and describe any material controls that had not operated effectively, along with the remedial action taken or planned.
