
Which material controls protect which principal risks?
Not a list of policies. Not an org chart. A clear, defensible map from risk to control to outcome — one a non-executive director can follow without a translator.
The UK Corporate Governance Code now requires boards to declare the effectiveness of their material internal controls — annually, and on evidence. Previously boards stated that controls existed. The bar is considerably higher now.

If you hesitated on any of them, that hesitation is the gap.

Not a list of policies. Not an org chart. A clear, defensible map from risk to control to outcome — one a non-executive director can follow without a translator.

With documented evidence, not process descriptions. Evidence that would satisfy an auditor, an investor or a regulator — and that hasn't quietly expired since it was gathered.

With active monitoring, escalation and remediation tracking. Not reactive fire-fighting followed by a retrospective explaining why nobody noticed.
Provision 29 forms part of the UK Corporate Governance Code as revised by the Financial Reporting Council in January 2024 — the most significant governance change in that revision. It applies to accounting periods beginning on or after 1 January 2026.


Monitor the risk management and internal control framework continuously through the year — not in a scramble at annual review time.

Review the effectiveness of all material controls at least annually — financial, operational, reporting and compliance alike.

Make a declaration in the annual report on the effectiveness of material controls, with a description of how the conclusion was reached.
Control maturity stopped being a compliance exercise and became a commercial one.

Due diligence is now control-centric. Integrated frameworks are expected rather than checklists, and control gaps translate directly into valuation risk — and deal friction at exactly the wrong moment.

Supply-chain assurance demands keep escalating: ISO 27001, GDPR accountability, cyber resilience — with evidence of testing rather than just a certificate, increasingly as a gate on the contract itself.

DORA, the EU AI Act and UK GDPR accountability all expect documented, testable controls with clear ownership. Self-attestation is no longer sufficient, and a point-in-time snapshot is not ongoing effectiveness.
ISO 27001 lives in InfoSec. GDPR sits with Legal. AI risk often isn't mapped at all. There is no single line of sight from risk to control to evidence to outcome — which is precisely the line Provision 29 asks the board to draw.

Start with the free 15-minute diagnostic — no account needed.