Applies to accounting periods from 1 January 2026

Provision 29: from risk register
to annual declaration.

The UK Corporate Governance Code now requires boards to declare the effectiveness of their material internal controls — annually, and on evidence. Previously boards stated that controls existed. The bar is considerably higher now.

8
Principal risk categories
2
Score calculation modes
90
Point scoring scale
100%
Audit trail coverage

Three questions your board will be asked

If you hesitated on any of them, that hesitation is the gap.

Which material controls protect which principal risks?

Not a list of policies. Not an org chart. A clear, defensible map from risk to control to outcome — one a non-executive director can follow without a translator.

Are those controls tested and effective?

With documented evidence, not process descriptions. Evidence that would satisfy an auditor, an investor or a regulator — and that hasn't quietly expired since it was gathered.

Will you catch control failures before they become incidents?

With active monitoring, escalation and remediation tracking. Not reactive fire-fighting followed by a retrospective explaining why nobody noticed.

The shift

Boards used to say controls existed. Now they must say they work.

Provision 29 forms part of the UK Corporate Governance Code as revised by the Financial Reporting Council in January 2024 — the most significant governance change in that revision. It applies to accounting periods beginning on or after 1 January 2026.

  • From existence to effectiveness. A statement that a control is in place no longer answers the question.
  • All material controls, not just financial ones — operational, reporting and compliance alike.
  • A much wider evidence surface than most organisations currently hold.
  • The declaration is annual; the evidence behind it has to be continuous.
Take the free 15-minute assessment

What boards must now do

Monitor

Monitor the risk management and internal control framework continuously through the year — not in a scramble at annual review time.

Review

Review the effectiveness of all material controls at least annually — financial, operational, reporting and compliance alike.

Declare

Make a declaration in the annual report on the effectiveness of material controls, with a description of how the conclusion was reached.

It isn't only the regulator asking

Control maturity stopped being a compliance exercise and became a commercial one.

Private equity & investors

Due diligence is now control-centric. Integrated frameworks are expected rather than checklists, and control gaps translate directly into valuation risk — and deal friction at exactly the wrong moment.

Enterprise customers

Supply-chain assurance demands keep escalating: ISO 27001, GDPR accountability, cyber resilience — with evidence of testing rather than just a certificate, increasingly as a gate on the contract itself.

Regulators

DORA, the EU AI Act and UK GDPR accountability all expect documented, testable controls with clear ownership. Self-attestation is no longer sufficient, and a point-in-time snapshot is not ongoing effectiveness.

The underlying problem

Fragmentation is why the line can't be drawn.

ISO 27001 lives in InfoSec. GDPR sits with Legal. AI risk often isn't mapped at all. There is no single line of sight from risk to control to evidence to outcome — which is precisely the line Provision 29 asks the board to draw.

  • Principal risks link to the operational risks beneath them and the controls that mitigate them.
  • Controls carry evidence with review dates, so expiry is visible before an auditor finds it.
  • Effectiveness testing produces a record, not a recollection.
  • The annual report section is generated from that record — with an immutable audit trail behind every figure.
See the risk module

The declaration is annual.
The evidence has to be continuous.

Start with the free 15-minute diagnostic — no account needed.