Provision 29: What You Need to Know

New internal-control reporting requirements are putting greater accountability on UK boards. Here is what Provision 29 means, who it affects and why credible compliance depends on trustworthy data.

The idea for this article began from a conversation with Paul Bell, Global Head of Data Trust & Integrity at Entain, one of Ortecha’s long-standing clients: what does Provision 29 mean in practice, and how should organisations prepare?

For most business leaders, internal controls are not a new idea. Companies already have approval processes, risk registers, audit programmes, reporting checks, access controls and governance committees.

Provision 29 asks a more difficult question: can the board demonstrate that the company’s most important controls actually worked?

That distinction matters. It moves the conversation from whether policies and controls exist to whether the board has reliable evidence of their effectiveness.

For CEOs, CFOs and CROs, this creates greater accountability. For CDAOs, CIOs and their teams, it presents a substantial data, technology and evidence challenge.

With the first declarations under the revised provision due to appear in annual reports from 2027, companies with December 2026 year-ends are already in the period that counts.

What is Provision 29?

Provision 29 forms part of the UK Corporate Governance Code 2024. It applies to financial years beginning on or after 1 January 2026.

It requires the board to monitor the company’s risk-management and internal-control framework and review its effectiveness at least annually. That monitoring and review must cover all material controls, including financial, operational, reporting and compliance controls.

The annual report must then include:

  • a description of how the board monitored and reviewed the framework;
  • a declaration on whether the material controls were effective at the balance-sheet date; and
  • details of any material controls that were not operating effectively, including the action taken or proposed to improve them.

The provision is designed to increase board-level accountability and give investors greater confidence in how companies manage risk.

It is also important to understand what Provision 29 is not. It is not a blanket new law covering every business in the UK, and it is not simply a British version of the US Sarbanes-Oxley regime.

Who does Provision 29 apply to?

The UK Corporate Governance Code applies directly to companies listed in the equity shares (commercial companies) or closed-ended investment funds categories. It operates on a comply-or-explain basis. Other organisations may choose to follow the Code voluntarily, but being a large or non-financial UK business does not automatically bring a company into scope.

Nor does Provision 29 automatically require an external auditor to attest to the board’s declaration. The board must form its own view, based on the evidence available to it.

What is a material control?

There is no standard list.

The Financial Reporting Council has deliberately left it to each board to determine which controls are material, based on the company’s risks, business model, strategy, operations and stakeholders.

A useful way of thinking about a material control is to ask:

If this control failed, could it seriously affect the company’s performance, reputation, reporting, regulatory position or ability to operate?

That clearly includes important financial controls. But the scope is much wider.

Depending on the organisation, material controls might also cover:

  • cybersecurity and access to critical systems;
  • customer, product or operational data;
  • health and safety;
  • supply-chain resilience;
  • regulatory and legal compliance;
  • sustainability and other non-financial reporting;
  • business continuity;
  • fraud prevention;
  • data protection; and
  • the use of artificial intelligence.

The FRC’s supporting guidance specifically identifies information and technology risks, including cybersecurity, data protection and AI, as areas that may require material controls.

This is why Provision 29 cannot be treated as a finance-only initiative.

Why data is the real challenge

Most companies already have a substantial number of controls. The problem is that the evidence is often fragmented.

The risk register may sit in one platform. Control descriptions may be stored in a governance, risk and compliance system. Evidence may be gathered through email, spreadsheets or screenshots. Audit findings may live in another application. Remediation actions may be tracked in a ticketing tool. Operational data may come from several ERP systems, data platforms and business units.

At the end of this chain, the board receives a summary, but may have limited ability to trace its conclusions back to the underlying evidence.

Provision 29 makes that weakness much harder to ignore.

For a declaration to be credible, a company should be able to follow a clear line from:

principal risk → material control → accountable owner → system or process → evidence → testing → exception → remediation → board conclusion

If that chain is incomplete, the problem is not solved by writing a better declaration. The underlying information environment needs attention.

Data governance and data engineering are therefore central to the control framework. Companies need consistent definitions, accountable owners, reliable data pipelines, source-to-report lineage, documented evidence, controlled access and clear records of changes and decisions.

The answer is not necessarily a large new compliance platform. In many cases, companies can connect the systems they already use and create a reliable evidence layer across them.

What are companies doing now?

Companies have moved beyond simply discussing the new provision.

EY’s June 2026 review of more than 100 FTSE 350 annual reports found that 65% of companies discussed enhancing or introducing internal-control testing, while 41% specifically referenced testing material controls. However, only 15% referred to assurance mapping, and EY concluded that the board’s own monitoring and review still required more attention.

Companies are also implementing or improving GRC systems, control-monitoring processes, reporting trackers and evidence-retention capabilities.

Organisations are now moving from defining their approach to showing that it works.

Six questions every leadership team should ask

Provision 29 does not need to begin with a large transformation programme. It should begin with an honest assessment of the evidence already available.

Leadership teams should ask:

  • Can we trace every material control to the principal risk it addresses?
  • Can we show what evidence demonstrates that each control operated effectively?
  • How much of that evidence is still gathered manually through email, spreadsheets and screenshots?
  • Are control failures, near misses and overdue remediation visible and escalated quickly enough?
  • Can the board reconcile evidence from management, risk, compliance and internal audit?
  • Do we have appropriate controls over critical data, external reporting and AI?

If the answer to several of these questions is “not consistently”, the organisation is likely to have an evidence problem rather than a policy problem.

How should companies prepare for Provision 29?

A practical approach has three stages.

01. Assess

Map a representative group of material controls to their owners, systems, data, evidence, testing and board reporting. Identify manual processes, unclear ownership, missing lineage and inconsistent evidence.

02. Connect

Create a joined-up view across existing risk, control, audit and operational systems. Establish common identifiers, traceability and controlled evidence retention without assuming that every process must move onto a single platform.

03. Monitor

Automate selected control tests and evidence collection where this improves reliability. Use dashboards and alerts to expose exceptions, remediation status and changes in risk, while retaining accountable human judgement over effectiveness.

AI can help find anomalies, identify inconsistent control descriptions and summarise evidence with links back to source material. It should support the people responsible for the declaration, not make the decision for them.

The wider opportunity

Provision 29 may look like another reporting requirement, but it can deliver more than compliance.

It can expose duplicated controls, weak data ownership, manual reporting processes and disconnected assurance activity. Addressing those weaknesses can improve decision-making, reduce operational risk and give management a clearer picture of how the organisation is actually performing.

The companies that benefit most will not be those that produce the longest control documents. They will be the ones that give the board timely, reliable and traceable evidence, then act quickly when that evidence shows something is wrong.

That is the real standard Provision 29 is setting.

How confident are you in the evidence behind your Provision 29 declaration?

Ortecha helps organisations connect material risks and controls to trustworthy operational data, automated monitoring and board-ready evidence. 

Speak to us about your Provision 29 Data & Evidence readiness ➞ 

Sources and further reading

Let's do a quick recap

When does Provision 29 take effect?

Provision 29 applies to financial years beginning on or after 1 January 2026. For companies with a 31 December year-end, the first board declarations are expected in annual reports published in 2027. The requirement concerns the effectiveness of material controls at the balance-sheet date.

Provision 29 applies directly to companies that follow the UK Corporate Governance Code, including companies listed in the commercial companies or closed-ended investment funds categories. The Code operates on a comply-or-explain basis. Other organisations can adopt it voluntarily, but large UK businesses are not automatically in scope.

No. Provision 29 does not automatically require external assurance over the board’s declaration. The board must form its own view using evidence from its monitoring and annual review. It is for each board to decide whether external assurance is needed and, if so, which parts of the control framework it should cover.

No. Provision 29 is not simply a UK version of the US Sarbanes-Oxley Act. It covers material financial, operational, reporting and compliance controls, while SOX focuses primarily on internal control over financial reporting. Companies that report under SOX may build on that work, but still need to address Provision 29’s wider scope.

The FRC does not prescribe a target number of material controls. Each board must decide what is material for its organisation, based on its risks, business model, strategy, operations and complexity. The FRC has observed that many companies have identified between 30 and 50, but this is not a benchmark or requirement.

Let's talk about how you're implementing AI into your business.