Provision 29: Why identifying material controls is the real challenge
Provision 29 of the UK Corporate Governance Code (UKCGC) marks a significant shift for businesses. For accounting periods beginning on or after 1 January 2026, companies adopting the Code will need to declare whether their material controls were effective at the balance sheet date and explain any significant shortcomings.
While much of the discussion has focused on the disclosure itself, the bigger challenge may be far less obvious: deciding which controls are actually material and creating a robust framework to support the board’s declaration. A robust framework should help the board understand how material controls have been identified, who owns them, how they are tested, what evidence supports their effectiveness and how deficiencies will be escalated, remediated and reported.
With no prescribed template from the Financial Reporting Council (FRC) and limited guidance on what constitutes a material control, businesses are entering a period where judgement, governance and documentation will be under increasing scrutiny.
Who this matters to
These requirements are particularly relevant to:
- audit committee members;
- boards of directors;
- internal audit teams;
- risk and compliance leaders;
- finance and governance professionals at UKCGC adopters.
The challenge may be greatest for smaller Code adopters or organisations with limited internal audit resource.
Compliance is not the hardest part
A common misconception is that Provision 29 is primarily a reporting exercise. In reality, the declaration is simply the visible outcome of a much broader process.
The real challenge lies in defining, documenting and testing material controls. Unlike financial reporting controls alone, material controls can extend across a business’s wider risk landscape. They may relate to strategic risks, solvency and liquidity, reputation, fraud, cyber security, technology systems or information that could influence investor decisions.
The FRC has made it clear that it does not intend to provide definitive examples. That means every organisation must develop its own view based on its business model, risk profile and principal risks.
This creates a governance challenge rather than a compliance exercise. Two organisations operating in the same sector could reasonably identify different sets of material controls based on their circumstances.
Why businesses risk underestimating the scale
One of the emerging themes from organisations already preparing for the new requirements is the volume of work involved.
Recent FRC observations indicate that listed companies have identified anywhere between 30 and 50 material controls, with some identifying even more.
For businesses at an earlier stage of preparation, the practical implications can be substantial. Questions that boards may need to address include:
- What constitutes an effective control?
- Is there an acceptable level of deviation?
- How frequently should controls be tested?
- How much evidence is required before the audit committee can make a declaration?
- Who owns the process and reports the results?
These discussions often reveal that governance expectations, testing requirements and reporting responsibilities are more complex than initially anticipated.
Demonstrating resilience
Another area that businesses may overlook is the need to think beyond the first declaration.
Many organisations are naturally focused on demonstrating compliance for the initial reporting period. However, investors and other stakeholders are likely to pay close attention not only to the outcome, but also to how businesses respond when weaknesses are identified.
If a material control is found to be ineffective, companies will need to explain both the issue and the actions being taken to address it.
This places greater importance on governance processes, decision-making and accountability. Businesses should be considering how remediation plans will be approved, monitored and communicated long before disclosures are drafted.
In practice, organisations that begin this work early are often better placed to identify gaps, refine testing methodologies and avoid last-minute governance pressures.
The role of the audit committee is evolving
The new requirements are also changing expectations of audit committees.
Historically, discussions around internal controls may have focused heavily on financial reporting. Provision 29 broadens the conversation, requiring committees to consider risks that could affect the wider resilience and sustainability of the business.
This raises important questions around materiality. A control weakness may not be financially significant in isolation, but could still have substantial reputational, operational or strategic consequences.
As businesses gain experience with the new requirements, we are likely to see more sophisticated approaches to risk assessment, control identification and ongoing monitoring.
Looking ahead
Provision 29 will not be a one-off governance exercise. As organisations complete their first reporting cycles, expectations will continue to evolve. Boards will refine their definitions of material controls, emerging risks will influence testing programmes and benchmarking against peers is likely to become increasingly important.
The quality of board discussions, governance documentation and control monitoring processes may ultimately become just as important as the final declaration itself.
For many businesses, the coming months offer an opportunity to assess whether current plans remain on track and whether existing resources, expertise and governance structures are sufficient for the challenge ahead.
Conclusion
The introduction of Provision 29 represents more than a new disclosure requirement. It signals a broader shift towards greater accountability for the effectiveness of material controls.
The organisations best positioned for success are unlikely to be those focusing solely on the wording of the declaration. Instead, they will be the ones investing time now in defining material controls, strengthening governance processes and building evidence to support their conclusions.
For boards and audit committees, the key question may not be whether a declaration can be made, but whether it can be made with confidence.
For more information, contact us.
