error
Subscriptions are not available for this site while you are logged into your current account.
close
Skip to main content

      Provision 29 of the UK Corporate Governance Code (the “Code”) requires company Boards to make a formal declaration on the effectiveness of its material internal controls. This is an important development in governance, risk management and internal controls.  

      Explore the insights from our Risk Consulting team below.

      Michael Daughton

      Partner, Enterprise Risk Services

      KPMG in Ireland


      An evolving governance landscape

      The 2024 UK Corporate Governance Code introduces an enhanced focus on risk management and internal controls through Provision 29. Provision 29 applies to accounting periods beginning on or after 1 January 2026, with the first reports due in 2027.

      Boards are required to provide additional transparency regarding how they have monitored and reviewed the effectiveness of their organisation’s material controls and whether those controls were effective at the balance sheet date.

      While much of the discussion surrounding Provision 29 has focused on risk management systems, material controls, documentation and assurance activities, the implications extend beyond compliance and reporting.

      At its core, Provision 29 reinforces the Board’s role in overseeing the risk management and internal controls framework and encourages greater transparency in relation to how Boards gain confidence in the effectiveness of these arrangements.

      For many organisations, this presents an opportunity to strengthen governance, the risk management and internal control framework, identification and assessment of material risks and controls, enhance assurance arrangements and improve the quality of information available to support decision-making at Board level.




      Looking beyond financial controls

      A key message from the Financial Reporting Council (FRC) is that organisations should consider material controls across a range of areas and not solely financial controls.

      Consequently, Boards are increasingly seeking greater visibility over risk management and internal controls in areas such as:


      • Cybersecurity
      • Artificial intelligence
      • Data governance and privacy
      • Regulatory compliance
      • Third-party and supply chain risks
      • Operational resilience, IT resilience, business continuity and IT disaster recovery
      • Health and safety
      • People
      • Strategic and operational risks that could significantly impact organisational objectives.

      For many organisations, these critical areas would be subject to oversight, but this oversight is often distributed across different governance forums and functions, and there is no single enterprise wide view of risks and controls.

      The challenge is also ensuring that information in relation to these areas and the broader Provision 29 requirements is presented to the Board in a manner that enables effective oversight and informed decision-making.


      Key areas for Board focus

      Effective oversight begins with a clear understanding of the organisation’s principal and material risks, risk appetite and the material controls relied upon to mitigate these risks.

      Boards that have a strong understanding of the business model, operating environment and key risks are generally better positioned to assess whether appropriate governance, risk management and control arrangements are operating across the organisation.

      This aligns closely with leading practices identified through Board and Audit Committee effectiveness reviews.

      The quality of information received by the Board can significantly influence the quality of oversight. Increasingly, Boards are looking for concise, insight-driven reporting that highlights key risks, emerging issues, control concerns and management actions rather than simply presenting large volumes of data.

      Effective reporting helps facilitate constructive discussion and enables Boards to focus attention on the matters that are most important.

      Provision 29 places renewed focus on the assurance activities that support Board oversight, including in relation to the Boards responsibilities to monitor the company’s risk management and internal control framework, and at least annually, carry out a review of its effectiveness.

      While the FRC has clarified that external independent assurance is not a strict requirement of the Code, Boards need to consider the appropriateness of the existing assurance arrangements and whether it collectively provides sufficient assurance into the effectiveness of the material controls which have been identified.

      This involves evaluating how first-line monitoring, risk and compliance activities, Internal Audit reviews and specialist assurance work together to provide a comprehensive view of the control environment.

      This is also resulting in the concept of ‘integrated assurance’ frameworks and processes being more and more important for organisations. 

      The Board needs to provide the following information in the Annual Report:

      • A description of how the Board has monitored and reviewed the effectiveness of the framework;
      • A declaration of effectiveness of the material controls as at the balance sheet date; and
      • A description of any material controls which have not operated effectively as at the balance sheet date, the action taken, or proposed, to improve them and any action taken to address previously reported issues.

      In line with these requirements, Boards are increasingly focused on how control deficiencies are identified, evaluated and remediated. This includes understanding management's approach to tracking remediation activities, monitoring progress and assessing the impact of identified weaknesses.

      As reporting periods approach, many Boards are reviewing the governance processes, underlying evidence and form of their Provision 29 declarations, including level of detail to be included. 

      As organisational risks become increasingly complex, Boards are continuing to assess whether they possess the necessary skills, experience and diversity of perspectives to oversee evolving risk and control environments effectively.

      Areas such as cybersecurity, technology risk, operational resilience and regulatory compliance can require ongoing professional development and targeted Board education to ensure informed oversight.

      The organisations that are making the greatest progress are typically treating Provision 29 as part of a broader governance agenda rather than a standalone reporting exercise.

      Board evaluations, committee effectiveness reviews, governance assessments and targeted deep dives into key risk areas can all play an important role in supporting ongoing improvement and strengthening confidence in governance arrangements over time.


      What the FRC has clarified

      The FRC’s Provision 29 Mythbuster provided several helpful clarifications for organisations preparing for implementation and reporting. In particular, it highlights that:

      • There is no prescribed number of material controls that organisations should identify.
      • Organisations are not expected to disclose a detailed list of all material controls.
      • Assurance and testing procedures completed do not need to be publicly reported.
      • External independent assurance is not mandated by the Code.
      • Reporting should include discussion on the governance, oversight and review processes supporting the Board’s conclusions.

      Most importantly, the Mythbuster reinforces that Provision 29 is intended to be proportionate and judgement-based, recognising that organisations will differ in terms of complexity, risk-profile and governance arrangements. 


      Beyond compliance

      Provision 29 represents an important evolution in UK corporate governance. Whilst the reporting requirements are new, the underlying objective is familiar: helping Boards establish an effective risk management and internal control framework, developing a clear understanding of principal and material risks, scoping and identifying material controls, monitoring the risk management and internal control framework, obtaining assurance on the effectiveness of material controls, and providing stakeholders with confidence in the governance of the organisation.

      Organisations that approach Provision 29 as an opportunity to strengthen governance, enhance assurance and improve decision-making are likely to derive benefits well beyond compliance alone.

      By investing in governance maturity today, Boards can enhance the quality of Board oversight, strengthen organisational resilience and build greater confidence in the effectiveness of their control environment. 


      How KPMG can help

      • Bringing together governance, risk and controls expertise

        KPMG has extensive experience supporting Boards, Audit Committees and executive teams in the areas of governance, enterprise risk management, internal controls, internal audit and regulatory compliance. By combining expertise across these disciplines, we help organisations take a practical and proportionate approach to Provision 29 readiness.

      • Supporting readiness

        We work with organisations to assess their current state, identify potential gaps and develop pragmatic roadmaps aligned to their governance and risk profile. This can include reviewing existing controls frameworks, assisting with the identification of material controls and assessing the effectiveness of governance and assurance arrangements.

      • Enhancing governance and board oversight

        Our Board Effectiveness specialists have extensive experience conducting Board, Audit Committee and Risk Committee evaluations across a broad range of sectors. These reviews help organisations enhance governance structures, information flows, committee effectiveness, Board composition and oversight arrangements.

      • Strengthening assurance and controls

        We support organisations in enhancing assurance frameworks, assessing control environments, improving management reporting and strengthening the evidence available to support Board oversight. Our objective is not to add complexity, but to help organisations establish sustainable governance and assurance arrangements that are appropriate for their size, complexity and risk profile.



      Get in touch

      Speak to our team about preparing for Provision 29 and strengthening your organisation’s governance, assurance and Board oversight.

      Michael Daughton

      Partner, Enterprise Risk Services

      KPMG in Ireland

      Rebecca Whitmore

      Director

      KPMG in Ireland


      Read more in Consulting

      Something went wrong

      Oops!! Something went wrong, please try again

      Consulting

      Improving business performance through business consulting and the effective use of IT
      Four people watching a presentation