Until now, if your company is subject to the UK Corporate Governance Code, its annual report needed only a reference to having a system of internal controls. From this year, that changes completely.
Provision 29 of the UK Corporate Governance Code 2024 applies to financial years beginning on or after 1 January 2026, meaning most affected boards are inside their qualifying year right now. It requires three things in the annual report: a description of how the board actually monitored and reviewed its control framework across the year, an explicit declaration of whether material controls were effective at the balance sheet date, and, where they weren't, a disclosure of what went wrong and what's being done about it.
That third element is the one boards are least prepared for. Grant Thornton's 2025 Corporate Governance Review found 45% of companies had only partially met the spirit of Provision 29 so far. Most of the gap isn't technical. It's the discomfort of writing down, in a public document, that something didn't work.
Why this covers more boards than you might assume
Provision 29 applies to two listing categories: the FCA's commercial companies' category and closed-ended investment funds. The FCA treats this as a Listing Rule obligation, not a courtesy.
The Code itself operates on a comply-or-explain basis, so a board can depart from Provision 29's substance if it explains that decision adequately. What isn't optional is making the declaration or the explanation at all: failing to do either is the actual breach, and a director knowingly involved in that failure is one the FCA can investigate directly. The practical risk is still reputational, and it cuts against instinct. An annual report that stays vague on control effectiveness reads worse to investors than one that names a genuine weakness alongside a credible remediation plan. Silence is now the worst answer available. Disclosed imperfection, honestly explained, is not.
Andrew Kemp, Audit Committee Chair at The Berkeley Group and Chair of the Audit Committee Chairs' Independent Forum, puts it plainly: "The detail of the declaration is relatively low value." What actually matters to investors, he argues, is knowing the process behind it was genuine.
The judgement call
Here is where Provision 29 gets genuinely difficult, and deliberately so. The FRC has not defined what counts as a "material control." No checklist, no minimum list, no template. That decision sits entirely with the board.
This is not an oversight. Mark Babington, the FRC's Executive Director of Regulatory Standards, has said: "The flexibility of the Code remains fundamental." Doug Webb, Audit Committee Chair at Johnson Matthey and a United Utilities audit committee member, welcomes the same approach from the practitioner's side: "It is encouraging that the FRC is not expecting 'one size fits all.'"
Not every board agrees the ambiguity is a good thing. Jock Lennox, Board Chair at Johnson Service Group, wants more concrete direction, arguing "there should be some example of what this should or shouldn't look like." The disagreement itself tells you something: even experienced practitioners aren't settled on how much guidance is enough, which means your own board's judgement here isn't going to have an obvious right answer to copy from elsewhere.
The same principle, everywhere at once
This is not an isolated UK development. It's one instance of a pattern regulators are converging on from every direction: a policy on paper is no longer sufficient evidence of governance.
The EU's Digital Operational Resilience Act, in force since January 2025, places the same expectation on financial entities' management bodies specifically for ICT risk: ultimate ownership, not delegated oversight. Ireland's Central Bank has said explicitly it is examining whether boards genuinely control strategic decisions, not merely receive updates on them. The UK's own FCA reached a parallel milestone in March 2025, requiring firms to name their important business services and demonstrate, not assert, that they can survive disruption within stated tolerances.
Different regulators, different sectors, no coordination between them, and the same underlying demand. The function can sit with management, a service provider, or a specialist committee. The evidence of ownership cannot be outsourced to anyone.
What this actually asks of the board, this year
The honest test for any board right now: if asked today which controls it considers material, could it point to the evidence its own management and risk functions have provided, explain how that evidence was tested this year, and say plainly whether it held? Most boards aren't there yet, according to Grant Thornton's own findings. But the boards that get there before their reporting deadline arrives, rather than scrambling once it does, are the ones that will write a credible declaration instead of a defensive one.
MyDirector-OS was built to support exactly this kind of oversight, one that looks different for every appointment a director holds.
BoardLens reviews board packs and any other document through the lens of the specific regulatory framework governing each appointment, so a director can see whether the evidence a board pack presents is actually adequate to support a Provision 29 declaration, rather than discovering a gap after the fact. The Director's Assistant answers governance questions grounded in the framework that applies to each specific board a director sits on, not generic principles borrowed from wherever a model happened to learn them.
The boards already reviewing real evidence, not just a policy reference, are exactly where they need to be. The ones still relying on a description of a framework have a narrowing window to close the gap before their own declaration falls due.
