Provision 29 First-year Reporting: Seven Evidence Tests for a Defensible Board Declaration

August 24, 2026

Symbiant GRC helps youprepare for first-year Provision 29 reporting with seven evidence tests covering material controls, testing, incidents, remediation and board oversight.

First reporting under the revised Provision 29 begins from 2027. The annual-report statement may be concise, but the board’s conclusion must rest on a connected, credible evidence trail built throughout the reporting period.

For companies with calendar-year reporting, 2026 is not merely a preparation year. It is the period in which the monitoring, testing, incidents, exceptions, remediation and board challenge behind the first Provision 29 declaration are being generated.

The Financial Reporting Council (FRC) expects reporting under the revised provision to begin from 2027. Its January 2026 mythbuster also indicates that the final annual-report discussion should usually remain proportionate and concise. The shortness of the disclosure should not be mistaken for a light evidence burden: the board still needs a reasonable basis for the conclusion it reaches.

 

The central question: Can the organisation trace the board’s conclusion from principal risk, to material control, to evidence of design and operation, to exceptions and remediation, and finally to informed board challenge?

Provision 29 in 2026: the facts that matter

The revised UK Corporate Governance Code 2024 applies from financial years beginning on or after 1 January 2025, with the revised Provision 29 applying to financial years beginning on or after 1 January 2026. For each applicable reporting period, the board should:

  • Monitor the company’s risk management and internal control framework and review its effectiveness at least annually.
  • Cover all controls the board has determined to be material, including financial, operational, reporting and compliance controls.
  • Describe in the annual report how the board monitored and reviewed the framework.
  • Declare whether the material controls were effective at the balance-sheet date.
  • Describe any material controls that were not operating effectively at that date, together with action taken or proposed and action on previously reported issues.


The Code applies through the UK Listing Rules to companies in the commercial companies category and the closed-ended investment funds category, regardless of where they are incorporated. Other organisations may choose to use the Code or its principles voluntarily, but that is different from being required to report against Provision 29.

 

Five boundaries that prevent overstatement

  • The declaration is not about every control. It covers the controls the board judges to be material.
  • Materiality is company-specific. The FRC does not prescribe a control framework, universal definition or target number.
  • Monitoring and declaration are not the same time test. The framework is monitored through the year; the declaration addresses material-control effectiveness at the balance-sheet date.
  • The conclusion is reasonable, not absolute. Controls have inherent limitations, and an effective control does not eliminate the underlying risk.
  • External audit is not automatic assurance over Provision 29. The external auditor’s financial-statement opinion does not cover the Provision 29 statement, and the auditor is not required by that statement alone to test the identified controls.


The FRC has reported that many companies it engaged with were considering around 30 to 50 material controls, with some financial-sector companies identifying more. It explicitly says this is not a target and that peer comparison is not required. A small, defensible population is better than a copied benchmark that does not reflect the company’s risks. FRC January 2026 mythbuster

Seven evidence tests for first-year reporting

1. The scope test: can each material-control decision be defended?

A control should not be classified as material simply because it is senior, familiar or easy to test. The board should be able to explain why a deficiency in that control could matter to the company, shareholders or other stakeholders.

The FRC’s guidance identifies useful starting points: controls over principal risks; price-sensitive or investor-relevant external reporting; fraud and management override; and information and technology risks, including cybersecurity, data protection and artificial intelligence. These are prompts for judgement, not a mandatory checklist. FRC Corporate Governance Code Guidance

The evidence file should therefore include the selection criteria, the risk or reporting outcome protected, the consequence of failure, relevant stakeholder impact, the approving authority and any changes to scope. It should also record why apparently important controls were not designated as material. Without that rationale, the population may be difficult to defend when the business, risk profile or control environment changes.

Ask: If a board member challenged why this control is material – or why another one is not – could management answer from documented criteria rather than recollection?

2. The definition test: is every material control described well enough to assess?

A label such as ‘management review’ or ‘cybersecurity monitoring’ is not an assessable control. A useful control record identifies what the control is intended to achieve, how it operates, who owns it, when or how often it operates, what evidence it produces, what counts as successful performance, which systems or third parties it depends on and what triggers escalation.

This matters because effectiveness is not one undifferentiated concept. The board needs evidence that the control is appropriately designed, has been implemented and is operating as intended. An elegant control description does not prove operation, while a completed activity does not establish that the design addresses the relevant risk.

Where controls are shared across business units, legal entities, systems or service providers, the record should make the boundaries and accountabilities explicit. Ambiguous ownership becomes especially dangerous when an exception needs to be escalated or remediated.

3. The operation test: does the evidence show performance, not just existence?

Policies, process maps and control narratives establish context. They are not, on their own, evidence that a control operated effectively. Testing should be proportionate to the nature, frequency, automation, judgement and risk significance of the control.

For each material control, agree the assessment method, evidence source, population or period covered, tester, reviewer, frequency, result criteria and treatment of deviations. Evidence may come from operational monitoring, management review, compliance testing, system logs, attestations, internal audit work or selected external assurance. The point is not to maximise paperwork; it is to create enough reliable evidence for the board to understand what was assessed, by whom, on what basis and with what result.

A first-year programme should also identify evidence gaps early. If a quarterly control first produces usable evidence in the final quarter, the board may have too little history to evaluate consistent operation or to challenge unexplained variation.

4. The contradiction test: are incidents, near misses and overrides connected to the control conclusion?

Control assessments rarely tell the whole story. Incidents, near misses, complaints, policy exceptions, threshold breaches, audit findings, data-quality issues and management overrides may contradict a clean self-assessment or reveal that a control only narrowly achieved its intended outcome.

The FRC’s guidance specifically asks boards to consider failings, weaknesses and near misses. A credible process therefore reconciles formal testing with real-world signals. If a control is marked effective while repeated incidents or exceptions point in the opposite direction, the board pack should explain the discrepancy rather than hide it in another system.

This is where connected records matter. A control conclusion should make relevant events visible and allow reviewers to follow the response, impact assessment and any change to the risk position.

5. The remediation test: can every weakness be followed to verified closure?

Finding a weakness is not the governance failure. Losing it between a meeting note, spreadsheet and email chain is. Each deficiency should move through a controlled lifecycle: classification, owner, agreed action, due date, escalation, evidence of completion, retest and authorised closure.

The balance-sheet date creates a critical cut-off. If a material control remains ineffective at that date, Provision 29 requires the annual report to describe the control and the action taken or proposed. Where a failure was remediated before the balance-sheet date, the FRC does not treat the earlier failure as automatically making the year-end declaration invalid. However, the event, its significance, the remediation and the retest still form part of the board’s cumulative assessment; publicised issues may also need to be addressed in the reporting.

A status of ‘complete’ should therefore mean more than an owner confirming that an action was performed. The organisation should retain closure evidence and, where appropriate, a test showing that the changed control is now designed and operating effectively.

6. The assurance test: is coverage coordinated, sufficient and appropriately independent?

Provision 29 does not mandate a particular assurance model or require external assurance. The board must decide what information and assurance it needs in light of the company’s risks, complexity, maturity and resources.

In practice, evidence may be distributed across operational owners, risk, compliance, finance, technology, internal audit and external providers. A coverage map can show which material controls are monitored by management, challenged by oversight functions, independently assessed, or not yet covered. It can also reveal duplication: several teams may be testing the same comfortable controls while higher-risk areas receive little scrutiny.

The FRC’s June 2026 auditor mythbuster draws an important boundary. The external auditor’s opinion on the financial statements does not cover the Provision 29 statement. The auditor reads and considers the statement as other information under ISA (UK) 720, but is not required solely because of Provision 29 to test the design, implementation or operating effectiveness of the board’s material controls. The board should not assume the statutory audit fills an assurance gap that management has not mapped. FRC June 2026 auditor mythbuster

For organisations using the Three Lines Model, the same evidence architecture can support operational ownership, second-line monitoring and challenge, and internal audit’s independent assurance while preserving separate responsibilities. Symbiant’s practical Three Lines guide

7. The board-judgement test: does reporting support challenge rather than simply summarise activity?

The board cannot discharge its responsibility by receiving a green dashboard or a year-end management attestation. FRC guidance says the board should form its own view from the evidence obtained and exercise the care generally applicable to directors. It should also use professional judgement and scepticism when considering management reporting alongside information from other sources.

Board and audit-committee reporting should therefore explain changes in the material-control population, testing coverage, significant deviations, contradictory evidence, unresolved actions, overdue retesting, assurance gaps, matters where effectiveness cannot yet be determined and the position at the balance-sheet date. Trends and exceptions are usually more decision-useful than a long control inventory.

The final declaration should be the output of that governance process. Software can organise evidence, surface relationships and report status; it cannot decide materiality, exercise scepticism or make the declaration on the board’s behalf.

A practical timetable relative to the balance-sheet date

Companies have different reporting calendars, so readiness is better planned backwards from the relevant balance-sheet date than around a single universal deadline.

Timing

Priority

Evidence to retain

T-6 months or earlier

Confirm materiality criteria, scope, owners and assurance plan.

Approved scope rationale; control records; coverage map; testing calendar.

T-3 to T-6 months

Complete planned testing, reconcile incidents and identify gaps.

Test results; source evidence; exceptions; risk impacts; board or committee challenge.

T-1 to T-3 months

Remediate, retest and rehearse the conclusion.

Action status; closure evidence; retest results; draft board paper; unresolved matters.

At and after balance sheet

Freeze the relevant status, complete permitted post-close procedures and finalise disclosure.

Date-specific control status; final evidence pack; board decision record; disclosure rationale.

Planning note: tailor timing, testing frequency and governance steps to the company’s reporting calendar, risk profile and assurance model.

How Symbiant can support a connected Provision 29 evidence trail

Provision 29 is a governance responsibility, not a software feature. The practical role of technology is to reduce fragmentation and make the relationships behind the board’s judgement visible, controlled and reportable.

Evidence need

How Symbiant can support it

Scope and line of sight

Risk Registers and Business Objectives can connect strategic objectives, principal risks, appetite, ownership and the controls intended to manage exposure.

Control records and testing

Controls and Policies can centralise key or active controls, link policies and supporting documents, record reviews and support risk control self-assessments.

Structured evidence collection

Questionnaires, Surveys and Assessments can issue scheduled or targeted assessments, apply configurable question logic and retain response history.

Operational signals

Incident Reporter and Key Risk Indicators can connect events, near misses and threshold changes to affected risks and controls.

Independent assurance

Audit Universe and Audit Working Papers can support risk-based audit planning, testing records, related documents and links to risks, controls and incidents.

Remediation

Risk, audit and compliance action tracking can assign owners and due dates, automate reminders, retain updates and evidence, and report overdue or blocked actions.

Board reporting

Connected dashboards and configurable reporting can bring current control status, exceptions, incidents, assurance and remediation into a more coherent board view.

Important: Symbiant can support the workflow, traceability and evidence base. It does not determine which controls are material, prescribe the assurance needed, replace directors’ judgement or guarantee compliance with Provision 29.

Explore Symbiant’s Provision 29 solution, controls and policies software and audit management software to see how connected modules can support a proportionate evidence model.

Questions for the board and audit committee before year-end

  • Can we explain and evidence why every control in scope is material?
  • Have we distinguished control design, implementation and operating effectiveness?
  • Does the evidence cover the relevant period and reflect the control’s frequency and risk?
  • Have incidents, near misses, overrides, complaints, KRI breaches and audit findings been reconciled to the control conclusions?
  • Are material weaknesses, overdue actions and unverified closures visible rather than averaged into a green status?
  • Is assurance coverage sufficient, coordinated and appropriately independent for the risks involved?
  • What information has the board challenged, and how is that challenge evidenced?
  • Can we state the position of every material control at the balance-sheet date, including any control whose effectiveness cannot yet be determined?

From a short declaration to a strong evidence chain

Provision 29 is not primarily a disclosure-writing exercise. It is a test of whether the board can reach a proportionate, evidence-based conclusion about the material controls that matter most to the company and its stakeholders.

The strongest first-year programmes will not be those with the largest control inventories or the most testing documents. They will be those that can show a clear chain from risk and materiality, through control design and operation, to exceptions, remediation, assurance and informed board judgement.

That is also the opportunity. When the evidence is connected and responsibilities are clear, Provision 29 can improve risk visibility and governance throughout the year rather than becoming a compressed annual-report exercise.

 

 

 

Sources and further reading:

1. UK Corporate Governance Code 2024. Financial Reporting Council. Applicability, effective dates and Provision 29.

2. Corporate Governance Code Guidance. Financial Reporting Council. Material controls, monitoring, review and declaration guidance.

3. Provision 29 Mythbuster. Financial Reporting Council, January 2026. Proportionality, timing, assurance and reporting.

4. Provision 29 and auditor responsibilities mythbuster. Financial Reporting Council, June 2026. Boundary with the financial-statement audit.

5. The IIA’s Three Lines Model. The Institute of Internal Auditors. Governance roles and independent assurance.

Disclaimer: This article provides general information and should not be treated as legal, regulatory, accounting or audit advice. Organisations should consider the Code, FRC guidance and professional advice in light of their own circumstances.

Build the evidence behind your Provision 29 declaration

Symbiant connects risks, material controls, assessments, incidents, audit work and remediation in one configurable platform, helping teams create a traceable evidence base for board oversight. See how Symbiant supports Provision 29 or book a tailored demonstration.

Stafford Railway Building Society uses Symbiant to enhance compliance and governance

Provision 29 FAQs

When does Provision 29 take effect?

The revised Provision 29 applies to financial years beginning on or after 1 January 2026. The FRC expects reporting against it to begin from 2027 onwards.

The FRC does not prescribe a definition or list. The board determines material controls for the company, considering how a deficiency could affect the company, shareholders or other stakeholders and taking account of the company’s risks and circumstances.

There is no required number. The FRC has observed that many companies it engaged with were considering 30 to 50, with some identifying more, but it expressly says this is not a target or peer benchmark.

No. The board monitors the risk management and internal control framework, while the declaration is about the effectiveness of the controls the board has determined to be material.

No. The Code does not mandate external assurance. The board and management decide whether it is needed and to what degree, based on the company’s circumstances and the assurance already available.

Not automatically. The FRC’s June 2026 mythbuster says the financial-statement audit opinion does not cover the Provision 29 statement and the auditor is not required solely because of the statement to test the design, implementation or operating effectiveness of the board’s identified material controls.

The annual report should describe the material control and the action taken or proposed to improve it, together with action on previously reported issues. If the board cannot determine effectiveness, the FRC guidance indicates that the company can use the Code’s comply-or-explain approach and explain the position.

‘UK SOX’ is market shorthand, not the name used in the Code. Provision 29 remains principles-based: the FRC does not prescribe a controls framework, standard declaration wording or mandatory external assurance. It should not be presented as a direct equivalent of the US regime.