UK CORPORATE GOVERNANCE CODE 2024 | PROVISION 29
Build the Evidence Behind Your Provision 29 Declaration with Symbiant GRC Software
Connect material controls to principal risks, testing, incidents, assurance and remediation in one auditable platform – giving boards a clear, current evidence base for their own assessment of control effectiveness.
Provision 29 applies to financial years beginning on or after 1 January 2026. The first reporting under the revised provision is expected from 2027 onwards.
Meet Provision 29 requirements easily with Symbiant from just £300/month with 5 users*
Award-Winning GRC & Audit Software, Trusted Since 1999 by Companies of All Sizes
UK Corporate Governance Code Provision 29
Preparing for Provision 29 of the UK Corporate Governance Code
For financial years beginning on or after 1 January 2026, companies applying the 2024 UK Corporate Governance Code must meet the revised requirements of Provision 29. Boards must explain how they have monitored and reviewed the company’s risk management and internal control framework, declare whether its material financial, operational, reporting and compliance controls were effective as at the balance sheet date, and describe any material controls that did not operate effectively, together with the actions taken or proposed.
Sometimes referred to as “UK SOX”, Provision 29 is more than another compliance management requirement. It places greater emphasis on board judgement, proportionate evidence and clear oversight of material controls.
Symbiant’s integrated GRC and Audit Management software supports this process by connecting risks, material controls, testing, incidents, audits, findings and remediation in one clear, auditable platform. This gives boards a current and traceable evidence base to support their assessment and confidently report under Provision 29.
PROVISION 29 IN PRACTICE
The Declaration Is Brief. The Evidence Behind It Is Not.
Provision 29 of the UK Corporate Governance Code asks the board to monitor the company’s risk management and internal control framework, review its effectiveness at least annually and report on all material financial, operational, reporting and compliance controls.
-
Explain the monitoring and reviewDescribe how the board monitored and reviewed the effectiveness of the risk management and internal control framework.
-
Make the declaration Declare whether the company's material controls were effective as at the balance sheet date.
-
Disclose weaknesses and action Describe any material controls that were not operating effectively at that date, together with action taken or proposed to improve them.



FROM POLICY TO DEFENSIBLE EVIDENCE
Turn Disconnected Control Activity Into a Traceable Assurance Story
1. Principal risks and objectives
Identify what could affect the organisation’s objectives and maintain a clear view of principal risk exposure.
2. Material controls
Document controls, ownership and supporting policies, then link each control to the risks it is intended to manage.
3. Monitoring and testing
Schedule assessments, RCSAs, management reviews or audit work and collect evidence in a repeatable format.
4. Signals and weaknesses
Connect failed tests, incidents, near misses, KRIs and audit findings to the relevant controls and risks.
5. Remediation
Assign actions, due dates and owners; retain updates and supporting evidence through to completion.
6. Board reporting
Bring current control status, assurance results, exceptions and remediation into clear dashboards and reports.
CONNECTED CONTROLS ASSURANCE
Build a Repeatable Provision 29 Evidence Process
Symbiant brings risk, control, assurance and remediation activity into a configurable workflow. Your organisation decides what is material, how controls should be assessed and what evidence the board needs; the platform makes that process easier to operate, monitor and report.
1. Define and organise your control population
Create a central library of controls and policies, identify key or material controls according to your own methodology, assign ownership and link controls to principal risks and business objectives.
- Consistent taxonomy across teams
- Clear ownership and review dates
- Links between objectives, risks, controls and policies
2. Run structured monitoring and testing
Use configurable assessments, questionnaires, RCSAs and audit workflows to gather evidence and record results throughout the reporting period.
- Scheduled reviews and automated reminders
- Conditional questions and evidence requests
- Complete history of results and supporting documents
3. Bring real-world signals into the review
Link incidents, near misses, KRI movements and audit findings to the controls and risks they affect, giving reviewers more context than a standalone test result can provide.
- Control failures connected to risk exposure
- Early-warning indicators and trend visibility
- One current view across operational and assurance data
4. Track weaknesses and remediation
Record issues, assign accountable owners, set due dates and follow corrective action through to completion with a visible audit trail.
- Automated notifications and escalation
- Evidence attached to every action
- Clear status for management, assurance teams and committees
5. Prepare board-ready reporting
Use live dashboards and configurable reports to bring together control status, monitoring activity, exceptions and remediation for board and audit committee review.
- Current rather than end-of-year-only visibility
- Drill-down from summary to source evidence
- Configurable outputs aligned to your reporting process
MODULAR BY DESIGN
Choose the Capabilities You Need. Keep the Evidence Connected.
Provision 29 does not require one prescribed system or process. Symbiant’s modular platform lets you start with the capabilities you need and expand over time while maintaining one connected source of risk, control and assurance information.
Capability | Provision 29 contribution |
Maintain the control library, ownership, policies, evidence and review history. | |
Connect controls to principal risks, objectives, incidents and current risk exposure. | |
Schedule control testing, RCSAs, attestations and evidence collection. | |
Add operational signals, failures, near misses and thresholds to the control picture. | |
Document independent testing, findings, evidence and assurance conclusions. | |
Assign, monitor and evidence remediation arising from reviews, testing or audit. | |
Dashboards & Report Wizard | Create role-based oversight and board-ready reporting with drill-down traceability. |
Show how principal risks and controls relate to the outcomes the organisation is trying to achieve. |
UK Corporate Governance Code Provision 29
Create a Single Source of Truth (SSOT) for Risk and Control with Symbiant GRC, Risk Management and Audit Software
Unify fragmented processes into one connected, organisation-wide framework. Symbiant replaces spreadsheets and siloed systems with a modular, fully customisable, intuitive and auditable platform that grows with your business.
- Maintain connected registers – risks, controls, policies, incidents, audits, and issues are all linked and cross-referenced in real time.
- Apply consistent frameworks – align controls and risks with ISO 31000 and ISO 27001, ensuring a common taxonomy across business units.
- Ensure full traceability – link strategic objectives to risks, controls, and incidents, giving boards a clear line of sight to control effectiveness.
- Capture and monitor incidents – log real-time events that impact risk or control performance, triggering reviews and remedial action plans.
- Scale with ease – modular design and £100 per module* licensing mean you only pay for what you need, while unlimited user access ensures organisation-wide visibility.
UK Corporate Governance Code 2024
How Symbiant Helps You Meet Provision 29 of the UK Corporate Governance Code
Provision 29 isn’t about processes on paper — it’s about evidence your board can trust. Symbiant’s modular GRC and Audit platform was built to calculate, report, and demonstrate the effectiveness of your internal controls in real time.
How Symbiant’s Modules Support Provision 29
Lets you build a centralised control library of active and key controls.
Supports Risk Control Self-Assessments (RCSA) and automatically adjusts residual risk scores when controls fail.
Allows reviews and remedial action plans to be tracked to completion, giving you auditable proof of control effectiveness.
Simplifies ISO 27001 compliance with one-click Statements of Applicability.
Links risks to controls, incidents, and policies to give full traceability.
Provides dynamic residual scoring and multiple risk scoring methods to show how controls impact risk exposure.
Supports board reporting by aggregating risk and control data into a single, connected register.
Captures real-time events that impact risk or control performance.
Links incidents directly to risks and controls, helping boards understand how failures are addressed.
Automatically generates reviews and remedial action plans, with tracking through to completion.
Questionnaires, Surveys & Assessments Module
Allows you to schedule control testing and assurance activities across the business.
Supports Risk Control Self-Assessments and structured reviews, producing evidence for annual reporting.
Uses dynamic questions and conditional logic to dig deeper into control performance.
Provides a single folder for all audit evidence, including linked risks, controls, incidents, and test results.
Enables one-click generation of complete audit reports, ensuring boards receive clear evidence of control effectiveness.
Creates a permanent audit trail to support year-end declarations.
Logs weaknesses and remediation actions arising from audits or testing.
Assigns ownership, due dates, and automated reminders to ensure accountability.
Provides boards with visibility of progress and assurance that failures are being addressed.
Key Risk Indicators (KRI) Module
Acts as an early-warning system for risks that may affect controls.
Monitors environmental factors and aggregates data into KRIs linked to the Risk Register.
Helps boards anticipate where control weaknesses might emerge.
Together, these modules mean that with Symbiant:
Controls are documented, tested, and continuously monitored.
Weaknesses are logged, assigned, and remediated with accountability.
Risks, incidents, audits, and controls are fully connected and auditable.
Boards get clear, real-time dashboards and one-click reports for annual Provision 29 declarations.
Calculate and Report Control Effectiveness
With Symbiant, internal control effectiveness isn’t left to subjective judgement. Our platform links risks directly to controls and dynamically recalculates residual risk scores whenever a control is tested or fails. This means boards have a live, accurate view of whether controls are performing as intended. This automated scoring goes beyond static spreadsheets, providing assurance that your organisation’s risk exposure is always up to date.
Evidence Every Step with a Single Source of Truth
Symbiant replaces fragmented systems with a connected framework that links risk registers, control libraries, audit working papers, incidents, and policies into a single, auditable source of truth. Every control is mapped and cross-referenced, ensuring full traceability from strategic objectives down to control effectiveness. This traceability is central to meeting Provision 29, which requires boards to demonstrate not just the presence of controls but their real-world performance and alignment to governance outcomes.
Track Remediation with Accountability
Provision 29 requires transparency when controls have not operated effectively, including the actions taken to address weaknesses. Symbiant makes this simple with integrated action tracking. You can log weaknesses, assign clear ownership, set deadlines, and automatically notify responsible employees until actions are completed. Progress can be monitored in real time, ensuring that remediation is not only recorded but actively managed to completion. This turns weaknesses into opportunities for continual improvement, fully aligned with the FRC’s expectations.
Board-Ready Dashboards and Reports
For boards and audit committees, assurance must be clear, visual, and actionable. Symbiant provides real-time dashboards that show control effectiveness. By aligning reports to the UK Corporate Governance Code’s focus on outcomes-based governance, Symbiant enables directors to make informed, confident declarations with evidence they can trust.
Affordable, Scalable, and Easy to Implement
Unlike complex and costly platforms, Symbiant is modular, affordable, agile, fully customisable and designed to grow with your organisation. Each module is just £100 per month* with unlimited users, so you only pay for what you need while ensuring complete organisational coverage. Our no-code flexibility means you can configure forms, workflows, and dashboards without external consultants, making compliance with Provision 29 both sustainable and cost-effective.
Optional AI Insights for Proactive Assurance
For organisations that want to go further, Symbiant offers an optional AI Assistant to provide advanced insights. This includes detecting hidden risks, performing root cause and consequence analysis, and recommending new or improved controls to strengthen your assurance framework. By surfacing patterns across your GRC data, AI moves you from reactive monitoring to proactive governance, supporting boards in delivering stronger, evidence-based declarations under Provision 29.
UK-Based, Secure, and Trusted
With over 23 years of experience supporting UK and global businesses, charities, and government bodies, Symbiant is built on trust and proven performance. Hosting is UK-based, with ISO 27001 and Cyber Essentials Plus certification, ensuring data security and compliance with UK regulatory expectations. Trusted by organisations like UKHSA, Whistl, CITB, and more, Symbiant delivers a solution that combines affordability, flexibility, and assurance at the highest governance level.
BUILT AROUND YOUR ORGANISATION
Support Clear Accountability Without Dictating Your Governance Model
Symbiant does not prescribe how your organisation should structure governance or assurance. Configure fields, workflows, permissions, approval steps, scoring methods and reporting to support a traditional Three Lines model, combined assurance or an alternative framework.
Operational management
Own risks and controls, complete reviews, provide evidence and deliver actions.
Risk and compliance
Set methodologies, monitor completion, challenge results and identify emerging concerns.
Internal audit
Plan and document independent assurance using the same underlying risk and control information while retaining separate permissions and accountability.
Board and committees
Review a consolidated picture of control status, assurance coverage, weaknesses and remediation.
Provision 29 FAQs
When does Provision 29 apply?
Provision 29 applies to financial years beginning on or after 1 January 2026. The FRC expects reporting against the revised provision to begin from 2027 onwards.
Who does the UK Corporate Governance Code apply to?
The Code applies to companies listed in the commercial companies category or the closed-ended investment funds category, regardless of where they are incorporated. Other organisations may choose to use it as a governance benchmark, but private companies are not automatically within its scope.
What does Provision 29 require the board to report?
The annual report should describe how the board monitored and reviewed the risk management and internal control framework, include a declaration on the effectiveness of material controls at the balance sheet date, and describe any material controls that were not operating effectively together with action taken or proposed.
What is a material control under Provision 29?
The FRC does not prescribe a standard list or definition for every company. The board determines which controls are material in the context of the organisation’s principal risks, circumstances, complexity and risk appetite.
Does Provision 29 require external assurance?
No. The Code does not require external assurance over material controls. The board decides whether external or additional assurance is appropriate and over which areas.
Is Provision 29 the same as UK SOX?
‘UK SOX’ is sometimes used as shorthand, but Provision 29 is not the same as the US Sarbanes-Oxley regime. The UK Code is principles-based and operates on a comply-or-explain basis. Its material-control scope includes financial, operational, reporting and compliance controls.
Can software decide whether controls are effective?
Software can structure testing, consolidate results, track exceptions and provide reporting, but the board remains responsible for its own assessment and declaration. Symbiant GRC supports that judgement with connected, traceable evidence.
Can software decide whether controls are effective?
Software can structure testing, consolidate results, track exceptions and provide reporting, but the board remains responsible for its own assessment and declaration. Symbiant GRC supports that judgement with connected, traceable evidence.