UK CORPORATE GOVERNANCE CODE 2024 | PROVISION 29

Build the Evidence Behind Your Provision 29 Declaration with Symbiant GRC Software

Connect material controls to principal risks, testing, incidents, assurance and remediation in one auditable platform – giving boards a clear, current evidence base for their own assessment of control effectiveness.

Provision 29 applies to financial years beginning on or after 1 January 2026. The first reporting under the revised provision is expected from 2027 onwards.

Meet Provision 29 requirements easily with Symbiant from just  £300/month with 5 users*

Award-Winning GRC & Audit Software, Trusted Since 1999 by Companies of All Sizes

Arrow Global Medical Protection Forvis Mazars ILO Natural Resources Wales UKHSA United Arab Bank Cardiff Met Bank of England ABP TF Bank CITB Auckland Transport HM Customs University of Dundee Office of the Public Appointments (Oil Agency) Office for Nuclear Regulation Arrow Global Medical Protection Forvis Mazars ILO Natural Resources Wales UKHSA United Arab Bank Cardiff Met Bank of England ABP TF Bank CITB Auckland Transport HM Customs University of Dundee Office of the Public Appointments (Oil Agency) Office for Nuclear Regulation

UK Corporate Governance Code Provision 29

Preparing for Provision 29 of the UK Corporate Governance Code

For financial years beginning on or after 1 January 2026, companies applying the 2024 UK Corporate Governance Code must meet the revised requirements of Provision 29. Boards must explain how they have monitored and reviewed the company’s risk management and internal control framework, declare whether its material financial, operational, reporting and compliance controls were effective as at the balance sheet date, and describe any material controls that did not operate effectively, together with the actions taken or proposed.

Sometimes referred to as “UK SOX”, Provision 29 is more than another compliance management requirement. It places greater emphasis on board judgement, proportionate evidence and clear oversight of material controls.

Symbiant’s integrated GRC and Audit Management software supports this process by connecting risks, material controls, testing, incidents, audits, findings and remediation in one clear, auditable platform. This gives boards a current and traceable evidence base to support their assessment and confidently report under Provision 29.

Be ready for the 2026 Provision 29 requirement. Symbiant’s award-winning software helps boards monitor, evidence, and report on internal control effectiveness with confidence

PROVISION 29 IN PRACTICE

The Declaration Is Brief. The Evidence Behind It Is Not.

Provision 29 of the UK Corporate Governance Code asks the board to monitor the company’s risk management and internal control framework, review its effectiveness at least annually and report on all material financial, operational, reporting and compliance controls.

Governance professional reviewing control effectiveness, assurance evidence, exceptions and board-review status in a connected GRC platform.

Board director reviewing the effectiveness of material controls and preparing the Provision 29 declaration as at the balance sheet date.

Governance professional reviewing a material control weakness, remediation actions, ownership and scheduled retesting for Provision 29 disclosure.

FROM POLICY TO DEFENSIBLE EVIDENCE

Turn Disconnected Control Activity Into a Traceable Assurance Story

Evidence for Provision 29 is rarely created in one place. It can sit across risk registers, control spreadsheets, self-assessments, incident logs, audit files and action trackers. Symbiant connects those records so each conclusion can be traced back to its source.

1. Principal risks and objectives

Identify what could affect the organisation’s objectives and maintain a clear view of principal risk exposure.

2. Material controls

Document controls, ownership and supporting policies, then link each control to the risks it is intended to manage.

3. Monitoring and testing

Schedule assessments, RCSAs, management reviews or audit work and collect evidence in a repeatable format.

4. Signals and weaknesses

Connect failed tests, incidents, near misses, KRIs and audit findings to the relevant controls and risks.

5. Remediation

Assign actions, due dates and owners; retain updates and supporting evidence through to completion.

6. Board reporting

Bring current control status, assurance results, exceptions and remediation into clear dashboards and reports.

CONNECTED CONTROLS ASSURANCE

Build a Repeatable Provision 29 Evidence Process

Symbiant brings risk, control, assurance and remediation activity into a configurable workflow. Your organisation decides what is material, how controls should be assessed and what evidence the board needs; the platform makes that process easier to operate, monitor and report.

1. Define and organise your control population

 

Create a central library of controls and policies, identify key or material controls according to your own methodology, assign ownership and link controls to principal risks and business objectives.

2. Run structured monitoring and testing

Use configurable assessments, questionnaires, RCSAs and audit workflows to gather evidence and record results throughout the reporting period.

  • Scheduled reviews and automated reminders
  • Conditional questions and evidence requests
  • Complete history of results and supporting documents

3. Bring real-world signals into the review

Link incidents, near misses, KRI movements and audit findings to the controls and risks they affect, giving reviewers more context than a standalone test result can provide.

  • Control failures connected to risk exposure
  • Early-warning indicators and trend visibility
  • One current view across operational and assurance data

4. Track weaknesses and remediation

Record issues, assign accountable owners, set due dates and follow corrective action through to completion with a visible audit trail.

  • Automated notifications and escalation
  • Evidence attached to every action
  • Clear status for management, assurance teams and committees

5. Prepare board-ready reporting

Use live dashboards and configurable reports to bring together control status, monitoring activity, exceptions and remediation for board and audit committee review.

  • Current rather than end-of-year-only visibility
  • Drill-down from summary to source evidence
  • Configurable outputs aligned to your reporting process
1. Define and organise your control population 2. Run structured monitoring and testing 3. Bring real-world signals into the review 4. Track weaknesses and remediation 5. Prepare board-ready reporting

MODULAR BY DESIGN

Choose the Capabilities You Need. Keep the Evidence Connected.

Provision 29 does not require one prescribed system or process. Symbiant’s modular platform lets you start with the capabilities you need and expand over time while maintaining one connected source of risk, control and assurance information.

Capability

Provision 29 contribution

Controls & Policies

Maintain the control library, ownership, policies, evidence and review history.

Risk Register

Connect controls to principal risks, objectives, incidents and current risk exposure.

Assessments & Questionnaires

Schedule control testing, RCSAs, attestations and evidence collection.

Incident Reporter & KRIs

Add operational signals, failures, near misses and thresholds to the control picture.

Audit Working Papers

Document independent testing, findings, evidence and assurance conclusions.

Audit Action Tracker

Assign, monitor and evidence remediation arising from reviews, testing or audit.

Dashboards & Report Wizard

Create role-based oversight and board-ready reporting with drill-down traceability.

Business Objectives

Show how principal risks and controls relate to the outcomes the organisation is trying to achieve.

UK Corporate Governance Code Provision 29

Create a Single Source of Truth (SSOT) for Risk and Control with Symbiant GRC, Risk Management and Audit Software

Unify fragmented processes into one connected, organisation-wide framework. Symbiant replaces spreadsheets and siloed systems with a modular, fully customisable, intuitive and auditable platform that grows with your business.

  • Maintain connected registers – risks, controls, policies, incidents, audits, and issues are all linked and cross-referenced in real time.
  • Apply consistent frameworks – align controls and risks with ISO 31000 and ISO 27001, ensuring a common taxonomy across business units.
  • Ensure full traceability – link strategic objectives to risks, controls, and incidents, giving boards a clear line of sight to control effectiveness.
  • Capture and monitor incidents – log real-time events that impact risk or control performance, triggering reviews and remedial action plans.
  • Scale with ease – modular design and £100 per module* licensing mean you only pay for what you need, while unlimited user access ensures organisation-wide visibility.
Meet Provision 29 with ease. Symbiant’s software helps boards evidence internal control effectiveness, streamline reporting, and ensure UK Corporate Governance Code compliance.webp

UK Corporate Governance Code 2024

How Symbiant Helps You Meet Provision 29 of the UK Corporate Governance Code

Provision 29 isn’t about processes on paper — it’s about evidence your board can trust. Symbiant’s modular GRC and Audit platform was built to calculate, report, and demonstrate the effectiveness of your internal controls in real time.

How Symbiant’s Modules Support Provision 29

Controls & Policies Module

  • Lets you build a centralised control library of active and key controls.

  • Supports Risk Control Self-Assessments (RCSA) and automatically adjusts residual risk scores when controls fail.

  • Allows reviews and remedial action plans to be tracked to completion, giving you auditable proof of control effectiveness.

  • Simplifies ISO 27001 compliance with one-click Statements of Applicability.

Risk Registers Module

  • Links risks to controls, incidents, and policies to give full traceability.

  • Provides dynamic residual scoring and multiple risk scoring methods to show how controls impact risk exposure.

  • Supports board reporting by aggregating risk and control data into a single, connected register.

Incident Reporter Module

  • Captures real-time events that impact risk or control performance.

  • Links incidents directly to risks and controls, helping boards understand how failures are addressed.

  • Automatically generates reviews and remedial action plans, with tracking through to completion.

Questionnaires, Surveys & Assessments Module

  • Allows you to schedule control testing and assurance activities across the business.

  • Supports Risk Control Self-Assessments and structured reviews, producing evidence for annual reporting.

  • Uses dynamic questions and conditional logic to dig deeper into control performance.

Audit Working Papers Module

  • Provides a single folder for all audit evidence, including linked risks, controls, incidents, and test results.

  • Enables one-click generation of complete audit reports, ensuring boards receive clear evidence of control effectiveness.

  • Creates a permanent audit trail to support year-end declarations.

Audit Action Tracker Module

  • Logs weaknesses and remediation actions arising from audits or testing.

  • Assigns ownership, due dates, and automated reminders to ensure accountability.

  • Provides boards with visibility of progress and assurance that failures are being addressed.

Key Risk Indicators (KRI) Module

  • Acts as an early-warning system for risks that may affect controls.

  • Monitors environmental factors and aggregates data into KRIs linked to the Risk Register.

  • Helps boards anticipate where control weaknesses might emerge.


Together, these modules mean that with Symbiant:

  • Controls are documented, tested, and continuously monitored.

  • Weaknesses are logged, assigned, and remediated with accountability.

  • Risks, incidents, audits, and controls are fully connected and auditable.

  • Boards get clear, real-time dashboards and one-click reports for annual Provision 29 declarations.

Calculate and Report Control Effectiveness

With Symbiant, internal control effectiveness isn’t left to subjective judgement. Our platform links risks directly to controls and dynamically recalculates residual risk scores whenever a control is tested or fails. This means boards have a live, accurate view of whether controls are performing as intended. This automated scoring goes beyond static spreadsheets, providing assurance that your organisation’s risk exposure is always up to date.

Evidence Every Step with a Single Source of Truth

Symbiant replaces fragmented systems with a connected framework that links risk registers, control libraries, audit working papers, incidents, and policies into a single, auditable source of truth. Every control is mapped and cross-referenced, ensuring full traceability from strategic objectives down to control effectiveness. This traceability is central to meeting Provision 29, which requires boards to demonstrate not just the presence of controls but their real-world performance and alignment to governance outcomes.

Track Remediation with Accountability

Provision 29 requires transparency when controls have not operated effectively, including the actions taken to address weaknesses. Symbiant makes this simple with integrated action tracking. You can log weaknesses, assign clear ownership, set deadlines, and automatically notify responsible employees until actions are completed. Progress can be monitored in real time, ensuring that remediation is not only recorded but actively managed to completion. This turns weaknesses into opportunities for continual improvement, fully aligned with the FRC’s expectations.

Board-Ready Dashboards and Reports

For boards and audit committees, assurance must be clear, visual, and actionable. Symbiant provides real-time dashboards that show control effectiveness. By aligning reports to the UK Corporate Governance Code’s focus on outcomes-based governance, Symbiant enables directors to make informed, confident declarations with evidence they can trust.

Affordable, Scalable, and Easy to Implement

Unlike complex and costly platforms, Symbiant is modular, affordable, agile, fully customisable and designed to grow with your organisation. Each module is just £100 per month* with unlimited users, so you only pay for what you need while ensuring complete organisational coverage. Our no-code flexibility means you can configure forms, workflows, and dashboards without external consultants, making compliance with Provision 29 both sustainable and cost-effective.

Optional AI Insights for Proactive Assurance

For organisations that want to go further, Symbiant offers an optional AI Assistant to provide advanced insights. This includes detecting hidden risks, performing root cause and consequence analysis, and recommending new or improved controls to strengthen your assurance framework. By surfacing patterns across your GRC data, AI moves you from reactive monitoring to proactive governance, supporting boards in delivering stronger, evidence-based declarations under Provision 29.

UK-Based, Secure, and Trusted

With over 23 years of experience supporting UK and global businesses, charities, and government bodies, Symbiant is built on trust and proven performance. Hosting is UK-based, with ISO 27001 and Cyber Essentials Plus certification, ensuring data security and compliance with UK regulatory expectations. Trusted by organisations like UKHSA, Whistl, CITB, and more,  Symbiant delivers a solution that combines affordability, flexibility, and assurance at the highest governance level.

BUILT AROUND YOUR ORGANISATION

Support Clear Accountability Without Dictating Your Governance Model

Symbiant does not prescribe how your organisation should structure governance or assurance. Configure fields, workflows, permissions, approval steps, scoring methods and reporting to support a traditional Three Lines model, combined assurance or an alternative framework.

Operational management

Own risks and controls, complete reviews, provide evidence and deliver actions.

Risk and compliance

Set methodologies, monitor completion, challenge results and identify emerging concerns.

Internal audit

Plan and document independent assurance using the same underlying risk and control information while retaining separate permissions and accountability.

Board and committees

Review a consolidated picture of control status, assurance coverage, weaknesses and remediation.

Provision 29 FAQs

When does Provision 29 apply?

Provision 29 applies to financial years beginning on or after 1 January 2026. The FRC expects reporting against the revised provision to begin from 2027 onwards.

The Code applies to companies listed in the commercial companies category or the closed-ended investment funds category, regardless of where they are incorporated. Other organisations may choose to use it as a governance benchmark, but private companies are not automatically within its scope.

The annual report should describe how the board monitored and reviewed the risk management and internal control framework, include a declaration on the effectiveness of material controls at the balance sheet date, and describe any material controls that were not operating effectively together with action taken or proposed.

The FRC does not prescribe a standard list or definition for every company. The board determines which controls are material in the context of the organisation’s principal risks, circumstances, complexity and risk appetite.

No. The Code does not require external assurance over material controls. The board decides whether external or additional assurance is appropriate and over which areas.

‘UK SOX’ is sometimes used as shorthand, but Provision 29 is not the same as the US Sarbanes-Oxley regime. The UK Code is principles-based and operates on a comply-or-explain basis. Its material-control scope includes financial, operational, reporting and compliance controls.

Software can structure testing, consolidate results, track exceptions and provide reporting, but the board remains responsible for its own assessment and declaration. Symbiant GRC supports that judgement with connected, traceable evidence.

Software can structure testing, consolidate results, track exceptions and provide reporting, but the board remains responsible for its own assessment and declaration. Symbiant GRC supports that judgement with connected, traceable evidence.

Pricing Disclaimer

* Modules are charged at a standard monthly fee, not on a per-user basis. All users can access each module at any required level. Please note that costs exclude VAT, AI features, and additional modules you may wish to use. User seats are required.