In short. Provision 29 turns “our controls are broadly fine” into a written board declaration with a named signatory, for periods beginning on or after 1 January 2026. The FRC has deliberately left “material control” undefined and will not supply wording, because it wants the definition to be board owned. That gap is not licence to improvise on the day. It is solved with a three tier cascade: first line control owners certify what actually happened, second line functions certify design and aggregate the exceptions, and the board certifies the whole on the strength of that evidence chain. Twelve months of lead time, working back from a December year end declaration, is enough if scoping starts now. Most first cycle failures are not about control design. They are about aggregation, deficiency thresholds, and evidence that cannot be found six months later.
1. What Provision 29 actually requires
Provision 29 of the UK Corporate Governance Code 2024 applies for accounting periods beginning on or after 1 January 2026. For a company with a 31 December year end, that means the first Provision 29 statement lands in the annual report published in early 2027, sitting alongside the audited financial statements it does not form part of. The Code applies on a comply or explain basis, and it binds the commercial companies and closed-ended investment funds categories under the 2024 Code: in practice, premium listed companies and the wider population that reports against the Code by convention or investor expectation.
The provision asks the board to include three distinct things in the annual report, and it is worth separating them because they are frequently drafted as one paragraph when they are three different exercises:
- A description of how the board has monitored and reviewed the effectiveness of the company’s risk management and internal control framework across the reporting period. This is a narrative of governance activity, of committee cycles, reporting lines and assurance sources, not a list of controls.
- A declaration on the effectiveness of the company’s material controls, as at the balance sheet date. This is the new element. It is a point-in-time conclusion, not a description of process.
- A description of any material controls that did not operate effectively as at the balance sheet date, the remedial action taken or proposed, and progress against anything reported the previous year. This closes the loop: a board cannot declare a weakness once and then go silent on it.
One further point changes what “audit ready” means for this specific document. The Provision 29 statement sits in the annual report as other information under ISA (UK) 720. The auditor’s obligation under that standard is limited to considering whether there is a material inconsistency between the statement and the financial statements, or the auditor’s own knowledge from the audit. There is no requirement for the auditor to test the material controls or to give assurance over the board’s conclusion. That is a materially lighter touch than a SOX 404(b) attestation, and it means the discipline behind the declaration has to be self imposed. Nobody external is going to test it into shape.
2. The material controls definition problem, and a usable framework
The FRC’s Provision 29 mythbuster is explicit on this point: the board decides what its material controls are, the FRC will not give an opinion on the list, will not say whether the number chosen is right, and does not intend to issue further guidance. Reporting should be proportionate, weighed against the entity’s own risk appetite, and should avoid both a wall of immaterial detail and a bare assertion with nothing behind it. This is deliberate design, not an oversight the FRC will correct later.
In practice, boards without a framework default to one of two weak answers. The first is to list every control in the risk register and call the list the declaration, which is exactly the unnecessary duplication the FRC has said it does not want. The second is to nominate the same three headline financial controls every company nominates: period end journal review, bank reconciliation, delegation of authority. The hope is that nobody asks what sits underneath them.
A material control, for Provision 29 purposes, is one where a reasonable board member, properly informed of its condition, would expect that condition to change the declaration. That test only becomes usable once it is broken into components a control owner can actually assess. We weigh four, together rather than any one in isolation:
- Quantum. If the control failed, could the resulting misstatement, loss, or regulatory exposure reasonably approach the entity’s financial statement materiality benchmark, or a qualitative equivalent such as a going concern implication, a safeguarding breach, or a reportable regulatory event?
- Pervasiveness. Does the control sit over a process or population that touches multiple financial statement line items, multiple business units, or the entity level, rather than a narrow, contained population with limited downstream effect?
- Reliance chain. Do other controls, or the external auditor’s planned audit approach, rely on this control operating? A control sitting at the top of a reliance chain carries more weight than one that is a supporting check further down.
- History. Has the control, or the process it sits within, produced a deficiency, a restatement, a regulatory finding, or an auditor management letter point in the last two reporting cycles?
Two candidate controls illustrate the difference. A monthly bank reconciliation review is well controlled, evidenced, and sits over a contained population: low pervasiveness, short reliance chain, no history of failure. Absent a specific event, it is unlikely to be material. A manual journal entry authorisation control sits at the top of the reliance chain for period end financial reporting, touches every material line item through top side adjustments, and generated a management letter point in the prior cycle. On the same four tests, it is very likely material. The framework does not remove judgement. It gives the board a documented, repeatable basis for the judgement it is already required to make, which is the difference between a declaration the Audit Committee can interrogate and one it can only accept on trust.
The published list itself should stay short. The FRC’s own steer on proportionate reporting points the same way: a wall of control by control detail is exactly what the mythbuster warns against, and specific testing detail belongs in the file, not the annual report. The discipline sits in the framework behind the page, not in the page length.
3. The three tier sub-certification cascade
The declaration a board signs is only as reliable as the evidence chain underneath it. A cascade with three distinct tiers, each with a distinct question to answer, is what makes that chain auditable in substance even though no external auditor is required to test it.
- Tier 1: first line control owners. Process owners across R2R, P2P, O2C, treasury, payroll, and IT certify, on a defined cycle (quarterly as a floor, monthly for higher volatility processes), that the controls within their process operated as designed during the period, and disclose exceptions against a standard schedule rather than free text.
- Tier 2: second line certification. Group Finance, Risk, or Compliance, supported by Internal Audit where the function exists, reviews every Tier 1 submission, aggregates the exceptions, applies the materiality of controls framework from Section 2 to decide which exceptions rise to a material control not operating effectively, and certifies the aggregate position up to the Audit Committee.
- Tier 3: board declaration. The Audit Committee reviews and challenges the Tier 2 aggregation memorandum, and the board signs the Provision 29 statement on the strength of that review, not on the strength of a summary slide produced the week before.
This is deliberately the same cascade architecture used in SOX 302 environments and in J-SOX component programmes for UK subsidiaries of overseas parents. The discipline of first line attestation feeding second line aggregation feeding a top level certification is not new. What differs is the legal basis. Provision 29 sits inside a comply or explain Code provision, not a statute. There is no SEC style civil penalty regime and no criminal exposure equivalent to SOX 906. But the Audit Committee, institutional shareholders, and proxy advisers all read the declaration, and a declaration that later proves wrong is a public governance failure the board owns, not a certification technicality that can be quietly corrected.
4. Certification wording: a model, not a script
The FRC has deliberately withheld wording so that every board sets its own. What follows is an illustrative model built to map directly onto the three elements Provision 29 requires. It is a starting point for the board’s own drafting, not text to copy into an annual report unedited.
Tier 1: first line control owner certification. “For the period [ ] to [ ], I confirm that the controls listed in Appendix [ ] for [process or area] operated as designed, except for the exceptions listed in the attached schedule. I am not aware of any matter that should be brought to the attention of Group Finance or the Audit Committee beyond those disclosed. I understand this certification supports the board’s Provision 29 declaration.” The attached exception schedule should carry, as a minimum, the control reference, a description of the exception, the period affected, the root cause where known, any compensating control applied, and the remediation status.
Tier 2: second line certification. “Having reviewed the first line certifications for the period, applied the Group’s materiality of controls framework to the exceptions disclosed, and considered [Internal Audit findings and any other assurance sources, where applicable], I certify that the material controls listed in Appendix [ ] operated effectively during the period, with the exception of [list, or state none], for which remedial action is set out in Appendix [ ].”
Tier 3: board declaration. “The board has monitored and reviewed the effectiveness of the Group’s risk management and internal control framework throughout the period through [describe the mechanism: quarterly Audit Committee review of the sub-certification cascade, Internal Audit reporting, and communications from the external auditor]. Based on this review, the board declares that the Group’s material controls, identified through the process described above, operated effectively as at [balance sheet date], with the exception of [material control name], details of which, together with remedial action taken and planned, are set out below. The board further confirms that the action taken in response to the material control weakness reported in the prior year has been [completed / is progressing], as follows: [ ].”
Every bracket in that wording is a decision the board has to take deliberately: the frequency of Tier 1 certification, the composition of the assurance sources feeding Tier 2, and the specific mechanism of board oversight named in Tier 3. Boilerplate that skips the brackets is the fastest route to a declaration nobody on the board could actually defend under questioning.
5. A 12-month readiness timeline, worked back from a December year end declaration
Working backward from the declaration date is more reliable than working forward from an arbitrary start, because it forces the mid-year rehearsal to actually happen rather than sliding into the same quarter as year end close.
- Month 0: declaration date (31 December). The board signs the Provision 29 statement for inclusion in the annual report published the following quarter.
- Month -1 to -2. Tier 3 review and challenge session at the Audit Committee. Final aggregation memorandum agreed. Declaration wording shared informally with the external auditor’s ISA 720 reviewer to pre-empt an inconsistency query before it becomes a late stage fire drill.
- Month -3. Tier 2 aggregation complete for the full year position. Deficiency register closed out. Remediation status confirmed for anything raised earlier in the cycle.
- Month -4 to -6. A full mid-year rehearsal: the entire cascade run once on H1 data, treated explicitly as a dry run. This is where template gaps, unclear ownership, and missing evidence-retention practice surface while there is still time to fix them.
- Month -7 to -9. Control owner training, exception reporting templates issued, and the first live Tier 1 certification cycle begun on real data.
- Month -10 to -11. Materiality of controls framework agreed and signed off by the Audit Committee. First cut material controls list drafted. Risk and control matrix built or refreshed, scoped specifically to the material controls list rather than the full risk register.
- Month -12: start. Process landscape mapped, control population identified, and a gap analysis run against whatever documentation already exists.
Two qualifications on that clock. Groups with an existing SOX 404 programme, typically UK subsidiaries of US listed parents, or groups with mature ICFR documentation from other work, are not starting from month -12; they are largely repurposing an existing control population and materiality logic, and the timeline compresses accordingly. Groups with no ICFR documentation at all should treat twelve months as a floor rather than a comfortable planning assumption, particularly where the finance calendar means the fourth quarter is already consumed by close and the statutory audit.
6. Where files fail: the part nobody puts in the deck
The pattern below is not hypothetical. It is the same pattern that shows up, cycle after cycle, in FRC audit quality inspection findings on documentation generally: the file does not fail because the underlying work was wrong, it fails because the reasoning behind a conclusion cannot be traced.
- Aggregation never actually happens. Tier 1 exceptions are certified individually and filed, but never rolled up into a single Tier 2 view. The board declaration ends up drafted from memory and a summary slide, rather than from a written aggregation memorandum that shows the working.
- Deficiency thresholds are applied inconsistently. There is no agreed, documented threshold for when an exception becomes a material control not operating effectively, versus an isolated and remediated blip. Different reviewers apply different personal judgement across the year, and the year end aggregation cannot be defended as consistent when it is questioned.
- Evidence retention is an afterthought. Tier 1 certifications reference evidence that lived in an inbox, a shared drive folder that was later reorganised, or with a person who has since left the business. By the time the Audit Committee, or the auditor’s ISA 720 reviewer, asks a question, the certification survives but the evidence trail does not.
- The declaration is treated as a compliance sign-off rather than a governance conclusion. Certifications are collected as a box-ticking exercise with no genuine challenge at Tier 2 or Tier 3, so the resulting declaration reflects process completion rather than a real view on control effectiveness. This is the failure mode that produces a false declaration, not the one that produces a late filing.
- Remediation is not tracked across cycles. Prior year material control weaknesses are not carried to closure in a visible tracker, leaving the board unable to answer the Code’s explicit requirement to describe action taken on issues previously reported.
7. Closing checklist
- Process landscape mapped and the control population identified
- Materiality of controls framework drafted and agreed by the Audit Committee
- First cut material controls list agreed: a curated list, not the full risk register
- Risk and control matrix built or refreshed, scoped to the material controls list
- Tier 1 certification cycle designed: frequency, template, and exception schedule fixed
- Tier 2 aggregation methodology and deficiency threshold policy documented
- Tier 3 board and Audit Committee review calendar fixed for the year
- Mid-year rehearsal cycle run and the lessons from it actually actioned
- Evidence retention policy defined before the first live cycle, not after: where, for how long, and who owns it
- Remediation tracker in place, carrying prior cycle items through to closure
- Declaration wording drafted and shared informally with the external auditor’s ISA 720 reviewer ahead of sign-off
- Board declaration signed against the full aggregation memorandum, not the summary
None of this removes the judgement the Code deliberately leaves with the board. It gives that judgement a paper trail. A board that can point to a documented framework, a working cascade, and an aggregation memorandum it actually read is in a materially different position, if the declaration is ever challenged, than a board that can only point to a paragraph drafted the week before signing.
This note sets out a working model, not FRC-endorsed wording. Atlas Verum Limited is not authorised or regulated by the Financial Conduct Authority or the Prudential Regulation Authority, and nothing in this article constitutes regulated financial or legal advice. Every board must set its own materiality of controls framework and adapt certification wording to its own facts, risk appetite, and governance structure.
— DK Buledi, August 2026