Why 2026 year-end reporting matters
For those with a 31 December 2026 year-end, the reporting process is likely to raise a number of practical questions:
- which controls are sufficiently important to be considered "material"?
- what evidence exists to support a conclusion that those controls operated effectively throughout the year?
- where control testing has not been performed, can the board confidently make an effectiveness declaration?
- how should control deficiencies and remediation activities be described in public disclosures?
It is worth noting that these are not purely compliance questions. They go directly to the heart of governance, accountability and the information that boards are prepared to stand behind publicly. This in turn will drive closer collaboration between risk management, compliance, finance, operations and internal audit, as boards seek to ensure they have sufficient evidence to support their public declaration on the effectiveness of material controls.
Why auditors will be critical to the conversation
Provision 29 is not an audit requirement, and auditors are not being asked to provide attestation on internal controls, as is the case in the US under the Sarbanes-Oxley Act. Nevertheless, auditors are likely to encounter Provision 29-related issues during year-end engagements.
Boards preparing their annual reports will need to consider the evidence supporting their effectiveness declarations. Audit committees are likely to seek assurance over the robustness of management's assessment processes. Internal audit functions may also be asked to increase controls testing, while external auditors may find themselves discussing the maturity of control frameworks, remediation activity and governance disclosures with management and those charged with governance.
Where there are gaps between management's assessment of effectiveness and the available evidence, it is clear that Provision 29 may become a significant area of focus during year-end reporting.
The importance of compliance controls
One common misconception is that this new provision is primarily about financial controls. The UK Corporate Governance Code is clear that material controls extend beyond finance and can include operational, reporting and compliance controls.
For many organisations, particularly those operating in regulated sectors, material controls may include areas such as:
- fraud prevention and detection;
- anti-bribery and corruption frameworks;
- sanctions compliance;
- anti-money laundering controls;
- whistleblowing arrangements; and
- third-party risk management processes.
Consequently, compliance and legal functions may find themselves playing a much more prominent role in helping boards assess and evidence control effectiveness.
From existence to effectiveness
Perhaps the most significant aspect of Provision 29 is the change in mindset it encourages. Historically, organisations have often focused on whether a control framework exists. Provision 29 asks a different question: can management demonstrate that its most important controls are operating effectively and produce evidence to support that conclusion?