Provision 29 is a requirement in the UK Corporate Governance Code 2024 that asks listed companies to declare annually whether their material internal controls are effective. It covers financial, operational, compliance, and non-financial reporting risks, and it pushes boards to evidence how controls work in practice, not only how they are described on paper.
Expanded Definition
Provision 29 sits within the UK Corporate Governance Code 2024 and requires boards of listed companies to state annually whether material internal controls are effective. Its scope is broader than financial reporting alone: it spans operational, compliance, and other non-financial risks where control failure could affect the company’s ability to meet obligations or produce reliable reporting.
The practical boundary is important. Provision 29 is not just a disclosure about having controls documented, and it is not satisfied by policy language alone. It asks for an evidence-based view of whether controls operate effectively in practice, which means the board must understand control design, testing, remediation, and residual weakness. That makes it closer to a governance assertion than a compliance checkbox.
For readers comparing it with control catalogues, the nearest conceptual match is not a single technical safeguard but a governance expectation over the full control environment. The UK Corporate Governance Code is the authoritative source for the provision itself, while control frameworks can help organisations structure the evidence they use to support the annual declaration.
Examples and Use Cases
Provision 29 appears in board reporting, assurance planning, and annual governance statements where leadership needs a defensible view of control effectiveness rather than a narrative summary.
- A listed company reviews whether key financial controls were tested during the year and whether any material weaknesses remained unresolved at the reporting date.
- An audit committee examines operational controls that affect service continuity, such as approval workflows, segregation of duties, and escalation handling.
- A compliance team maps regulatory obligations to control owners so the board can assess whether monitoring and evidence are sufficient for the annual declaration.
- A risk function combines internal audit findings with management testing results to identify where controls are designed well but are not operating consistently.
- An organisation with outsourced processes checks whether third-party control evidence is good enough to support the company’s own statement of effectiveness.
A common implementation tradeoff is that expanding the evidence base improves confidence, but it also increases the burden of coordination across finance, operations, compliance, and risk owners. The challenge is not volume of paperwork; it is whether the evidence is specific enough to support the assertion being made.
Security Implications
Although Provision 29 is a corporate governance requirement, its security relevance is clear: weak internal controls often create blind spots in authorisation, change management, logging, exception handling, and evidence retention. If boards treat the declaration as a narrative exercise, they may miss control failures that are already affecting integrity, availability, or accountability.
The practical consequence is that control weaknesses can persist across business processes even when formal documentation looks complete. That can lead to unauthorised changes going unreviewed, reconciliations being delayed, incidents not being escalated promptly, or control owners relying on manual workarounds that are not sustainable at scale. In other words, the issue is not simply non-compliance; it is loss of reliable assurance over how the organisation actually operates.
A practitioner observation that matters here is that material weaknesses are often exposed first by inconsistency between teams, not by a single failed control. Where evidence cannot be reproduced, traced, or reconciled, the board’s ability to sign off on effectiveness is weakened even if no incident has yet occurred.
Domain and Governance Relevance
Provision 29 matters because it forces governance to connect with operational reality. For identity, security, finance, and compliance teams, the key question is whether the organisation can demonstrate that controls are working across the processes that materially affect the business, not just whether a control exists in a policy library.
This is especially relevant where non-human identities, privileged access, or automated workflows support material controls. If service accounts, API keys, or system-to-system approvals are poorly governed, the board may be relying on a control environment that is technically documented but operationally brittle. That does not turn Provision 29 into an identity standard, but it does mean identity and access evidence can become part of the control assurance story.
For NHIMG readers, the useful governance lens is evidential: who owns the control, how it is tested, what fails when it breaks, and whether the organisation can prove performance rather than assume it. Provision 29 is ultimately about board accountability for control effectiveness, with security and identity assurance feeding into that judgement where they are part of the material control environment.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
NIST CSF 2.0, CIS Controls v8 and NIST SP 800-63 set the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| NIST CSF 2.0 | GV.RM-03 — Risk Management Strategy | Boards need a repeatable way to judge material control effectiveness. |
| GV.OV-03 — Oversight | Provision 29 is fundamentally a governance and oversight assertion. | |
| PR.AC-1 — Identity Management, Authentication, and Access Control | Access control failures often sit inside material control weaknesses. | |
| Recommendation — Align board reporting to GV.RM-03 and test whether control evidence supports the annual effectiveness statement. Use GV.OV-03 to assign control ownership, review assurance gaps, and track remediation to closure. Apply PR.AC-1 to verify that access approvals and exceptions are operating as designed. | ||
| CIS Controls v8 | 5 — Account Management | Control effectiveness depends on accurate ownership and access lifecycle evidence. |
| 8 — Audit Log Management | Evidence of control operation often depends on logs and traceability. | |
| Recommendation — Use CIS Control 5 to validate account ownership, review exceptions, and support board assurance. Apply CIS Control 8 to retain logs that prove controls executed and issues were escalated. | ||
| NIST SP 800-63 | Digital Identity Guidelines | Identity assurance can underpin material controls when system access is part of the evidence chain. |
| Recommendation — Map identity proofing and authentication strength to the controls whose operation the board relies on. | ||
Related resources from NHI Mgmt Group
- How should UK boards implement automated IT general controls to evidence control effectiveness under Provision 29?
- Why do manual segregation of duties and user access review processes create compliance risk under Provision 29?
- What breaks when boards rely on spreadsheet based access reviews instead of automated controls for Provision 29?
- What breaks when organisations pre-provision identities for ephemeral AI agents?
Deepen Your Knowledge
Reviewed and updated by the NHIMG editorial team on September 6, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org