Provision 29 has changed how companies and their auditors look at internal controls across both financial and non-financial applications.
For most UK boards, this is no longer a dry run. The provision applies to financial years beginning on or after the first of January 2026, putting many companies inside their first live reporting cycle.
In this blog, we will cover what Provision 29 requires and the impact of the latest revision. You’ll also see why automating IT general controls (ITGC), like segregation of duties (SoD) and user access reviews (UAR), inside your critical line-of-business applications is one of the most effective ways to meet the new declaration requirements.
Provision 29 of the UK Corporate Governance Code 2024 requires UK-listed companies to make an annual declaration on the effectiveness of all material internal controls, covering financial, operational, compliance and non-financial reporting risks. Those controls span both financial and non-financial applications, raising the bar for how boards demonstrate that they are working effectively.
Controls are now judged on how they operate day-to-day, not just how they read on paper
Under Provision 29, boards must make an annual statement covering the effectiveness of all material internal controls, including both financial reporting and the company’s principal risks. That statement must include:
evidence supporting the board’s annual review and assessment of its controls.
disclosure of any controls identified as not effective.
a detailed remediation plan for any weakness identified.
Across all three elements, ITGCs are essential. SoD and UAR address risk inside the financial applications that underpin financial reporting, like ERP systems. That makes them a natural place for auditors to test first.
It’s tempting to compare Provision 29 to the US Sarbanes-Oxley Act (SOX), but the comparison is overstated. Provision 29 is principles-based and sits within the UK’s established “comply or explain” framework. From an audit perspective, it requires no external attestation and imposes no fines or penalties. There’s nothing resembling the mountain of requirements and prescriptive controls testing that SOX demands.
| Provision 29 vs SOX: what each one actually requires | ||
| Requirement | Provision 29 | SOX |
| Annual declaration on control effectiveness | ||
| External auditor attestation | — | |
| Fines and penalties | — | |
| Prescriptive controls testing | — | |
| Comply or explain framework | — | |
Instead, Provision 29 creates a mechanism for transparency. It sharpens investor scrutiny and puts reputational accountability squarely in front of the board. The best way to support that transparency is with a strong internal control system that spans both financial reporting and operational process controls, with compliance considerations running through both.
Trends are already developing among UK companies that are successfully managing Provision 29 requirements:
They build an inventory of key controls and map each one to a principal risk and reporting area, with ITGCs prominent in financial and accounting applications.
Once controls and risks are identified, they establish clear governance processes so boards and other oversight groups are comfortable with their internal control systems.
They maintain strong documentation of their internal controls and of any remediation activities undertaken during the review period.
Automating ITGCs has a direct role in all three steps. Take access management controls as an example: When you automate both the collection of access data and the review itself, documenting a control like UARs gets much easier. So does producing the underlying evidence when an auditor asks for it.
Manual SoD and UAR processes tend to break down under Provision 29. Point-in-time spreadsheet reviews, email sign-offs and periodic dumps of access data are hard to evidence consistently across a full financial year, and they leave gaps in remediation disclosure. Automating these controls closes those gaps in several concrete ways:
Continuous SoD risk monitoring: Automated SoD analysis flags conflicting access as it arises, instead of surfacing it months later at the next scheduled review.
Defensible audit trail: Every review, approval and exception is logged automatically, giving the board supporting evidence for Provision 29.
Faster UARs: Automated collection and review of user access reduce manual effort and produce more consistent and reliable results.
Consistency across business applications: The same control approach applies across ERP and other line-of-business systems, which matters because Provision 29’s scope reaches both financial and non-financial applications.
Documented remediation: When a control gap is detected automatically, the remediation plan the board discloses can point to a specific, time-stamped finding rather than a general statement of intent.
No company likes dealing with new regulations, or changes to existing regulations. But Provision 29 gives UK boards the chance to improve their accountability around risk management and internal controls. That accountability supports investor trust, and in turn helps companies strengthen governance in all business process areas, where ITGCs reside.
To learn more about automating ITGCs, download our whitepaper: Automating Your Control Environment