# Provision 29: Evidence Before the Declaration **Category:** GRC **Author:** John Hotham, CEO, Simplif-i **Published:** 2026-10-08 **Read Time:** 5 min read ## Summary Provision 29 is a board-level conclusion about material controls, not a wording exercise. Define scope, test operation and make unresolved exceptions visible before reporting. ## Full Content # Provision 29: Evidence Before the Declaration A polished annual report cannot repair a weak control review. If management cannot explain what a material control is, who operates it and what evidence shows it worked, the board has little to challenge beyond assurance language. Provision 29 of the UK Corporate Governance Code 2024 applies to financial years beginning on or after 1 January 2026. It requires the board to monitor and review the risk management and internal control framework and report on the effectiveness of material controls at the balance sheet date. Where controls are not effective, the Code expects the report to explain the action taken or proposed. Read the Code and FRC guidance for the precise scope and reporting expectations. [FRC, UK Corporate Governance Code](https://www.frc.org.uk/library/standards-codes-policy/corporate-governance/uk-corporate-governance-code/) and [FRC, Code guidance](https://www.frc.org.uk/library/standards-codes-policy/corporate-governance/corporate-governance-code-guidance/) ![Material risks connected to control owners, evidence and remediation](https://static.prod-images.emergentagent.com/jobs/sched-2866d31f-92d1-431d-ac9f-1a8d77fdfd4c-1791446460045/images/d0fa1719c36942ab2ec40127844f9d0e968b0b31aa6787cec908d72fa0d8b314.jpeg) ## Define what makes a control material Start with risks that could materially affect the organisation’s strategy, operations, reporting or compliance. Identify controls that address those risks and document why they are in scope. Record the control objective, owner, frequency, evidence source, reviewer and escalation route. Do not confuse a long control inventory with a good framework. Scope should be clear enough for management to explain and for the board to challenge. Where a control depends on another team, system or third party, name that dependency. ## Test operation, not policy language A policy demonstrates intent. It does not prove that a control operated. Select evidence that matches the control design: approvals, reconciliations, access reviews, exception records or other relevant artefacts. Record the period tested, method, reviewer, outcome and limitations. For automated controls, document system dependencies and evidence that configuration and access remained appropriate. For manual controls, define good performance and retain proof of review. Testing should be proportionate to risk, but never reconstructed after the event. ![Control testing chain showing operation, review and retained evidence](https://static.prod-images.emergentagent.com/jobs/sched-2866d31f-92d1-431d-ac9f-1a8d77fdfd4c-1791446460045/images/5134487341272e500c8dfb16458dc0e5bf56239f5c401eaa0146f40b40e1e41d.jpeg) ## Put exceptions on the record When evidence is missing or a control fails, record the exception plainly. Assess its significance, assign an accountable owner, set remediation steps and agree a retest date. Escalate material weaknesses through the established governance route. A green status that hides an unresolved issue is not assurance. Keep the trail connected from risk to control, test result, issue and action. This shows whether management addressed the underlying cause or merely closed a ticket. ## Give the board a conclusion it can challenge Before the annual report is finalised, assemble the scope, review activity, evidence, exceptions and remediation status. Explain changes in material risks and controls during the period. Make clear what remains unresolved and what the board is being asked to conclude. ![Board assurance view connecting material controls, open exceptions and corrective actions](https://static.prod-images.emergentagent.com/jobs/sched-2866d31f-92d1-431d-ac9f-1a8d77fdfd4c-1791446460045/images/778f7ee00b1b4596e3bbbd949621b40567c867bedc219fcc1875d9a844c680bf.jpeg) Provision 29 is not solved by adding a sentence to the report. It requires a disciplined review that management can evidence and the board can challenge. Technology can organise ownership and records. It cannot make the judgement for directors. For cyber risk, the National Cyber Security Centre’s Board Toolkit provides a practical framework for board oversight, risk management and assurance. Use it alongside the company’s materiality assessment, not as a substitute for it. [NCSC, Board Toolkit](https://www.ncsc.gov.uk/collection/board-toolkit) --- Source: https://simplif-i.com/api/blog/readable/grc/provision-29-controls-evidence-board-20261008 Web Version: https://simplif-i.com/blog/grc/provision-29-controls-evidence-board-20261008 © Simplif-i - Unified Business Management Platform