For corporate boards and Chief Financial Officers across the UK, the expectations surrounding governance and risk have fundamentally shifted.
With Provision 29 of the UK Corporate Governance Code 2024 taking effect for financial years beginning on or after 1 January 2026, the era of passive management attestations has ended. While the Code operates on a “comply or explain” basis for commercial companies on the main market, the market’s tolerance for weak explanations is shrinking rapidly. Company directors can no longer comfortably rely on high-level assurances or manual, end-of-year reconciliations. Instead, boards face unprecedented regulatory and shareholder pressure to provide an explicit annual declaration in their financial reports, confirming the effectiveness of all material controls—spanning financial, operational, compliance, and reporting domains.
If your organisation is still attempting to monitor a complex, enterprise-wide control environment using fragmented legacy systems and static spreadsheets, you don’t merely have a tech stack problem—you have a direct governance exposure.
In this article, we examine what Provision 29 entails, why traditional compliance methods struggle to withstand modern audit scrutiny, and how modern Cloud ERPs and unified data analytics platforms empower boards to replace frantic year-end remediation with real-time, automated assurance.
Understanding Provision 29: A Fundamental Shift in Board Accountability
Published by the Financial Reporting Council (FRC), the revised Corporate Governance Code places risk management and internal controls firmly at the board’s door.
Under Provision 29, boards are required to:
Monitor and Review:
Continuously oversee the company’s risk management and internal control framework throughout the operating year.
Formally Declare:
Provide an annual declaration confirming that all material controls—spanning financial, operational, compliance, and reporting domains—were operating effectively as at the balance sheet date.
Disclose Weaknesses & Remediation:
Clearly document any material control failures or gaps identified during the period, alongside concrete action plans and timelines to address them.
| Traditional Reporting | Provision 29 Requirement |
| Management attestation | Direct Board ownership |
| Focus on financial reporting controls only | Financial + Operational + Compliance + Non-Financial |
| Annual retrospective review at year-end | Continuous monitoring throughout the reporting year |
| Narrative “boiler-plate” claims | Verifiable, evidence-backed declaration |
Who Does Provision 29 Apply To? (And Why Unlisted Businesses Are Paying Attention)
Strictly speaking, the Code officially applies only to companies listed on the London Stock Exchange in the “commercial companies” or “closed-ended investment funds” categories (historically referred to as “premium-listed” companies).
If your business is AIM-listed, a private company, or listed on an overseas exchange, you are not directly required to comply with Provision 29. However, the mandate is rapidly becoming the de facto gold standard for corporate governance across the UK. Many unlisted businesses are adopting its principles for several strategic reasons:
Voluntary Alignment:
Many AIM-listed and large private businesses voluntarily align their internal controls with the Code to signal robust governance and risk management to institutional investors, lenders, and key stakeholders.
Pre-IPO Preparation:
Private companies planning to float on the main market in the future must build Provision 29-compliant frameworks well before their initial public offering. You cannot build a compliant control environment overnight.
Alternative Frameworks:
While private companies do not follow the UK Corporate Governance Code, large private companies are often required to report under the Wates Corporate Governance Principles. While Wates is less prescriptive, the expectation for boards to maintain and review robust internal controls is highly similar in spirit.
Regardless of listing status, the operational challenge remains the same: proving control effectiveness without drowning in manual work.
Why 2026 Demands Urgent Action
While other elements of the updated Code took effect in 2025, the FRC deliberately granted a grace period for Provision 29 to allow organisations to build robust monitoring mechanisms.
That timeline has now expired. For FY2026 financial cycles, the board’s sign-off depends on data gathered and tested day-to-day throughout the entire year. Waiting until month 11 to test controls or pull together evidence is no longer a viable strategy.
The Spreadsheet Trap: Why Legacy Infrastructure Fails Provision 29
Most medium-to-large enterprises do not lack internal controls; they lack visibility and verifiability.
Over decades of growth, corporate IT landscapes naturally fragment into isolated departmental silos.
- Finance operates in an older on-premise ERP;
- Sales and customer contracts sit in a detached CRM;
- Supply chain and inventory tracking rely on regional operational databases;
- Compliance teams bridge these gaps using thousands of disconnected Excel workbooks.
When a board attempts to sign a Provision 29 declaration backed by this legacy architecture, three critical failure points emerge:
The Sileron Pivot: Turning Compliance Into Automated Assurance
You cannot attest to what you cannot see.
At Sileron, we believe compliance should never be a frantic year-end documentation exercise. Instead, it should be the natural byproduct of an intelligent, unified digital architecture.
By replacing siloed applications with modern Cloud ERP solutions and unified enterprise data platforms, we help boards turn Provision 29 from a legal threat into an operational advantage.
| Modern Cloud ERP | Unified Data & Analytics |
| Automated Segregation of Duties | Real-Time Board Dashboards |
| Enforced Approval Workflows | Continuous Anomaly Detection |
| Immutable System Audit Logs | Single Source of Truth |
Building a Single Source of Truth
Our implementation model integrates financial, supply chain, HR, and compliance data into a single source of truth. By unifying system workflows, key internal controls are embedded directly into your software logic rather than enforced manually by human intervention:
Automated Segregation of Duties (SoD):
Built-in system permissions ensure that no individual user can initiate and approve high-value transactions without explicit, logged authorization.
Embedded System Rules:
Automated controls prevent purchase orders from bypassing approval thresholds or invoices from being processed without matching goods-received notes (3-way matching).
Immutable Logs:
Every transaction, master data change, and system configuration update is permanently time-stamped and stored in an immutable digital ledger.
Real-Time Assurance Dashboards for Directors
Board members and Audit Committees cannot review millions of underlying ERP transactions. They require clear, aggregated executive visibility.
Sileron designs tailored Board Assurance Dashboards powered by cloud analytics platforms. These tools provide senior leadership with immediate, drill-down visibility into:
Control Health Indicators:
Real-time metrics showing whether automated and manual controls are operating within normal parameters.
Exception & Anomaly Alerts:
Automated flagging of control overrides, duplicate payments, or access policy violations as they occur, enabling immediate remediation before year-end.
Remediation Tracking:
Transparent status reporting on open audit findings, complete with assigned owners, target resolution dates, and re-testing schedules.
A 4-Step ERP Roadmap for Provision 29 Readiness
If your organisation is evaluating its compliance posture for the current reporting year, follow this structured IT and governance roadmap:
From Regulatory Burden to Competitive Advantage
Provision 29 of the UK Corporate Governance Code raises the bar for corporate governance. While the regulatory pressure is real, organisations that treat this requirement as a catalyst for enterprise modernisation will reap benefits far beyond compliance.
By centralising data, automating control frameworks, and implementing real-time board reporting through a modern ERP architecture, you eliminate regulatory anxiety while building a faster, leaner, and more resilient business.
Ready to Secure Your Board Declaration?
Don’t let legacy data silos jeopardize your FY2026 annual report. Book a Provision 29 Readiness Assessment with Sileron’s Enterprise Architecture Team today to discover how our Cloud ERP and Data Integration solutions make compliance seamless and automated.
This article was written by Alice Gautron, Head of Marketing & Communications at Sileron.



