Provision 29: Beyond the Slideware
As we start 2026, LinkedIn is full of posts about readiness for Provision 29 – predominantly from advisers (and yes, I acknowledge I am one!). Much of the focus is on:
- Process steps, change programmes, dry-runs and testing
- Comparisons of Material Control numbers
- GRC tools, data and software modules
I wanted to add a different perspective; what I’m seeing at the clients we at BRAVE are working with, what I’m hearing in market discussions, and a personal reflection.
What do Boards actually think?
One thing that strikes me is how little we hear from Board members themselves. Amid the slideware, testing strategies and tool demonstrations, Board expectations are often absent from the conversation.
One comment from an Audit Committee Chair has stayed with me:
“Provision 29 won’t be an issue for a well-run company — and we are a well-run company.”
That sentiment feels important (obviously providing that they have a basis for saying that!).
In that vein, and as the FRC have reminded us, the 2024 changes are an enhancement of the 2018 Code, not a fundamental reset – and a set of principles that most organisations have happily said that they comply with for many years. And whilst I acknowledge that many organisations probably couldn’t easily state what their material controls were 18 months ago, most I’ve worked with have been able to get to a first draft pretty quickly.
Material Control numbers: missing the point?
Eighteen months ago, the narrative was “below 100”.
Twelve months ago, it became “below 50”.
Now, it’s “less than 30”.
In reality, I think the most sensible guidance remains that of the FRC:
“Companies need only satisfy themselves that the number of material controls they have is right for them.”
That is exactly what I’m seeing in practice. Organisations are thinking more carefully about what truly matters — the controls that mitigate threats to the business model, solvency, liquidity, long-term viability or that could create existential shocks i.e. our core objectives. Comparisons with other companies are, in most cases, inherently meaningless.
What is a Material Control, really?
Having heard the FRC speak at several events, one message stands out:
The revision is, in my view, primarily about improving communication between executives and the Board.
The focus on Material Controls and their effectiveness is a mechanism for improving that communication. At its core, a Material Control is simply a means of articulating the mitigation of risks to achieving critical business objectives.
If this is about responding to threats and taking opportunities, and it’s about Exec/Board communication, then we should only be interested in what the Exec and the Board really focus on. For P29 purposes, the most practical proxy for that is (rightly in my opinion) Principal Risks plus significant external reporting (including, but not limited to, the ARA), rather than complicated bottom-up scoping.
From what I’ve seen, a ‘top-down’, framework-based approach is often the most logical, practical and pragmatic way to identify Material Controls – the framework being a ‘wrapper’ around control components supporting a common objective, with an (Exec/Board-level) oversight mechanism to identify whether goals are achieved or missed at the top.
These can then be supplemented by true entity-level controls, particularly those essential to setting, supporting, and monitoring culture.
Assurance: are we over-engineering this?
Many posts place heavy emphasis on testing — DE and OE, schedules, dry-runs, roll-forwards, roll-ups etc – essentially the language of US SOX.
Is this necessary? If Provision 29 is an enhancement to a Code that most businesses have long said that they comply with, why are we layering on so much additional activity and cost to meet a standard that, in substance, should already be met?
I fully understand why the Board declaration sharpens focus. But within the context of directors’ existing responsibilities, is this really such a dramatic step change?
The approach I would advocate for P29 assurance is straightforward:
- Break each Material Control into the most important components making up the framework, with an emphasis on the oversight mechanism.
- Capture the core attributes in a simple spreadsheet.
- Talk about why management is confident the associated risks are mitigated properly – that is your management assurance.
- Identify sources of oversight assurance (e.g. Internal Audit, ISO).
- Review the evidence with the Material Control’s Exec-level owner and perform additional testing only where clearly justified by risk, performance or gaps in existing assurance (with the owner accountable for that judgement and the Board consulted).
- Have the Material Control owner make an assertion to the Board, citing rationale, performance, sources of assurance and any issues identified – they are accountable.
- Allow adequate time at C-suite and the Board to discuss whether they feel confident to make the declaration and any required additional work.
- And that’s it.
Provision 29 doesn’t need to become a compliance industry of its own. For a well-run company, it should reinforce discipline, clarity and accountability — not bury them under unnecessary complexity and testing regimes.




