“UK SOX” never happened, and it is arriving anyway. The statutory, US-style regime that the 2021 white paper proposed, with directors attesting to internal controls under threat of sanction, was dropped by the government in 2022, and the Audit Reform and Corporate Governance Bill that would create a stronger regulator has still not been introduced to Parliament as of September 2026. What did happen is Provision 29 of the 2024 UK Corporate Governance Code: from financial years beginning on or after 1 January 2026, boards of premium-listed companies must declare in the annual report whether their material internal controls were effective at the balance sheet date, describe how they monitored and reviewed them, and disclose any that were not working and what they did about it. The first declarations appear in annual reports published in 2027, on a comply-or-explain basis, covering financial, operational, reporting, and compliance controls. That is a wider scope than Sarbanes-Oxley, with a lighter enforcement regime, and it lands on boards that in many cases have never had to say in writing which controls they rely on.
This guide is for internal auditors and audit committee members in UK companies preparing for that declaration, and for their counterparts elsewhere watching a model that other markets are likely to copy. It sets out where UK audit reform actually stands in 2026, what Provision 29 requires element by element, how it compares with Sarbanes-Oxley, how boards are defining material controls (with a worked list of 42 for a food manufacturer), the assurance model that supports a declaration, internal audit’s role and the lines it must not cross, a quarter-by-quarter readiness timeline for a December year-end, a worked first-year program at a listed company, a model declaration, and the mistakes emerging from the first readiness cycles. It was rewritten in September 2026 from the Code, the FRC’s guidance, its January 2026 Provision 29 Mythbuster, and the government’s stated position on the Bill. The US regime it is most often compared with is covered in the site’s SOX 404 guide, and the scoping method that transfers across is in the SOX scoping guide.
In this guide
- Where UK audit reform stands in 2026
- Provision 29, element by element
- Provision 29 against Sarbanes-Oxley
- Defining material controls: method and a worked list
- The assurance model behind a declaration
- Internal audit’s role, and the lines it must not cross
- A readiness timeline for a December year-end
- Worked example: Pennine Foods plc’s first-year program and declaration
- Common mistakes in Provision 29 readiness
Where UK audit reform stands in 2026
The reform program began with three reviews in 2018 and 2019, Kingman on the regulator, the Competition and Markets Authority on the audit market, and Brydon on the purpose of audit, prompted by Carillion, BHS, Patisserie Valerie, and Thomas Cook. The 2021 white paper proposed a new regulator, the Audit, Reporting and Governance Authority, a wider definition of public interest entities, and a directors’ attestation on internal controls modeled on Sarbanes-Oxley section 404. The government’s 2022 response kept the regulator and the wider PIE scope and dropped the statutory attestation in favor of changes to the Corporate Governance Code, which is how the substance of “UK SOX” ended up in Provision 29. The Code changes were finalized in January 2024, effective for financial years beginning 1 January 2025 with Provision 29 deferred a year. The Bill to create the regulator was announced in the July 2024 King’s Speech, was not introduced in the 2024 to 2025 session, and in July 2025 the responsible minister confirmed it would not be introduced then either, citing legislative volume; a further consultation was signaled for autumn 2025 and had not concluded by early 2026. The latest official signals describe the new regulator as the Corporate Reporting Authority, with civil sanction powers over directors for serious failures of existing reporting duties, and a PIE threshold for large private companies of 1,000 employees and £1 billion turnover, higher than the 750 and 750 previously discussed.
| Date | Event | Status in September 2026 |
|---|---|---|
| 2018 to 2019 | Kingman review (regulator), CMA market study, Brydon review (audit purpose) | Foundational; recommendations partly implemented through the FRC’s own reforms |
| March 2021 | BEIS white paper: ARGA, wider PIE definition, directors’ internal controls attestation, resilience statement, audit and assurance policy | Superseded |
| May 2022 | Government response drops the statutory attestation; internal controls to be addressed through the Code | The route taken |
| May 2023 | FRC publishes Audit Committees and the External Audit: Minimum Standard; Code consultation launched | Minimum Standard in force for FTSE 350 audit committees |
| January 2024 | UK Corporate Governance Code 2024 published with guidance; Provision 29 introduced | Effective 1 Jan 2025 (general); Provision 29 from 1 Jan 2026 |
| July 2024 | Audit Reform and Corporate Governance Bill announced in the King’s Speech | Not introduced; July 2025 confirmation of further delay; consultation pending |
| 1 January 2026 | Provision 29 applies to financial years beginning on or after this date | Live; first declarations in 2027 annual reports |
| 29 January 2026 | FRC Provision 29 Mythbuster published | Current FRC position on number of controls, assurance, wording, and disclosure of failures |
| 2027 | First annual reports containing the declaration (December 2026 year-ends onward) | The test of the regime |
The practical consequence is that UK companies face a Code obligation with real market consequences (investors, proxy advisers, and the FRC’s corporate reporting reviews) but no statutory attestation, no mandated external audit of controls, and no regulator with new sanction powers yet. Boards that prepare only to the letter of the Code will meet it; boards that prepare as if the statutory regime will eventually arrive, which it may, will find the second step short. The site’s guides to UK regulatory compliance for internal auditors and what UK audit committees expect from internal audit give the wider context.
Provision 29, element by element
Provision 29 sits under Principle O, which requires the board to establish and maintain an effective risk management and internal control framework and to determine the nature and extent of the principal risks it is willing to take. The provision requires the board to monitor the company’s risk management and internal control framework and, at least annually, to review its effectiveness, and it specifies what the annual report must then contain. The FRC has said it will not prescribe wording, expects the reporting to run to about two pages, and does not require external assurance over the controls or the declaration, though boards may obtain it. The table breaks the provision into the elements a board has to be able to evidence.
| Element | What the board must do | What the annual report must contain | Evidence behind it |
|---|---|---|---|
| Scope of the framework | Maintain a risk management and internal control framework covering all material controls: financial, operational, reporting (including narrative and sustainability reporting), and compliance | A description of how the board has monitored and reviewed the effectiveness of the framework | The framework documentation; the board’s and committee’s review process and cadence; the list of material controls and the rationale for it |
| The declaration | Reach a view on whether the material controls were effective as at the balance sheet date | A declaration of effectiveness of the material controls as at the balance sheet date | Testing and monitoring results for the year; management attestations; internal audit’s assurance; the committee’s assessment |
| Ineffective controls | Identify any material control that has not operated effectively as at the balance sheet date | A description of those controls and the action taken, or proposed, to improve them, with progress on previously reported issues | The deficiency evaluation; remediation plans with owners and dates; evidence of progress |
| Basis and framework | Choose a recognized framework to assess against (COSO is the common choice; the FRC guidance does not mandate one) | Reference to the basis of the assessment where useful to readers | The framework mapping |
| Comply or explain | Comply, or explain why not, under the Listing Rules | The explanation, where the company does not make the declaration | Board minute of the decision; the FRC and investors will read explanations closely in year one |
| Timing | The declaration speaks to the balance sheet date; issues discovered later that did not exist at that date do not invalidate it, but issues existing at the date must be disclosed | Dated statement | A cut-off process for control failures identified between year end and signing |
Three points from the FRC’s January 2026 Mythbuster have shaped first-year preparation. There is no target number of material controls; the FRC observed that companies were identifying around 30 to 50, with financial services firms more, and said explicitly that companies should not benchmark to peers. External assurance is a choice, not a requirement, and a company may seek it over some parts of the framework in some years and not others. And a material control failure must be disclosed with a description of remediation, but commercially sensitive technical detail need not be; the disclosure is about the control and the response, not the vulnerability. The control deficiency evaluation guide covers the judgment of whether a failure is material, which is the judgment the third element turns on.
Provision 29 against Sarbanes-Oxley
The comparison matters because most of the methodology available to UK companies was built for Sarbanes-Oxley, and because dual-listed groups have to run both. The short version: Provision 29 is wider in scope and lighter in enforcement, and the SOX methodology transfers for the financial reporting controls but not for the operational, compliance, and reporting controls that make up most of a Provision 29 list.
| Dimension | Sarbanes-Oxley (US, sections 302 and 404) | Provision 29 (UK Code 2024) | Implication |
|---|---|---|---|
| Legal basis | Statute; SEC and PCAOB rules | Corporate Governance Code, comply-or-explain under the Listing Rules | No criminal or civil sanction attached to the declaration itself; market and regulatory reputation are the enforcement |
| Who is accountable | CEO and CFO certify (302); management assesses (404(a)) | The board as a whole declares | Every director, including non-executives, has to be satisfied; committee process matters more |
| Scope of controls | Internal control over financial reporting only | Material controls across financial, operational, reporting, and compliance objectives | The list is broader and the judgment of materiality harder; operational controls have no established testing methodology |
| External attestation | Required for accelerated filers under 404(b) | Not required; optional | No auditor opinion to lean on; the board’s own assurance model carries the weight |
| Framework | A suitable recognized framework, in practice COSO 2013 | Not mandated; FRC guidance references recognized frameworks; COSO common | COSO’s five components and 17 principles remain the practical structure |
| Point in time | As of fiscal year end | As at the balance sheet date | Same discipline of year-end cut-off for known failures |
| Deficiency disclosure | Material weaknesses disclosed; significant deficiencies to the audit committee | Material controls not operating effectively disclosed with remediation | UK disclosure threshold is set by the board’s own definition of material control |
| Testing expectation | Documented design and operating effectiveness testing, evidence retained, auditor reviews | The board must be able to evidence its monitoring and review; no prescribed testing form | In practice, testing of some kind for every material control, proportionate to the risk |
| Cost experience | Substantial first-year cost for US registrants in 2004 to 2007; ongoing programs of 2,000 to 20,000 hours | Early UK readiness programs described by advisers and audit committees suggest first-year efforts in the range of roughly 800 to 4,000 hours for mid-sized listed companies, depending on maturity | Proportionality is the FRC’s stated intent; over-engineering is the first-year risk |
Dual-listed companies and UK subsidiaries of SEC registrants have an advantage on the financial reporting controls, which they already test, and a specific trap: treating the existing SOX control set as the Provision 29 list. The FRC’s Mythbuster addressed this directly, noting that companies under Sarbanes-Oxley are adapting their approaches because Provision 29 extends beyond SOX’s financial focus. The SOX ITGC scoping guide and the management review controls guide cover the two SOX techniques that transfer best.
Defining material controls: method and a worked list
The hardest judgment in Provision 29 is the first one: which controls are material. The FRC deliberately did not define the term, and the method that has emerged in the first readiness cycles starts from the principal risks the board already reports under the strategic report, asks for each principal risk which controls, if they failed, would leave the risk unmanaged in a way that would matter to the board and to investors, and adds the controls that protect the integrity of the annual report itself. The result is a list, typically 30 to 50 controls, each with an owner, a description in testable form, the objective it serves, the assurance source that will evidence it, and a rationale for its inclusion; equally important is a record of what was considered and excluded and why, because the FRC’s reviews will look at the scoping logic before they look at the testing. The table is the list Pennine Foods plc, a £900 million food manufacturer with a December year-end, settled on for its first declaration: 42 controls in seven groups, with the count per group and a representative control from each.
| Group | Objective | Count | Representative material controls | Principal risk addressed |
|---|---|---|---|---|
| Entity-level and governance | All | 6 | Board risk appetite and principal risk review (annual); delegation of authority matrix maintained and enforced in systems; code of conduct attestation and speak-up process; management certification cascade for the annual report | Governance and culture; reporting integrity |
| Financial reporting | Reporting | 12 | Group consolidation review with variance analysis; revenue cut-off and rebate accrual review; impairment and going-concern assessment approved by the board; manual journal approval by independent reviewer; balance sheet reconciliations reviewed monthly | Financial misstatement; covenant compliance |
| Food safety and quality | Operational; compliance | 7 | HACCP plan verification and critical control point monitoring at every site; supplier approval and audit program; product recall procedure tested annually; allergen labeling verification | Product safety and recall; regulatory action |
| Supply chain and operations | Operational | 5 | Critical supplier dual-sourcing for the twelve identified single-source inputs; demand and capacity planning review; site business continuity plans tested | Supply disruption; customer service failure |
| Cyber and IT | Operational; reporting | 6 | Privileged access management with quarterly certification; patching within defined windows; immutable backups with quarterly restore tests; change management for financial systems; incident response plan exercised | Cyber attack; system failure; reporting integrity |
| Compliance | Compliance | 4 | Anti-bribery due diligence on agents and distributors; competition law training and dawn-raid procedure; environmental permit monitoring; modern slavery supply chain assessment | Legal and regulatory breach |
| Sustainability and narrative reporting | Reporting | 2 | Data controls over the Scope 1 and 2 emissions figures in the annual report; review and evidence trail for the strategic report’s non-financial KPIs | Reporting integrity outside the financial statements |
| Total | — | 42 | — | — |
Two features of the list are deliberate. Each control is stated in the seven-attribute form (performer, action, object, frequency, criterion, evidence, follow-up) so that it can be tested, which the site’s guide to what a control is sets out; “the company has a food safety culture” did not make the list, while “HACCP critical control points are monitored and verified at every site” did. And the list is short in the financial reporting group relative to a SOX program, because SOX’s key control population includes many process-level controls whose failure would be a significant deficiency but would not, on Pennine’s analysis, leave a principal risk unmanaged; Provision 29’s materiality is the board’s, not the auditor’s.
The assurance model behind a declaration
A board cannot test 42 controls itself, and the FRC does not expect it to. What it expects is a described process by which the board obtained enough assurance to declare, and the practical structure is an assurance map: for each material control, who operates it, who monitors it, who independently tests it, and what the board sees. The three lines model supplies the vocabulary, and the map is where Provision 29 connects to internal audit’s plan.
| Assurance source | Role in the declaration | What it produces | Limits |
|---|---|---|---|
| Control owners (first line) | Operate the control; self-assess and attest at year end that it operated as designed, with evidence | Signed attestations per control with supporting evidence; exceptions declared | Self-assessment; must be corroborated for the declaration to mean anything |
| Risk, compliance, quality, and IT security functions (second line) | Monitor the controls in their domains through the year; report metrics and exceptions | Monitoring results, KPI and KRI reporting, compliance testing where performed | Coverage varies by domain; second-line testing is not independent of management |
| Internal audit (third line) | Independently test the design and operating effectiveness of material controls on a cycle agreed with the committee; assess the assurance model itself; report to the committee | Test results per control tested; findings; an overall view on the reliability of the first- and second-line assurance | Cannot test everything every year; must not own the framework or the list |
| External assurance (optional) | Independent assurance over specified controls or the process, where the board chooses to obtain it | A report over the agreed scope | Not required; costly; scope must be defined by the board |
| Audit committee | Reviews the map, the results, and the exceptions; recommends the declaration to the board | Minuted assessment; challenge recorded | Depends on the quality of what reaches it |
| Board | Reviews the committee’s assessment; declares | The declaration and the description of monitoring and review | — |
The map makes one thing visible that boards find uncomfortable: for most operational and compliance controls, the only independent testing available is internal audit’s, because the external auditor does not test them and the second line is part of management. That is why internal audit’s plan and Provision 29 have become the same conversation in most UK companies, and why the Chartered IIA has positioned the function as the provider of independent assurance that the material controls have operated effectively. The GIAS Domain III guide covers the board’s side of that relationship.
Internal audit’s role, and the lines it must not cross
Provision 29 is the best thing to happen to UK internal audit’s standing in a decade and the fastest way to compromise its independence, and the difference is entirely in who owns what. The Global Internal Audit Standards prohibit the function from assuming management responsibility, and the Code’s guidance references both the Standards and the Chartered IIA’s Internal Audit Code of Practice; a function that designs the framework, writes the material controls list, and then tests it has audited its own work, and the committee’s declaration rests on a circle. The table separates what internal audit should do from what it should decline, with the form of words that keeps the boundary clear.
| Activity | Internal audit should | Internal audit should not | How to say it |
|---|---|---|---|
| Defining material controls | Advise on method; challenge the draft list for gaps and for untestable descriptions; assess the scoping rationale | Decide the list or own the rationale | “We reviewed management’s proposed list against the principal risks and identified three areas we believe warrant inclusion; the decision is management’s and the committee’s” |
| Framework design | Assess whether the framework meets Principle O and the Code guidance; benchmark to COSO | Design, implement, or operate it | “Our assessment of the framework’s design is at Appendix B; management owns its implementation” |
| Testing | Test design and operating effectiveness of material controls on a cycle agreed with the committee; retain evidence to the Standards | Test controls it helped design; certify anything on management’s behalf | “Internal audit tested 28 of the 42 material controls in 2026 and relied on second-line monitoring, which we assessed, for 9; 5 were not tested this year and are scheduled for 2027” |
| Management attestations | Assess the attestation process and corroborate a sample against evidence | Collect or sign the attestations | “We tested 15 attestations to evidence; two were not supported and are reported as exceptions” |
| Remediation | Validate that remediated controls operate; report status | Perform the remediation or own the action plan | “Management’s remediation of the rebate accrual control was validated by re-performance in November” |
| The declaration | Provide the committee with an independent view on the reliability of the assurance behind it and the exceptions it should weigh | Draft the declaration, recommend its wording, or be cited as the basis for it without qualification | “Internal audit’s work supports, subject to the exceptions reported, the assurance the board is relying on for the controls we tested” |
| Resourcing | Report to the committee the hours the program requires and what it displaces | Absorb the program silently by cutting risk-based coverage | “Provision 29 testing is 900 hours of the 2026 plan; the following engagements were deferred as a result” |
Two organizational points follow. The material controls testing program should sit in the audit plan as a named, mandatory line with its own hours, as the site’s audit planning guide recommends for any mandate-driven work, so that the committee sees what it costs and what it displaces. And the function’s own independence confirmation to the committee should state explicitly what role it played in the Provision 29 program, because an external quality assessor will ask, and because the first FRC reviews of declarations will look for boards that leaned on an internal audit function that had built what it tested.
A readiness timeline for a December year-end
A company with a 31 December 2026 year-end declares in its 2027 annual report on the controls in place at 31 December 2026, which means the program has to be running through 2026, not designed in it. The timeline below is the one Pennine Foods followed, compressed into four quarters from a standing start in late 2025; a company beginning later in 2026 should still aim to have the list, the attestation process, and a first round of testing done before year end, and explain in the annual report what remains.
| Period | Management and the board | Internal audit | Output |
|---|---|---|---|
| Q4 2025 | Board approves the approach and materiality method; executive sponsor and program lead appointed; framework benchmarked to COSO | Advises on method; assesses the framework’s design; agrees the testing cycle and hours with the committee | Approved method; program charter; plan line for testing |
| Q1 2026 | Material controls list drafted from principal risks; controls described in testable form; owners assigned; assurance map built; gaps identified (controls that should exist and do not) | Challenges the list; identifies gaps; scopes the first test cycle to the highest-risk controls | Approved list with rationale; assurance map; gap remediation plan |
| Q2 2026 | Gap remediation underway; attestation process designed; second-line monitoring aligned to the list; first management self-assessment | First test cycle (design and operating effectiveness, interim period) on roughly half the list; reports exceptions | Interim test results; remediation of design gaps started early enough to operate for a period before year end |
| Q3 2026 | Remediation completed for design gaps; monitoring reporting to the committee in the new format; disclosure drafting begins | Second test cycle on the remaining controls; validation of remediated controls; assessment of the attestation process | Full-list test results; validated remediations; committee paper on the state of the framework |
| Q4 2026 | Year-end attestations collected; cut-off process for late failures; committee reviews the assurance map and exceptions; draft declaration and monitoring description prepared | Roll-forward testing to year end for controls tested at interim; attestation corroboration; independent view to the committee on the reliability of the assurance and the exceptions | Committee assessment; board declaration decision; two pages of disclosure drafted |
| Q1 2027 | Board approves the annual report with the declaration; disclosure of any ineffective material controls and remediation; comply-or-explain statement | Reports to the committee on the year’s program and the 2027 cycle | The first declaration; the 2027 plan line |
Worked example: Pennine Foods plc’s first-year program and declaration
Pennine Foods plc is a premium-listed food manufacturer with £900 million of revenue, five UK sites, a December year-end, a four-person internal audit function, and no prior Sarbanes-Oxley exposure. Its program produced the 42-control list above. Internal audit’s testing line was 900 hours: 28 controls tested directly across two cycles, 9 covered by second-line monitoring that internal audit assessed and sampled, and 5 deferred to 2027 with the committee’s agreement and disclosed as such. The program found three material controls not operating effectively during the year: the rebate accrual review (the reviewer lacked the customer contract data to challenge the estimate), the privileged access certification (two quarters missed at one site during a system migration), and the critical supplier dual-sourcing control (four of the twelve single-source inputs had no qualified alternative). The first two were remediated and operated effectively for the final quarter, validated by re-performance; the third could not be fully remediated by year end, because qualifying alternative suppliers takes months, and became the subject of the disclosure. The declaration below is Pennine’s, compressed; note that it declares, describes the process, names the exception, and says what is being done, in about 200 words, and that it does not claim assurance it did not obtain.
Board declaration on material controls (Provision 29). The board has monitored the company’s risk management and internal control framework throughout 2026 and reviewed its effectiveness at the year end. The framework is assessed against the COSO Internal Control – Integrated Framework and covers the material controls the board has identified as necessary to manage the company’s principal risks across its financial, operational, reporting, and compliance objectives; 42 such controls were identified for 2026 on the basis described on page 71. The board’s review drew on management’s year-end attestations for each material control, monitoring by the risk, quality, and information security functions, independent testing by internal audit of 28 of the 42 controls together with its assessment of the second-line monitoring covering a further nine, and the audit committee’s assessment of that assurance.
On the basis of that review, the board declares that, as at 31 December 2026, the company’s material controls were operating effectively, with one exception. The control requiring a qualified alternative supplier for each single-source critical input was not fully effective at the year end: four of twelve such inputs had no qualified alternative. Management has qualified two alternative suppliers since the year end and expects to complete qualification of the remaining two by the third quarter of 2027; in the interim, safety stock for the affected inputs has been increased to twelve weeks. Two further material controls that did not operate effectively during the year, relating to rebate accrual review and privileged access certification, were remediated during the fourth quarter and operated effectively at the year end. Five material controls were not independently tested in 2026 and are scheduled for testing in 2027; the board relied on management attestation and second-line monitoring for those controls.
The declaration’s last sentence is the one most first-year boards will want to omit and should not. The FRC’s guidance asks for a description of how the board monitored and reviewed, and a truthful description of a first-year program includes what was not tested; a board that implies full independent testing it did not obtain has made a statement it cannot support, and the FRC’s corporate reporting reviews are built to notice. The report examples guide shows the internal audit report that fed the committee’s assessment, and the issue log template the tracking behind the three exceptions.
Common mistakes in Provision 29 readiness
| Failure | What it looks like | Why it matters | Fix |
|---|---|---|---|
| Copying the SOX list | A dual-listed group’s ICFR key controls presented as the material controls | Operational, compliance, and reporting objectives uncovered; the FRC has said this directly | Start from principal risks; add the non-financial groups |
| Too many controls | A list of 200 built by asking every function what it does | Untestable in a year; the board declares on a list it cannot have reviewed | Materiality from the board’s perspective; 30 to 50 is where most land, but derive it, do not target it |
| Untestable descriptions | “Robust supplier management” as a material control | No evidence can support a declaration about it | Seven-attribute descriptions; if it cannot be written that way it is not a control |
| Internal audit owning the framework | The function drafts the list, designs the attestation, and tests it | Independence gone; the assurance is circular | Advise and challenge; management owns; the committee decides |
| No assurance map | Nobody can say who tested what | The board cannot describe its monitoring and review | One map, one owner, reviewed by the committee each half-year |
| Attestations without corroboration | Forty-two signed forms, none checked | Self-certification is not assurance | Sample attestations to evidence; report the ones that fail |
| Late remediation | Design gaps found in Q3 with no time to operate before year end | The control cannot be declared effective at the balance sheet date | Gap analysis in Q1; remediation operating by Q3 |
| Hiding the exception | A failed control described as “an opportunity to enhance” | The provision requires disclosure of ineffective material controls; investors and the FRC will compare to what was known | Name the control, the failure, the remediation, and the date |
| Claiming assurance not obtained | A declaration implying full independent testing after a partial first year | An unsupportable statement in a regulated document | Describe what was tested and what was relied on |
| Preparing only for the Code | A minimum-compliance program with no path to statutory attestation | The Bill may yet arrive; a program built to the Code’s floor will need rebuilding | Build the evidence discipline of a 404(a) program at Provision 29’s scope |
Provision 29 asks boards to do in public what good boards have always done in private: know which controls they rely on, find out whether those controls work, and say so. For internal audit it is an invitation to become the source of that knowledge, on the condition that it does not become the owner of the thing it assures. The Internal Audit Code of Practice guide covers the UK-specific expectations the Code’s guidance now references, and the Global Internal Audit Standards guide the independence requirements that draw the line.
Related guides
- SOX 404 — the US regime Provision 29 is compared with
- SOX scoping — the scoping method that transfers to material controls
- Management review controls — the largest category on most material controls lists
- Control deficiency evaluation — deciding whether a failure is material
- What is an internal control? — writing controls in testable form
- GIAS Domain III: governing — the board’s duties to the function
- How to build an internal audit plan — putting the testing program in the plan honestly
- The Internal Audit Code of Practice (UK) — the Chartered IIA’s expectations
- UK audit committees and internal audit — the committee’s perspective
- UK regulatory compliance for internal auditors — the wider regulatory setting
- All Guides — the full index
Leave a Reply