, ,

UK SOX in 2026: Provision 29 and Internal Audit’s Role

“UK SOX” never happened, and it is arriving anyway. The statutory, US-style regime that the 2021 white paper proposed, with directors attesting to internal controls under threat of sanction, was dropped by the government in 2022, and the Audit Reform and Corporate Governance Bill that would create a stronger regulator has still not been introduced to Parliament as of September 2026. What did happen is Provision 29 of the 2024 UK Corporate Governance Code: from financial years beginning on or after 1 January 2026, boards of premium-listed companies must declare in the annual report whether their material internal controls were effective at the balance sheet date, describe how they monitored and reviewed them, and disclose any that were not working and what they did about it. The first declarations appear in annual reports published in 2027, on a comply-or-explain basis, covering financial, operational, reporting, and compliance controls. That is a wider scope than Sarbanes-Oxley, with a lighter enforcement regime, and it lands on boards that in many cases have never had to say in writing which controls they rely on.

This guide is for internal auditors and audit committee members in UK companies preparing for that declaration, and for their counterparts elsewhere watching a model that other markets are likely to copy. It sets out where UK audit reform actually stands in 2026, what Provision 29 requires element by element, how it compares with Sarbanes-Oxley, how boards are defining material controls (with a worked list of 42 for a food manufacturer), the assurance model that supports a declaration, internal audit’s role and the lines it must not cross, a quarter-by-quarter readiness timeline for a December year-end, a worked first-year program at a listed company, a model declaration, and the mistakes emerging from the first readiness cycles. It was rewritten in September 2026 from the Code, the FRC’s guidance, its January 2026 Provision 29 Mythbuster, and the government’s stated position on the Bill. The US regime it is most often compared with is covered in the site’s SOX 404 guide, and the scoping method that transfers across is in the SOX scoping guide.

In this guide

Where UK audit reform stands in 2026

The reform program began with three reviews in 2018 and 2019, Kingman on the regulator, the Competition and Markets Authority on the audit market, and Brydon on the purpose of audit, prompted by Carillion, BHS, Patisserie Valerie, and Thomas Cook. The 2021 white paper proposed a new regulator, the Audit, Reporting and Governance Authority, a wider definition of public interest entities, and a directors’ attestation on internal controls modeled on Sarbanes-Oxley section 404. The government’s 2022 response kept the regulator and the wider PIE scope and dropped the statutory attestation in favor of changes to the Corporate Governance Code, which is how the substance of “UK SOX” ended up in Provision 29. The Code changes were finalized in January 2024, effective for financial years beginning 1 January 2025 with Provision 29 deferred a year. The Bill to create the regulator was announced in the July 2024 King’s Speech, was not introduced in the 2024 to 2025 session, and in July 2025 the responsible minister confirmed it would not be introduced then either, citing legislative volume; a further consultation was signaled for autumn 2025 and had not concluded by early 2026. The latest official signals describe the new regulator as the Corporate Reporting Authority, with civil sanction powers over directors for serious failures of existing reporting duties, and a PIE threshold for large private companies of 1,000 employees and £1 billion turnover, higher than the 750 and 750 previously discussed.

DateEventStatus in September 2026
2018 to 2019Kingman review (regulator), CMA market study, Brydon review (audit purpose)Foundational; recommendations partly implemented through the FRC’s own reforms
March 2021BEIS white paper: ARGA, wider PIE definition, directors’ internal controls attestation, resilience statement, audit and assurance policySuperseded
May 2022Government response drops the statutory attestation; internal controls to be addressed through the CodeThe route taken
May 2023FRC publishes Audit Committees and the External Audit: Minimum Standard; Code consultation launchedMinimum Standard in force for FTSE 350 audit committees
January 2024UK Corporate Governance Code 2024 published with guidance; Provision 29 introducedEffective 1 Jan 2025 (general); Provision 29 from 1 Jan 2026
July 2024Audit Reform and Corporate Governance Bill announced in the King’s SpeechNot introduced; July 2025 confirmation of further delay; consultation pending
1 January 2026Provision 29 applies to financial years beginning on or after this dateLive; first declarations in 2027 annual reports
29 January 2026FRC Provision 29 Mythbuster publishedCurrent FRC position on number of controls, assurance, wording, and disclosure of failures
2027First annual reports containing the declaration (December 2026 year-ends onward)The test of the regime

The practical consequence is that UK companies face a Code obligation with real market consequences (investors, proxy advisers, and the FRC’s corporate reporting reviews) but no statutory attestation, no mandated external audit of controls, and no regulator with new sanction powers yet. Boards that prepare only to the letter of the Code will meet it; boards that prepare as if the statutory regime will eventually arrive, which it may, will find the second step short. The site’s guides to UK regulatory compliance for internal auditors and what UK audit committees expect from internal audit give the wider context.

Provision 29, element by element

Provision 29 sits under Principle O, which requires the board to establish and maintain an effective risk management and internal control framework and to determine the nature and extent of the principal risks it is willing to take. The provision requires the board to monitor the company’s risk management and internal control framework and, at least annually, to review its effectiveness, and it specifies what the annual report must then contain. The FRC has said it will not prescribe wording, expects the reporting to run to about two pages, and does not require external assurance over the controls or the declaration, though boards may obtain it. The table breaks the provision into the elements a board has to be able to evidence.

ElementWhat the board must doWhat the annual report must containEvidence behind it
Scope of the frameworkMaintain a risk management and internal control framework covering all material controls: financial, operational, reporting (including narrative and sustainability reporting), and complianceA description of how the board has monitored and reviewed the effectiveness of the frameworkThe framework documentation; the board’s and committee’s review process and cadence; the list of material controls and the rationale for it
The declarationReach a view on whether the material controls were effective as at the balance sheet dateA declaration of effectiveness of the material controls as at the balance sheet dateTesting and monitoring results for the year; management attestations; internal audit’s assurance; the committee’s assessment
Ineffective controlsIdentify any material control that has not operated effectively as at the balance sheet dateA description of those controls and the action taken, or proposed, to improve them, with progress on previously reported issuesThe deficiency evaluation; remediation plans with owners and dates; evidence of progress
Basis and frameworkChoose a recognized framework to assess against (COSO is the common choice; the FRC guidance does not mandate one)Reference to the basis of the assessment where useful to readersThe framework mapping
Comply or explainComply, or explain why not, under the Listing RulesThe explanation, where the company does not make the declarationBoard minute of the decision; the FRC and investors will read explanations closely in year one
TimingThe declaration speaks to the balance sheet date; issues discovered later that did not exist at that date do not invalidate it, but issues existing at the date must be disclosedDated statementA cut-off process for control failures identified between year end and signing

Three points from the FRC’s January 2026 Mythbuster have shaped first-year preparation. There is no target number of material controls; the FRC observed that companies were identifying around 30 to 50, with financial services firms more, and said explicitly that companies should not benchmark to peers. External assurance is a choice, not a requirement, and a company may seek it over some parts of the framework in some years and not others. And a material control failure must be disclosed with a description of remediation, but commercially sensitive technical detail need not be; the disclosure is about the control and the response, not the vulnerability. The control deficiency evaluation guide covers the judgment of whether a failure is material, which is the judgment the third element turns on.

Provision 29 against Sarbanes-Oxley

The comparison matters because most of the methodology available to UK companies was built for Sarbanes-Oxley, and because dual-listed groups have to run both. The short version: Provision 29 is wider in scope and lighter in enforcement, and the SOX methodology transfers for the financial reporting controls but not for the operational, compliance, and reporting controls that make up most of a Provision 29 list.

DimensionSarbanes-Oxley (US, sections 302 and 404)Provision 29 (UK Code 2024)Implication
Legal basisStatute; SEC and PCAOB rulesCorporate Governance Code, comply-or-explain under the Listing RulesNo criminal or civil sanction attached to the declaration itself; market and regulatory reputation are the enforcement
Who is accountableCEO and CFO certify (302); management assesses (404(a))The board as a whole declaresEvery director, including non-executives, has to be satisfied; committee process matters more
Scope of controlsInternal control over financial reporting onlyMaterial controls across financial, operational, reporting, and compliance objectivesThe list is broader and the judgment of materiality harder; operational controls have no established testing methodology
External attestationRequired for accelerated filers under 404(b)Not required; optionalNo auditor opinion to lean on; the board’s own assurance model carries the weight
FrameworkA suitable recognized framework, in practice COSO 2013Not mandated; FRC guidance references recognized frameworks; COSO commonCOSO’s five components and 17 principles remain the practical structure
Point in timeAs of fiscal year endAs at the balance sheet dateSame discipline of year-end cut-off for known failures
Deficiency disclosureMaterial weaknesses disclosed; significant deficiencies to the audit committeeMaterial controls not operating effectively disclosed with remediationUK disclosure threshold is set by the board’s own definition of material control
Testing expectationDocumented design and operating effectiveness testing, evidence retained, auditor reviewsThe board must be able to evidence its monitoring and review; no prescribed testing formIn practice, testing of some kind for every material control, proportionate to the risk
Cost experienceSubstantial first-year cost for US registrants in 2004 to 2007; ongoing programs of 2,000 to 20,000 hoursEarly UK readiness programs described by advisers and audit committees suggest first-year efforts in the range of roughly 800 to 4,000 hours for mid-sized listed companies, depending on maturityProportionality is the FRC’s stated intent; over-engineering is the first-year risk

Dual-listed companies and UK subsidiaries of SEC registrants have an advantage on the financial reporting controls, which they already test, and a specific trap: treating the existing SOX control set as the Provision 29 list. The FRC’s Mythbuster addressed this directly, noting that companies under Sarbanes-Oxley are adapting their approaches because Provision 29 extends beyond SOX’s financial focus. The SOX ITGC scoping guide and the management review controls guide cover the two SOX techniques that transfer best.

Defining material controls: method and a worked list

The hardest judgment in Provision 29 is the first one: which controls are material. The FRC deliberately did not define the term, and the method that has emerged in the first readiness cycles starts from the principal risks the board already reports under the strategic report, asks for each principal risk which controls, if they failed, would leave the risk unmanaged in a way that would matter to the board and to investors, and adds the controls that protect the integrity of the annual report itself. The result is a list, typically 30 to 50 controls, each with an owner, a description in testable form, the objective it serves, the assurance source that will evidence it, and a rationale for its inclusion; equally important is a record of what was considered and excluded and why, because the FRC’s reviews will look at the scoping logic before they look at the testing. The table is the list Pennine Foods plc, a £900 million food manufacturer with a December year-end, settled on for its first declaration: 42 controls in seven groups, with the count per group and a representative control from each.

GroupObjectiveCountRepresentative material controlsPrincipal risk addressed
Entity-level and governanceAll6Board risk appetite and principal risk review (annual); delegation of authority matrix maintained and enforced in systems; code of conduct attestation and speak-up process; management certification cascade for the annual reportGovernance and culture; reporting integrity
Financial reportingReporting12Group consolidation review with variance analysis; revenue cut-off and rebate accrual review; impairment and going-concern assessment approved by the board; manual journal approval by independent reviewer; balance sheet reconciliations reviewed monthlyFinancial misstatement; covenant compliance
Food safety and qualityOperational; compliance7HACCP plan verification and critical control point monitoring at every site; supplier approval and audit program; product recall procedure tested annually; allergen labeling verificationProduct safety and recall; regulatory action
Supply chain and operationsOperational5Critical supplier dual-sourcing for the twelve identified single-source inputs; demand and capacity planning review; site business continuity plans testedSupply disruption; customer service failure
Cyber and ITOperational; reporting6Privileged access management with quarterly certification; patching within defined windows; immutable backups with quarterly restore tests; change management for financial systems; incident response plan exercisedCyber attack; system failure; reporting integrity
ComplianceCompliance4Anti-bribery due diligence on agents and distributors; competition law training and dawn-raid procedure; environmental permit monitoring; modern slavery supply chain assessmentLegal and regulatory breach
Sustainability and narrative reportingReporting2Data controls over the Scope 1 and 2 emissions figures in the annual report; review and evidence trail for the strategic report’s non-financial KPIsReporting integrity outside the financial statements
Total42

Two features of the list are deliberate. Each control is stated in the seven-attribute form (performer, action, object, frequency, criterion, evidence, follow-up) so that it can be tested, which the site’s guide to what a control is sets out; “the company has a food safety culture” did not make the list, while “HACCP critical control points are monitored and verified at every site” did. And the list is short in the financial reporting group relative to a SOX program, because SOX’s key control population includes many process-level controls whose failure would be a significant deficiency but would not, on Pennine’s analysis, leave a principal risk unmanaged; Provision 29’s materiality is the board’s, not the auditor’s.

The assurance model behind a declaration

A board cannot test 42 controls itself, and the FRC does not expect it to. What it expects is a described process by which the board obtained enough assurance to declare, and the practical structure is an assurance map: for each material control, who operates it, who monitors it, who independently tests it, and what the board sees. The three lines model supplies the vocabulary, and the map is where Provision 29 connects to internal audit’s plan.

Assurance sourceRole in the declarationWhat it producesLimits
Control owners (first line)Operate the control; self-assess and attest at year end that it operated as designed, with evidenceSigned attestations per control with supporting evidence; exceptions declaredSelf-assessment; must be corroborated for the declaration to mean anything
Risk, compliance, quality, and IT security functions (second line)Monitor the controls in their domains through the year; report metrics and exceptionsMonitoring results, KPI and KRI reporting, compliance testing where performedCoverage varies by domain; second-line testing is not independent of management
Internal audit (third line)Independently test the design and operating effectiveness of material controls on a cycle agreed with the committee; assess the assurance model itself; report to the committeeTest results per control tested; findings; an overall view on the reliability of the first- and second-line assuranceCannot test everything every year; must not own the framework or the list
External assurance (optional)Independent assurance over specified controls or the process, where the board chooses to obtain itA report over the agreed scopeNot required; costly; scope must be defined by the board
Audit committeeReviews the map, the results, and the exceptions; recommends the declaration to the boardMinuted assessment; challenge recordedDepends on the quality of what reaches it
BoardReviews the committee’s assessment; declaresThe declaration and the description of monitoring and review

The map makes one thing visible that boards find uncomfortable: for most operational and compliance controls, the only independent testing available is internal audit’s, because the external auditor does not test them and the second line is part of management. That is why internal audit’s plan and Provision 29 have become the same conversation in most UK companies, and why the Chartered IIA has positioned the function as the provider of independent assurance that the material controls have operated effectively. The GIAS Domain III guide covers the board’s side of that relationship.

Internal audit’s role, and the lines it must not cross

Provision 29 is the best thing to happen to UK internal audit’s standing in a decade and the fastest way to compromise its independence, and the difference is entirely in who owns what. The Global Internal Audit Standards prohibit the function from assuming management responsibility, and the Code’s guidance references both the Standards and the Chartered IIA’s Internal Audit Code of Practice; a function that designs the framework, writes the material controls list, and then tests it has audited its own work, and the committee’s declaration rests on a circle. The table separates what internal audit should do from what it should decline, with the form of words that keeps the boundary clear.

ActivityInternal audit shouldInternal audit should notHow to say it
Defining material controlsAdvise on method; challenge the draft list for gaps and for untestable descriptions; assess the scoping rationaleDecide the list or own the rationale“We reviewed management’s proposed list against the principal risks and identified three areas we believe warrant inclusion; the decision is management’s and the committee’s”
Framework designAssess whether the framework meets Principle O and the Code guidance; benchmark to COSODesign, implement, or operate it“Our assessment of the framework’s design is at Appendix B; management owns its implementation”
TestingTest design and operating effectiveness of material controls on a cycle agreed with the committee; retain evidence to the StandardsTest controls it helped design; certify anything on management’s behalf“Internal audit tested 28 of the 42 material controls in 2026 and relied on second-line monitoring, which we assessed, for 9; 5 were not tested this year and are scheduled for 2027”
Management attestationsAssess the attestation process and corroborate a sample against evidenceCollect or sign the attestations“We tested 15 attestations to evidence; two were not supported and are reported as exceptions”
RemediationValidate that remediated controls operate; report statusPerform the remediation or own the action plan“Management’s remediation of the rebate accrual control was validated by re-performance in November”
The declarationProvide the committee with an independent view on the reliability of the assurance behind it and the exceptions it should weighDraft the declaration, recommend its wording, or be cited as the basis for it without qualification“Internal audit’s work supports, subject to the exceptions reported, the assurance the board is relying on for the controls we tested”
ResourcingReport to the committee the hours the program requires and what it displacesAbsorb the program silently by cutting risk-based coverage“Provision 29 testing is 900 hours of the 2026 plan; the following engagements were deferred as a result”

Two organizational points follow. The material controls testing program should sit in the audit plan as a named, mandatory line with its own hours, as the site’s audit planning guide recommends for any mandate-driven work, so that the committee sees what it costs and what it displaces. And the function’s own independence confirmation to the committee should state explicitly what role it played in the Provision 29 program, because an external quality assessor will ask, and because the first FRC reviews of declarations will look for boards that leaned on an internal audit function that had built what it tested.

A readiness timeline for a December year-end

A company with a 31 December 2026 year-end declares in its 2027 annual report on the controls in place at 31 December 2026, which means the program has to be running through 2026, not designed in it. The timeline below is the one Pennine Foods followed, compressed into four quarters from a standing start in late 2025; a company beginning later in 2026 should still aim to have the list, the attestation process, and a first round of testing done before year end, and explain in the annual report what remains.

PeriodManagement and the boardInternal auditOutput
Q4 2025Board approves the approach and materiality method; executive sponsor and program lead appointed; framework benchmarked to COSOAdvises on method; assesses the framework’s design; agrees the testing cycle and hours with the committeeApproved method; program charter; plan line for testing
Q1 2026Material controls list drafted from principal risks; controls described in testable form; owners assigned; assurance map built; gaps identified (controls that should exist and do not)Challenges the list; identifies gaps; scopes the first test cycle to the highest-risk controlsApproved list with rationale; assurance map; gap remediation plan
Q2 2026Gap remediation underway; attestation process designed; second-line monitoring aligned to the list; first management self-assessmentFirst test cycle (design and operating effectiveness, interim period) on roughly half the list; reports exceptionsInterim test results; remediation of design gaps started early enough to operate for a period before year end
Q3 2026Remediation completed for design gaps; monitoring reporting to the committee in the new format; disclosure drafting beginsSecond test cycle on the remaining controls; validation of remediated controls; assessment of the attestation processFull-list test results; validated remediations; committee paper on the state of the framework
Q4 2026Year-end attestations collected; cut-off process for late failures; committee reviews the assurance map and exceptions; draft declaration and monitoring description preparedRoll-forward testing to year end for controls tested at interim; attestation corroboration; independent view to the committee on the reliability of the assurance and the exceptionsCommittee assessment; board declaration decision; two pages of disclosure drafted
Q1 2027Board approves the annual report with the declaration; disclosure of any ineffective material controls and remediation; comply-or-explain statementReports to the committee on the year’s program and the 2027 cycleThe first declaration; the 2027 plan line

Worked example: Pennine Foods plc’s first-year program and declaration

Pennine Foods plc is a premium-listed food manufacturer with £900 million of revenue, five UK sites, a December year-end, a four-person internal audit function, and no prior Sarbanes-Oxley exposure. Its program produced the 42-control list above. Internal audit’s testing line was 900 hours: 28 controls tested directly across two cycles, 9 covered by second-line monitoring that internal audit assessed and sampled, and 5 deferred to 2027 with the committee’s agreement and disclosed as such. The program found three material controls not operating effectively during the year: the rebate accrual review (the reviewer lacked the customer contract data to challenge the estimate), the privileged access certification (two quarters missed at one site during a system migration), and the critical supplier dual-sourcing control (four of the twelve single-source inputs had no qualified alternative). The first two were remediated and operated effectively for the final quarter, validated by re-performance; the third could not be fully remediated by year end, because qualifying alternative suppliers takes months, and became the subject of the disclosure. The declaration below is Pennine’s, compressed; note that it declares, describes the process, names the exception, and says what is being done, in about 200 words, and that it does not claim assurance it did not obtain.

Board declaration on material controls (Provision 29). The board has monitored the company’s risk management and internal control framework throughout 2026 and reviewed its effectiveness at the year end. The framework is assessed against the COSO Internal Control – Integrated Framework and covers the material controls the board has identified as necessary to manage the company’s principal risks across its financial, operational, reporting, and compliance objectives; 42 such controls were identified for 2026 on the basis described on page 71. The board’s review drew on management’s year-end attestations for each material control, monitoring by the risk, quality, and information security functions, independent testing by internal audit of 28 of the 42 controls together with its assessment of the second-line monitoring covering a further nine, and the audit committee’s assessment of that assurance.

On the basis of that review, the board declares that, as at 31 December 2026, the company’s material controls were operating effectively, with one exception. The control requiring a qualified alternative supplier for each single-source critical input was not fully effective at the year end: four of twelve such inputs had no qualified alternative. Management has qualified two alternative suppliers since the year end and expects to complete qualification of the remaining two by the third quarter of 2027; in the interim, safety stock for the affected inputs has been increased to twelve weeks. Two further material controls that did not operate effectively during the year, relating to rebate accrual review and privileged access certification, were remediated during the fourth quarter and operated effectively at the year end. Five material controls were not independently tested in 2026 and are scheduled for testing in 2027; the board relied on management attestation and second-line monitoring for those controls.

The declaration’s last sentence is the one most first-year boards will want to omit and should not. The FRC’s guidance asks for a description of how the board monitored and reviewed, and a truthful description of a first-year program includes what was not tested; a board that implies full independent testing it did not obtain has made a statement it cannot support, and the FRC’s corporate reporting reviews are built to notice. The report examples guide shows the internal audit report that fed the committee’s assessment, and the issue log template the tracking behind the three exceptions.

Common mistakes in Provision 29 readiness

FailureWhat it looks likeWhy it mattersFix
Copying the SOX listA dual-listed group’s ICFR key controls presented as the material controlsOperational, compliance, and reporting objectives uncovered; the FRC has said this directlyStart from principal risks; add the non-financial groups
Too many controlsA list of 200 built by asking every function what it doesUntestable in a year; the board declares on a list it cannot have reviewedMateriality from the board’s perspective; 30 to 50 is where most land, but derive it, do not target it
Untestable descriptions“Robust supplier management” as a material controlNo evidence can support a declaration about itSeven-attribute descriptions; if it cannot be written that way it is not a control
Internal audit owning the frameworkThe function drafts the list, designs the attestation, and tests itIndependence gone; the assurance is circularAdvise and challenge; management owns; the committee decides
No assurance mapNobody can say who tested whatThe board cannot describe its monitoring and reviewOne map, one owner, reviewed by the committee each half-year
Attestations without corroborationForty-two signed forms, none checkedSelf-certification is not assuranceSample attestations to evidence; report the ones that fail
Late remediationDesign gaps found in Q3 with no time to operate before year endThe control cannot be declared effective at the balance sheet dateGap analysis in Q1; remediation operating by Q3
Hiding the exceptionA failed control described as “an opportunity to enhance”The provision requires disclosure of ineffective material controls; investors and the FRC will compare to what was knownName the control, the failure, the remediation, and the date
Claiming assurance not obtainedA declaration implying full independent testing after a partial first yearAn unsupportable statement in a regulated documentDescribe what was tested and what was relied on
Preparing only for the CodeA minimum-compliance program with no path to statutory attestationThe Bill may yet arrive; a program built to the Code’s floor will need rebuildingBuild the evidence discipline of a 404(a) program at Provision 29’s scope

Provision 29 asks boards to do in public what good boards have always done in private: know which controls they rely on, find out whether those controls work, and say so. For internal audit it is an invitation to become the source of that knowledge, on the condition that it does not become the owner of the thing it assures. The Internal Audit Code of Practice guide covers the UK-specific expectations the Code’s guidance now references, and the Global Internal Audit Standards guide the independence requirements that draw the line.

Related guides

Comments

Leave a Reply

Discover more from internalauditguide.com

Subscribe now to keep reading and get access to the full archive.

Continue reading