Skip to Content

How to Report on Provision 29 with Confidence: Insights from LogicGate & PwC

Provision 29 of the UK Corporate Governance Code requires boards to declare whether material controls were effective at the balance sheet date. Meeting that standard takes continuous monitoring, timestamped testing evidence, and documented remediation, not a year-end scramble. LogicGate and PwC explained how in a webinar on October 7, 2026.

With December 2026 year-ends approaching, the first Provision 29 reports are right around the corner. To help organizations navigate this shift from a theoretical governance exercise to a year-round operational mandate. To help organizations navigate it, LogicGate recently hosted a live, focused webinar in partnership with PwC.

The session brought together Adam Wisniski, Vice President of Channel and Strategic Alliances at LogicGate, Stuart Rimmer, a Director in PwC’s consulting practice who leads risk and regulatory change for UK listed and global multinationals, and Ryan Sadler, Implementation Manager at LogicGate. 

Together, they unpacked the latest regulatory expectations and showcased the market’s first purpose-built solution to solve material control reporting.

What Does Provision 29 and Principle O Require of Boards?

Under Provision 29 of the revised UK Corporate Governance Code, must declare in their annual report whether material controls were effective at the balance sheet date. Boards must also explain the basis for that conclusion in the annual report and disclose any ineffective controls along with remediation plans. Provision 29 applies to financial years beginning on or after 1 January 2026.

This requirement is underpinned by Principle O, which shifts the board’s obligation from simply establishing a framework to actively establishing and maintaining it. The real compliance challenge is continuous, meaning a point-in-time declaration requires a year-round operating model.

What Are Material Controls?

During the live session, Stuart Rimmer clarified exactly what is at stake when scoping these efforts: 

“What are material controls? They’re the biggest controls that relate to the biggest risks that a business face, without which the business would be insolvent, illiquid, or damaged in terms of reputational harm.”

In short, material controls are the controls that mitigate a company’s biggest risks: those whose failure could cause insolvency, illiquidity, or reputational harm.

What Does Good Provision 29 Reporting Look Like?

Historically, governance and controls compliance has relied heavily on manual processes and disconnected spreadsheets. If teams are scrambling to assemble evidence from disparate tickets, emails, and logs during year-end reporting cycles, it is already too late to credibly stand behind a Provision 29 declaration.

“Disconnected controls, risk, and assurance processes are a nightmare when you have different frameworks that you’re trying to bring together,” noted Wisnieski.

To achieve what ‘good’ looks like, organizations need:

  • Continuous Monitoring: Dashboards that surface real-time control status and threshold alerts that trigger evaluations when risk levels change.
  • A Defensible Evidence Base: A structured testing program with timestamped, defensible results rather than relying solely on self-assessments.
  • Planned Remediation: Documented corrective action plans and remediation timelines maintained continuously in the platform.

This operational shift also requires a cultural one. A recent PwC roundtable highlighted that control failures must become acceptable to report, provided they are promptly acted upon.

How Do LogicGate and PwC Support Provision 29 Reporting?

To bridge the gap between regulatory requirements and execution, LogicGate and PwC have partnered to create a Provision 29 compliance application on LogicGate’a AI GRC Platform. 

“It’s exciting to me because we, as a leading technology platform, have now partnered up with one of the most leading advisory firms in the world to leverage their expertise,” Wisnieski shared. “It’s really that true connectivity of where governance expertise meets our purpose-built technology.”

Rimmer echoed the value of this collaboration for the market: “We’re delighted from PwC to be working alongside LogicGate on this particular project, but also more broadly partnering together into the market as one of the leading tech providers, and us as a leading brand and voice into this space as well.”

What Are the Core Capabilities of the Provision 29 Application?

The application unifies data in one connected system so your team can skip the year-end fire drill. It optionally connects to your broader GRC program, including Enterprise Risk Management and Internal Audit Management. Your declaration is then backed by the same data used across the business.

Key capabilities include:

  • Demonstrating Control Effectiveness: Trace principal risks to the material controls that mitigate them, with tags by domain (financial, operational, reporting, and compliance) to ensure ownership is clear.
  • Improving Board Oversight: Provide your board with a single dashboard showing control effectiveness by domain, open remediation, and testing coverage across all three lines of defense.
  • Simplifying Declarations: Pull the latest control results into your declaration in one click, with repeat exceptions automatically flagged and every corrective action plan thoroughly documented.
  • Accelerating Issue Response: Prevent board-level surprises by automatically generating assessments on a set cadence and surfacing overdue remediation in real time.

Inside the Demo: Purpose-Built Control & Assurance Workflows

During the live demo, Ryan Sadler walked attendees through how the application unifies risk taxonomy, assurance plans, and board reporting into a single workspace. Sadler emphasized that organizations don’t need to throw away their existing risk registers to adopt the solution:

“This application was meant to be standalone, but also we wanted to build something that had the ability to sit on top of existing enterprise and controls applications, so you could pull in existing risks and existing controls, flag them as material, so you didn’t have to rework that data.”

Watch the full demo:

What are the Key Takeaways from the Demo?

  • Unified workspace: The application combines risk taxonomy, assurance plans, and board reporting in one place.
  • Built on existing data: Teams can pull in existing risks and controls and flag them as material without reworking data.
  • Standalone or connected: The application works on its own or sits on top of existing enterprise and controls applications.
  • Board-ready reporting: A single dashboard shows control effectiveness by domain, open remediation, and testing coverage.

How Can Teams Get Ready for Provision 29 Reporting?

“Our intent here, and our hope, is to help businesses move from that ad hoc in-moment reporting, so that’s through the year monitoring, testing, and attestation capability, and show that with an evidence base,” Rimmer explained, ensuring boards can confidently explain their control environment to executives, regulators, and investors.

For teams looking to accelerate their readiness, PwC and LogicGate are offering tailored 60-minute workshops to review governance structures and regulatory exposure. The partnership will also host community working sessions to collaborate on leading practices for board reporting, scoping, and deficiency tracking.

To discuss Provision 29 readiness or see the application in action, request a demo today.


Frequently Asked Questions

What Is Provision 29 of the UK Corporate Governance Code?

Provision 29 requires boards to declare whether material controls were effective at the balance sheet date. Boards must explain the basis for that conclusion and disclose any ineffective controls with remediation plans. Principle O underpins it, shifting the board’s obligation from establishing a framework to establishing and maintaining one.

When Does Provision 29 Take Effect?

Provision 29 applies to financial years beginning on or after 1 January 2026. Companies with December 2026 year-ends will be among the first to report.

What Are Material Controls?

Material controls are the biggest controls relating to a business’s biggest risks. Without them, the business could become insolvent, illiquid, or suffer reputational harm, according to PwC’s Stuart Rimmer.

What Evidence Do Boards Need to Support a Provision 29 Declaration?

Boards need a defensible evidence base: a structured testing program with timestamped results, not only self-assessments. They also need documented corrective action plans and remediation timelines maintained throughout the year. Continuous monitoring, including real-time control status and threshold alerts, keeps that evidence current.

Can Teams Use Existing Risk Registers for Provision 29 Reporting?

Yes. The application can sit on top of existing enterprise risk management and controls compliance applications. Teams can pull in existing risks and controls, flag them as material, and avoid reworking data.

AUTHORED BY

Related Posts