Mastering Risk Management for Organisational Resilience (Part 1)
The UK Corporate Governance Code has undergone its most significant update in years, and if you're responsible for governance in your organisation, 2025 is the year to get serious about preparation and implementation. 
The Financial Reporting Council (FRC) published the revised Code in January 2024, with changes taking effect from 2025 and 2026. While the update takes a "limited but targeted" approach, don't let that fool you – the introduction of the material controls requirement represents a fundamental shift in how boards need to think about risk management and internal controls. 
 
Whether you're a board director, company secretary, or compliance professional, understanding these changes and their implications is crucial for your organisation's governance framework. 
 
So, let me walk you through what's changed, why it matters, and most importantly, how to prepare effectively. 

What's Changed? The Key Updates at a Glance 

The 2024 revision represents what the FRC calls a "limited but targeted" update, focusing on areas where strengthening was most needed. While there are several changes worth noting, one stands head and shoulders above the rest in terms of impact. 
 
The smaller changes include updates to diversity reporting (removing specific group references to allow for broader diversity policies), enhanced governance reporting requirements, and new provisions around malus and clawback in executive remuneration. These are important refinements, but they're evolutionary rather than revolutionary. 
 
The real headline act is the introduction of Provision 29 – the new material controls declaration requirement. This isn't just another compliance box to tick. It represents a fundamental shift towards comprehensive risk management and board accountability. 
 
Most changes take effect for financial years beginning on or after 1 January 2025. However, recognising the significant preparation required, the FRC has given organisations an extra year for the material controls provisions, which apply to financial years beginning on or after 1 January 2026. Smart organisations are using this extra lead time wisely. 

The New Material Controls Requirement: Provision 29 Explained 

Let’s now work through what Provision 29 actually requires, because this is where many organisations will need to significantly enhance their current practices. 
 
What You'll Need to Do 
The new provision requires boards to monitor their company's risk management and internal control framework and carry out an annual review of its effectiveness. But here's the crucial difference from current practice – this must cover all material controls, not just financial ones. 
 
The four distinct categories are as follows: 
 
Financial controls (which most organisations already have covered) 
Operational controls 
Reporting controls (including non-financial reporting) 
Compliance controls 
 
Thus, moving forward, your annual report will need to include three specific elements: 
 
A description of how the board has monitored and reviewed the effectiveness of the framework – this means demonstrating active board oversight, not just delegation to management. 
A declaration of effectiveness of material controls as at the balance sheet date – a clear, public statement of whether your controls are working. 
Transparency around failures – if material controls haven't operated effectively, you'll need to describe what went wrong, what you're doing to fix it, and how you're addressing any previously reported issues. 
 
What Makes This Different 
In my experience working with boards across various sectors, this represents a significant evolution in governance thinking. We're moving from a narrow focus on financial controls to a comprehensive, risk-based approach that encompasses the full spectrum of organisational risks. 
 
The board accountability aspect is particularly significant. This isn't something that can be buried in the audit committee's work – it requires active board engagement and public declaration. The transparency requirement around control failures might feel uncomfortable, but I think it's actually a positive step towards building stakeholder trust through honest reporting. 
 
Importantly, the FRC has deliberately avoided a prescriptive, Sarbanes-Oxley-style approach. Instead, they're relying on board judgement and the principle of proportionality. This means the framework can be tailored to your organisation's size, complexity, and risk profile. 

Who Does the Updated Corporate Governance Code Affect? 

The Code applies to all companies listed in the commercial companies category or closed-ended investment funds category, regardless of where they're incorporated. If you're listed on the London Stock Exchange, these changes apply to you. 
 
Dual-listed entities have an interesting position. If you're already complying with requirements like US Sarbanes-Oxley, you have a head start on financial controls. However, the UK Code's broader scope means you'll still need to extend your framework to cover operational, compliance, and non-financial reporting controls. 
 
It’s worth mentioning at this point that, in my view, even if you're not required to comply with the Code, these principles represent best practice. I've seen non-listed companies, charities, and smaller organisations voluntarily adopt similar frameworks because the benefits extend far beyond compliance. 
 
The Code is built on proportionality, which means smaller organisations can tailor their approach to their size and complexity. You don't need to implement a FTSE 100-level framework if you're a smaller listed company, but you do need to demonstrate that you've thought systematically about your material risks and controls. 

Why This Matters: The Business Case for Strong Governance Controls 

I must emphasise that treating this simply as a compliance requirement fails to capture the real strategic benefits available to organisations. The business case for strengthening internal controls extends far beyond meeting regulatory requirements. 
 
The Real Benefits 
Enhanced credibility is perhaps the most immediate benefit. Robust controls improve the quality and reliability of both financial and non-financial reporting, which directly impacts stakeholder confidence. Given how much trust in corporate reporting has been tested recently, this is invaluable. 
 
Fraud prevention is another tangible benefit. While we can't attribute fraud reduction solely to better controls, there's clear evidence that comprehensive control frameworks help organisations identify fraud risks and implement appropriate safeguards. This isn't just about financial fraud, either. Operational and compliance controls can prevent a wide range of misconduct. 
 
Operational efficiency often surprises organisations. When done well, control enhancement leads to streamlined processes, elimination of redundant activities, and better use of technology. I've worked with organisations that have realised significant cost savings through control rationalisation. 
 
Better decision-making flows from having more reliable, real-time information. When your control framework is properly designed, it generates the management information you need to run the business effectively, not just report on it after the fact. 
 
Cultural transformation is perhaps the most profound long-term benefit. A controls-focused culture, led from the top, changes how people think about risk and accountability throughout the organisation. This has implications well beyond traditional governance areas – it affects how you approach ESG reporting, cybersecurity, and operational resilience. 
 
Learning from Experience 
The evidence supporting these benefits isn't just theoretical. The US experience with Sarbanes-Oxley, despite its criticisms, demonstrates tangible improvements in reporting quality and fraud detection. The UK approach, being more flexible and risk-based, has the potential to deliver similar benefits with less of a bureaucratic burden. 
 
The recommendations from the Brydon and Kingman reviews, which influenced these Code changes, were based on an extensive analysis of governance failures and their underlying causes. Strengthening internal controls was identified as fundamental to restoring trust in corporate reporting. 

Don't Wait Until 2026 to Start Preparing for Changes to the UK Corporate Governance Code 

While the material controls provisions don't take effect until 2026, smart organisations are starting their preparation now. Remember, the lead time is an opportunity to strengthen your governance framework in ways that deliver real business benefits, rather than merely fulfilling a compliance exercise
 
Whether you need help with initial gap analysis, framework design, or ongoing implementation support, I can provide the expertise and practical assistance to ensure you're ready. 
 
So, if you want to lean on some external expertise, feel free to contact me to discuss how I can support your organisation's specific needs. I’m available by phone on 07576 829 591 or via email at amy@corporateassist.co.uk to arrange a consultation regarding your governance and compliance requirements. 
 
Every organisation's governance journey is different, and I look forward to helping you find the right path forward. 
Share this post: