---
title: "Why Provision 29 is raising the bar for board accountability"
url: https://daily.dev/posts/why-provision-29-is-raising-the-bar-for-board-accountability-lsaujlisj
source_url: https://www.itsecurityguru.org/2026/08/26/why-provision-29-is-raising-the-bar-for-board-accountability
type: article
source: "IT Security Guru"
published: 2026-08-26T11:35:41.187Z
updated: 2026-08-26T11:36:03.655Z
tags: ["compliance"]
reading_time: 5
upvotes: 0
comments: 0
language: en
---

> ## Documentation Index
> Fetch the complete documentation index at: https://daily.dev/llms.txt
> Use this file to discover all available pages before exploring further.

# Why Provision 29 is raising the bar for board accountability

**[IT Security Guru](https://daily.dev/sources/itsecurityguru)** · 5 min read · 0 upvotes · 0 comments

## Summary

An opinion piece by the CEO of Quod Orbis explains how Provision 29 of the 2024 UK Corporate Governance Code raises expectations for boards to demonstrate that material internal controls are working effectively, not just compliant on paper. It argues that annual, point-in-time reporting is insufficient in complex digital environments spanning cloud, legacy infrastructure and third-party suppliers, and advocates for continuous, real-time assurance and shared reporting architecture across risk, audit and compliance teams so boards can report with confidence and improve cyber resilience.

## Full article

daily.dev links to this article rather than hosting it. Read it at the original source: <https://www.itsecurityguru.org/2026/08/26/why-provision-29-is-raising-the-bar-for-board-accountability>

## Questions this post answers

### What does Provision 29 of the UK Corporate Governance Code require from boards?

It requires boards to demonstrate that their material internal controls are working effectively, not merely that they exist on paper. Under the 2024 UK Corporate Governance Code, boards must provide consistent evidence that is timely, accurate, and reliable across finance, compliance, and reporting, validated with real-time data rather than periodic, point-in-time reviews.

_Teams tracking governance requirements like Provision 29 can follow related compliance coverage on daily.dev._

### Why is annual testing of security controls considered insufficient under Provision 29?

Annual testing only captures a snapshot at one point in time, similar to a car's annual MOT reporting only on problems present that day. Since businesses continuously evolve their cloud platforms, infrastructure, and third-party integrations, controls deemed effective months earlier may no longer be, leaving decisions based on outdated information.

_daily.dev helps security and compliance engineers keep up with shifting governance and risk practices._

## Similar posts on daily.dev

- [Building trust with the board through evidence-based proof](https://daily.dev/posts/building-trust-with-the-board-through-evidence-based-proof-uc9sksl7t) · CSO Online · 0 upvotes · 0 comments
- [Communicating Cyber Risk to the Board: Executive Reporting Best Practices](https://daily.dev/posts/communicating-cyber-risk-to-the-board-executive-reporting-best-practices-opnancdxu) · Security Boulevard · 0 upvotes · 0 comments
- [Boards don’t need cyber metrics — they need risk signals](https://daily.dev/posts/boards-don-t-need-cyber-metrics-they-need-risk-signals-635nafzbw) · CSO Online · 0 upvotes · 0 comments
- [NIS2 Expects CEOs and Governing Bodies to Be Liable for Resilience From AI-Powered Adversaries, Not Just the Next Audit](https://daily.dev/posts/nis2-expects-ceos-and-governing-bodies-to-be-liable-for-resilience-from-ai-powered-adversaries-not--lwvud2e7w) · Security Boulevard · 0 upvotes · 0 comments

---

Tags: [#compliance](https://daily.dev/tags/compliance)

[View this post on daily.dev](https://daily.dev/posts/why-provision-29-is-raising-the-bar-for-board-accountability-lsaujlisj)
