Book a Demo

Provision 29 on Autopilot.
Protect what
matters.

Turn your Provision 29 declaration into an ongoing, evidence-backed process, not a year-end scramble.

Quod Orbis is trusted by companies worldwide...

You need to feel confident that your controls will perform under pressure
as Provision 29 demands proof, not paperwork.

Provision 29 demands proof, not paperwork. And with AI accelerating cyber risk, the question isn't whether you need continuous monitoring — it's whether you can afford not to.

Boards must now formally declare controls are effective

Most lack the year-round evidence to back that up

Annual testing cycles and fragmented spreadsheets

These cannot produce the continuous, auditable proof the FRC requires

Compliance, regulatory and investor pressure is intensifying

A qualified declaration is reputational risk

Most organisations are already subject to DORA, NIS2

Managing these alongside Provision 29 across separate tools creates duplication, gaps and unnecessary cost

Powerful Continuous Controls Monitoring
gives you the resilience you deserve through...
Real-time visibility of all material controls
Year-round evidence for the board declaration
Continuous compliance across financial, operational, reporting and compliance domains
Automated evidence collection — no manual spreadsheets
Board-ready dashboards and one-click reporting
Instant alerting when controls fail — with remediation tracking
Audit readiness at any point in the year
Five Eyes-aligned continuous assurance that controls perform under pressure
An award-winning solution
Continuous Controls Monitoring
built for every stakeholder

Learn more Continuous Controls Monitoring

Five Eyes agencies: a warning boards cannot ignore

IIn June 2026, the Five Eyes cybersecurity agencies — US, UK, Canada, Australia, New Zealand — issued a rare joint statement: cyber risk is now a board-level responsibility, not a technical one. Having controls isn't enough; boards must know they'll hold up during a real incident. The statement landed just as Provision 29 came into force. QO gives boards exactly what the FRC and Five Eyes both demand: live, evidence-backed assurance that controls are working — not just documented.

AI governance built for every risk type

Every organisation faces a different combination of AI risks. Our consulting approach is tailored to your specific risk environment, whether that is Shadow AI proliferating across your business, agentic AI acting without oversight or regulatory obligations that are tightening faster than your controls.

01 — From Annual Snapshots to Continuous Evidence

Provision 29 requires: The FRC is explicit — the framework must not be seen as a periodic compliance exercise. Monitoring must be ongoing and integral to day-to-day governance. QO delivers: Continuous monitoring replaces the annual snapshot with year-round evidence generation — producing the audit trail boards need to support their formal declaration.

02 — Boards Cannot Sign Off on What They Cannot See

Provision 29 requires: The declaration sits with the board. Boards and audit committees must own the conclusion, understand the basis on which it is reached, and be able to explain how they challenged it. QO delivers: Real-time dashboards give boards the live visibility they need to genuinely own — and defend — their declaration at the balance sheet date.

03 — Fragmented Systems Cannot Produce a Defensible Declaration

Provision 29 requires: Boards must produce an outcome statement backed by evidence that stands up to investor scrutiny — covering financial, operational, reporting and compliance controls. QO delivers: QO centralises controls, testing and assurance into a single auditable source of truth, replacing fragmented spreadsheets and siloed systems.

04 — Sampling Is No Longer Sufficient

Provision 29 requires: Scoping of material controls must be defensible — not just internally but if challenged by regulators or investors. Companies must articulate which processes, locations and controls are in scope and why. QO delivers: 100% data coverage rather than periodic sampling, eliminating gaps in the evidence trail that could undermine the board’s declaration.

05 — Weaknesses Must Be Disclosed and Remediated

Provision 29 requires: If a material control has not worked as it should, the board must explain why and what is being done to correct it — publicly, in the annual report. QO delivers: Real-time alerting catches failures as they happen, enables faster remediation, and creates the documented audit trail boards need to disclose and evidence corrective action.

Already subject to DORA, NIS2? QO covers all of them.

DORA, NIS2 and Provision 29 overlap significantly. QO maps your controls once and generates evidence across all three simultaneously — one platform, one evidence trail.

Hear from our customers

“We've had some light bulb moments in the platform where particularly around vulnerabilities, the CCM platform has highlighted things we simply didn't know and the trending information will start to demonstrate areas we need to keep an eye on."

Chris Taylor, Cyber Security Lead, Martin Baker

"As the business has seen the power of Continuous Controls Monitoring, and seen how Quod Orbis literally can connect to almost any control, we've implemented Continuous Controls Monitoring in areas that weren't originally envisaged."

Matthew Browsing, Head of cyber Oversight, Direct Line

"The real difference is in the quality of the security assurance and compliance information: we're getting dramatically-better, higher-quality information–and we're getting it continuously."

David Wigley, CISO, Daiwa

Why not explore
our buyers guide?

Find out more from our experts

Redefining Continuous Controls Monitoring with Business Impact Intelligence

The Cost of Blind Spots: Why Visibility Is the Missing Link in Boards Cyber Resilience

5 Myths About Continuous Controls Monitoring

Ready? Let's talk.
Book a demo today.

Your questions, answered

Provision 29 requires boards of UK premium-listed companies to make a formal annual declaration that their material internal controls are effective, covering financial, operational, reporting and compliance controls. It applies to financial years beginning on or after 1 January 2026.

All companies with a premium listing on the London Stock Exchange on a comply-or-explain basis. Many large private and regulated organisations are also voluntarily aligning with its requirements as a governance best practice benchmark.

Boards must confirm whether material controls were effective at the balance sheet date, describe how they monitored the framework across the year, disclose any controls that were not effective, and explain what remediation action is being taken.

CCM replaces periodic manual testing with continuous automated monitoring. QO gives boards a live, evidence-backed view of control effectiveness throughout the year, centralises this evidence, and generates the board-ready reporting that underpins a defensible Provision 29 declaration.

In June 2026, the Five Eyes cybersecurity agencies issued a joint statement warning that AI is transforming cyber risk in months not years. Their core message: it is not enough to have controls. Boards and executives must be confident those controls will perform during a real incident — exactly what Provision 29 now requires boards to formally attest to.

Often called UK SOX, Provision 29 introduces a board-level declaration similar in spirit to the Sarbanes-Oxley Act. However it does not require external auditor attestation, and its scope extends beyond financial reporting to cover operational, compliance and reporting controls.

No. QO is built to map controls across multiple regulatory frameworks simultaneously. Organisations already subject to DORA (digital operational resilience for financial services), NIS2 (cybersecurity for critical infrastructure) or NIST (the global cybersecurity framework) will find significant overlap with Provision 29 — particularly around operational and compliance controls. QO lets you map a control once and generate evidence that satisfies all applicable frameworks, eliminating duplication and reducing compliance cost across your entire regulatory stack.

Contact Us

To find out more about cyber security and Continuous Controls Monitoring, please complete the form below with a short message and we’ll get right back to you. Alternatively, you can book a meeting directly.

Address:
5th Floor,
72 King William Street,
London,
EC4N 7HR

 
Take a tour of our platform

Register for updates

Please register your contact details with us to receive links to insightful blog articles as soon as they are published.

Address:
2nd & 3rd Floor,
2 Burgon Street,
City Of London,
London,
EC4V 5DR

 

Thank you.

Please register your contact details with us to receive links to insightful blog articles as soon as they are published.