Book a Demo
Skip to contentTurn your Provision 29 declaration into an ongoing, evidence-backed process, not a year-end scramble.




Quod Orbis is trusted by companies worldwide...


Provision 29 demands proof, not paperwork. And with AI accelerating cyber risk, the question isn't whether you need continuous monitoring — it's whether you can afford not to.
Most lack the year-round evidence to back that up
These cannot produce the continuous, auditable proof the FRC requires
A qualified declaration is reputational risk
Managing these alongside Provision 29 across separate tools creates duplication, gaps and unnecessary cost
1000
More devices unearthed




Sign off the effectiveness declaration with confidence. QO gives you live, year-round evidence to genuinely own your Provision 29 statement — not just countersign it.
Challenge management with live data. QO gives your committee a continuous view of control performance, weaknesses and remediation — not a point-in-time pack.
Move from annual testing cycles to continuous assurance. Automated monitoring covers 100% of controls so your team focuses effort where it matters.
Map every material control to its principal risk. Already subject to DORA, NIS2 or NIST? QO maps controls once and generates evidence across all frameworks simultaneously — so Provision 29 doesn’t duplicate work you’re already doing.
Sign off the effectiveness declaration with confidence. QO gives you live, year-round evidence to genuinely own your Provision 29 statement — not just countersign it. today – and scales with you as you grow.
Challenge management
with live data. QO gives your committee a continuous view of control performance, weaknesses and remediation — not a point-in-time pack.ne single source of truth.
Move from annual testing cycles to continuous assurance. Automated monitoring covers 100% of controls so your team focuses effort where it matters.
Map every material control to its principal risk. Already subject to DORA, NIS2 or NIST? QO maps controls once and generates evidence across all frameworks simultaneously — so Provision 29 doesn’t duplicate work you’re already doing.
Five Eyes agencies: a warning boards cannot ignore
IIn June 2026, the Five Eyes cybersecurity agencies — US, UK, Canada, Australia, New Zealand — issued a rare joint statement: cyber risk is now a board-level responsibility, not a technical one. Having controls isn't enough; boards must know they'll hold up during a real incident. The statement landed just as Provision 29 came into force. QO gives boards exactly what the FRC and Five Eyes both demand: live, evidence-backed assurance that controls are working — not just documented.
AI governance built for every risk type
Every organisation faces a different combination of AI risks. Our consulting approach is tailored to your specific risk environment, whether that is Shadow AI proliferating across your business, agentic AI acting without oversight or regulatory obligations that are tightening faster than your controls.
01 — From Annual Snapshots to Continuous Evidence
Provision 29 requires: The FRC is explicit — the framework must not be seen as a periodic compliance exercise. Monitoring must be ongoing and integral to day-to-day governance. QO delivers: Continuous monitoring replaces the annual snapshot with year-round evidence generation — producing the audit trail boards need to support their formal declaration.
02 — Boards Cannot Sign Off on What They Cannot See
Provision 29 requires: The declaration sits with the board. Boards and audit committees must own the conclusion, understand the basis on which it is reached, and be able to explain how they challenged it. QO delivers: Real-time dashboards give boards the live visibility they need to genuinely own — and defend — their declaration at the balance sheet date.
03 — Fragmented Systems Cannot Produce a Defensible Declaration
Provision 29 requires: Boards must produce an outcome statement backed by evidence that stands up to investor scrutiny — covering financial, operational, reporting and compliance controls. QO delivers: QO centralises controls, testing and assurance into a single auditable source of truth, replacing fragmented spreadsheets and siloed systems.
04 — Sampling Is No Longer Sufficient
Provision 29 requires: Scoping of material controls must be defensible — not just internally but if challenged by regulators or investors. Companies must articulate which processes, locations and controls are in scope and why. QO delivers: 100% data coverage rather than periodic sampling, eliminating gaps in the evidence trail that could undermine the board’s declaration.
05 — Weaknesses Must Be Disclosed and Remediated
Provision 29 requires: If a material control has not worked as it should, the board must explain why and what is being done to correct it — publicly, in the annual report. QO delivers: Real-time alerting catches failures as they happen, enables faster remediation, and creates the documented audit trail boards need to disclose and evidence corrective action.
Already subject to DORA, NIS2? QO covers all of them.
DORA, NIS2 and Provision 29 overlap significantly. QO maps your controls once and generates evidence across all three simultaneously — one platform, one evidence trail.
“We've had some light bulb moments in the platform where particularly around vulnerabilities, the CCM platform has highlighted things we simply didn't know and the trending information will start to demonstrate areas we need to keep an eye on."
Chris Taylor, Cyber Security Lead, Martin Baker
"As the business has seen the power of Continuous Controls Monitoring, and seen how Quod Orbis literally can connect to almost any control, we've implemented Continuous Controls Monitoring in areas that weren't originally envisaged."
Matthew Browsing, Head of cyber Oversight, Direct Line
"The real difference is in the quality of the security assurance and compliance information: we're getting dramatically-better, higher-quality information–and we're getting it continuously."
David Wigley, CISO, Daiwa
Your questions, answered
Provision 29 requires boards of UK premium-listed companies to make a formal annual declaration that their material internal controls are effective, covering financial, operational, reporting and compliance controls. It applies to financial years beginning on or after 1 January 2026.
All companies with a premium listing on the London Stock Exchange on a comply-or-explain basis. Many large private and regulated organisations are also voluntarily aligning with its requirements as a governance best practice benchmark.
Boards must confirm whether material controls were effective at the balance sheet date, describe how they monitored the framework across the year, disclose any controls that were not effective, and explain what remediation action is being taken.
CCM replaces periodic manual testing with continuous automated monitoring. QO gives boards a live, evidence-backed view of control effectiveness throughout the year, centralises this evidence, and generates the board-ready reporting that underpins a defensible Provision 29 declaration.
In June 2026, the Five Eyes cybersecurity agencies issued a joint statement warning that AI is transforming cyber risk in months not years. Their core message: it is not enough to have controls. Boards and executives must be confident those controls will perform during a real incident — exactly what Provision 29 now requires boards to formally attest to.
Often called UK SOX, Provision 29 introduces a board-level declaration similar in spirit to the Sarbanes-Oxley Act. However it does not require external auditor attestation, and its scope extends beyond financial reporting to cover operational, compliance and reporting controls.
No. QO is built to map controls across multiple regulatory frameworks simultaneously. Organisations already subject to DORA (digital operational resilience for financial services), NIS2 (cybersecurity for critical infrastructure) or NIST (the global cybersecurity framework) will find significant overlap with Provision 29 — particularly around operational and compliance controls. QO lets you map a control once and generate evidence that satisfies all applicable frameworks, eliminating duplication and reducing compliance cost across your entire regulatory stack.
To find out more about cyber security and Continuous Controls Monitoring, please complete the form below with a short message and we’ll get right back to you. Alternatively, you can book a meeting directly.
Address:
5th Floor,
72 King William Street,
London,
EC4N 7HR
Email:
[email protected]
Please register your contact details with us to receive links to insightful blog articles as soon as they are published.
Address:
2nd & 3rd Floor,
2 Burgon Street,
City Of London,
London,
EC4V 5DR
Email:
[email protected]
Please register your contact details with us to receive links to insightful blog articles as soon as they are published.