The UK Corporate Governance Code and Surveillance Risk

From financial years beginning on or after 1 January 2026, boards of premium-listed companies are expected to declare the effectiveness of their material internal controls under Provision 29 of the 2024 Code. The confidentiality of the boardroom itself is a control most companies have never tested.

Framework: United KingdomLast reviewed: 2026-09-03

What changed in the 2024 Code

The Financial Reporting Council's 2024 revision of the UK Corporate Governance Code strengthened board accountability for internal control. Provision 29 asks boards to monitor the company's risk management and internal control framework and — for financial years beginning on or after 1 January 2026 — to make a declaration in the annual report on the effectiveness of material controls as at the balance sheet date.

The Code applies on a comply-or-explain basis to companies with a UK premium listing, but its expectations increasingly shape governance practice across large private companies and regulated firms. The declaration forces a concrete question: which controls are material, and what evidence supports the claim that they operated effectively?

Why boardroom confidentiality is a control, not a given

Boards routinely discuss price-sensitive information: results before announcement, M&A intent, litigation strategy, executive changes. The control environment around that information is usually framed in terms of documents and systems — insider lists, information barriers, access rights. The room where the information is spoken aloud rarely appears in the framework at all.

Commercially available covert recording and transmitting devices make interception of spoken information a low-cost attack, and renovation work, third-party facilities staff, and hybrid-meeting hardware all widen the route in. If leakage of board-level discussion would be material to the company — and for a listed company it plainly can be — then the integrity of the spaces where those discussions happen is a material control candidate.

What a board should be able to say

A board relying on its declaration should be able to answer three questions. Has technical surveillance risk been assessed and recorded, with an owner, in the risk framework? Is there a proportionate, documented inspection programme for the spaces where material information is discussed? And when was that control last tested — by whom, with what method, and with what findings?

The answers do not need to be dramatic. A short, dated record of a professional technical surveillance countermeasures inspection of board and executive spaces, on a defined cadence and before sensitive meetings, is exactly the kind of evidence the effectiveness declaration is designed to rest on.

Building the control without overbuilding it

Proportionality matters. For most companies this is a narrow control: a defined list of sensitive spaces, a sweep cadence tied to the board calendar, trigger events for fit-outs and suspected leaks, and a standing line in the audit or risk committee pack confirming the control operated. Our guidance on the TSCM risk register entry and on board reporting sets out wording you can adapt directly.

Primary sources

This guidance is general information, not legal advice. Regulatory obligations depend on your entity classification, jurisdiction and facts — confirm specifics with your counsel or compliance function.

Scope an assessment

A short conversation establishes scope and a fixed price. Assessments run across the UK, Europe and the US.

Speak to a specialist