ITSecurityGuru

Why Provision 29 is raising the bar for board accountability


By Tim Williams, CEO at Quod Orbis

Under the 2024 UK Corporate Governance Code, the revised Provision 29 requires boards to demonstrate that their material internal controls are working effectively. Every business has hundreds of controls, however material controls have the potential to create an immense operational, security or regulatory impact. The message behind this latest update is that it’s no longer enough to be compliant on paper, and boards – now more than ever – must provide consistent evidence that is timely, accurate, reliable and capable of surfacing risks.

In the past, it was easier for businesses to claim they had good internal controls, but Provision 29 has changed the game. It calls for businesses to maintain assurance that their controls work across finance, compliance and reporting, and be able to validate their claims with real-time, accurate data.

Regulations usually demand annual, point-in-time, reporting exercises, however, the Financial Reporting Council is explicit that this new framework should not be seen as a periodic compliance exercise, but instead as an integral part of the company’s day-to-day business and governance processes.

Security teams face a new era of accountability 

Provision 29 places greater responsibility on IT, security teams and the board when it comes to reporting the effectiveness of their internal controls. Teams have become accustomed to conducting infrequent manual data collections that provide a small snapshot of their entire system that becomes out of date the moment you have it. But businesses are now expected to have visibility over their controls throughout the year, not just before a review, and having accurate and timely data gives teams greater confidence that the decisions they are making today reflect the current risk exposure of their business.

Reporting and gathering data in silos is a hard task, especially when boards have to manually reconcile five conflicting reports, indicating varying levels of risk. Shared reporting architecture resolves this, providing greater collaboration between risk, internal audit and compliance teams, which is invaluable for verifying whether businesses have truly achieved organisational resilience., Provision 29 need not be a burden, but instead an opportunity to gain better visibility of how their controls are performing and improve their overall security posture and cyber resilience. While most boards comply, the most resilient are explaining their findings, and disclosing their reports properly.

Annual testing is no longer enough 

Businesses are reassessing their existing risk management strategies to make sure they are robust enough to provide the evidence boards need to report with confidence. Annual reporting cannot keep up with businesses operating in complex digital ecosystems, made up of cloud platforms, traditional infrastructure and third-party suppliers.

When you take a car in for its annual MOT, the mechanic only reports on the problems that exist there and then. What an MOT can’t do is warn of potential faults that may arise as soon as you leave the garage. The same logic applies to annual testing of security controls. What was deemed effective a few months ago may not be now, especially as many businesses keep evolving their systems and exposing them to new risks.

Businesses need continuous visibility to understand how their control environment changes over time. By relying on annual reports, businesses risk making important decisions based on a snapshot of information that becomes outdated the second it’s extracted. They thereby move forwards with a false sense of security over their entire system.

Getting ahead of the risk

Most businesses know what internal controls they have, but lack the visibility into whether they are operating effectively. Closing that gap means pinpointing where their internal controls are situated across their estate and what potential risks they could be exposed to.

Continuous assurance lets businesses monitor their internal controls in real-time, allowing them to identify degraded systems, know how long the exposure existed and explain what was done to resolve it. When security, IT, risk and compliance teams have consistent visibility over their internal controls, they can prioritise their efforts on strengthening resilience and preparing for risks before they arise. Imagine knowing that your car’s headlight is going to go out before it does?

This continuous visibility also helps teams communicate with the board. When it comes to reporting, Provision 29 can give boards greater confidence when they sign the declaration as it encourages a more evidence-led view of whether controls are operating as they should. Continuous monitoring reinforces this confidence by providing teams and boards with timely, accurate data rather than manual and sporadic assessments. Think of it as a navigation system rather than a handbrake. A handbrake only stops you from rolling backwards while a navigation system shows you the road ahead, warns you of the hazards you cannot yet see and keeps you moving towards where you want to go. The guidance provided through Provision 29 is designed to give businesses the confidence to move forward and know exactly where they stand.



Source link