UK SOX compliance: How to prove your P2P controls actually work

UK SOX compliance: How to prove your P2P controls actually work

The UK Corporate Governance Code requires proof of effective financial controls, and sign off from your board. Can you demonstrate strong controls?

Are your P2P controls board-ready?

Picture the scene: December 2026. For UK SOx compliance, your board must sign a declaration that your financial controls are documented and demonstrably effective. You are longer able to simply declare you have a process for checking duplicates. Now, you need definitive proof.

That’s the stipulation coming from Provision 29 of the UK Corporate Governance Code (informally known as UK SOx), effective as of January 2026 for premium-listed companies.

Unfortunately, this legislation appears to have flown under the radar. Grant Thornton research found only 2% of FTSE 350 companies have disclosed all recommended information for the new governance requirements, according to ICAEW.

So how can you prove that your finance risk controls truly work?

About the UK Corporate Governance Code (2024), Section 29

Otherwise known as UK SOx (for the similarity to the US’s Sarbanes Oxley legislation), the UK Corporate Governance Code sets that standard for effective board leadership, accountability and stakeholder engagement. The 2024 code focused on strengthening risk management and internal controls.

It is applicable to premium-listed companies in the ‘commercial companies’ category or the ‘closed-ended investment funds’ category in the London Stock Exchange. 

The code requires boards to monitor their risk management and internal control framework throughout the year, and to review its effectiveness annually. It must cover all material controls, including financial, operational, reporting, and compliance activities.

The 2018 UK Corporate Governance Code already required that boards monitor, review and report on financial, operational and controls. The 2024 version, however, asks that the board make a formal declaration of control effectiveness, and so they must clearly set out how the Board has completed this work.

The report should also communicate any ineffective material controls, outline actions to address them, and provide a progress update on weaknesses identified in the previous report.

Why ‘we have controls’ is no longer enough

The critical word for this new provision is effectiveness.

Most organisations have solid P2P risk controls on paper. They show segregation of duties, approval hierarchies, duplicate invoice checks. They have already documented their controls. Now, the onus is on organisations to prove the process is working, share how it was monitored and reveal how effective it is.

In short, you now need evidence and statistics.

Your reporting goes from “this is our duplicate detection procedure” to “we caught 247 duplicates before payment, totalling £183,000 this year.” When board members must put their signatures on it, the pressure is on.

Let’s look at what this means in Accounts Payable.

Three AP controls under the microscope

When your board reviews AP control effectiveness, they’ll ask specific questions that require specific evidence of measurable success.

Duplicate Payment Detection

  • Paper control: “We check for duplicate invoices before processing.”
  • Example of proof required: “In 2026, our risk management software flagged 247 potential duplicates worth £183,000. Of these, 230 were confirmed duplicates prevented before payment. 17 were false positives, resolved within 24 hours.”

It’s worth noting that nearly two-thirds of finance professionals had received duplicate invoices in the UK (Westgatemoore). To sign off happily, your board needs to know you can catch duplicate invoices before they’re paid.

Supplier verification and control

  • Paper control: “Our onboarding process features verification steps.”
  • Example of proof required: “Our supplier file is analysed for risks in real time. This year, we found and archived 37 dormant suppliers. We also blocked 12 potentially risky supplier additions due to supplier duplication, and appearance on sanctions lists. All supplier changes require dual authorisation, with 100% compliance logged. Changes to supplier details are highlighted and checked immediately to ascertain correct authorisation.”

Supplier risk controls matter. 79% of companies reported attempted or actual payments fraud in 2024 (Tax1099 Blog), with ghost vendors and bank detail fraud among the most common schemes. Sharing the results of your controls, especially when it comes to vigilance in terms of supplier details, is key.

Supplier statement reconciliation

  • Paper control: “We reconcile supplier statements quarterly.”
  • Proof required: “Automated supplier statement reconciliation is conducted in real time. It identified 34 discrepancies totalling £47,000 in missing credits and invoices in Q4. £45,000 is currently recovered. Average resolution time: 3 days. Outstanding items: 2, under investigation with documented action plans.”

Completing statement reconciliation is something that many teams would like to do to cover most of their supplier base. The more suppliers are covered, the higher your level of risk control. Statement reconciliation is key for finding liabilities – the things you didn’t even know you were missing, like invoices and untaken credits. Great recovery results cement the effectiveness of your controls.

Weaving in systematic controls

Did you notice the pattern? Proving effectiveness requires systematic, continuous monitoring, rather than one-time checks. Technology-enabled controls management creates the audit trail and reports that boards need without drowning your team in added tasks.

Why organisations struggle with UK SOx compliance

The 2% incomplete disclosure of information rate doesn’t necessarily reflect poor controls. Rather, it reflects a problem with retrieving evidence and information. When someone reviews an invoice by eye, catches a potential duplicate, and resolves it, that’s a control working. But manual controls are difficult to evidence comprehensively. And without time-consuming, systematic logging, how do you prove it happened?

Leading organisations are shifting to technology-enabled controls management environments, to enable faster and easier controls, and to comply with Provision 29 requirements. That technology features audit trails, reports and statistics designed to help you create the evidence trail you need.

The time is now to get AP controls evidence in place

The challenge, should you choose to shift to automated risk controls, is in implementing these systems. That requires time, and there’s a small timeline issue.

Provision 29 applies to financial years beginning on or after 1 January 2026. For most organisations, that means the first attestation covers January-December 2026, with declarations due in early 2027.

The critical point is that if your board is expected to sign off on the effectiveness of your internal controls at the end of next year, they’ll need hard evidence in place for that year, fast.

That leaves a narrow window to implement, stabilise, and accumulate a meaningful evidence trail. So the time is now to implement that change.

FISCAL's custom reporting module allows you to build your own reports

Be SOx compliance confident

When your board signs their attestation this December, declaring that your controls operated effectively throughout 2026, can you demonstrate that you delivered those results?

Do you need extra help to get you there? If so, reach out to FISCAL.

We’ll discuss how we can help create strong risk controls, and the board-ready evidence you need.

Learn how FISCAL supports UK SOx compliance

Share This

Ready to transform your Account Payable Process?

For further information or to request a demo:

Would you like to know more about what FISCAL can do for you? Contact us at:
[email protected] or call +44 (0) 845 680 1905

OR

Related

Popular

Archive

Archives

Category

Categories