A board meeting starts with a decision that wasn’t on the agenda. The company wants to approve a major transaction involving a director’s long-standing business partner. The chair asks whether the conflicted director should leave the room, whether the audit committee must review the terms, and whether shareholders need an explanation. Everyone has an opinion, but nobody can point to a shared rule.
That moment is where a corporate governance code earns its place. It gives directors a practical operating system for making decisions, assigning responsibility, handling conflicts, and explaining their choices. A well-designed code doesn’t sit untouched in the annual report. It shapes agendas, committee work, board papers, minutes, disclosures, and the conversations that happen when pressure is highest.
Table of Contents
- Why Every Board Needs a Governance Code
- What a Corporate Governance Code Actually Is
- The Core Principles That Hold a Code Together
- How Major Jurisdictions Approach Governance Codes
- Drafting, Applying, and Reporting on a Code
- Common Pitfalls and Lessons From Real Cases
- Putting It Into Practice and Final Questions
Why Every Board Needs a Governance Code
Without a written code, the chair often becomes the default interpreter of governance. That might work for a small board with long-standing relationships, but it creates a fragile system. A new director may understand the same issue differently, an executive may influence the process, or a disagreement may become personal because nobody agreed in advance how it should be resolved.
The problem isn’t just regulatory exposure. Unclear governance creates three practical risks:
- Unilateral decisions: one powerful director or executive can move a decision forward without sufficient challenge.
- Opaque accountability: the board approves an outcome, but the minutes don’t show who tested the assumptions or owned the follow-up.
- Silent conflicts of interest: a relationship is known informally but never declared, assessed, recorded, or managed.
A governance code turns those risks into defined actions. It can require directors to declare interests before discussion, specify which committee reviews a transaction, establish how the chair handles dissent, and set out what the board must disclose. For companies dealing with wider regulatory obligations, a clear governance structure also makes it easier to connect board decisions with operational controls, as the practical distinction between governance and regulatory compliance becomes easier to manage.

The board’s operating system
Think of the code as the board’s operating system. The constitution of the company establishes the legal structure, but the code provides repeatable instructions for how directors work within it. It should answer questions such as:
- Who sets the agenda, and how can directors add an item?
- What information must accompany a major investment proposal?
- Which decisions belong to the board, a committee, or management?
- How does the board test the independence of a director?
- What evidence supports the annual statement on governance and controls?
The code also protects good directors. A documented process gives a chair a defensible basis for pausing a rushed decision, asking for independent advice, or requiring a conflicted director to recuse themselves.
Modern codes increasingly connect these board habits with sustainability, resilience, internal control, investor protection, and market integrity. The OECD’s revised framework reflects that wider purpose. A board that treats the code as a living control system is better positioned to manage the six principles discussed below and to respond as national codes become more operational and disclosure-focused.
What a Corporate Governance Code Actually Is
A corporate governance code is a set of principles and provisions that defines how a board is structured, how it behaves, and how it remains accountable to shareholders and other stakeholders. It translates broad expectations, such as independence or transparency, into practices that directors can follow and investors can assess.
The modern international reference point began with the OECD Principles of Corporate Governance. The principles were first developed after an OECD Council call in April 1998, agreed in 1999, updated in 2004, and revised after an 18-month review process. The revised G20/OECD Principles of Corporate Governance were adopted by the OECD Council at Ministerial level in June 2023 and endorsed by G20 Leaders in September 2023, as set out in the OECD legal instrument for the G20/OECD Principles. The framework now addresses capital markets, investor protection, sustainability, and financial stability alongside traditional board responsibilities.
Three layers of authority
Readers often confuse a code with company law or exchange rules. A useful analogy is transport:
- Company law is the constitution. It establishes the legal personality of the company, director duties, shareholder rights, and formal powers.
- Listing rules are the traffic signals. They impose market-specific requirements on companies admitted to an exchange, including disclosure and eligibility conditions.
- A governance code is the driving manual. It explains how the board should organise itself, exercise judgement, supervise management, and communicate its approach.
The layers interact, but they aren’t interchangeable. A code generally shouldn’t repeat every statutory duty. Instead, it should explain how the board will perform those duties in practice. A provision about conflicts, for example, may go beyond the legal minimum by setting a declaration process, a recusal rule, a register owner, and a reporting expectation.
The OECD describes its principles as non-binding guidance for national frameworks, exchanges, investors, corporations, and regulators. In many markets, that guidance supports a comply-or-explain model. The company follows a provision or explains why it has adopted a different arrangement.
| Layer | Source | Binding force | Enforced by | Applies to |
|---|---|---|---|---|
| Company law | Legislature and corporate statutes | Mandatory legal requirements | Courts, regulators, and public authorities | Companies within the relevant legal jurisdiction |
| Listing rules | Stock exchange or market regulator | Binding market conditions | Exchange and market regulator | Issuers within the relevant listing category |
| Governance code | National code, exchange framework, or international principles | Often soft law with disclosure expectations | Investors, regulators, exchanges, and market scrutiny | Usually listed companies, with adaptations for other organisations |
Comply-or-explain creates useful flexibility. A smaller board may not need the same committee structure as a large listed issuer. The weakness appears when an explanation becomes a vague excuse. “The board considers this arrangement appropriate” tells investors very little unless the company describes the alternative, why it works, and how the board tests it.
The Core Principles That Hold a Code Together
A code works only when directors can turn principles into boardroom behaviour. It is less like a poster on the wall and more like the operating system beneath the board’s work. The G20/OECD framework gives an international reference point, while national codes adapt the ideas to local markets and legal structures. The G20/OECD Principles of Corporate Governance emphasise practical board conditions such as independence, disclosure, investor rights, and responsible oversight.

Accountability
Accountability means a named person or body owns a decision and can explain the reasoning behind it. A chief financial officer who signs off a forecast should be able to explain a material variance, the assumptions used, and the corrective action. The board should apply the same standard to strategy, risk, remuneration, and major transactions.
A practical code assigns ownership in committee terms of reference and records challenge in the minutes. It does not require every director to agree. It requires the board to show that it considered the issue responsibly.
Fairness
Fairness protects shareholders from decisions that favour a controlling group, an executive, or a connected party. Consider a rights issue. A fair process gives shareholders the relevant information and applies the same rights framework rather than allowing insiders to receive an undisclosed advantage.
Fairness also affects how the board handles dissent. The chair should allow a minority view to enter the record when it could improve the decision or reveal a material risk.
Transparency
Transparency is not the same as publishing more pages. It means providing information that lets an informed reader understand what happened and why. If a proposed transaction involves a director’s associate, the board should disclose the relationship, explain the review process, and describe the safeguards before approval.
The code should define who maintains the conflicts register, when declarations are refreshed, and how material matters appear in board and shareholder reporting. Good disclosure reduces the need for investors to reconstruct the decision from scattered documents.
Responsibility
Responsibility places active oversight on the board. A board that reviews cyber risk only after an incident is reacting, not governing. A stronger code requires recurring risk reporting, clear escalation thresholds, and evidence that directors understand the exposure well enough to challenge management.
This principle also applies to sustainability and resilience. Directors do not need to run every operational programme, but they do need to understand the material risks, assign oversight, and test whether management’s controls produce reliable information.
Independence
Independence is a condition for objective judgement, not merely a label attached to a director. The OECD states that a sufficient number of directors and key committee members should be independent of management. According to the OECD’s 2023 comparative review, 58% of jurisdictions require at least a majority of independent audit committee members, while 72% recommend full or majority independence for remuneration committees and 64% do so for nomination committees. OECD comparative data on committee independence
A code should map each director against the applicable independence tests. It should also state how the board handles relationships that could affect judgement, especially in concentrated-ownership or state-influenced companies.
Risk and internal control
Risk oversight works when it is integrated with decision-making. The board should understand the controls supporting financial reporting, cybersecurity, sustainability data, major suppliers, and strategic execution. A committee mandate that says “oversee risk” is not enough. The board needs reporting routes, review frequency, escalation criteria, and evidence of follow-up.
National frameworks may use different names, but many map back to these habits. The result is a governance code that describes what directors do, not a slogan repeated in an annual report. A sound quality assurance process for board papers and approvals can help turn those expectations into repeatable evidence, rather than leaving them to individual memory.
How Major Jurisdictions Approach Governance Codes
A board can face different governance expectations depending on where the company is incorporated, listed, or regulated. The key question is which parts of the framework are mandatory, which parts follow comply or explain, and which parts sit in disclosure, company law, or exchange rules.
The UK model is usually associated with a code built from principles and provisions. In practice, it asks listed companies to explain how they apply the framework and why they depart from it. The direction of travel is more operational now. The Financial Reporting Council’s current code materials identify a shift toward board declarations about the effectiveness of material internal controls, so a board needs evidence, not just a statement in the annual report. A provision can become applicable before the company is ready to support it with records, testing, and clear ownership.
The EU approach often combines national governance codes with wider reporting and sustainability duties. A board may therefore have to align governance disclosures, sustainability information, internal control evidence, and the work of assurance providers. That creates a practical test. Can the company tell one consistent story across the annual report, sustainability reporting, committee papers, and control records? If those sources disagree, the code may be followed on paper while the operating system underneath it is still weak.
The US framework is more distributed. It draws on exchange standards, state corporate law, securities regulation, and company policies. A listed company may need to meet mandatory listing requirements while also explaining its governance choices to investors. Companies with material financial reporting duties should connect board oversight to documented internal controls. The same discipline applies to personal data. A company that understands how GDPR compliance works in practice is usually better placed to separate policy language from the records needed to prove compliance. That same mindset helps with governance evidence. Written rules matter, but so do logs, approvals, and escalation trails.
A simple comparison helps. The UK tends to rely on principles backed by explanation. EU regimes often layer governance codes onto broader reporting duties. The US places heavier weight on listing rules and legal requirements, with investor scrutiny filling the gaps.
| Dimension | UK, FRC Code 2018, updated 2024 | EU, CSRD and national codes | US, NYSE or Nasdaq and state law |
|---|---|---|---|
| Main orientation | Principles and provisions with explanations for departures | National governance expectations combined with wider reporting duties | Listing standards, securities rules, state law, and company practice |
| Binding force | A mixture of listing obligations and comply-or-explain expectations | Depends on the applicable national and reporting framework | Mandatory exchange and legal requirements, with market scrutiny of additional practices |
| Scope | Depends on listing category and applicable market rules | Depends on jurisdiction, issuer status, and reporting obligations | Depends on listing, incorporation, issuer status, and any controlled-company treatment |
| Enforcement pressure | Disclosure quality, investor response, exchange expectations, and regulator review | Filing, reporting, assurance, regulator, and investor scrutiny | Exchange compliance, securities enforcement, state remedies, and investor scrutiny |
| Typical evidence | Board effectiveness review, committee work, controls assessment, and explanations | Governance records linked to financial and sustainability reporting | Committee charters, control certifications, policies, disclosures, and board minutes |
A company secretary should not copy a foreign code without checking the local legal perimeter. The safer sequence is to identify the mandatory layer first, then use a recognised code to fill out the operating detail. That is the same approach teams use in SOX compliance guide 2026, where control evidence and governance reporting have to support each other rather than sit in separate folders.
Drafting, Applying, and Reporting on a Code
A code works best when it behaves like the board’s operating system, not a filing cabinet of good intentions. A family-owned company, a regulated subsidiary, and a listed parent may all use the same principles, yet each one needs different controls, reporting lines, and explanations. Start with the company’s ownership structure, listing status, jurisdictions, regulated activities, committees, stakeholder exposures, and main risks. Then choose the framework that fits that perimeter.
Five practical drafting steps
-
Set the perimeter. Decide which entities, directors, committees, and reporting periods the code covers. Separate the provisions that are mandatory from the ones the company can tailor.
-
Choose a reference framework. Begin with a recognised national code or the G20/OECD principles. Use it as a control map, not as text to paste into a policy folder.
-
Tailor the provisions. A small board may combine committees, but it still needs a clear way to preserve independent challenge. A larger issuer may need separate mandates, skills matrices, and formal escalation routes. Each adaptation should name the safeguard that replaces the standard structure.
-
Connect the code to committee mandates. The audit committee should own the financial reporting, control, and assurance responsibilities tied to its role. The remuneration and nomination committees need defined authority, membership expectations, and reporting duties. If a duty appears in the code but nowhere in a committee charter, it has no clear operational owner.
-
Embed the code in board routines. Put conflicts declarations into meeting packs. Map skills against the annual board calendar. Record attendance and challenge. Include governance training in induction. Schedule reviews of material controls. The board should be able to produce evidence without rebuilding its process months later.
Making comply or explain credible
The OECD says companies should report governance practices in regular filings, with public disclosure at least annually and, in some markets, more often. Hong Kong’s framework shows how that works in practice by requiring issuers to state compliance, explain deviations, disclose board composition and meeting information, and describe the division of responsibilities between the board and management in its governance reporting guidance.
A useful explanation does not hide behind a conclusion. It identifies the provision, describes the company’s alternative, explains why that alternative fits the business, names the safeguard, and says when the board will review it again.
Apply and explain: The board has combined the nomination and remuneration committees because of its current size. The independent chair leads both committees, conflicts are recorded before each meeting, and the board reviews the structure during its annual effectiveness review. The board will revisit the arrangement if the company’s scale, ownership, or risk profile changes.
The recent UK changes on internal controls raise the bar on readiness. The 2024 Code moved Provision 29 toward a board declaration on the effectiveness of material internal controls from 2026, while the FRC’s 2025 review said it would assess annual reports against the updated code and expected Provision 29 reporting to begin in 2027 the FRC’s 2025 review of the UK Corporate Governance Code. The gap between formal reporting and readiness matters. It is the time to test whether the board can identify material controls, assess effectiveness, document weaknesses, and explain remediation.
Keep a practical evidence file. It should let the board prove what it did, not reconstruct it from memory.
- Board minutes: record decisions, challenge, recusals, and follow-up owners.
- Conflicts register: capture declarations, management actions, and review dates.
- Committee papers: show the information reviewed and the recommendation made.
- Skills matrix: connect director capabilities with current risks and committee assignments.
- Induction log: show that directors received the code and understood their responsibilities.
- Control assessment: retain the basis for conclusions about material internal controls.
A governance code can sit beside security and assurance programmes without becoming the same thing. A company that documents access reviews and control evidence may use a SOC 2 certification overview as a separate reference, while keeping the board code focused on oversight, accountability, and decision rights.
Common Pitfalls and Lessons From Real Cases
The most common mistake is treating the code as a filing exercise. A board approves polished language, publishes a compliance statement, and then continues making decisions through informal relationships. That approach creates the appearance of control without the underlying habits.
Independence reduced to a label
A director may satisfy a formal test and still avoid difficult questions because of social, commercial, or historical ties. The remedy isn’t to assume that every relationship disqualifies the person. It is to document the assessment, give independent directors access to information, and require the chair to test whether the committee can challenge management without pressure.
Conflicts recorded but not managed
A register signed once a year is not a functioning control. A director may declare an interest during appointment and later face a new transaction involving the same relationship. Good practice requires declarations at the relevant meeting, a decision about participation, a recorded recusal where appropriate, and a review of whether the arrangement remains acceptable.
Board evaluation reduced to a questionnaire
A questionnaire can reveal themes, but it can’t replace a conversation about how the board made a difficult decision. The chair should examine the quality of challenge, the timing of information, committee effectiveness, and whether directors changed their view when evidence changed. The board should record actions, owners, and completion status.
Diversity disclosure without boardroom challenge
A demographic description may look complete while the board continues recruiting people with the same background, networks, and assumptions. A stronger code links diversity to succession planning, skills, constructive challenge, and the nomination process. It asks whether the board is becoming more capable, not merely more presentable.
These are practical failure patterns, not claims about a particular company. They also apply to incident governance. When a serious event occurs, directors need a defined escalation path, decision record, and post-incident review. A structured incident response guide can support the operational side, while the governance code determines who oversees the response and how the board learns from it.
A code fails when its language substitutes for judgement. Strong boards use the code to improve the conversation, not to avoid having one.
Putting It Into Practice and Final Questions
A 90-day adoption plan gives the board a manageable start.
- Days 1 to 30: map the current governance framework, compare it with the G20/OECD principles, interview the chair and committee leads, and produce a scope statement plus gap register. The decision gate is approval of the code’s perimeter and priority gaps.
- Days 31 to 60: draft the code, align committee terms of reference, test independence and conflicts processes, and complete legal and compliance review. The decision gate is agreement on the operating model and evidence owners.
- Days 61 to 90: run a dry-run comply-or-explain report, train directors, ratify the code, issue the induction pack, and schedule the first annual review. The decision gate is confirmation that the board can produce evidence for each material provision.

Final questions from first-time drafters
Does a private company need a code? It may not need the same code as a listed issuer, but a written set of decision, conflict, oversight, and accountability rules can prevent founder dependence and make growth safer.
How often should the code be refreshed? Review it on a defined annual cycle and whenever ownership, listing status, regulation, strategy, or material risk changes. The OECD’s 2025 Factbook records updates across several jurisdictions and describes Japan’s 2026 revision as a move toward more practical interpretation and substance over form, showing why static documents become outdated in its governance and institutional framework review.
What if a provision can’t be applied? Explain the alternative clearly, identify the safeguard, assign ownership, and set a review trigger. An explanation without an operating substitute is only an admission of a gap.
How does the board evidence effectiveness? Use minutes, committee reports, conflicts records, skills reviews, control testing, training logs, and documented follow-up. Evidence should show what directors did, not merely what the code says they should do.
Capgo provides role-based access controls, audit logs for organisation activity and deployment changes, and enterprise features such as single sign-on and member management. If your board oversees a mobile application team and needs clearer evidence of who changed what and when, visit Capgo to evaluate how those records could support your wider governance and review process.