Skip to main content
Category: Governance Codes and Frameworks

Governance Code

Also known as: Corporate Governance Code, Code of Corporate Governance
Simply put

A governance code is a published set of principles and recommended practices that guides how a company's board and directors should oversee the organisation. It is generally a voluntary standard of good practice rather than a binding law, and codes vary by country, market, and the type of company they address. Codes aim to promote effective board leadership, accountability, and consideration of shareholders and wider stakeholders.

Formal definition

A governance code is a structured, typically non-binding instrument setting out principles and recommended practices for the governance of an entity, most commonly directed at the board and its committees and covering areas such as board leadership and purpose, division of responsibilities, composition and succession, audit and risk oversight, and remuneration. Codes are generally applied on a comply-or-explain or apply-and-explain basis, meaning adherence may be expected through listing rules or market convention rather than imposed as a statutory obligation; the precise legal status, scope, and enforceability depend on jurisdiction, sector, and entity type. For example, the UK Corporate Governance Code 2024 is organised into five sections: Board Leadership and Company Purpose; Division of Responsibilities; Composition, Succession and Evaluation; Audit, Risk and Internal Control; and Remuneration. Other codes, such as the QCA Corporate Governance Code, offer a more flexible set of principles aimed at growing companies. This entry addresses corporate governance codes and does not cover the unrelated software-engineering concept of code governance; it is educational and not legal, audit, or compliance advice.

Why it matters

Governance codes shape how boards are expected to behave in markets around the world, even though they are generally voluntary standards of good practice rather than binding law. Because many codes operate on a comply-or-explain or apply-and-explain basis, a company may be expected to follow the code's principles through listing rules or market convention, or else publicly explain why it has departed from them. This creates a form of accountability that relies on transparency and investor scrutiny rather than statutory enforcement, and it allows codes to set expectations on matters such as board leadership, division of responsibilities, board composition and succession, audit and risk oversight, and remuneration.

For boards, directors, and the assurance and compliance functions that support them, understanding the applicable code matters because the precise legal status, scope, and enforceability depend on jurisdiction, sector, and entity type. A code aimed at large listed companies, such as the UK Corporate Governance Code, sets different expectations from a more flexible instrument aimed at growing companies, such as the QCA Corporate Governance Code. Applying the wrong code, or treating a recommended practice as a legal requirement (or vice versa), can lead to misplaced compliance effort and gaps in oversight.

Codes also influence investor confidence and reputation. Because departures from a code are typically disclosed and explained, the quality of that explanation, and the underlying governance behaviour, can affect how shareholders and wider stakeholders assess a company's board. This entry is educational and not legal, audit, or compliance advice; whether and how a particular code applies to a given entity depends on the facts and the relevant jurisdiction.

Who it's relevant to

Board members and directors
Governance codes are primarily addressed to boards and directors, guiding how they approach board leadership, division of responsibilities, composition and succession, audit and risk oversight, and remuneration. Directors typically need to understand which code applies to their entity and how comply-or-explain or apply-and-explain expectations affect their disclosures and conduct.
General counsel and company secretaries
Those advising the board on governance need to track the applicable code, its status under listing rules or market convention, and how any departures should be explained. Because legal status and enforceability vary by jurisdiction and entity type, they help distinguish binding requirements from recommended practice.
Chief compliance and risk officers
Codes commonly include expectations around audit, risk, and internal control oversight, held at board level, which risk and compliance functions support in practice. Understanding that a code is generally a standard of good practice rather than statutory law helps these functions calibrate effort appropriately.
Internal auditors and assurance functions
Assurance providers may assess whether governance practices align with the applicable code and whether explanations for departures are sound. The audit, risk, and internal control themes found in many codes are directly relevant to how assurance work is scoped and reported.
Growing and smaller companies
Not all codes are aimed at large listed entities. More flexible instruments, such as the QCA Corporate Governance Code, are designed to help growing companies run better for their staff, investors, partners, and the wider stakeholder community, offering principles suited to their scale and stage.

Inside Governance Code

Comply-or-explain mechanism
The characteristic enforcement approach of many governance codes, particularly in the UK and across much of Europe. Rather than mandating compliance, the code invites companies to apply its provisions or to explain publicly why they have departed from them. This preserves the code's status as principles-based, non-binding guidance rather than binding law, though the disclosure obligation itself may be anchored in listing rules or regulation depending on the jurisdiction.
Principles and provisions structure
Governance codes typically distinguish higher-level principles (broad statements of expected governance outcomes) from more detailed provisions (specific practices against which comply-or-explain reporting is made). The principles articulate the intent; the provisions offer the more granular benchmarks. This layering allows flexibility of application across differing company sizes, sectors, and circumstances.
Board leadership and company purpose
A core thematic area addressed by many codes, covering the board's collective responsibility for the long-term success of the entity, the setting of purpose, values, and culture, and the alignment of strategy with those elements. This concerns the board's stewardship role rather than day-to-day management, which remains with executives.
Division of responsibilities
A thematic area addressing the clarity of roles at the top of the organisation, including the separation between the chair and chief executive, the role of non-executive directors, and the balance of the board. It reinforces the distinction between the board's oversight function and management's operational function.
Composition, succession and evaluation
A thematic area covering board appointments, diversity, succession planning, and the periodic evaluation of board and committee effectiveness. It typically speaks to how boards are refreshed and assessed over time.
Audit, risk and internal control
A thematic area addressing the board's responsibilities for financial reporting integrity, the relationship with external and internal audit, the establishment and monitoring of risk management and internal control systems, and the role of the audit committee. Accountability for oversight sits with the board and its audit committee, while the design and operation of controls sits with management and assurance functions.
Remuneration
A thematic area addressing the design of executive pay, the alignment of remuneration with long-term performance and company purpose, and the role of the remuneration committee. It typically covers how pay is set, disclosed, and linked to sustained value creation rather than short-term outcomes.
Reporting and disclosure expectations
Codes generally rely on transparency to function, expecting companies to report how they have applied the principles and to explain any departures from provisions. The credibility of the comply-or-explain model depends heavily on the quality and specificity of these disclosures, which are typically found in the annual report.

Common questions

Answers to the questions practitioners most commonly ask about Governance Code.

Is a governance code legally binding, so that a company can be prosecuted for not following it?
Generally, no. A governance code is typically a set of principles and provisions issued by a regulator, exchange, or standard-setting body as best-practice guidance rather than binding statute. Most well-known codes operate on a 'comply or explain' basis, meaning a company that departs from a provision is expected to explain its reasons rather than face legal sanction for the departure itself. That said, the position varies by jurisdiction and entity type. In some markets, adherence to a code is a listing rule requirement enforced by the exchange, and the obligation to report against the code (or to explain non-compliance) may itself be mandatory even where the underlying provisions are not. Separately, conduct addressed by a code may also be governed by binding law, so failing to act well can still create legal exposure through statutes, regulations, or directors' duties independent of the code. This entry is educational and not legal advice; assess your specific obligations by reference to the applicable code, listing rules, and law.
Does complying with a governance code guarantee good governance or protect against corporate failure?
No. A governance code sets out a framework of expected practices, but reporting compliance with its provisions does not by itself demonstrate that governance is effective or that risks are being managed well. Codes generally emphasise the substance of behaviour over box-ticking, and a 'comply or explain' report describes whether provisions are followed rather than whether the board is functioning effectively in practice. Effective governance depends on factors a code cannot fully capture, including board culture, the quality of challenge, information flows, and the judgement of individuals. Compliance also does not eliminate business, financial, or strategic risk. Treating a code as a checklist rather than as principles to be applied thoughtfully is a common misconception that codes themselves typically caution against.
Who within an organisation is responsible for applying a governance code and reporting against it?
Accountability for applying a governance code generally rests with the board as a whole, which is typically responsible for the company's overall governance and for the code-related statements in its reporting. In practice, responsibility is often distributed: the board and its chair set the tone and oversee application; board committees (such as audit, nomination, and remuneration committees) address the areas within their remit; and management implements the underlying practices and prepares supporting information. Company secretaries or governance professionals frequently coordinate the reporting process. It is important to preserve the distinction between the board's oversight role and management's operational role, and not to attribute code-related oversight duties to management or day-to-day implementation to the board without qualification. The precise allocation depends on the applicable code and the organisation's structure.
How should a company approach a 'comply or explain' departure from a code provision?
Under a 'comply or explain' approach, a company that does not follow a particular provision is generally expected to provide a clear, specific, and reasoned explanation rather than a generic statement. Good practice typically involves describing the background to the departure, explaining how the company's alternative arrangements are consistent with the relevant principle, indicating whether the departure is time-limited, and noting any mitigating actions. The aim is to give shareholders and stakeholders enough information to assess the approach. An explanation is not treated as inherently inferior to compliance; codes generally recognise that a well-reasoned departure can be appropriate for a company's particular circumstances. Whether a given explanation is adequate is a matter of judgement and may depend on the expectations of investors and any relevant regulator or exchange.
How does reporting against a governance code fit with a company's other reporting and assurance obligations?
Governance code reporting typically appears within a company's annual report or a dedicated governance statement, and it usually sits alongside, rather than replaces, other obligations such as financial reporting, statutory disclosures, and any regulatory reporting. It is important to distinguish the code-related narrative from binding financial and regulatory requirements, which may be subject to separate rules and, in some cases, external audit or assurance. Code statements are often narrative and may not carry the same assurance as audited financial statements, though some elements may draw on the work of assurance functions. Organisations generally coordinate governance, risk, and compliance functions to ensure code reporting is consistent with underlying practices, while keeping clear which function owns each activity. The specific interaction depends on jurisdiction, sector, and applicable rules.
What should a board consider when deciding which governance code applies and how to implement it?
The applicable code generally depends on factors such as the company's jurisdiction of incorporation or listing, the market or exchange on which its securities trade, its size, and its sector, since different codes and, in some cases, tiered or proportionate versions may apply to different entity types. Boards typically begin by confirming which code or codes apply and whether adherence is expected as a matter of listing rules, best practice, or both. Implementation generally involves mapping the code's principles and provisions to existing governance arrangements, identifying gaps, allocating responsibilities appropriately between the board, its committees, and management, and establishing a process for reporting and for explaining any departures. Because requirements and expectations vary and evolve, boards commonly seek professional advice tailored to their circumstances; this entry is educational and not a substitute for such advice.

Common misconceptions

A governance code is binding law that companies must obey.
Governance codes are generally non-binding guidance rather than statute or regulation. Many operate on a comply-or-explain basis, allowing departures provided they are explained. The related disclosure obligation may, however, be imposed by listing rules or regulation in a given jurisdiction, so the legal weight varies by jurisdiction and entity type.
One governance code applies universally to all companies everywhere.
Governance codes are jurisdiction-specific and often sector- or listing-specific. The UK Corporate Governance Code, for example, addresses premium-listed companies in that market and differs from codes elsewhere. Applicability depends on where an entity is incorporated or listed, its size, and its regulatory status.
Following a code means the board handles the operational detail of risk and controls.
Codes generally frame the board's role as oversight of risk management and internal control, not the operation of those systems. The design and day-to-day operation of controls typically sits with management and assurance functions, while accountability for oversight rests with the board and its relevant committees.

Best practices

Confirm which code applies to your entity based on jurisdiction, listing status, size, and sector before benchmarking, since applicability and the associated disclosure obligations vary.
Treat departures from provisions as an opportunity for meaningful explanation rather than boilerplate; the comply-or-explain model depends on specific, reasoned disclosure of why an alternative approach serves the company.
Distinguish clearly in board papers and reporting between the board's oversight responsibilities and management's operational responsibilities for risk, control, and remuneration, so accountability is not blurred.
Map the code's thematic areas, board leadership and purpose, division of responsibilities, composition and evaluation, audit, risk and internal control, and remuneration, to your governance framework to identify gaps.
Ensure disclosures on application of the principles are grounded in evidence of what the board actually did, rather than aspirational statements, to preserve the credibility of comply-or-explain reporting.
Revisit the applicable code periodically, as codes are updated over time; verify the current text and structure directly from the issuing body rather than relying on prior editions, and seek professional advice where legal or regulatory consequences turn on the facts.