Mission Intelligence Systems
Risk · Authority

What the Duty of Oversight Actually Requires

The question every board eventually asks, usually too late to answer well.

Some version of it arrives in every boardroom: if this goes badly, are we exposed? The legal answer is narrower than the anxiety behind the question. The practical answer is more demanding, because it is not about the outcome at all. It is about whether the board built something that would have told it, and whether there is a record that it listened.

Published

Key Takeaways

Research foundation

The legal account rests on primary sources: In re Caremark (Del. Ch. 1996), Stone v. Ritter (Del. 2006), Marchand v. Barnhill (Del. 2019) and In re Boeing (Del. Ch. 2021), with Shapira (2021) in the Washington University Law Review for the shift in how these claims are surviving dismissal. The artifact standard rests on the GAO Cost Estimating and Assessment Guide (GAO-20-195G) and the GAO Schedule Assessment Guide (GAO-16-89G). This article is governance analysis, not legal advice. The Four A's are the executive lens applied on top.

The question is almost never asked in the abstract. It arrives attached to something: a program that has moved twice, an auditor who has started asking for the basis of an estimate, a peer organization in the news. And it is almost always asked in a form that cannot be answered, which is some variant of are we covered.

You are not covered or uncovered. That is not the shape of the standard. The standard asks a question about architecture.

What is the duty of oversight?

It began as a footnote to a settlement approval. In 1996, Chancellor Allen used In re Caremark International Inc. Derivative Litigation to say something that had not been squarely held before: that a director's obligation includes a good faith attempt to assure that a corporate information and reporting system exists, and that a sustained or systematic failure to do so could establish the lack of good faith that is a necessary condition for liability. He also called it, in the same breath, possibly the most difficult theory in corporation law on which to win a judgment.

Ten years later, Stone v. Ritter formally adopted the Caremark articulation and located it inside the duty of loyalty rather than the duty of care. That relocation mattered more than it sounds, because charter provisions that shield directors from care-based liability do not shield them from loyalty-based liability. Stone also set out the two branches that practitioners still work from. Liability requires either that the directors utterly failed to implement any reporting or information system or controls, or that, having implemented such a system, they consciously failed to monitor or oversee its operations, thereby disabling themselves from being informed of risks requiring their attention.

Read those two branches carefully, because almost every misunderstanding of the duty lives in the gap between them and what people assume they say.

They do not say the board must be right. They do not say the board must prevent the failure. They do not say the board must understand the technical detail. They say the board must build a channel, and then not ignore the channel.

What did Marchand change?

Blue Bell Creameries had a listeria outbreak. Three people died. The company shut down production, recalled its product, laid off a third of its workforce and needed a liquidity injection to survive. A stockholder brought an oversight claim. The Court of Chancery dismissed it. In 2019 the Delaware Supreme Court reversed.

What is striking about Marchand v. Barnhill is how little the court had to reach for. The company made one product. Food safety was not one risk among many, it was the risk. And on that risk, the board had no committee, no regular process by which management reported compliance to it, no protocol requiring escalation of red flags, and no board-level discussion recorded in any minutes. Management had received reports of contamination. The board had not.

The reasoning generalizes further than the facts. Where a risk is central and mission critical to the enterprise, a board cannot discharge its obligation by knowing that management is handling it. It has to make a good faith effort to establish a board-level system that surfaces information about that risk to the board itself. Delegation of the work is fine. Delegation of the visibility is the problem.

In re Boeing Co. Derivative Litigation in 2021 applied the same logic to the 737 MAX. Again the pattern: no board committee charged with airplane safety, no regular safety reporting to the board, safety not appearing as a standing agenda item, and a board that publicly represented it was monitoring safety in a way the internal record did not support. Vice Chancellor Zurn declined to dismiss. The action settled for 237.5 million dollars.

Shapira, surveying this line in the Washington University Law Review, argues that the practical significance is not that the doctrine changed but that plaintiffs began arriving with the internal documents needed to plead it, obtained through books and records demands before filing. The standard was always demanding. What changed is that the record is now visible before the complaint is written.

Does this apply to a public agency board or a council?

Not directly, and it is worth being precise about that, because the conflation is common and unhelpful.

Caremark and its successors are Delaware corporate law governing directors of Delaware corporations. A municipal council, a transit authority board, a special district, a state university board of trustees and a nonprofit board each operate under different statutes, different immunity regimes and fiduciary standards that vary state by state. Nothing in Marchand creates a cause of action against a city council member. Anyone with a live exposure question should be asking counsel, not reading an article.

What has traveled is the evaluative logic, and it has traveled quite far. Read the question sets that governance bodies now publish for their own directors and the Delaware architecture is visible in them: is there a process for identifying and escalating emerging risk, are the right signals reaching the right people with enough time to act, and, most pointedly, if the organization faced a severe disruption, what evidence could the board rely on to demonstrate that its oversight was real. Funders ask a version of this. Auditors ask a version of this. Oversight procedures on federally funded programs ask a documented version of this.

The liability rule stops at the state line. The question does not.

What actually counts as evidence of oversight?

Here is where most organizations discover they have been producing the wrong artifact for years.

A record that a presentation occurred is weak. It establishes attendance. It does not establish that the board was told anything specific enough to act on, and it certainly does not establish that the board acted. A slide reading project remains on budget alongside a green status indicator is worse than weak, because if the program later moves by thirty percent, that slide is now an exhibit demonstrating that the reporting system did not work.

Strong evidence has a particular shape. It shows that information was produced, that it was specific, that it reached the board on a defined cadence rather than when someone remembered, and that decisions changed in response to it.

On a capital program that resolves into a fairly short list.

The GAO Cost Estimating and Assessment Guide is useful here for a reason that has nothing to do with federal funding. It treats a risk and uncertainty analysis as a component of a credible cost estimate, alongside sensitivity analysis and independent review. That framing converts the absence of one from a stylistic preference into a documented deficiency against a published federal standard. An organization that has never run one is not merely doing things differently. It is missing a named element of a named characteristic, and that is a much harder thing to explain afterwards than it is to fix beforehand.

Why a probability is better oversight evidence than a status report

This is the part that tends to land with boards, so it is worth stating plainly.

A single-point budget with a green status indicator carries no information about what the board was told. If the program lands over, the number was wrong and nothing in the record shows that anyone knew the range of outcomes. If the program lands under, the number was also wrong and nobody noticed, because nobody measures that direction.

A budget approved at a stated confidence level carries a different kind of record. It says: at the time of approval, the modelled probability of completing at or below this figure was sixty five percent, which means the board was informed that roughly one program in three of this type would exceed it. If the program then exceeds it, the board is not exposed by the overrun. It was told the overrun was a live possibility, and it approved anyway, which is a decision rather than a surprise. That is what informed oversight looks like in a document.

The value of a confidence level in the record is not that it makes the estimate more accurate. It is that it converts a later overrun from evidence of a broken reporting system into evidence of a working one.

This is also why the argument that ranges make boards nervous gets the incentive backwards. A range is the artifact that protects the board. A single number is the artifact that indicts it.

What a board should actually require

Four things, and they are all cheap relative to the exposure.

First, name where the mission critical risks are reported. Not who manages them. Where they surface at board level, in what forum, on what cadence. If the answer is that they appear in the program update when there is something to say, there is no system.

Second, require that the confidence level be stated whenever a budget or a date is approved. This is a one-line change to a report template and it changes what the board is agreeing to.

Third, define the escalation trigger in advance and in writing. The failure mode in both Marchand and Boeing was not that nobody knew. Somebody in the organization knew. There was no obligation on anyone to tell the board.

Fourth, ask once a year what would have to be true for the reporting to be misleading, and put the answer in the minutes. That question is the cheapest oversight artifact in existence and almost nobody produces it.

Evidence matrix

ClaimEvidence tierSource
Directors must attempt in good faith to assure an information and reporting system existsPrimary legal sourceIn re Caremark, 698 A.2d 959 (Del. Ch. 1996)
The duty sits within the duty of loyalty and requires bad faithPrimary legal sourceStone v. Ritter, 911 A.2d 362 (Del. 2006)
A mission critical risk requires a board-level monitoring and reporting systemPrimary legal sourceMarchand v. Barnhill, 212 A.3d 805 (Del. 2019)
The same reasoning applied to product safety at a large manufacturerPrimary legal sourceIn re Boeing, 2021 WL 4059934 (Del. Ch. 2021)
Oversight claims are surviving dismissal more often because records are obtained firstPeer reviewed law reviewShapira (2021), Wash. U. L. Rev. 98(6)
A risk and uncertainty analysis is a component of a credible cost estimateGovernment standardGAO-20-195G (2020)
Caremark liability extends to municipal and nonprofit boardsNot establishedDelaware corporate law; other entities governed by other statutes
Oversight fails as an Authority condition before it fails as a legal oneFour A's interpretationBuilders Build, Authority

What to do with this

Take the two or three risks that would genuinely threaten the organization if they landed badly, and for each one write down where it is reported at board level and on what cadence. Most organizations can do this for financial risk and cannot do it for the others. The gap is the finding. It does not require a lawyer to see it and it does not require a program to fix it.

Then look at how the last budget was approved. If the record shows a number and a color, the board has no evidence of what it was told. If it shows a number, a confidence level and a basis, the board has a defensible record whichever way the program lands. The second version costs one sentence more than the first.

References

  1. In re Caremark International Inc. Derivative Litigation, 698 A.2d 959 (Del. Ch. 1996). The origin of the board-level information and reporting system obligation.
  2. Stone v. Ritter, 911 A.2d 362 (Del. 2006). Adopts Caremark and locates the oversight duty within the duty of loyalty.
  3. Marchand v. Barnhill, 212 A.3d 805 (Del. 2019). law.justia.com. Reversal of dismissal where the board had no committee, process or protocol covering a mission critical risk.
  4. In re Boeing Co. Derivative Litigation, C.A. No. 2019-0907-MTZ, 2021 WL 4059934 (Del. Ch. Sept. 7, 2021). Application of Marchand to airplane safety oversight; settled for 237.5 million dollars in 2022.
  5. Shapira, Roy. “A New Caremark Era: Causes and Consequences.” Washington University Law Review, vol. 98, no. 6, 2021, pp. 1857–1911. openscholarship.wustl.edu.
  6. U.S. Government Accountability Office. Cost Estimating and Assessment Guide: Best Practices for Developing and Managing Program Costs. GAO-20-195G, March 2020. gao.gov/products/gao-20-195g. Risk and uncertainty analysis as a component of a credible estimate.
  7. U.S. Government Accountability Office. Schedule Assessment Guide: Best Practices for Project Schedules. GAO-16-89G, December 2015. gao.gov/products/gao-16-89g.
  8. Committee of Sponsoring Organizations of the Treadway Commission. Enterprise Risk Management: Integrating with Strategy and Performance. COSO, 2017. coso.org/guidance-erm.
  9. International Organization for Standardization. Risk Management: Guidelines. ISO 31000:2018. iso.org/standard/65694.html. Clause 5.4.3 on roles, authorities and accountabilities.
DF

About the Author

Dan Flynn

Creator of The Four A's of Organizational Readiness™ · Enterprise Transformation Executive · Author, Builders Build

Dan Flynn has spent thirty years inside federal, defense, and commercial organizations: diagnosing the invisible conditions that determine whether capable people produce extraordinary results. He is the creator of The Four A's of Organizational Readiness™ framework, has reached more than 11,000 professionals across corporate, civic, and national security contexts, and took a federal data platform from one release every six months to seventy-two every two weeks by changing organizational conditions: not people.

His book, Builders Build: The Four A’s of Organizational Readiness™, is forthcoming.