Corporate Governance & Directors and Officers (D&O)

Corporate governance is the framework of rules, practices, and relationships through which a company is directed and controlled. For directors and officers, it defines the fiduciary duties they owe to the corporation and its shareholders, the standard of care they must meet in making business decisions, and the personal liability they face when things go wrong. For shareholders, it sets the rules that protect their investment and give them recourse when management fails them. Whether you are a board member navigating a crisis, an officer facing a shareholder demand, a general counsel advising on governance risk, or a private equity sponsor structuring a portfolio company, understanding the fundamentals of corporate governance law is essential.

Fiduciary Duties of Directors and Officers

Directors and officers of US corporations owe fiduciary duties to the corporation and its shareholders. The three core duties are the duty of care, the duty of loyalty, and the duty of good faith. The duty of care requires directors and officers to act with the care that a reasonably prudent person in a similar position would exercise under similar circumstances—essentially, to be informed and deliberate when making business decisions. The duty of loyalty requires them to act in the best interests of the corporation rather than in their own personal interests, and to avoid self-dealing transactions that benefit themselves at the corporation’s expense. The duty of good faith, often treated as a component of the duty of loyalty under Delaware law, requires directors and officers to act with an honest belief that their actions are in the best interests of the company.

These duties are not merely abstract principles. Breach of fiduciary duty is one of the most common theories of liability in corporate litigation, and failures—particularly in the context of self-dealing transactions, conflicted compensation decisions, and inadequate oversight of compliance functions—have resulted in significant personal liability for directors and officers in high-profile cases. Shareholders who believe directors or officers have breached these duties may bring derivative suits on behalf of the corporation or direct claims in their own right.

The Business Judgment Rule

The business judgment rule is the primary shield that protects directors from personal liability for good-faith business decisions. Under this doctrine, courts will defer to decisions made by directors who were informed, acted in good faith, and did not have a personal financial interest in the outcome—even if the decisions turned out to be wrong. The rule reflects a fundamental principle of corporate law: courts are not in the business of second-guessing reasonable business decisions made by people with relevant expertise. However, the business judgment rule is not unlimited. It will not protect decisions infected by conflicts of interest, decisions made without adequate information, or decisions that constitute an abdication of the board’s responsibilities rather than an exercise of judgment.

Board Oversight and the Caremark Standard

One of the most significant developments in corporate governance law over the past three decades is the recognition that directors can face liability not just for bad decisions they make, but for failing to have adequate oversight systems in place. The standard comes from the Delaware Court of Chancery’s 1996 decision in In re Caremark International Inc. Derivative Litigation, which held that a board’s failure to implement a reasonable compliance and reporting system—or its failure to act on red flags that such a system surfaces—can constitute a breach of the duty of loyalty.

While Caremark claims have historically been difficult for plaintiffs to win, recent Delaware decisions have allowed oversight claims to survive in cases involving serious compliance failures, including data security incidents, financial fraud, and regulatory violations that the board knew about or should have known about. For today’s boards, this means that meaningful oversight of compliance, cybersecurity, financial controls, and legal risk is not just good governance—it is a legal obligation. Boards should ensure that reporting structures, audit functions, and whistleblower channels are designed to surface problems before they become crises.

Director Independence and Committee Requirements

Public companies listed on major US stock exchanges are required to maintain a board with a majority of independent directors, and audit, compensation, and nominating/governance committees composed entirely of independent directors. Independence requirements are designed to ensure that directors exercising oversight of management—approving executive compensation, overseeing financial reporting, and nominating future directors—are not beholden to the executives they are supposed to oversee. The SEC, NYSE, and Nasdaq have detailed and sometimes overlapping standards for what constitutes independence, and companies must carefully evaluate the relationships of their directors against those standards. A director who fails an independence test can compromise the composition of a key committee, trigger disclosure obligations, and expose the company to shareholder criticism and litigation.

Audit Committee Responsibilities

The audit committee is the board’s primary oversight body for financial reporting, internal controls, and the external audit function. Under the Sarbanes-Oxley Act and SEC rules, audit committees of public companies are responsible for appointing, compensating, and overseeing the independent auditor; reviewing annual and quarterly financial statements; overseeing internal audit functions and internal controls over financial reporting; and establishing procedures for receiving and handling complaints about accounting and auditing matters, including anonymous submissions from employees. The audit committee is also increasingly expected to oversee cybersecurity risk, given that material cybersecurity incidents can have a direct impact on financial reporting and disclosure obligations.

D&O Insurance: Coverage, Gaps, and Policy Pitfalls

Directors and officers (D&O) insurance is designed to protect individual directors and officers from personal financial loss arising from claims made against them in their corporate capacity. A typical D&O policy has three coverage parts: Side A covers individual directors and officers when the company cannot or does not indemnify them; Side B reimburses the company when it indemnifies directors and officers; and Side C (entity coverage) covers the company itself for securities claims. Understanding the boundaries of each coverage part—and the exclusions, retentions, and notice requirements that apply—is critical before a claim arises, not after.

Common D&O coverage disputes arise over the conduct exclusion (which can bar coverage for fraudulent or criminal acts), the insured-versus-insured exclusion (which can bar coverage for claims by the company against its own directors and officers), late notice, and allocation between covered and uncovered claims. Companies should review their D&O policies carefully on a regular basis, ensure that Side A limits are adequate for individual directors and officers, and consider whether difference-in-conditions (DIC) Side A coverage is appropriate as an additional layer of protection.

Indemnification of Directors and Officers

Corporate law in most US states allows—and in some circumstances requires—companies to indemnify their directors and officers against expenses, judgments, fines, and settlements arising from their service to the corporation, provided they acted in good faith and in a manner they reasonably believed to be in the corporation’s best interests. Most companies provide maximum indemnification protections through their charter, bylaws, and individual indemnification agreements. These agreements often include advancement of defense costs, which can be critical when an individual director or officer faces a lengthy government investigation or litigation and needs funding to pay counsel before any final disposition. The interplay between corporate indemnification and D&O insurance—and the question of which source of protection pays first—can be complex and should be carefully structured in advance.

Shareholder Litigation: Derivative and Direct Claims

Shareholders who believe that directors or officers have breached their fiduciary duties can bring claims in two procedural forms. A direct claim is one where the shareholder alleges a harm to themselves personally—most commonly in the context of securities fraud or disclosure violations. A derivative claim is one brought by a shareholder on behalf of the corporation to redress harm done to the company—for example, a claim that directors approved an interested transaction that enriched themselves at the corporation’s expense. Derivative suits require the plaintiff to make a pre-suit demand on the board (or demonstrate that such demand would be futile), are subject to dismissal if the board or a special litigation committee properly investigates and decides in good faith not to pursue the claim, and are governed by rules that can vary significantly by state of incorporation.

Corporate Governance for Private Companies

Strong governance is not only a public company issue. Private companies—including venture-backed startups, family businesses, and private equity portfolio companies—face the same fiduciary duty principles that apply to public companies, and the consequences of governance failures can be just as serious. Investor agreements typically impose governance obligations on portfolio companies, including board composition requirements, information rights, and approval rights for significant transactions. Founders and controlling shareholders of private companies must be especially alert to the duty of loyalty in squeeze-out transactions, charter amendments, and financing rounds that dilute minority holders. Disputes among founders, between founders and investors, and in connection with M&A transactions are a significant source of private company governance litigation.

Emerging Governance Issues: Cybersecurity, AI, and ESG

Boards today face governance obligations that would have seemed novel a decade ago. The SEC’s cybersecurity disclosure rules require public companies to disclose material cybersecurity incidents within four days and to make annual disclosures about cybersecurity risk management, strategy, and governance—including whether and how the board oversees cybersecurity risk. The rise of agentic AI has introduced new board-level oversight questions about autonomous decision-making systems, data governance, and liability exposure for AI failures. And the expanding ESG regulatory landscape—from SEC climate disclosure rules to California’s SB 253 and the EU’s CSRD—is creating new governance obligations around environmental and social risk disclosure. Boards that treat these as IT, legal, or sustainability department issues alone, rather than governance priorities requiring meaningful board engagement, are taking on risk.

How We Can Help

Our corporate governance practice advises directors, officers, general counsel, and audit committees on fiduciary duty compliance, board composition and independence, D&O insurance program structure and claims, indemnification agreements, special committee engagements, and governance-related disclosure obligations. We represent companies and individuals in derivative litigation, books-and-records demands, and government investigations involving governance failures. We also advise private companies and their founders and investors on governance structures, investor agreements, and dispute resolution. Whether you are building a governance framework for a growing company, responding to a shareholder demand, or navigating a board-level crisis, we are here to help.

See Also