Every corporate director understands, at least in the abstract, that serving on a board involves more than showing up to quarterly meetings and approving management’s recommendations. Directors are fiduciaries who owe duties of care and loyalty to the corporation and its shareholders. But there is a third dimension of the duty of care — one that courts have increasingly emphasized over the past three decades — that concerns not specific business decisions but the ongoing, systemic obligation to ensure that the corporation has adequate information and compliance systems in place to detect and respond to legal and regulatory violations. This oversight duty, commonly called the Caremark duty after the Delaware Court of Chancery’s landmark 1996 decision in In re Caremark International Inc. Derivative Litigation, represents one of the most important — and most challenging — aspects of modern board governance.

Caremark claims are notoriously difficult for plaintiffs to win. For most of the two decades following the original Caremark decision, courts consistently dismissed such claims, describing them as the most difficult claims in Delaware corporate law. Yet recent developments — particularly the Delaware Supreme Court’s 2019 decision in Marchand v. Barnhill and the Boeing derivative litigation that resulted in a $237.5 million settlement in 2021 — have demonstrated that Caremark claims can and do succeed when boards have made fundamental, systemic failures to oversee mission-critical risks. For corporate directors, these developments serve as a powerful reminder that oversight is not an optional or ceremonial function. It is a legal obligation, and its failure can carry severe consequences.

The Original Caremark Decision

In re Caremark arose from a series of federal criminal charges and civil litigation against Caremark International, a healthcare company, alleging that the company had paid physicians improper referral fees in violation of federal anti-kickback statutes. The company ultimately pleaded guilty to a criminal charge, paid substantial fines, and entered into settlement agreements with the government. Shareholders then brought a derivative suit alleging that the directors had breached their duty of care by failing to implement adequate compliance systems to prevent the misconduct.

Chancellor Allen’s opinion in Caremark set out the now-canonical framework for board oversight liability. He acknowledged that the business judgment rule generally protects boards from second-guessing of business decisions, but he held that the rule’s protection does not extend to a situation where the board has utterly failed to implement any reporting and information systems or controls, or where, having implemented such systems, the board has consciously failed to monitor them. The Chancellor articulated two distinct paths to Caremark liability: the first is a failure to implement adequate information and reporting systems in the first instance; the second is an active, conscious decision to disregard red flags — known information suggesting that legal violations are occurring — without taking appropriate remedial action.

Critically, Chancellor Allen set a very high bar. He held that director liability for a failure of oversight requires a sustained or systematic failure to exercise reasonable oversight — something qualitatively different from, and far more culpable than, mere inattention or honest mistake. The standard requires a showing that the directors were conscious of their failure to act, not merely that the oversight was less than optimal. This high threshold reflected a deliberate judicial choice: courts do not want to chill directors from serving on boards by exposing them to personal liability every time a compliance failure occurs on their watch.

Stone v. Ritter and the Refinement of the Standard

In 2006, the Delaware Supreme Court unanimously affirmed and refined the Caremark standard in Stone v. Ritter. The court held that Caremark articulates the necessary conditions for establishing director oversight liability: first, the directors utterly failed to implement any reporting or information system or controls; or second, having implemented such a system, they consciously failed to monitor or oversee its operations, thereby disabling themselves from being informed of risks or problems requiring their attention. The Supreme Court also clarified that oversight liability is properly characterized as a subset of the duty of loyalty — specifically, as a violation of the good faith obligation that is itself a component of the duty of loyalty — rather than a pure duty of care claim. This characterization matters because it means that exculpatory charter provisions that eliminate liability for duty of care violations do not protect directors from oversight liability grounded in bad faith or conscious disregard.

Stone v. Ritter also confirmed that a Caremark claim requires the plaintiff to demonstrate not merely a compliance failure in the organization, but a conscious failure at the board level. The fact that employees violated the law, that the company suffered regulatory sanctions, or even that the company paid hundreds of millions in fines and penalties is not, by itself, sufficient to establish that the board breached its oversight duty. Plaintiffs must show that the board made a deliberate choice to remain uninformed — that directors knew they had no oversight systems and did nothing, or that they received red flags and ignored them.

Marchand v. Barnhill: The Revival of Caremark Liability

For many years after Stone v. Ritter, Caremark claims continued to be dismissed at the pleading stage. Courts consistently held that plaintiffs had not adequately alleged the conscious, systematic failure required to rebut the business judgment presumption. Then, in 2019, the Delaware Supreme Court reversed the dismissal of a Caremark claim in Marchand v. Barnhill, allowing the case to proceed against the board of Blue Bell Creameries. The Marchand decision was significant not only for its outcome but for the Supreme Court’s pointed observation that, for a company operating in a highly regulated industry where a critical compliance risk is central to the company’s mission, the board’s failure to put in place any monitoring system for that risk can itself constitute an utter failure of oversight.

Blue Bell Creameries, an ice cream manufacturer, had suffered a listeria contamination outbreak in 2015 that killed three people and caused the company to recall all of its products, shut down operations, lay off thousands of workers, and take on substantial debt to survive. The plaintiffs alleged that the board had completely failed to implement any food safety reporting or oversight system, even though food safety was obviously the most critical compliance and operational risk for a company that made and sold food products for human consumption. The Supreme Court agreed that this was a viable Caremark claim: a board that operates in an industry where the core product creates an existential safety risk, and that has put in place no board-level oversight mechanism for that specific risk, has failed the most basic requirement of Caremark.

Marchand teaches several important lessons for boards. First, industry-specific risks demand industry-specific oversight. A generic enterprise risk management program that addresses financial controls but ignores the most significant regulatory and safety risks of the particular industry does not satisfy the Caremark standard. Second, mission-critical risks must reach the board, not just management. If the board never receives information about the risks that could most severely damage the company — not just through financial metrics, but through direct oversight mechanisms — the board is not doing its job. Third, the level of oversight required is proportional to the significance of the risk: the more existential the risk, the more robust and direct the board’s oversight systems must be.

The Boeing Derivative Litigation

The most consequential Caremark case in recent corporate history involved the Boeing Company in the aftermath of two fatal crashes of the 737 MAX aircraft in 2018 and 2019 that killed 346 people. Following the crashes and the grounding of the 737 MAX worldwide, shareholders brought derivative litigation in Delaware alleging that Boeing’s board had abdicated its oversight responsibilities with respect to the company’s airplane safety compliance systems. In September 2021, Boeing’s board settled the derivative litigation for $237.5 million — at the time the largest derivative settlement in Delaware history — and agreed to significant governance reforms, including the creation of a board-level Aerospace Safety Committee.

The Boeing settlement was remarkable for several reasons. It demonstrated that a board can face serious Caremark consequences even when no individual director was personally implicated in the underlying misconduct. The plaintiffs successfully alleged that the Boeing board had received repeated warnings about safety culture issues and regulatory compliance concerns at the company, that no board-level committee had oversight responsibility for aerospace safety, and that the board had failed to respond adequately to red flags that reached it. The $237.5 million settlement, funded by the company’s D&O insurers and certain directors personally, sent an unmistakable message: boards of major companies with mission-critical regulatory or safety obligations cannot safely ignore those obligations or defer entirely to management on matters that could threaten the company’s existence.

Following the Boeing settlement, Delaware courts and commentators observed a pattern across Caremark cases. Successful Caremark claims tend to share certain features: the company operated in a heavily regulated industry or faced an existential operational risk; the board had no dedicated oversight mechanism for the specific risk area; the company received clear red flags — government warnings, prior violations, internal reports — that the board failed to act on; and the resulting harm was severe, resulting in massive financial penalties, criminal liability, or loss of human life. Where these features are present, the ‘utter failure’ standard may be satisfied notwithstanding the generally high bar for Caremark liability.

Recent Developments: McDonald’s and Expanding Caremark Scope

Delaware courts have continued to develop the Caremark standard in recent years. In In re McDonald’s Corporation Stockholder Derivative Litigation, decided in 2023, the Court of Chancery for the first time found that an officer — not a director — could be held personally liable under an oversight theory analogous to Caremark. The case involved McDonald’s former Chief People Officer, David Fairhurst, who was alleged to have personally created or perpetuated a culture of sexual misconduct and harassment within the company. The court found that an officer who is aware of serious compliance issues within his area of responsibility and who takes no steps to address them — or who is himself a source of the misconduct — may face oversight liability. While the court was careful to note that the standard for officer liability mirrors Caremark’s high bar, the decision expanded the scope of the doctrine and signaled that oversight obligations run not just to boards but to senior corporate executives as well.

Another developing area involves cybersecurity and data privacy oversight. As data breaches and ransomware attacks have become among the most significant operational and legal risks facing US corporations, plaintiffs have begun testing Caremark theories in the cybersecurity context, arguing that boards that fail to implement adequate cybersecurity oversight systems and that ignore known vulnerabilities have breached their oversight duties. While courts have not yet found board-level liability in a cybersecurity Caremark case, the SEC’s 2023 cybersecurity disclosure rules — which require public companies to disclose material cybersecurity incidents within four business days and to describe their board oversight of cybersecurity risks in annual reports — have put boards on notice that cybersecurity oversight is a board-level governance obligation, not merely a management function.

What Boards Must Do to Satisfy the Caremark Standard

Given the Caremark doctrine and its evolution, what must a board actually do to satisfy its oversight obligations? The analysis begins with identifying the material risks that the company faces — particularly the risks that are most likely to cause existential harm, trigger government enforcement, or result in massive liability. For a healthcare company, those risks likely include compliance with federal anti-kickback statutes, the False Claims Act, and FDA regulatory requirements. For a financial services firm, they include anti-money laundering, sanctions compliance, and consumer protection. For a food manufacturer, food safety is obviously paramount. For a technology company, cybersecurity, data privacy, and increasingly, AI governance are critical risk areas.

Once the material risk areas are identified, the board must ensure that it receives regular, substantive information about the company’s compliance posture in those areas. This does not mean that boards must manage compliance day-to-day — that remains a management function. But it does mean that someone at the board level must be responsible for overseeing the management of those risks, and that the board receives information sufficient to assess whether management is doing its job. The assignment of oversight responsibility is typically accomplished through board committee charters: the audit committee oversees financial reporting, internal controls, and legal compliance generally; the nominating and governance committee oversees corporate governance; and in industries with significant operational safety or regulatory risk, a dedicated board committee may be appropriate, as the Boeing governance reforms illustrated.

Red flag management is the second critical element. When management, legal counsel, internal audit, outside auditors, regulators, or whistleblowers surface information suggesting that a significant legal violation may be occurring or that a compliance system is failing, the board must take that information seriously and respond appropriately. ‘Red flags’ do not require certainty — they require a reasonable response in proportion to the severity of the potential harm. A board that receives a warning from a federal regulator about compliance deficiencies in a critical area and then does nothing for months, or that allows management to investigate itself without independent oversight, is at substantial Caremark risk.

Documentation matters enormously. Boards that are in fact engaged with oversight issues but that fail to document their engagement in board and committee minutes are poorly positioned to defend against Caremark claims. When the board discusses a compliance risk, asks management hard questions about a regulatory matter, or commissions an internal investigation, those activities should be reflected in the board record. Minutes that reflect a perfunctory ‘management update’ with no discussion of material compliance issues provide little evidence that the board was doing anything more than going through the motions.

Building a Caremark-Compliant Oversight Framework

Building a board-level oversight framework that satisfies the Caremark standard requires several structural elements. First, the board should conduct an annual risk assessment that identifies the company’s most significant legal, regulatory, operational, and reputational risks and assigns oversight responsibility for each to an appropriate board committee. Second, each committee’s charter should explicitly assign oversight responsibility for its designated risk areas and should specify the frequency and content of management reports to the committee. Third, management should provide regular, substantive compliance reports to the appropriate committee — not just high-level assurances, but detailed information about compliance metrics, ongoing investigations, government interactions, and known deficiencies. Fourth, the board should have direct access to the chief compliance officer, general counsel, and chief audit executive, with a clear protocol for escalating serious issues directly to the board, bypassing management when necessary. Fifth, the board’s independent auditors and any outside legal counsel retained for specific matters should have direct access to the full board and to audit committee members in executive session without management present.

Whistleblower systems deserve particular attention. The availability and integrity of a whistleblower hotline or reporting mechanism — one that employees trust and that actually results in issues being investigated and, where appropriate, escalated to the board — is an important indicator of a functioning compliance culture and an important element of a Caremark-compliant oversight structure. Boards should periodically review the volume and subject matter of whistleblower complaints, the results of investigations, and any patterns that might suggest systemic issues.

Finally, boards should periodically test the adequacy of their oversight systems by commissioning independent compliance assessments or tabletop exercises that simulate how the company would respond to a significant compliance crisis. These exercises — analogous to cybersecurity breach simulations that have become standard practice at many companies — can surface gaps in board-level information flows and escalation protocols before those gaps manifest themselves in an actual crisis. Directors who can demonstrate that they actively participated in building and testing the company’s compliance oversight framework are in a far stronger position to defend against Caremark claims than those who can only point to generic board minutes and management assurances.

The Caremark doctrine reflects a fundamental truth about corporate governance: boards cannot simply delegate risk management to management and then disclaim responsibility when things go wrong. The legal obligation to oversee the corporation — to ensure that adequate systems exist to detect and prevent violations of law — rests with the board, not just with management. As Delaware courts have made increasingly clear through Marchand, Boeing, and McDonald’s, boards that fail this obligation face not just embarrassment and remediation requirements, but the real prospect of personal financial liability. The investment in robust, well-documented board-level oversight is, in every sense, risk management for the directors themselves.

See Also