Directors owe a duty of oversight, breached where they utterly fail to implement a reporting system, or having implemented one, consciously fail to monitor it so that they are disabled from being informed of risks.
A demanding but no longer theoretical standard. Claims have survived dismissal where boards had no committee charged with the central compliance risk, no regular reporting on it, and no board-level record of discussion, and where red flags were presented and not pursued.
Mission-critical risks. Courts distinguish between ordinary business risk and the risk that is essential to the company’s operations. For those, the board must have a monitoring system directed specifically at that risk.
What a defensible record looks like. A committee with a charter covering the risk; regular reporting on defined metrics; minutes reflecting substantive discussion and the questions asked; escalation protocols; and evidence that red flags were pursued.
Red flags. Regulatory findings, whistleblower reports, internal audit adverse findings, and material incidents. What matters is what the board did on learning of them.
Practical steps. Identify the mission-critical risks explicitly; assign each to a committee or the full board; set a reporting calendar; and record the discussion, not only the resolution.
Books and records demands are the usual precursor to these claims, and the minutes are what will be produced.