From Caremark to AI: The Evolution of Board Monitoring Duty
From Caremark to AI: The Evolution of Board Monitoring Duty
The Caremark Doctrine: A 30-Year Journey
In 1996, the Delaware Supreme Court established a landmark principle: directors have a fiduciary duty not just to make good decisions, but to establish systems that monitor material risks. This is the Caremark doctrine, named after the case In re Caremark International Inc. Derivative Litigation.
The principle sounds simple: boards can't just hope things go well. They must build governance systems — monitoring, reporting, escalation — that surface risks so the board can respond.
For 20+ years, Caremark applied primarily to financial controls, anti-corruption, and compliance. The board's job was to ensure systems existed to catch accounting fraud, bribery, and regulatory violations.
Then two cases changed everything.
The Turning Point: Marchand v. Barnhill (2019)
Delaware expanded Caremark in Marchand v. Barnhill, a case about food safety at Blue Bell ice cream.
The key insight: Caremark applies not just to compliance risks, but to "mission-critical" operational risks. Food safety wasn't a back-office compliance issue — it was core to the business. When the company failed to establish a monitoring system for food safety, and a listeria outbreak occurred, directors were personally liable.
The court asked: Is this risk material enough that a reasonable director would monitor it? For Blue Bell, the answer was yes. Food safety is mission-critical.
This expanded Caremark beyond "compliance" into "material business risks."
The Modern Test: Boeing and the Red Flags Doctrine (2021)
The second turning point came in City of Providence v. Boeing, where Delaware clarified the red flags doctrine.
Directors are liable not just for failure to establish monitoring systems, but also for failure to respond to clear warning signs that a system has failed.
In Boeing's case:
- The company had a safety monitoring system (first-line oversight).
- Multiple red flags appeared (incidents, regulatory warnings, safety concerns).
- The board did not adequately respond to or escalate these red flags.
- Directors were held liable despite the existence of monitoring systems.
The lesson: Caremark requires not just systems, but attention. If red flags appear, the board must act.
Why This Matters for AI: The Mission-Critical Threshold
AI is now crossing the mission-critical threshold in three ways:
1. Revenue-Critical AI If AI systems directly generate revenue (product recommendations, pricing algorithms, customer service), failure exposes the company to revenue loss. This is material.
2. Compliance-Critical AI If AI systems make or inform decisions regulated by law (hiring, lending, benefits, criminal justice support), failure creates legal liability. This is mission-critical.
3. Safety-Critical AI If AI systems affect safety (autonomous systems, medical devices, industrial control), failure creates physical harm. This is obviously mission-critical.
Most companies have AI systems in at least one of these categories. The Caremark duty now applies to AI.
What Caremark Requires: The Three Obligations
For AI systems that meet the mission-critical threshold, directors must establish:
Obligation 1: A Monitoring System
The board must ensure formal systems exist to:
- Inventory high-risk AI systems
- Document their purpose, data sources, and decision impact
- Monitor performance and drift
- Surface incidents and safety concerns
- Report findings to senior management and the board
This is the Three Lines model. Operational teams monitor daily performance (first line). Risk and compliance teams audit for regulatory and fairness violations (second line). Internal audit tests the whole system (third line).
Without a formal monitoring system, directors breach their Caremark duty simply by deploying AI.
Obligation 2: Clear Reporting Lines
The board must ensure that AI governance reports flow to:
- The board or audit committee (quarterly or semi-annual)
- Executive leadership (monthly or quarterly)
- The CEO and CFO (for disclosure decisions)
If an incident occurs and the board was not informed because reporting lines were unclear, that's breach of duty.
Obligation 3: A Documented Response Protocol
If red flags appear (model drift, fairness violation, compliance breach, incident), the board must have a protocol to:
- Escalate immediately
- Investigate root cause
- Take corrective action
- Document the response
Inaction, with documented knowledge of a red flag, is the clearest evidence of breach.
Connecting the Dots: Caremark + Marchand + Boeing for AI
Here's how the evolution of Caremark applies to AI:
| Case | Principle | AI Application | |------|-----------|-----------------| | Caremark (1996) | Board must establish monitoring systems for material risks | AI systems touching material decisions require formal governance | | Marchand (2019) | Mission-critical operational risks also trigger Caremark duty | Revenue-critical, safety-critical, and compliance-critical AI are now "mission-critical" | | Boeing (2021) | Board must respond to red flags, not just establish systems | If audits reveal bias, compliance gaps, or incidents, the board must act |
Taken together: Directors now face personal liability for failure to establish AI governance systems, and for failure to respond when those systems surface red flags.
The Practical Fiduciary Test
Directors should ask themselves these questions:
-
Do we have a formal inventory of AI systems that are material to the business?
- If no: Caremark duty breach.
- If yes, but it's incomplete or out of date: Red flags doctrine — breach if incident occurs.
-
Do we have a second-line governance function that explicitly owns AI compliance, fairness, and regulatory alignment?
- If no: Caremark duty breach.
- If yes, but it's under-resourced: Red flags doctrine — breach if violation goes undiscovered.
-
Does AI governance report to the audit committee at least quarterly?
- If no: Caremark duty breach (board has no visibility).
- If yes, but the board doesn't respond to escalations: Boeing red flags — breach.
-
Do we have documented incident response protocols for AI?
- If no: Caremark duty breach.
- If yes, but we don't follow them: Boeing breach.
If you answer "no" to any of these, you have a documented governance gap that creates director liability.
Why Inaction Is the Riskier Position
Here's the uncomfortable truth: A director who votes for a formal AI governance system, even if imperfect, establishes a defense. The board has done its job — it's established a system to monitor a material risk.
A director who votes against AI governance, or abstains, with knowledge that the company deploys material AI systems, has no defense. If an AI incident occurs later, that director's inaction is documentary evidence of breach.
Delaware courts have made this clear: Caremark is about process, not outcomes. You don't have to guarantee AI systems are perfect. You have to guarantee the board knows what they're doing and has systems to respond.
Next Steps: The Board's Caremark Checklist
- [ ] Inventory of AI systems material to the business (complete and current)
- [ ] Second-line governance function with explicit AI responsibility
- [ ] Risk register documenting high-risk AI systems
- [ ] Quarterly reporting to audit committee on AI governance metrics
- [ ] Documented incident response protocol
- [ ] Board minutes showing discussion of AI governance and oversight
- [ ] Regular (annual or bi-annual) assessment of system adequacy
Boards that check all these boxes have a credible Caremark defense. Boards that don't are exposed.
Word count: ~1,800 | Reading time: 15 minutes