Notes:

  • Oversight vs. Management: The Board’s responsibility is oversight, not management. Management executes risk mitigation strategies; the Board ensures those strategies exist, are effective, and align with the company’s risk appetite.
  • The Caremark Standard (In re Caremark International Inc. Derivative Litigation):
    • A landmark Delaware court ruling establishing that directors have a fiduciary duty to implement and monitor an “information and reporting system” to keep them informed of critical risks.
    • Liability: Directors can be held liable for “sustained or systematic failure” to exercise oversight (e.g., ignoring red flags, failing to monitor critical risks).
    • Protection: To avoid liability, the Board must demonstrate a good-faith effort to establish and monitor a risk reporting system.
  • Risk Appetite and Tolerance:
    • The Board must define the Risk Appetite (the amount of risk the company is willing to accept to achieve its strategy).
    • Risk Tolerance refers to the acceptable variation around specific objectives.
    • The Board must approve these limits and ensure management operates within them.
  • Integration with Strategy: Risk oversight cannot be siloed. The Board must ask: “What risks could prevent us from achieving our strategic goals?” and “How do our risks impact our ability to execute our strategy?”
  • Frequency of Oversight: Risk oversight is not a quarterly checkbox. It requires continuous monitoring, regular briefings from the Chief Risk Officer (CRO), and deep-dive sessions on specific high-priority risks.