Notes:
- Oversight vs. Management: The Board’s responsibility is oversight, not management. Management executes risk mitigation strategies; the Board ensures those strategies exist, are effective, and align with the company’s risk appetite.
- The Caremark Standard (In re Caremark International Inc. Derivative Litigation):
- A landmark Delaware court ruling establishing that directors have a fiduciary duty to implement and monitor an “information and reporting system” to keep them informed of critical risks.
- Liability: Directors can be held liable for “sustained or systematic failure” to exercise oversight (e.g., ignoring red flags, failing to monitor critical risks).
- Protection: To avoid liability, the Board must demonstrate a good-faith effort to establish and monitor a risk reporting system.
- Risk Appetite and Tolerance:
- The Board must define the Risk Appetite (the amount of risk the company is willing to accept to achieve its strategy).
- Risk Tolerance refers to the acceptable variation around specific objectives.
- The Board must approve these limits and ensure management operates within them.
- Integration with Strategy: Risk oversight cannot be siloed. The Board must ask: “What risks could prevent us from achieving our strategic goals?” and “How do our risks impact our ability to execute our strategy?”
- Frequency of Oversight: Risk oversight is not a quarterly checkbox. It requires continuous monitoring, regular briefings from the Chief Risk Officer (CRO), and deep-dive sessions on specific high-priority risks.