A Caremark claim is a shareholder derivative lawsuit that holds corporate directors — and, since 2023, officers — personally liable for failing in bad faith to monitor their company’s legal and regulatory compliance, even when they did not participate in the underlying misconduct. The theory takes its name from the 1996 Delaware Court of Chancery decision In re Caremark International Inc. Derivative Litigation, which held that directors owe a duty to make a good-faith effort to ensure the corporation has adequate information and reporting systems.1Justia. In re Caremark International Inc. Derivative Litigation Delaware courts have described it as “possibly the most difficult theory in corporation law upon which a plaintiff might hope to win a judgment,” but recent rulings have given it real force where a company’s core business carries obvious regulatory risk.
The Two Ways a Board Fails Oversight
Every Caremark claim runs through one of two prongs, both aimed at the same question: did the board act in bad faith by ignoring its monitoring responsibilities?
The first prong is the “utter failure” scenario the original Caremark decision described. The board made no good-faith effort to establish any reporting or compliance framework at all. Directors stayed ignorant of operational and legal risks not because information was hidden from them, but because they never asked for it.1Justia. In re Caremark International Inc. Derivative Litigation
The second prong targets boards that had monitoring systems in place but consciously disregarded clear warning signs. This path requires evidence that specific red flags reached the directors and that they chose not to investigate or act.
The distinction shapes the litigation. A company with board committees, compliance officers, and regular management reports will usually defeat a first-prong claim. But if those reports contained warnings the board ignored, second-prong liability can follow. Delaware General Corporation Law Section 141(e) lets directors rely in good faith on reports from officers, employees, and outside experts, but that safe harbor presupposes the directors set up a system that actually generates reports worth relying on.2Delaware Code Online. Delaware Code 8-141 – Board of Directors; Powers; Number, Qualifications, Terms and Quorum A board that never asks for compliance reports cannot claim to have relied on them.
Caremark is not a negligence standard. Ordinary bad business decisions remain shielded by the business judgment rule. Liability attaches only when directors consciously abdicate their monitoring role, which Delaware courts treat as bad faith implicating the duty of loyalty.
Mission-Critical Risks Get Extra Scrutiny
Not every regulatory risk triggers heightened oversight obligations. Delaware courts have concentrated Caremark liability on risks that are “mission critical” to the company’s business. The idea is simple: if a legal or safety requirement is so central to operations that violating it could destroy the business, the board must have a system specifically designed to monitor that area.
The landmark modern case is Marchand v. Barnhill (2019). The Delaware Supreme Court revived a Caremark claim against the board of Blue Bell Creameries after a listeria outbreak killed three people, holding that “food safety was essential and mission critical” for an ice cream manufacturer and that the complaint supported a fair inference that “no board-level system of monitoring or reporting on food safety existed.”3Justia. Marchand v. Barnhill General compliance with some food safety regulations was not enough. What mattered was whether the board itself received regular information about food safety risks and had protocols for escalating problems.
The same logic has been applied to airplane safety for aviation manufacturers, cybersecurity for technology companies handling sensitive data, and workplace conduct for companies facing repeated harassment complaints. The test is whether a regulatory failure in that area could cause “egregious long-run harm to the firm.” Where it could, directors face enhanced obligations: designating a responsible board committee, requiring management to report compliance deficiencies, and taking primary responsibility for investigating problems when they surface.
Why Exculpation Clauses Do Not Help
DGCL Section 102(b)(7) lets companies shield directors and officers from personal liability for breaches of the duty of care, but it explicitly carves out breaches of the duty of loyalty, acts not in good faith, intentional misconduct, knowing violations of law, and transactions yielding improper personal benefits.4Delaware Code Online. Delaware Code 8-102 – Certificate of Incorporation; Contents Because Caremark claims are framed as loyalty breaches rooted in bad faith, exculpation provisions offer no defense. That is the structural feature that makes oversight litigation dangerous: the charter provision that protects directors from most shareholder lawsuits does not protect them here.
Directors’ and officers’ insurance often covers defense costs and settlement amounts, but D&O policies typically exclude coverage for conduct found to constitute bad faith or intentional misconduct, which is exactly what a Caremark claim targets. If a case goes badly enough, directors can end up personally responsible for amounts insurance will not cover.
Officers Now Owe the Same Duty
Until recently, Caremark applied only to boards. That changed in 2023, when the Delaware Court of Chancery held in In re McDonald’s Corp. Stockholder Derivative Litigation that corporate officers also owe oversight duties. Officers must make a good-faith effort to establish reasonable information and reporting systems within their areas of responsibility, and they must respond to red flags that come to their attention. The court recognized a practical limit — officers are generally responsible only for problems within their domain — but a “particularly egregious red flag” might require action even from an officer whose job description does not cover it.
What a Shareholder Has to Do to Bring a Claim
Caremark claims are derivative actions, meaning a shareholder sues on behalf of the corporation. The procedure imposes several requirements before a case can move forward.
Who Can Sue
The shareholder must have owned stock when the alleged oversight failure occurred and must continue holding shares throughout the litigation. These rules prevent someone from buying in after a scandal breaks just to file suit.
Demand and Demand Futility
Before filing, a shareholder normally has to ask the board to pursue the claim itself. Most Caremark plaintiffs skip that step by arguing demand futility — the board is too conflicted to fairly evaluate a lawsuit targeting its own members. In 2021, the Delaware Supreme Court consolidated older tests into a single three-part framework in United Food v. Zuckerberg. Courts now evaluate each director individually and ask whether that director received a material personal benefit from the alleged misconduct, faces a substantial likelihood of liability on the claims, or lacks independence from someone who did. If the answer to any of these questions is “yes” for at least half the board, demand is excused. The composition of the board at the time the suit is filed matters, because a board that has turned over significantly since the underlying events is harder to characterize as conflicted.
Timing
The Court of Chancery generally applies the doctrine of laches to fiduciary duty claims and analogizes to the three-year limitations period in 10 Del. C. § 8106, which covers actions for “damages caused by an injury unaccompanied with force.”5Delaware Code Online. Delaware Code 10-8106 – Actions Subject to 3-Year Limitation Filing more than three years after the claim accrued creates a presumption of unreasonable delay. Tolling can extend the window, but shareholders who sit on obvious red flags face an uphill battle.
Investigating First
Delaware courts expect shareholders to do their homework before filing. The primary tool is a books-and-records demand under DGCL Section 220, which gives any stockholder the right to inspect corporate records for a “proper purpose” reasonably related to their interest as a stockholder. Investigating suspected mismanagement or breaches of fiduciary duty qualifies. The demand must be made in writing under oath and must describe the purpose and the specific documents sought with reasonable particularity.6Justia. Delaware Code 8-220 – Inspection of Books and Records This is not fishing-expedition discovery; requested documents must be “essential and sufficient” to the stated purpose.
Shareholders typically seek board meeting minutes, audit committee reports, and internal memos about regulatory compliance. Electronic communications like emails and Slack messages may also be available, but only when they are the sole documentary evidence of board involvement on a particular issue and no formal minutes exist. The Marchand court specifically praised the plaintiff for following the Section 220 process before filing, and plaintiffs who skip that step risk having their complaints dismissed for insufficient factual support.3Justia. Marchand v. Barnhill
Filing
Caremark cases are filed in the Delaware Court of Chancery, the specialized equity court that handles most corporate governance disputes. All filings go through the File & ServeXpress system and require a Delaware-licensed attorney.7Delaware Courts. Court of Chancery The complaint must be verified by the plaintiff and must plead with particularity either the demand made on the board or the reasons demand was excused as futile.
How the Case Usually Ends
Most Caremark claims end at the motion-to-dismiss stage. Defendants argue that the complaint fails to plead facts supporting a reasonable inference of bad faith. The pleading standard is deliberately high, designed to screen out claims that second-guess legitimate business decisions while letting genuinely egregious oversight failures proceed to discovery.
A case that survives dismissal still faces another obstacle. The board can appoint a special litigation committee, typically two or three independent directors who were not on the board during the events at issue, to investigate the claims and recommend whether the suit should continue. Under the framework from Zapata Corp. v. Maldonado, if the committee concludes the litigation is not in the corporation’s best interest, the court examines whether the committee members were genuinely independent, whether the investigation was conducted in good faith, and whether the committee had a reasonable basis for its conclusion. The court may then apply its own independent business judgment. A well-constructed committee process can end a case even when the underlying facts are troubling, which is why plaintiffs try to build a Section 220 record strong enough that no committee can credibly conclude the directors acted in good faith.
Cases that survive both hurdles usually settle. Because derivative suits are brought on behalf of the corporation, any recovery flows to the company, not directly to the shareholder plaintiff. The individual plaintiff’s incentive comes from the fee structure: if the suit produces a benefit for the corporation, the Court of Chancery awards attorney’s fees from the recovery under the common benefit doctrine. Fee awards scale with the stage at which the case resolves — roughly 10 to 15 percent of the fund for early settlements, 15 to 25 percent after discovery and motion practice, and up to about 33 percent after trial. These are guidelines rather than fixed rules, and the court weighs the quality of the result, the complexity of the litigation, and the risk the plaintiffs’ attorneys assumed.
What Protects a Board
Companies that take compliance seriously before a crisis have the strongest defenses. Courts have dismissed Caremark claims where the board could demonstrate a track record of active oversight: committees specifically tasked with monitoring mission-critical risks, regular meetings to review detailed management reports, engagement of outside auditors and consultants, and documented deliberations and follow-up actions. The paper trail matters. A board that discussed food safety every quarter and acted on warnings is in a fundamentally different position from one that never put the topic on an agenda.
Directors should focus on areas of concentrated regulatory risk. A pharmaceutical company’s board needs a system for monitoring FDA compliance. A financial institution’s board needs reporting on lending practices and anti-money-laundering controls. A technology company handling sensitive customer data needs cybersecurity oversight. The more central the risk is to the business model, the more specific and robust the monitoring system needs to be. Generic compliance programs that check a box without funneling real information to the board will not satisfy the standard when something goes wrong.