Skip to content

Menu

LexBlog, Inc. logo
NetworkSub-MenuBrowse by SubjectBrowse by PublisherJoin the NetworkGet StartedSubscribeSupportContact
Search
Close

Guest Post: Board Oversight of Self-Insured Launch Risk

By Kevin LaCroix on August 17, 2026
Email this postTweet this postLike this postShare this post on LinkedIn
Vijay Jyotish

In the following guest post, Vijay Jyotish, who writes on forecasting and decision-making under uncertainty, argues that launch-day decisions for self-insured space missions can expose companies to hundreds of millions of dollars in risk, yet often bypass board-level oversight because they are treated as engineering decisions rather than enterprise risks. The author contends that evolving Delaware case law increasingly requires boards to have documented systems for monitoring mission-critical risks, and recommends a process for recording and reviewing launch-day risk assessments before each launch. Our thanks to Vijay for allowing us to publish his article on this site. Here is Vijay’s article.

*********************************

Somewhere in the next few weeks, an American company will make a multi-hundred-million-dollar decision in about thirty seconds, and no board committee will ever see a record of it.

The decision is the launch decision — not whether to build the satellite, buy the rocket, or sign the insurance binder, all of which boards see, but whether to fly on that particular day. In the American space economy that decision is made inside an engineering poll, documented (if at all) in ephemeral operational records, and treated by every layer of governance above it as a technical fact rather than a governable risk. Meanwhile the exposure riding on it has become one of the largest routinely unexamined line items in the market: a review of two dozen recent launches (2023–2026, across five launch organizations) finds the missions carried roughly $6.2 billion of publicly documented cost — NASA OIG, GAO, and SEC figures — with exactly one commercially insured asset among them, a $30 million policy.

This post makes three claims. First, launch-day risk systematically escapes the oversight structures boards already run, for reasons that are structural rather than negligent. Second, under the Caremark line of cases as sharpened by Marchand and applied in Boeing, that escape is becoming legally untenable for space-exposed companies: a substantially self-insured launch book is close to a textbook example of “mission-critical” risk for which directors are expected to demand a board-level information system. Third — and this is the constructive point — a documented, board-legible launch-day risk process is neither hypothetical nor expensive; its elements can be specified in a page, and a working example already exists in public. The post closes with five questions an audit committee of any space-exposed company can ask at its next meeting.

I. How a $6.2 billion exposure escapes four oversight systems at once

Boards of space-exposed companies are not inattentive. The same companies that fly self-insured missions run sophisticated enterprise-risk programs, audit committees with published charters, cyber oversight that would satisfy any proxy advisor, and disclosure-committee machinery tuned to the last comma. Launch-day risk slips past all four, through four distinct mechanisms.

1. It is classified as an engineering fact, not an enterprise risk. The go/no-go decision belongs to a launch director and a poll of subsystem leads. That is as it should be — nobody wants a board flying rockets. But classification drives paperwork: engineering decisions generate engineering records (telemetry, anomaly reports, readiness reviews), not risk records. There is typically no document, created before the window, that states in plain language what risk the enterprise believed it was accepting by flying that day rather than another — the one document a board, a regulator, or a plaintiff’s lawyer would later ask for.

2. Self-insurance removes the only external institution that prices the day. When a mission is commercially insured, an underwriter interrogates the risk, charges a premium that moves with the vehicle’s record, and creates a paper trail: submission, slip, premium, claim. When a company self-insures — as the largest launch operator does for its own vehicle risk, and as the U.S. government does for its payloads as standing practice — every one of those disciplines disappears. Self-insurance is not merely a choice about risk transfer; it is the silent dismissal of the one third party whose job was to write the risk down. A self-insured launch book is an underwriter that charges itself zero and files no reports.

3. Reliability statistics average over years, while the exposure is per-day. The standard governance artifact for launch risk — a vehicle reliability percentage — answers the wrong question. A 99%-reliable vehicle at the cadence the U.S. Space Force itself projects (up to 3,000 launches per year by 2036, per its Objective Force Design 2040 planning, as reported by Defense One) is a vehicle that fails roughly thirty times a year. At rate, failure is not an event; it is a line item. Boards govern line items with processes, not with percentages.

4. The costs of caution are invisible while the costs of loss are episodic. Scrubs and slips carry real money — schedule penalties, standing-army costs, and, for insured missions, a named actuarial problem: premium and reserves misaligned by delay. But slip costs dissolve into operations while losses arrive as discrete catastrophes. An oversight system that never sees the price of not flying cannot evaluate the decision to fly; it only ever audits the disasters.

The result is a governance inversion that would be unthinkable in any other risk domain: the single most value-dense hour in the company’s year — the hour when the entire asset either reaches orbit or does not — is the hour with the thinnest board-legible record. Exhibit 1 assembles recent, publicly documented outcomes. The pattern to notice is not the losses; it is the two right-hand columns. Where a third party priced the risk, a record exists. Where no one did, the record is whatever the post-incident investigation reconstructs.

Mission · DateDocumented outcomePriced by a third party?Pre-event record beyond engineering?
ViaSat-3 F1 · Jul 2023Antenna failure after a clean Falcon Heavy flight; $421M insurance claim — the anchor of the market’s worst loss year in decades.Yes — insuredUnderwriting file: submission, premium, claim record.
Peregrine / Vulcan Cert-1 · Jan 2024Lander lost hours after a flawless first flight; ~$97M of the $108M NASA delivery award was already milestone-paid — only ~10% was gated on success (NASA OIG CLPS audit reporting).No — structuralNone — payment structure decided years earlier; no day-level record.
Falcon 9 second stage · Jul 2024Vehicle failure (Starlink 9-3); zero commercial claim — the operator self-insures its own vehicle risk.No — self-insuredNone external — engineering records only.
SpainSat NG-2 · Oct 2025Military communications satellite declared non-recoverable; $400M insured loss — erased the market’s brief return to profit.Yes — insuredUnderwriting file exists.
BlueBird-7 / New Glenn NG-3 · Apr 2026Upper-stage underperformance stranded the satellite; $30M insured total loss; the owner’s 8-K puts total company impact at $155–160M.Partially — ~20% of impactUnderwriting file covers the insured slice only.

Exhibit 1 · What recent bad days cost — and who had priced the risk. Context: 2023 produced roughly $1.4B of space-insurance claims against ~$0.55B of premium, the market’s first negative five-year margin since 2001 (Carrier Management). Where the third-party column reads “No,” the enterprise bore the day unpriced — and undocumented.

II. What Caremark, Marchand, and Boeing actually require

The legal baseline is familiar to this readership. In re Caremark (Del. Ch. 1996) established that directors must make a good-faith effort to assure that adequate information and reporting systems exist; Stone v. Ritter (Del. 2006) framed liability as a bad-faith failure to implement any such system or to monitor it. For two decades the doctrine’s practical bite was limited — Chancellor Allen himself called it “possibly the most difficult theory in corporation law upon which a plaintiff might hope to win a judgment.”

Marchand v. Barnhill (Del. 2019) changed the geometry. For a monoline ice-cream maker, the Delaware Supreme Court held, food safety was “intrinsically critical” — mission-critical — and a board with “no committee overseeing food safety, no full board-level process to address food safety issues, and no protocol by which the board was expected to be advised of food safety reports” had not satisfied Caremark’s minimum. The teaching was not that boards must prevent bad outcomes; it was that for the risk at the heart of the business model, directors must be able to show a system — a standing, documented channel through which that specific risk reaches the board.

In re Boeing (Del. Ch. 2021) applied the template to aviation: for an airplane manufacturer, airplane safety is mission-critical, and the complaint’s allegations — no board committee charged with safety, no regular safety reporting, management treating safety as an engineering matter below the board’s line of sight — survived the motion to dismiss. The derivative claims settled for $237.5 million, reported as the largest Caremark-class settlement in Delaware history, with board-structure reforms attached.

Now run the syllogism for a company whose enterprise value concentrates in launched assets. Is launch success mission-critical in the Marchand sense? For a satellite operator whose constellation is the balance sheet, or a launch provider whose flight record is the product, the question answers itself. Does a documented, board-level information system exist for the risk as it is actually taken — day by day, window by window? At most space-exposed companies the honest answer today is the Blue Bell answer: the risk is managed diligently below the board, in a form the board never sees, generating no record the board could later point to.

Two clarifications keep this argument honest. First, Caremark claims remain hard to win, and nothing here predicts liability for any company. The claim is directional: the doctrine now asks, for mission-critical risk, “show me the system” — and launch-day risk at self-insured scale is drifting into the zone where “our engineers handle it” is the answer that failed in Marchand and Boeing. Second, the duty is not to fly less. It is to be able to demonstrate, contemporaneously and in writing, that flying was a considered risk decision. Oversight of the decision quality, not the outcome, is the entire ask.

The D&O market will do some of this work regardless. Underwriters who watched the Boeing settlement price board-structure questions into aviation-adjacent risk; a derivative complaint following a self-insured nine-figure launch loss writes itself — count the documents the board can produce about that specific day, and if the answer is zero, plead it. Directors would prefer the record to exist before the loss does.

III. What a board-legible launch-day information system looks like

The objection that arrives at this point in every boardroom conversation is practical: what would we even look at? Launch decisions are technical; boards cannot re-poll the engineers. Correct — and beside the point. A launch-day information system in the Marchand sense has five properties, none of which requires a director to understand propulsion:

  1. Written before the window. For each mission, a short document — one page suffices — stating the risk position for that specific launch day: nominal, elevated (with the concern named and located in the flight sequence), or adverse, together with what alternatives (later windows, different days) were considered. Signed by a named owner.
  2. Specific enough to be wrong. “Space is hard” is not a risk position. A document that cannot fail to match the outcome is a talisman, not a record. The statement must commit: what class of problem, in what phase, at what level of concern.
  3. Graded after the fact. Each pre-window document is scored against what actually happened — against the flight record, not against the author’s recollection. Hits and misses both.
  4. Misses kept. The grades accumulate in a ledger the board reviews on a cycle, with the failures retained at full weight. A record that only remembers its successes is marketing.
  5. Tamper-evident. The documents are timestamped and hash-sealed at creation — a solved problem, at negligible cost, using the same cryptographic plumbing that already secures the company’s software supply chain. This is what converts “we considered it” from testimony into evidence.

None of this is speculative. A working public example already demonstrates all five properties in combination — launch-day forecasts published and cryptographically sealed before each window, graded afterward against the public flight record with the misses retained, the entire ledger independently recomputable from public files. It is sustained by a single individual at negligible cost, and that is precisely the point: what one disciplined person can maintain as a private practice, a board can require as an institutional system. The five properties are what transfer — no particular practitioner, method, or vendor is needed to adopt them.

The asymmetry deserves one more sentence. Space-exposed companies spend eight and nine figures annually on assurance functions — external audit, cyber programs, compliance staffs — governing risks that are individually smaller than one launch. The marginal cost of the five properties above is a rounding error inside any of those budgets. The gap is not capability or cost. It is that no one at the board level has asked.

IV. Five questions for the next audit-committee meeting

The record question.  “Before our most recent launch, what written statement existed of that specific day’s risk — who signed it, and where is it filed now?”

If the answer is “the readiness review,” ask whether it states a risk position for the day, or certifies the vehicle. Those are different documents.

The shadow-premium question.  “For each self-insured mission in our forward book, what would a third-party underwriter charge us — mission by mission — and if we cannot answer, who in this company could?”

A premium is a price on a day. A company that cannot state its shadow premium is carrying an exposure it has never priced.

The slip question.  “When we scrub or slip, where does that cost appear in what this committee sees — as a risk outcome with a number attached, or nowhere?”

An oversight system that cannot see the cost of caution cannot evaluate the decision to proceed.

The discovery question.  “If tomorrow’s mission fails, exactly which contemporaneous documents would we produce to demonstrate that the board oversaw launch-day risk as a category — and would we be content to see them quoted in a complaint?”

This is the Marchand question asked prospectively, while it is still cheap.

The asymmetry question.  “What did we spend last year on audit, cyber, and compliance — and what would the five-property record described above cost beside those numbers?”

The purpose of the question is its answer: the cheapest assurance function the company could run is the one it does not have.

V. The close

Delaware law does not require boards to predict launch failures, and neither does this post. It requires something humbler and, for that reason, harder to excuse the absence of: a system by which the company’s most concentrated recurring risk is documented as it is taken, in a form the board can see, before the outcome arrives to grade everyone involved. The $6.2 billion already flew. The doctrine’s direction is not subtle. The only open question is whether the record that Marchand and Boeing teach boards to demand gets built before the next bad day — or reconstructed, expensively and adversarially, after it.

Vijay Jyotish writes on forecasting and decision-making under uncertainty. This post draws entirely on public sources — court opinions, NASA Office of Inspector General and GAO reports, SEC filings, and trade reporting.

This post’s legal discussion is general commentary, not legal advice.

Photo of Kevin LaCroix Kevin LaCroix

Kevin M. LaCroix is an attorney and Executive Vice President, RT ProExec, a division of RT Specialty. RT ProExec is an insurance intermediary focused exclusively on management liability issues.

Read more about Kevin LaCroixEmailKevin's Linkedin ProfileKevin's Twitter Profile
  • Posted in:
    Corporate Governance and Compliance
  • Blog:
    The D&O Diary
  • Organization:
    Kevin LaCroix
  • Article: View Original Source

Call us at 1-800-913-0988 or email sales@lexblog.com.

Facebook LinkedIn Twitter RSS
The Library at LexBlog
  • About LexBlog
  • The Field We Built
  • Library at LexBlog
  • Our Beliefs
  • Our Team
  • Contact LexBlog
  • Disclaimer
  • Editorial Policy
  • Terms of Service
  • Get Started
  • Publishing Solutions
  • Compass
  • Submit a Request
  • Support Center
  • System Status
Copyright © 2026, LexBlog, Inc. All Rights Reserved.
Law blog design & platform by LexBlog LexBlog Logo