Skip to content

Menu

LexBlog, Inc. logo
NetworkSub-MenuBrowse by SubjectBrowse by PublisherJoin the NetworkGet StartedSubscribeSupportContact
Search
Close

Guest Post: Governance Signal Decay as a D&O Severity Problem

By Kevin LaCroix on September 3, 2026
Email this postTweet this postLike this postShare this post on LinkedIn

Table of Contents

  • The interval, not the incident
  • Why the information stops moving
  • The underwriting problem this creates
  • What would actually be diagnostic
  • The market already prices this — after the loss
  • The limits
  • Conclusion
Stephen Hourigan

In the following guest post, Stephen Hourigan argues that a key driver of D&O claim severity is not necessarily board ignorance or misconduct, but the delay between when warning signs are known somewhere within the organization and when they are effectively communicated to the board. Steve suggests that there are questions underwriters can ask to determine the effectiveness of information communication to corporate boards. Steve is the Founder and CEO of Heardsafe, LLC. Our thanks to Steve for allowing us to publish his article as a guest post on our site.

*************************

In most derivative and securities actions that follow a corporate crisis, the most damaging document in the record is one the company produced itself, years earlier, and never escalated.

It is rarely a smoking gun in the conventional sense. More often it is an inspection note, a complaint log, an internal audit finding, a supervisor’s email, a slide from a business review that framed a growing problem as contained. It was accurate when it was written. It was routed correctly under the company’s own procedures. It was closed out by someone with the authority to close it out.

And in the complaint, it appears under a heading that begins: “Defendants were on notice as early as…”

That document is the central severity driver in a large share of oversight-based claims, and it is generated by the insured, inside the ordinary operation of a well-designed governance program, long before anyone perceives a problem. This post is about why that happens, why it is usually not misconduct, and why it is a harder underwriting problem than it looks.

Link to The interval, not the incident The interval, not the incident

The conventional framing of an oversight claim is that the board failed to know something. The more accurate framing, in most documented cases, is that the organization knew and the board learned later.

The distance between those two moments is the exposure.

Delaware’s trajectory since Caremark has made this increasingly consequential. Marchand focused attention on whether a board established any monitoring system for a mission-critical risk. In re McDonald’s extended oversight duties to officers. More recent Chancery decisions have pressed on the temporal dimension, treating unreasonable delay between a red flag and a board response as capable of supporting an inference of bad faith.

For D&O purposes, that shift matters in a specific way. Under a purely informational reading, the defense rests on what the board knew. Under a temporal reading, the defense has to account for how long the organization sat on what it collectively held. The second is considerably harder to defend, because the discovery record will show the interval with precision the defendants cannot contest — the documents are date-stamped.

Link to Why the information stops moving Why the information stops moving

The intuitive explanation is concealment. Someone knew and someone buried it. That happens, and where it happens the coverage analysis is relatively clean.

It does not describe most of the record.

In Wells Fargo, the independent directors’ investigation found that written and oral presentations to the Risk Committee in May 2015 and to the full board that October did not convey the full scope and seriousness of the sales-practices problem. The board was not uninformed. Information reached it. What did not survive the journey was the scale of the pattern and its systemic character. The same investigation found that improper conduct was frequently treated as a collection of individual violations rather than evidence of a failure in the sales model itself.

Consider what that looks like from the outside during the period in question. The company had terminated roughly 5,300 employees for sales-integrity violations. Read one way, that is a compliance function working — thousands of investigations, findings, consequences applied. Read another way, it is thousands of people responding identically to the same incentive structure. The first reading generates case files. The second generates a governance question. The company generated the first.

In Silicon Valley Bank, the Federal Reserve’s post-failure review found 54 supervisory findings issued from 2019 onward, with 31 safety-and-soundness findings open at the end of 2022. The review expressly found no evidence that supervisors acted unethically, characterizing the failures as problems of judgment, execution, policy, and process. It also observed that supervisors continued accumulating evidence as the institution’s condition deteriorated.

That last point generalizes well beyond bank supervision. Gathering more evidence before escalating feels like discipline. Nobody is ever criticized in the moment for wanting to be sure. And it produces delay, which is indistinguishable from inaction once the outcome is known and a plaintiff is reconstructing the timeline.

Neither case required a bad actor. Both required only that consequential information travel through multiple human layers, each with legitimate reasons to summarize, contextualize, or moderate it. Urgency, recurrence, and operating context are the first properties lost in transit. Call it governance signal decay: the information did not disappear, it was transformed.

The behavioral literature is consistent with this. Research on the communication of unfavorable information has long recognized that people delay, soften, or avoid transmitting bad news — the MUM effect. Work in accounting has found evidence consistent with managers withholding unfavorable information relative to favorable information. Inside a hierarchy the tendency compounds at every layer: a frontline report becomes a localized problem, becomes an implementation challenge, becomes corrective actions underway, becomes a dashboard trending green.

No participant intends to mislead. Each is attempting to communicate responsibly, avoid overreaction, or demonstrate control. The signal still changes materially in transit.

Link to The underwriting problem this creates The underwriting problem this creates

Here is the part I think should interest this readership most.

An underwriter assessing governance quality is working from artifacts produced by the same chain that produced the board’s picture. Application responses, program descriptions, hotline statistics, training completion rates, committee charters, management presentations at the renewal meeting — all of it originates inside the structure whose reliability is the thing being assessed.

The underwriter and the board therefore share an information problem, and it is the same one. Both are receiving an institutionally processed account, and neither holds an independent source against which to test it.

This is not a claim that companies misrepresent. It is a claim about verification. The failure mode that matters is not the account that is dishonest. It is the account that is sincere and wrong — and that is the case the investigations keep finding.

The problem is sharpest in the metrics that look most diagnostic. Reporting volume is the clearest example. A company reports declining concerns raised, and it is read as improving culture.

It may be. It may also mean employees have concluded that raising something is risky. Or that earlier reports produced no visible result. Or that contractors — often a substantial share of the people on site — have access to no channel at all. Or that issues get resolved informally by supervisors and never enter any record.

The research on organizational silence supports the pessimistic readings more than the optimistic one. Morrison and Milliken treated withholding as a collective phenomenon produced by structure and shared perception rather than individual deficits of courage. Detert and Edmondson found that employees suppress even constructive, pro-organizational suggestions because raising them would violate unwritten rules about hierarchy. Milliken, Morrison, and Hewlin found that the most commonly cited reason for withholding was not fear of formal retaliation but fear of being labeled negatively.

Fear and futility produce identical reporting data and require opposite remedies. A low number cannot distinguish between them. The absence of signal is ambiguous, and ambiguity is not reassurance — in underwriting any more than in oversight.

Link to What would actually be diagnostic What would actually be diagnostic

If existence-based questions cannot separate the well-governed insured from the one that will produce a five-year-old inspection note in discovery, the question is what would.

I would suggest the diagnostic variables are architectural rather than programmatic:

  • Latency. How long, historically, between an issue first appearing anywhere in the organization’s records and its appearance in board materials? This is measurable after the fact and almost never measured.
  • Aggregation. Are recurring concerns assembled across facilities, business units, and functions — or resolved separately inside each? A company that cannot answer this will not detect a pattern until a regulator assembles it.
  • Independence of route. Does any material information reach the board without passing through the management chain it would reflect on? For most insureds the honest answer is no.
  • Evidence of consequence. Can the company show that people who raised concerns observed a response? This distinguishes a channel that exists from one that is used.
  • Contractor and third-party coverage. Who is structurally outside every reporting mechanism the company describes?

None of these appear on a standard application. All of them are answerable, and the answers would tell an underwriter more about severity exposure than the presence or absence of a compliance program.

Link to The market already prices this — after the loss The market already prices this — after the loss

Worth noting that the instrument implied by all of this is not speculative.

When the Delaware Court of Chancery approved the settlement of the Boeing derivative litigation, the agreed relief included the creation of a channel by which employees could raise safety concerns directly to the board, outside the management chain. The same architecture recurs across deferred prosecution agreements, corporate integrity agreements, and consent orders.

In other words: courts and regulators repeatedly install an independent frontline-to-board route as part of the remedy for an oversight failure. It is, at present, almost exclusively a post-loss instrument — acquired at the price of the loss that produced it.

An instrument that consistently appears in the remedy is evidence about what the parties believed was missing beforehand. That seems like useful information for anyone pricing the risk of the same failure at a different insured.

Link to The limits The limits

A few caveats belong in an honest version of this argument.

More information reaching directors is not self-evidently better. Volume can overwhelm a board, blur oversight and management, and pull directors into operational case management where they add nothing. A route that delivers individual allegations to a board without separating them from verified patterns creates new problems, including new discoverable ones.

There is also a real tension worth naming for this audience: an architecture that improves the board’s visibility also creates a record of what the board could see. That cuts both ways in litigation, and any serious version of this has to be designed with that in mind rather than around it. My own view is that the interval is the more dangerous exposure — a board that learned late is harder to defend than a board that learned early and acted — but reasonable people in this market will weigh that differently, and I would be interested in the counterargument.

Finally, none of this is established. It is a hypothesis drawn from the documented record and it should be tested through implementation, independent research, and measurable outcomes, including outcomes that would falsify it.

Link to Conclusion Conclusion

Organizations rarely fail because they lack capable people. They fail because information capable of changing a decision does not reach the person making it while the decision is still open.

For directors, that is a governance problem. For the people who insure them, it is a severity problem with a measurable dimension that nobody currently measures — the interval between when the organization knew and when the board did.

That interval is already sitting in every insured’s document management system. It becomes visible when a plaintiff reconstructs it. There is no structural reason it could not be examined earlier, by someone with an economic interest in knowing.

Steve Hourigan is the author of The Trust Record: Why Governance Fails Before Anyone Lies (forthcoming).

Photo of Kevin LaCroix Kevin LaCroix

Kevin M. LaCroix is an attorney and Executive Vice President, RT ProExec, a division of RT Specialty. RT ProExec is an insurance intermediary focused exclusively on management liability issues.

Read more about Kevin LaCroixEmailKevin's Linkedin ProfileKevin's Twitter Profile
  • Posted in:
    Banking, Finance and Securities, Corporate Governance and Compliance
  • Blog:
    The D&O Diary
  • Organization:
    Kevin LaCroix
  • Article: View Original Source

Call us at 1-800-913-0988 or email sales@lexblog.com.

Facebook LinkedIn Twitter RSS
The Library at LexBlog
  • About LexBlog
  • The Field We Built
  • Library at LexBlog
  • Our Beliefs
  • Our Team
  • Contact LexBlog
  • Disclaimer
  • Editorial Policy
  • Terms of Service
  • Get Started
  • Publishing Solutions
  • Compass
  • Submit a Request
  • Support Center
  • System Status
Copyright © 2026, LexBlog, Inc. All Rights Reserved.
Law blog design & platform by LexBlog LexBlog Logo