On August 13, 2026, the Delaware Court of Chancery dismissed claims arising from the January 2024 Alaska Airlines door plug blowout. A door plug left Boeing’s factory without four securing bolts, the FAA grounded aircraft, and investigations identified production and quality problems. Yet corporate trauma did not establish bad-faith board oversight. The question was what the directors knew, what systems delivered that information, and how the company responded. For a Chief Compliance Officer, that distinction is the heart of the case. Boeing showed what evidence of conscientious oversight can look like. The Boeing Derivative Litigation, Consol. C.A. No. 2024-1210-MTZ (Del. Ch. Aug. 13, 2026) (the “Opinion”).)
This decision continues the evolution of the Caremark Doctrine and details what Boards of Directors need to consider to meet their obligations under the Caremark Doctrine. For compliance professionals, this case should be studied for not only its substantive analysis but also for how you will need to train
Caremark Still Asks Two Hard Questions
Caremark liability is rooted in the duty of loyalty and bad faith, not negligence or a poor outcome. Directors may face liability if they utterly fail to implement a reporting system, or if they establish one but consciously fail to monitor it, disabling themselves from learning about problems requiring attention. The required state of mind is an intentional dereliction of duty or conscious disregard of known responsibilities. A flawed effort is not the same as no good-faith effort.
That standard should not become a message that directors are protected unless they do nothing. Directors must demonstrate how they tried. Fiduciaries who implement and attend to a reasonable board-level reporting system meet the baseline duty. Even for mission-critical operations, “Caremark does not demand omniscience.” The Board’s task is therefore not perfect foresight. It is disciplined attention.
The Record That Protected the Board
The most useful part of the Opinion for compliance professionals is its description of Boeing’s governance machinery. The board met at least every two months, and airplane safety was discussed at every meeting. Management provided commercial-airplane updates on safety, quality, operational performance, and production targets. A Chief Aerospace Safety Officer delivered global safety updates twice each year.
Boeing also had an Aerospace Safety Committee with directors experienced in engineering, manufacturing, aerospace, aviation, or safety. It met at least 23 times from January 2022 through July 2024. Reporting included safety risk registers, in-service safety reports, Speak Up updates, and special-attention reports. Significant safety incidents or regulatory actions were to reach the board or committee within 24 hours or as soon as reasonably practicable. The Audit Committee separately monitored internal controls, legal compliance, the DOJ deferred prosecution agreement, and FAA obligations.
After the door plug incident, the Aerospace Safety Committee met within a day, met again twice during the following week, and arranged an onsite factory inspection. That record did not erase the operational failure. It demonstrated an active reporting and response system.
In an analysis from the law firm of Sullivan & Cromwell whose authors’ firm represented Boeing and the defendants, makes the same point: mission-critical reporting, clear committee mandates, escalation channels, and contemporaneous records can be decisive when a court examines good faith. “Delaware Court of Chancery Reinforces Limits on Oversight Liability; Stresses Importance of Conscientious Board Oversight,” Harvard Law School Forum on Corporate Governance (the “S&C Analysis”).)
Train Directors to Distinguish Red from Yellow
Plaintiffs characterized dozens of reports on manufacturing and safety risks as ignored red flags. The Court rejected that theory because it threatened to convert the “volume and depth” of reporting from a best practice into evidence of disloyalty. As the defendants put it, “if everything is a red flag, then nothing is.”
Recurring adverse information is not harmless, but the board must classify and connect it. A Caremark red flag must put directors on notice that the company is violating law or headed toward specific corporate trauma. It must also connect to the misconduct that caused the loss. General operational risks under active remediation may instead show that reporting is functioning. The Court described yellow flags involving operational risk, management responses, or matters insufficiently tied to the door plug incident.
Board training should therefore require directors to ask three questions whenever adverse information arrives: Is this a business risk or a legal compliance risk? What is management doing about it? What facts would require escalation, independent verification, or a change in strategy?
Business Judgment Has a Boundary
The Opinion also distinguished business risk from positive law. Production schedules and the management of ordinary operational risk generally receive business-judgment deference. Directors, however, have no discretion to cause the company knowingly to violate law.
The plaintiffs argued that Boeing’s production goals favored profits over safety. The Court found no particularized allegation that the targets themselves violated law or that directors pursued a lawbreaking strategy. The record also showed that Boeing adjusted targets, delayed production increases, and evaluated staffing, quality, supply-chain, and factory-health risks. Those actions supported an inference of good-faith business judgment, not conscious disregard.
For directors, the training point is not that every production decision is insulated. It is that the board should understand where business discretion ends and legal obligation begins. Compliance should identify the applicable mandates, show how they enter board reporting, and specify which thresholds require action rather than monitoring.
Books and Records Are Part of the Control Environment
The plaintiffs obtained extensive books and records describing committee responsibilities, recurring reports, risk metrics, remediation, and post-incident response. The record used to challenge the directors also demonstrated their engagement.
This is not a reason to create defensive minutes. It is a reason to create accurate, decision-useful records. Minutes should capture material questions, requested follow-up, commitments, and unresolved issues. Dashboards should show trends and control effectiveness, not merely activity. Closed items should include validation. Persistent issues should be elevated rather than repeatedly relabeled. As the S&C Analysis observes, contemporaneous records can be critical because the court examines what the board received, whether it signaled obvious illegality or specific trauma, and how directors and management responded.
Five Questions For Your Board
- Mission-critical risk.Which legal, safety, compliance, cybersecurity, or operational risks could threaten the company’s viability, customers, or license to operate? The board should identify these risks based on the company’s industry, regulatory obligations, business model, and risk profile. Directors should understand what controls address each mission-critical risk and which executives are accountable for their operation. Compliance should periodically test whether the board’s risk priorities remain aligned with changing regulations, business operations, and emerging threats.
- Reporting architecture.Which committee owns each risk, what information reaches it, and through which escalation channel? Committee charters should assign clear oversight responsibility and prevent material risks from falling into gaps between the board and its committees. Directors should receive decision-useful information that includes trends, control failures, remediation progress, and emerging exposure rather than raw operational data. The reporting architecture should also define when management must escalate an issue from a committee to the full board.
- Red-flag discipline.What criteria distinguish ordinary variance, a yellow flag requiring remediation, and a red flag requiring Board action? Management and the board should establish objective escalation thresholds based on legal exposure, customer harm, financial impact, recurrence, control failure, and the possibility of significant corporate trauma. Yellow flags should receive documented remediation plans, accountable owners, deadlines, and continuing monitoring. Red flags should trigger prompt board attention, independent inquiry where appropriate, and documented decisions about containment, investigation, disclosure, and corrective action.
- Response evidence.Do minutes and dashboards show questions, decisions, owners, deadlines, testing, and closure, or only that a presentation occurred? Board records should demonstrate that directors engaged with material information, challenged management assumptions, and requested appropriate follow-up. Dashboards should track remediation through completion and include evidence that corrective actions were tested for effectiveness. Minutes should accurately capture the substance of your Board’s oversight without becoming defensive narratives or sanitized accounts of difficult discussions.
- Speak-up integrity.Can employees raise concerns without retaliation, and does the board receive meaningful information about allegations, investigations, trends, and corrective action? Directors should understand how reports are received, triaged, investigated, escalated, and resolved across the organization. Board reporting should address substantiation rates, recurring allegations, investigation delays, retaliation claims, root causes, and the effectiveness of remediation. Your Board should also evaluate whether employees trust the reporting system and whether management responds consistently regardless of the seniority or business importance of the individuals involved.
Boeing continues to provide a wealth of lessons learned for compliance professionals. The Delaware Court Opinion reminds us that the Caremark Doctrine offers neither immunity nor a checklist safe harbor. It reminds boards that the Caremark Doctrine is tested through evidence of good-faith effort. Compliance must build that effort into governance before the next crisis and ensure the record shows that directors received, understood, challenged, and followed through on critical information.