Splitting Caremark’s Atom

Ryan Bubb is a Professor of Law and the Director of Strategic Initiatives at the USC Gould School of Law, and Gabriel Cohen is a Law Clerk on the U.S. District Court for the Eastern District of Pennsylvania and will join Bernstein Litowitz Berger & Grossmann LLP in the fall. This post is based on their recent paper and is part of the Delaware Law Series; links to other posts in the series are available here.

In December 2025, Vice Chancellor Will dismissed a derivative claim against a director whose sexual harassment of employees had produced roughly $1.6 million in liability for the corporation. Such “interpersonal” conduct, she held in Brola v. Lundgren, was “not a matter of corporate internal affairs,” and “[t]he legal system provided a remedy for his wrongdoing through New York’s employment laws.” She warned against turning the duty of loyalty into “a general morality code” and inviting “doctrinal sprawl” that would reach “a breakroom fistfight, a defamatory social media post, or theft of office supplies.”

Weeks later, Chancellor McCormick squarely declined to follow Brola in Los Angeles City Employees’ Retirement System v. Sanford, a derivative action asserting Caremark oversight and duty-of-loyalty claims arising from a pattern of sexual misconduct by agents of eXp Realty. The complaint alleged that the company’s founder had covered up reports of drugging and sexual assault at corporate events and that the board had failed to respond to repeated warnings. McCormick allowed both the loyalty claim against the founder and the red-flags oversight claims against the directors to proceed past dismissal. She reasoned that the duty of loyalty has always been defined capaciously enough to reach a fiduciary who consciously places his own interests above the corporation’s, “whatever the context.” “Human resources are company resources,” she wrote, and their misuse “for selfish purposes” is no different from embezzlement. Will’s limiting principles, she concluded, were innovations that “moved Delaware law” rather than faithful applications of it.

Both judges were asked to decide the same basic question: when is wrongdoing whose immediate victims are the corporation’s own workers—third parties protected by their own bodies of law—also a fiduciary wrong? For Will, only when the fiduciary abuses the distinct authority of the corporate office. Lundgren’s harassment was misconduct “any midlevel manager” could have committed, and the employment-law remedy was a reason for fiduciary law to stand down. For McCormick, whenever a fiduciary’s selfish misconduct harms the corporation—an answer she could give only by translating the wrong to those workers into the vocabulary of corporate injury: they became corporate resources, and their abuse a disloyal misuse of those resources.

Neither opinion strays from the conventional register of corporate interests. Yet Will’s answer keeps fiduciary law out of the business of reinforcing obligations the corporation and its agents owe to others, while McCormick’s answer does precisely that—under the cover of corporate injury. Whether fiduciary law should do such work at all is the question that divides them, and it has been buried inside the oversight doctrine since its creation. McCormick herself acknowledged that the two decisions may already amount to “a split in Delaware law,” and with Brola now on appeal, the Delaware Supreme Court has an immediate opportunity to address it. But whatever the Court decides, it will not be the last such conflict. The split is a symptom of something structural in the oversight doctrine itself.

Two purposes bound into one standard

The duty of oversight serves two distinct social purposes. The first is familiar: it polices the agency costs arising from the separation of ownership and control. Boards need information about the corporation’s affairs to supervise managers on behalf of shareholders. The second is public ordering. When Delaware requires directors to monitor the corporation’s compliance with law—and permits shareholders to sue them for failing to do so—it makes corporate governance an instrument for the enforcement of public law. Compliance systems bring potential violations to the attention of directors positioned to investigate and prevent conduct that harms workers, consumers, and the public.

That second purpose is not an import from outside corporate law. It descends from what we refer to as the duty of obedience: Delaware’s old, categorical, and uncontroversial condemnation of fiduciaries who knowingly cause or permit the corporation to violate the law, however profitable the violation. The term comes from the older ultra vires conception of the corporation. Because a corporation possessed only the powers conferred by its charter and governing law—and Delaware law still permits incorporation only for “lawful business or purposes”—fiduciaries were bound not to carry the enterprise beyond those limits. Modern Delaware law preserves the core commitment. As In re Massey Energy put it, “a fiduciary of a Delaware corporation cannot be loyal to a Delaware corporation by knowingly causing it to seek profit by violating the law.”

Compliance monitoring carries that commitment one step upstream. The duty of obedience governs what directors may do once illegality is known; oversight governs the systems through which potential illegality becomes known. Without those systems, the prohibition on knowing illegality could be defeated through systematic ignorance.

Neither purpose, standing alone, is an innovation—one is corporate law’s textbook concern, the other a commitment as old as the corporate form itself. Nor was the trouble that Caremark pursued both. Allen’s original decision required information systems addressing “both the corporation’s compliance with law and its business performance,” making the law and the business coordinate objects of the board’s attention. The trouble came in the doctrine that developed, where each became a condition of liability for neglecting the other. The public-ordering purpose now keeps Caremark from becoming a general duty to monitor the business; the agency-costs purpose keeps it from becoming a general duty to monitor compliance with law. That fusion—two purposes bound into a single standard, each confining the other—is what we call Caremark’s “atom.”

No single holding produced this transformation. It was the work of two doctrinal features. The first—the illegality prerequisite—generally confines oversight liability to failures to monitor violations of external law. The second—the business-centrality screen—makes a compliance risk’s centrality to the business the ordinary basis for inferring the bad faith that liability requires. Both trace to the same source: the modern duty draws its force from the duty of obedience, which Delaware relies on but is reluctant to avow. The illegality prerequisite flows from the reliance; the business-centrality screen, from the reluctance.

Start with the illegality prerequisite. Courts generally treat a violation of external law as necessary for oversight liability, placing even catastrophic failures to monitor ordinary business risk—the board inattention preceding the collapse of Silicon Valley Bank, for example—outside the doctrine’s practical reach. Agency-cost logic cannot draw that line: ignorance of a catastrophic business risk can threaten shareholders every bit as much as ignorance of a legal violation.

What draws the line is the doctrine’s public-ordering commitment. When a legal violation is at issue, the duty of obedience supplies a substantive obligation whose conscious disregard can constitute bad faith. Ordinary business risk supplies no comparable command; directors generally remain free to choose among lawful strategies and decide which attendant risks to accept. Once the bad-faith framework absorbed board inattention generally, failures to monitor business risk were left with little for bad faith to grip. Hence the illegality prerequisite.

But illegality ordinarily is not enough. Since Marchand, courts have also asked whether the compliance risk was central, or “mission critical,” to the corporation’s business. Centrality is not formally an element of liability. It operates through the structure of proof: when a board makes no good-faith effort to monitor a risk central to the enterprise, the omission itself can support an inference of bad faith.

That screen reflects the other half of the fusion: Delaware’s reluctance to theorize its obedience commitment openly. To do so would mean acknowledging that shareholders—suing derivatively, with any recovery flowing to the corporate treasury—are enforcing a duty whose ultimate beneficiaries include workers, consumers, and the public. Courts instead take refuge in agency-cost language, policing public obligations while describing their work as the protection of shareholders. A compliance risk’s importance to the firm supplies the ordinary basis for treating inattention to the public obligation as culpable. Delaware, in effect, infers indifference to the law from indifference to the business. Hence the business-centrality screen.

Figure 1 maps the structure. Each circle is the monitoring duty one purpose would support on its own: an agency-cost duty alone would reach significant business and operational risks, legal or not; a public-ordering duty alone would reach corporate compliance whether or not the risk mattered to the business. The illegality prerequisite largely empties the agency-cost crescent; the business-centrality screen thins the public-ordering crescent. Viable monitoring claims concentrate at the intersection, where public obligations and the corporation’s own interests coincide.

Figure 1. Caremark’s Atom.

Why the fusion is costly

Seeing the atom also reveals its costs. Start with public ordering. The intersection where the doctrine bites is precisely where fiduciary pressure adds the least. Business centrality tracks the firm’s own reasons to self-police: violations in core domains threaten the enterprise itself, apart from whatever sanctions the law imposes. The screen therefore concentrates the duty where private incentives are already strongest and withdraws it where its incremental value is greatest.

The public-ordering distortion goes deeper. Under the fused doctrine, the corporation’s own stake in a compliance risk measures the board’s obligation to monitor it. A good-faith decision about the level of monitoring resources—“if any,” as McDonald’s put it—to assign to a risk peripheral to the business is ordinarily protected business judgment, and courts review the systems a board does build only for the absence of good-faith effort, never for reasonableness. The doctrine thereby teaches boards to treat compliance monitoring as an ordinary business investment: fund it where violations threaten the enterprise, economize where they do not. And the incentive is sharpest at the point of detection. A board that builds reporting channels for a peripheral risk may receive red flags it cannot then consciously disregard; a board that builds none ordinarily leaves a plaintiff with no facts from which to plead bad faith. When undetected illegality benefits the firm, the rational response is not to look—a board that looks and finds problems cannot safely look away. This is an “efficient compliance” approach to oversight: treat expected penalties as prices, and comply only when compliance pays.

On a familiar economic view, that approach is not a pathology but sound management: if expected penalties approximate the social harm of regulated conduct, they tell the firm what compliance is worth, and a firm that violates when the gain exceeds the penalty is behaving as a Pigouvian tax intends. But that premise does not hold. Penalties under the FCPA, the organizational sentencing guidelines, environmental statutes, and OSHA, for example, are rough deterrence judgments structured by administrable factors like culpability and gain. They are not monetized estimates of social harm, and they are not meant to be. The state reaches for a sanction rather than a price precisely when it can specify prohibited conduct more reliably than it can measure the cost of departing from it. A firm that optimizes against the expected penalty reads the regime backwards: it extracts welfare guidance from the component that does not carry it, discards the component that does, and converts the sanction into a price the state declined to set because it could not set it well. Efficient compliance is not merely morally questionable. It is economically inefficient.

The agency-cost side has fared no better, and here our conclusion inverts the conventional account. Caremark is widely understood to have strengthened board accountability for failures of attention. We argue that in its post-Citigroup form it weakened it. Before Caremark, directorial inattention was cognizable under the duty of care through objective review of board process, and Delaware’s gross-negligence standard had been applied to failures of supervision. Modern doctrine relocated oversight to loyalty, replaced objective process review with a subjective bad-faith inquiry, and then largely confined liability to legal-compliance settings—narrowing the duty’s scope and ratcheting up its standard at the same time. For business-risk oversight, the combination produces what is effectively a “super bad faith” threshold. The loss is not confined to litigation. Chancellor Allen expected Caremark to shape boardroom norms through its articulation of the duty rather than the remote prospect of liability; that channel now runs in reverse, as directors and their counsel absorb a doctrine that tells them oversight duties “are not designed” to reach business risk. The result is less accountability, not merely fewer damages claims.

This result is the pattern one should expect when a doctrine cast in private-law terms is made to carry a public-ordering commitment: the inherited limits of the private function distort the public one, while the public function crowds out the private one.

Splitting the atom

What Delaware needs is not one doctrine doing two jobs badly, but two doctrines each doing one job well.

An agency-cost duty, grounded in the duty of care, would require boards to maintain reasonable information systems concerning business performance and significant operational risks. Courts would review the monitoring process for gross negligence while continuing to defer to informed substantive judgments, and Section 102(b)(7) exculpation would remain available.

A public-ordering duty would give independent doctrinal form to the monitoring extension of Delaware’s duty of obedience. It would require boards to orient corporate systems toward compliance with sanction law, without regard to whether the risk was central to the business. Inattention to the monitoring process would be reviewed for gross negligence; conscious facilitation of noncompliance, for bad faith. The duty would be non-exculpable, because shareholders cannot waive an obligation that does not exist exclusively for their benefit. Damages would be measured by the corporation’s gross enforcement-related losses, without netting gains from illegality.

The proposal is new in its rule for culpable ignorance, but not in the commitment it serves. It joins two premises Delaware law already recognizes: the duty of obedience bars fiduciaries from knowingly causing or permitting corporate illegality, and Caremark makes boards responsible for the corporation’s information systems. The resulting duty gives the obedience commitment the informational infrastructure its command presupposes.

The split is therefore an act of articulation rather than invention. It gives separate doctrinal form to two commitments Delaware law already holds. Freed from the public-ordering function, the agency-cost duty can return to the objective, process-based review traditionally associated with the duty of care. Freed from the need to establish a threat to shareholder interests, the public-ordering duty can address compliance directly. The alternative is perverse: fiduciary law would condemn a director who knows of corporate lawbreaking while protecting a board that organizes itself not to know.

Why it matters now

Vice Chancellor Glasscock once observed, in declining to resolve whether Caremark is about agency costs or public ordering, that “[t]hat question is for academic discussion, not judicial resolution.” We disagree. Delaware’s courts created Caremark, and the entire edifice of directors’ fiduciary duties, and they are responsible for determining its reach.

So long as a single standard binds together two purposes whose design requirements are incompatible, the tension will remain latent until cases press on the fault line—at which point the energy stored in the fused doctrine is released in unpredictable and contradictory ways. Brola and Sanford are one such release.

Chancellor McCormick’s response to the sprawl concern shows how little help the unified framework offers. She argues that the procedural architecture of derivative litigation—the demand requirement, the economics of contingent-fee litigation, and judicial control over attorneys’ fees—will cabin the practical consequences of a capacious duty. That is a market-based answer to a normative question. It explains why a broad duty may not generate unmanageable litigation. It does not explain why fiduciary law should reach the conduct in the first place.

Will and McCormick give different answers to a question the unified framework has never made explicit. The solution is not to paper over the tension with further epicycles, but to split the atom deliberately—making explicit the institutional choice the fused doctrine obscures: when fiduciary law protects investors, and when it reinforces the commands of public law.

The complete article is available for download here.