Duty of Care·26 August 2026

Duty of Care as a Demonstration

The board is not asked whether the program existed.

The plaintiff’s lawyer is reading from a binder.

“Mr. Reese. On the night of the incident, who advanced the route?”

The deposition is in its fourth hour. The witness is the company’s security director. He has not slept well in three weeks. The lawyer’s question is gentle, almost incurious. She already knows the answer.

“I would need to check the records.”

“Take your time.”

This is the moment.

Not the incident. Not the response. Not the press cycle that followed. A quiet room. A question that requires a document. A pause that lasts a beat too long.

Plaintiff’s counsel does not ask questions she cannot answer. She is reading from the binder because the binder is incomplete, and the incompleteness is the case. She will ask who was awake at 0400. Whether the person performing the work was a direct employee of a licensed firm or a one-night booking through a vendor’s vendor. Which statute that person was licensed under, and whether the licensure matched the work being performed. Who was directing the work, and whether that person had the authority to direct it. Whether the use-of-force policy in effect that night had been signed, dated, and trained against the standard it named. When the vendor was last reviewed, by whom, and what the review found.

Each question will land in the same quiet room. Each answer will either be in the binder or it will not.

Two different questions, asked of the same program

The board did not know it was going to be judged this way. The board approved a budget, reviewed a vendor list, signed a retainer. The board believed it had discharged its duty of care by procuring a service.

It had not.

Duty of care is not what the board bought. It is what the program did.

The reason this catches capable people by surprise is that a protective program gets examined twice in its life, by two different parties asking two structurally different questions, and only one of those examinations happens on a schedule.

Procurement asks whether the company bought responsibly. Was there a competitive process? Are the insurance limits adequate? Is the vendor reputable, solvent, and appropriately sized? Are the rates defensible? These are good questions. They are answered with documents that exist before the engagement begins, and a program that answers them well is a program that was purchased well.

Discovery asks what happened. Not what was contracted for — what occurred, on a specific night, involving specific people, and whether the arrangement in place could have produced any other outcome. These questions are answered with records generated during the engagement, most of which nobody thought to require, because procurement did not ask for them and no one else was asking anything at all.

Most programs are built to satisfy the first examination. Procurement is satisfied by paper. The lawyer reading from the binder is not satisfied by paper. She is reading the paper for absences.

What a board is actually answerable for

Here is the part that gets lost in the security conversation, because it is not a security question.

A board is not expected to be expert in protective operations, and no one will suggest it should have been. What a board is expected to do is exercise oversight — to have established that a risk was identified, that a decision was made about it by someone competent to make it, and that the decision was revisited when circumstances changed. The precise contours vary by jurisdiction and your counsel will have a view on yours, but the shape is consistent: the question is rarely whether the board got the answer right. It is whether the board can show it engaged the question at all.

That distinction is favorable to a board, and most boards do not use it.

A board that reviewed its executive protection arrangement, asked whether the personnel performing the work were licensed for it, received an answer, documented the answer, and acted on it is in a strong position even if something terrible later happens. Bad outcomes are not, by themselves, governance failures.

A board that never asked is in a different position entirely — and it is in the worst position of all if the record shows the question reached the organization and stopped somewhere below the board. That is the fact pattern plaintiff’s counsel is hoping to find, because it converts an accident into a decision.

Which is why the most dangerous document in a company is often the one where somebody raised the issue.

The binder is the wrong instrument

The binder in the deposition is thick. That is what makes it useful to her.

It contains the certificate of insurance, current and comfortably above the contractual minimum. The retainer agreement, countersigned by the general counsel two years ago and renewed without revision. Training records organized by quarter. A vendor questionnaire completed at onboarding.

Every item in it describes a state of affairs at the moment the engagement began. Nothing in it describes a night.

This is the structural failure, and it is not a failure of diligence — it is a failure of instrument. A binder is a compliance artifact. It records that conditions were satisfied once. What survives examination is something different: a record that a program was governed continuously, which means decisions revisited, changes noticed, questions asked more than once.

A vendor questionnaire completed at onboarding and never repeated tells the lawyer exactly one thing — that the company stopped looking. She will establish the date it was completed and then ask what changed between then and the night in question. Everything changed. Nothing was recorded.

The register

What holds up is unglamorous and takes about an hour a quarter.

A governance register is a running record of decisions, not conditions. For each material element of the protective arrangement, it captures four things: what was decided, who decided it, on what basis, and when it was last examined. Not the operational detail — the decision.

  • That the company engaged a licensed provider, and how licensure was verified rather than assumed.
  • That the arrangement was reviewed on a date, by a named person, against stated criteria.
  • That a question was raised, routed to counsel, and answered.
  • That an exception was granted for a specific trip, by someone with authority to grant it, for a stated reason.

Three things make this worth the hour.

  1. It converts scattered judgment into an institutional record. The security director in the deposition almost certainly knew the answers at the time. He is not failing because the program was bad; he is failing because the knowledge lived in one person and was never written down. Individual competence does not survive contact with a subpoena.
  2. It makes the board’s oversight visible without making the board operational. The register records that the question was asked and answered — which is precisely the thing a board is answerable for — without requiring anyone at that level to understand advance procedure.
  3. And it changes behavior upstream. An arrangement that has to be written down and reviewed quarterly tends to become an arrangement worth writing down. Most of the value is created before anyone ever reads the register.

What a general counsel can require

There is a real concern that asking too many questions creates responsibility for the answers — that a company which directs a vendor’s operations has assumed a duty it did not have.

The concern is legitimate and it is also frequently overstated, usually in a direction convenient to whoever does not want to be asked. The distinction that matters is between requiring an outcome and directing a method.

Requiring that personnel be licensed for the work performed is an outcome. Requiring that supervision of those personnel remain with their employer is an outcome. Requiring notice before any portion of the work is subcontracted is an outcome. Requiring an annual review against stated criteria is an outcome. None of these tells anyone how to protect anybody.

Two of those outcomes have been the subject of earlier pieces here. Whether personnel are licensed for the work they are performing in Texas, and where the exposure lands when they are not, is the subject of When the Detail Lands in Dallas. Who supervises whom when a visiting detail and a licensed local provider both have a role — and why that line cannot be left ambiguous for the sake of comfort — is the subject of The Visiting Detail.

Both articles arrive at the same place this one does. They are questions with documentable answers, asked before anything happens, by someone with the standing to ask them.

The lawyer turns a page.

What she finds was decided months before the incident. Not in this room. Not by this witness. In a program that was operating the way it was written, or operating the way it was convenient.

General information, not legal advice. Oversight obligations vary by jurisdiction and entity type; engage your own counsel.

Questions we’re asked

What does duty of care actually require of a board when it comes to executive protection?

Not operational expertise. Oversight — evidence that the risk was identified, that someone competent decided what to do about it, and that the decision was revisited as circumstances changed. The specific standard depends on your jurisdiction and entity type, and your counsel should frame it for you. But the practical implication is consistent: a board that engaged the question and documented the engagement is defensible even after a bad outcome. A board that never asked is exposed even if the program was excellent, because it has no way to show the program was excellent.

Our provider is a well-known national firm. Isn’t that sufficient diligence?

Brand recognition is not a diligence finding; it is a reason not to have performed one. The questions plaintiff’s counsel asks are specific to the night in question — who performed the work, who employed them, what they were licensed for, who was supervising. A large firm can answer those well or poorly, and so can a small one. What matters is whether the company asked and recorded the answer. “They are a major provider” is not an answer to any question that gets asked in a deposition.

What is a governance register, and what belongs in it?

A running record of decisions rather than conditions. For each material element of the arrangement: what was decided, who decided it, on what basis, and when it was last reviewed. It deliberately excludes operational detail — that belongs with the provider and is their responsibility to maintain. The register exists so that oversight is visible without the board becoming operational, and so that institutional knowledge survives the departure of the person who happened to be holding it.

How is this different from what procurement already does?

Procurement asks whether the company bought responsibly and is satisfied by documents that exist before the engagement starts. Discovery asks what actually happened and is satisfied only by records generated during it. Both examinations are legitimate; only one is scheduled. Most programs are built entirely for the first and are examined, eventually, by the second. Closing that gap is not a matter of buying differently — it is a matter of governing continuously after the buying is done.

Can we ask a provider these questions without assuming responsibility for their operations?

Yes, if you require outcomes rather than direct methods. Requiring that personnel hold the licenses the work requires, that supervision of those personnel stay with their employer, that subcontracting require written consent, and that the arrangement be reviewed annually against stated criteria — none of these instructs anyone how to perform protective work. They establish what must be true. A provider that treats reasonable questions as intrusive is telling you something useful about what the answers would be.

MJ Blais — Founder

MJ Blais is the Founder of Blue Goose Security Transportation. He served as a Navy SEAL, spent a career as a police detective across multiple specialized units, and has worked executive protection in support of details protecting heads of state, including the President of the United States.

Blue Goose Security Transportation, LLC — TX DPS License C310887015851 Legacy Circle, Sixth Floor, Plano, TX 75024
Schedule a program review.