In 2012, a director who raised cybersecurity at a board meeting would have been thanked and redirected to the IT function. It was a technical matter. It had an owner and a budget line, and no natural place on a board agenda that was already full. People had enough to do as it was. And it wasn't a board issue anyway.

Then Target lost 40 million card records to attackers who entered through a refrigeration contractor's credentials. The CEO "left". Directors were sued. Then the Equifax breach followed, then SolarWinds, where to make things more interesting the SEC pursued the company's own security officer personally. That tends to concentrate the mind. And a whole new world of risk (and director liability) came into view.

Within a decade the category had a mandatory disclosure regime, a standing place on audit committee agendas, and a global spend that grew from roughly $23 billion in 2003 to about $272 billion today.

What changed was not the technology. The threat had been there the whole time. What changed was a series of expensive and very visible failures that made it clear this was a board governance issue, not a management operational one.

Metrology data is at the point cybersecurity occupied around 2012. It sits with the quality function. It has an owner and a budget line, and no natural place on the agenda.

In our view, and from the work we do, three forces are going to change that, and very quickly.


First, the data already exists, at a huge scale most boards have never seen quantified

A modern manufacturing plant is saturated with measurement. Inline gauging on the line. Coordinate measuring machines in the metrology lab. Vision systems on the inspection station. Condition monitoring on the bearings. Torque tools that record every fastener. A single certified facility runs to tens of thousands of instruments generating millions of data points per shift, and multiples of this a day. And that's just the sensor estate inside the factory.

Every one of those readings is a (discoverable) record. Every record has a calibration certificate behind it and a tolerance band around it, governed by a retention policy that decides how long it survives. Every one of those measurements is linked to an instrument. Every instrument has a calibration and repair policy. And every instrument could potentially have many operators. In a company with ISO 9001 certification, the whole apparatus is documented by design.

The company holds vastly more evidence about its own operations than at any point in industrial history, and the board's view of that evidence has not materially changed since the 1980s.

In our experience boards almost never see any of it. What reaches the board pack is a quality slide: cost of poor quality, customer satisfaction, audit findings raised against findings closed. These are lagging proxies, three or four numbers standing in for millions. The annual surveillance audit that certifies the system samples a fraction of one percent of the underlying records, and it was designed to satisfy an ISO registrar rather than a director.

The result is an ignored asymmetry. The company holds vastly more evidence about its own operations than at any point in industrial history, and the board's view of that evidence has not materially changed since the 1980s.


Second, sensors and robotics are about to multiply the volume

The measurement estate is not stable. It is compounding. And in new ways. The International Federation of Robotics counted 4,664,000 industrial robots in operational use worldwide at the end of 2024, up 9% in a single year. Annual growth rates are increasing rapidly.

Robots do not simply replace human labour. They instrument it. A robotic cell that used to be a manual station now generates torque curves, position feedback, cycle-time data, force readings and vision-system pass/fail records for every part that passes through it. Work that produced no data at all five years ago now produces a continuous stream.

Cyber became a board issue because the attack surface expanded faster than the ability to govern it. Measurement data is on the same curve, driven by the same underlying force: more connected devices, generating more records, faster than the governance around them adapts.

Layer onto that the broader industrial Internet of Things build-out and the shift to automated inspection, alongside a growing use of machine learning to act on measurement data without a human in the loop. The trajectory is not ambiguous. A board that finds its current measurement estate difficult to oversee is looking at a problem that gets substantially harder every year, not easier.

This is the part that makes the cybersecurity parallel more than an analogy. Cyber became a board issue partly because the attack surface expanded faster than anyone's ability to govern it. Measurement data is on the same curve, driven by the same underlying force: more connected devices, generating more records, faster than the governance around them adapts. We see this every day and the pace and complexity of change is increasing.


Third, the liability has already started to land

The third force is the one that will actually put this on the agenda, because it is the one that turns an operational matter into a personal one.

The pattern in recent enforcement and litigation is consistent enough to be uncomfortable. A company held measurement data that identified a problem. The data did not reach anyone with the authority and the obligation to act on it. The failure surfaced later, at scale, in front of a regulator or a court.

Exhibit 1 — What happened. Eleven oversight failures, ranked by cost, 2023–2026. Sources: US DOJ, EPA, NTSB, NHTSA, CPSC, CPUC, FAA, Delaware Court of Chancery, SEC filings and company disclosures.

The costs arrive through multiple channels. Regulatory penalties from bodies such as the EPA, the CPUC, the CPSC and NHTSA. Criminal resolutions with the Department of Justice. Civil verdicts brought by private plaintiffs. In Boeing's case, an $8.3 billion acquisition to regain control of a supplier whose quality data it could no longer trust.

Most of that is corporate liability, paid by the company. One channel is different.

Under Caremark, the Delaware doctrine governing a director's duty of oversight, a board member can be held personally liable for failing to ensure a system existed to surface material risks. Boeing's board settled such a claim for $237.5 million in 2021, the largest oversight settlement in Delaware history. D&O insurance absorbs most of that exposure in practice, but coverage carries limits and bad-faith exclusions, and no policy shields a director from a deposition, a named-defendant docket entry, or the years a derivative action takes to resolve.

If a company makes a physical product, the conforming quality of that product is almost certainly a mission-critical compliance domain. The test a court applies with hindsight is whether a system existed to bring measurement evidence to the board's attention.

Of the eleven cases, only Boeing's produced an actual Caremark settlement. The other ten are the raw material from which such claims get built: documented failures to escalate data the company already held, sitting one derivative filing away from becoming the next Boeing.

The doctrine has also been getting easier to plead. Marchand v. Barnhill (2019) allowed a claim against Blue Bell Creameries' board after a listeria outbreak, because food safety was the company's mission-critical compliance domain and the board had no committee covering it. In 2023, McDonald's extended oversight duties beyond directors to corporate officers. In 2024, the Delaware Supreme Court revived an oversight claim against AmerisourceBergen's directors over opioid distribution monitoring. The perimeter of personal accountability keeps moving outward.

For a director of a manufacturer, the translation is direct. If the company makes a physical product, the conforming quality of that product is almost certainly a mission-critical compliance domain. The test a court applies with hindsight is whether a system existed to bring measurement evidence to the board's attention.


The case that shows the mechanism

Boeing repays close reading because nothing malfunctioned. The failure was governance.

Exhibit 2 — Anatomy of a metrology governance failure: Boeing. Five-year sequence, cause, cost and board consequence. Sources: NTSB, US DOJ Criminal Division, FAA, Delaware Court of Chancery, company disclosures.

On 5 January 2024, a mid-exit door plug separated from a 737 MAX 9 at roughly 16,000 feet. The plug had been opened on the factory floor to repair rivet defects and reinstalled without its four retention bolts. No instrument gave a false reading. No sensor failed.

What was missing was the record. The NTSB's investigation turned on the absence of documentation for a non-routine removal, and Boeing's own position was that if the removal was undocumented, there would be no documentation to share. Upstream of that sat a supplier estate that stopped at the factory gate while Spirit AeroSystems was failing 54% of its federal quality audits.

The resulting NTSB finding — a failure to provide the training and oversight necessary for personnel to comply with the parts-removal process — is not a manufacturing finding. It is a governance finding about a manufacturing process. We think this is a crucial distinction that many boards miss. And drives the pressing point that resolution is not more measurement. Its more governance.

Boeing's underlying problems run deeper than measurement. The production culture that followed the 1997 McDonnell Douglas merger contributed, as did the outsourcing of fuselage work and sustained pressure on production rates. Better metrology governance would not have fixed Boeing. It is the layer at which a problem of that kind becomes visible to a board before it becomes visible to everyone else.


What a board actually needs

Quality management is an operational function. It runs the machinery, for the product, under management. What the pattern above demands in our experience is different: a board-level system that can answer one question with evidence — can the board demonstrate that it knew what its instruments knew?

We call this metrology governance. It stands to the quality management system as cyber governance stands to IT operations. It does not run the equipment. It ensures the equipment's output reaches the people carrying the legal duty, in a form that survives scrutiny. We see this made up of Five key components:

1. Sensor estate mapping. Every measurement point touching product conformance or a regulatory obligation, ranked by criticality, extended to critical suppliers. This is often simpler than it appears, much of the envelope in our experience has already been shaped by a quality system.

2. Obligations register. This is less simple. Each measurement stream needs to be mapped to the specific duty it evidences: a certification requirement, a contractual clause, a safety regulation, an environmental limit. In our experience this is where many boundaries blur and expectations differ. Often this exposes the cultural differences of different teams, and sometimes our role is to ajudicate, as much as it is to record.

3. Evidence chain review. The trace from instrument to board pack. Calibration status and traceability. Data integrity in transit, including whether readings can be altered, suppressed or auto-deleted. The aggregation points where individual exceedances vanish into averages. The last one is often key. Most manufacturing environments exclude "bad" readings. And practically this works. Until the trend of bad readings is smoothed by their exclusion. Again, this in our experience speaks as much to culture as compliance and is often a key finding from a diagnostic.

4. Automation and escalation risk. Where automated systems act on measurement data without human review, and where escalation depends on individual judgement rather than a defined trigger with a named owner. This is increasing in importance and the use of inline sensing especially for quality control is a key area to monitor.

5. Board attestation framework. Committee ownership and reporting cadence, with a documentation standard built for a books-and-records demand rather than a registrar's audit.

If boards and companies in Exhibit 1 had a Metrology Governance framework things may have been very different.

Exhibit 3 — What would have been different with a metrology governance program. The same eleven cases, mapped against the four technical steps of the diagnostic. Empty cells indicate the step is not the primary gap for that case.

Two patterns stand out. The evidence chain carries seven of the eleven cases — most large oversight failures happen between the instrument and the boardroom, not at the instrument. And several cells stay empty, because a framework that claimed to prevent everything would deserve less trust, not more.


What this does when a claim arrives

General counsel will ask whether any of this stops a books-and-records demand. It does not. The credible basis standard is the lowest burden of proof in Delaware corporate law, and AmerisourceBergen (2020) held that a stockholder showing a credible basis to infer wrongdoing need not demonstrate the wrongdoing is actionable. A derailment or a consent decree supplies that basis on its own.

The demand is the wrong battlefield. Oversight claims are won and lost at the motion to dismiss, and what decides them is what the production reveals.

In NiSource (Del. Ch., June 2022), following a series of pipeline explosions, Chancery rejected the claim because the books and records the plaintiffs themselves obtained showed the board had established a system for monitoring the mission-critical risk. The production demonstrated the existence of a system rather than its absence.

SolarWinds (Del. Ch., September 2022, affirmed May 2023) dismissed on similar grounds, as did Centene (Del. Ch., July 2024), where a compliance reporting system was in place and appeared to be functioning at least to some extent. Marchand is the mirror image: Blue Bell lost because there was no board-level committee and no reporting stream at all.

The knife cuts both ways, and a board should understand that going in. A review that identifies gaps creates documented, board-level red flags. In Brewer v. Regions Bank (2025), an internal document identifying legal risk became the plaintiff's most powerful evidence, and Chancery rejected the directors' argument that they had responded, merely not as quickly as the plaintiff wanted, holding that delay can itself be a tactic. Findings without remediation are worse than no findings. That is the argument for structuring the work around a report on a process rather rather than a report for a drawer somewhere, "just in case"


How to organise a Metrology Governance process

In our experience a review of this kind should run the way a board already runs any serious risk assessment, not as a novel exercise invented for the problem. There are 3 key principles:

First, involve counsel from the outset. The company's own counsel should scope the engagement, determine what protections attach to the work product, and advise on how findings are documented. Whether particular materials attract privilege is a legal question specific to the engagement and the jurisdiction.

Second, understand the discovery landscape. Any board-level risk review can become relevant in later litigation or regulatory inquiry. That is true of cyber assessments and safety audits alike, and it is not a reason to avoid the review. Delaware's caselaw is consistent: boards are better served by having conducted a diligent, documented assessment and acted on it than by never having looked.

Third, produce action rather than a document. The true value of a metrology governance program, of of any board driven governance programs, is to set a standard, communicate expectations and shape behaviours.

Exhibit 4 — An example best practice metrology governance diagnostic. Indicative timings, tasks, team and deliverables.

The approach is deliberate. Mobilisation and board attestation form the legal and governance wrapper. The four technical steps sit inside it. Most of our work is in these steps, ensuring capability is transferred to the client team wherever possible. Mobilisation settles scope and reporting lines before any data moves. Board attestation closes the loop by designing the quarterly governance pack and setting committee ownership, then stress-testing the resulting record against the kind of demand that broke Boeing.


The future of metrology governance

Cybersecurity did not arrive on the board agenda because directors developed an interest in network architecture. It arrived because the cost of not having it there became obvious, publicly, to everyone at once.

Measurement data is on the same path, and the formal crystallisation of expectations and reporting by boards means Metrology Governance programs will be inevitable. The volume is already enormous. Robotics and industrial sensing are compounding it at close to 10% a year. The enforcement pattern is established and the doctrine is expanding. The need to close the metrology governance gap has never been greater, and forward thinking boards are already taking steps to close these gaps.


Metrology governance reviews for boards and audit committees are conducted through metrology.com's advisory practice, scoped in coordination with client counsel. The standard diagnostic runs eight weeks. This article is general commentary and not legal advice; companies should consult their own counsel on privilege and disclosure questions specific to their circumstances. To discuss any aspect of our work or the themes raised above contact us at team@metrology.com


  1. International Federation of Robotics, World Robotics 2025, September 2025.
  2. NTSB probable-cause finding and public hearing, Alaska Airlines Flight 1282.
  3. Boeing statement to NTSB regarding removal documentation, March 2024.
  4. In re The Boeing Company Derivative Litigation, C.A. No. 2019-0907-MTZ (Del. Ch.).
  5. DOJ non-prosecution agreement, May 2025.
  6. Philips Q1 2024 results; Respironics settlements and consent decree.
  7. DOJ and EPA, Cummins Clean Air Act settlement, December 2023.
  8. CPUC Administrative Consent Order, PG&E Dixie Fire, January 2024.
  9. Marchand v. Barnhill, 212 A.3d 805 (Del. 2019).
  10. In re McDonald's Corp. Stockholder Derivative Litigation (Del. Ch. 2023).
  11. AmerisourceBergen Corp. v. Lebanon County Employees' Retirement Fund, 243 A.3d 417 (Del. 2020).
  12. City of Detroit Police & Fire Ret. Sys. v. Hamrock (NiSource), 2022 WL 2387653 (Del. Ch. June 30, 2022).
  13. Construction Industry Laborers Pension Fund v. Bingle (SolarWinds), 2022 WL 4102492 (Del. Ch. Sept. 6, 2022), aff'd May 17, 2023.
  14. Bricklayers Pension Fund of Western Pennsylvania v. Brinkley (Centene), Del. Ch., 12 July 2024.
  15. Brewer v. Regions Bank directors, Del. Ch., 2025.
  16. In re Caremark International Inc. Derivative Litigation, 698 A.2d 959 (Del. Ch. 1996).
Share this post
The link has been copied!