Core Questions About Legal Strategy and Risk
What is the current top legal risk facing the company, and how is it being mitigated? General counsels at major public companies now routinely flag cybersecurity, data privacy, and cross-border sanctions as leading enterprise risks. For example, the SEC's 2023 cybersecurity disclosure rules require public companies to describe governance, risk management, and incident response in filings on the SEC website. How does the legal team quantify and report these risks to the board? Effective GC reporting uses clear metrics, such as open high-risk matters, reserve adequacy, and regulatory inquiry status, to support timely decisions.
How does the legal strategy align with the company's business objectives and capital allocation? In recent years, GCs at firms like Tesla and SpaceX have emphasized aligning legal work with product timelines and global expansion plans Tesla's official site and SpaceX's official site. What are the current priorities for managing litigation, regulatory investigations, and contract risk? A direct question about the backlog of material matters and the expected resolution timeline helps the board understand resource needs and potential business disruption.
Compliance, Investigations, and Regulatory Readiness
Key Compliance Frameworks and Regulatory Questions
What compliance programs are in place for anti-corruption, anti-money laundering, and export controls? Under the U.S. Foreign Corrupt Practices Act and related guidance, companies must maintain robust internal controls and training. The DOJ's Evaluation of Corporate Compliance Programs guidance outlines specific questions prosecutors and regulators expect GCs to answer, including whether the company has conducted a thorough risk assessment and whether it has self-disclosed potential violations on the DOJ website. How does the GC measure the effectiveness of these programs, and what metrics are reported to the audit committee?
How does the company handle internal investigations and government inquiries? The GC should explain the process for selecting external counsel, preserving evidence, and managing privilege. In the context of SEC enforcement actions and large-scale investigations, a central question is whether the company has a clear protocol for escalating issues to the board and the audit committee. For GCs at public companies, the ability to produce timely, accurate disclosures while protecting sensitive information is a key measure of readiness.
GC Reporting, Team Structure, and Technology
Board Reporting and Organizational Design
How does the GC report to the board, and what is the cadence of legal updates? Best practice is a regular written legal risk report, supplemented by briefings on active investigations, significant litigation, and regulatory changes. The GC should be able to describe the structure of the legal department, including the use of centralized functions, regional counsel, and outside counsel. For companies with complex global operations, a key question is how the legal team coordinates across jurisdictions to manage local regulatory requirements and international disputes.
Technology, Spend, and Efficiency
What legal technology tools are used for contract management, e-discovery, and matter management? Modern legal departments track metrics such as matter volume, outside counsel spend, and cycle time for routine transactions. The GC should be prepared to discuss how AI-assisted review and automation are being used to reduce costs and improve accuracy. A direct question about the budget for legal operations and the ROI of key technology investments helps the CFO and board evaluate the efficiency of the legal function.
Talent, Succession, and External Counsel
How is the legal team staffed, and what is the plan for leadership continuity? GCs at large companies often manage a mix of in-house lawyers, compliance professionals