South Korea D&O Liability Risk: 2025–2026 Briefing
Overview
Directors’ and officers’ liability (D&O) risk in South Korea continues to trend upwards. The main drivers are statutory expansion of directors’ duties, broader personal accountability for oversight failures, tougher labor and data-protection policy, increasing cyber and AI governance expectations, and a more plaintiff-friendly environment for minority shareholders and other stakeholders.
For boards and senior executives, the practical consequence is that governance failures are now more likely to be framed as personal breaches of duty rather than isolated operational incidents. This is especially relevant for listed companies, chaebol affiliates, financial institutions, private equity firms, and any company with significant labor, cyber, AI, or ESG exposure.
Current status of D&O risk
The current South Korean D&O environment is defined by broader causes of action, stronger incentives for claimants, and greater willingness by regulators and courts to attribute compliance failures to management and board oversight. The result is higher expected D&O claim frequency and greater severity risk for both civil and regulatory matters.
Three themes are especially important:
- Shareholder-facing duties have expanded, making it easier to allege that directors harmed investors directly rather than only the company.
- Oversight failures around internal controls, cyber security, labor practices, safety, and AI use are increasingly treated as board-level issues.
- Public policy since 2025 has favored stronger accountability for corporate misconduct, especially where vulnerable stakeholders, minority shareholders, workers, or data subjects are affected.
Key 2025-2026 developments
1. Commercial Act reform expanded directors’ duties
The most significant legal reform is the 2025 amendment to the Commercial Act, effective July 22, 2025, which revised Article 382-3 to require directors to perform their duties faithfully for both the company and its shareholders. The amendment also emphasizes protection of controlling and minority shareholders’ interests through equal treatment principles, significantly strengthening the basis for shareholder claims against individual directors.
This reform matters because it shifts many disputes from being framed solely as corporate-law questions into potential personal liability matters relating to expanded fiduciary duties of directors and officers. Decisions involving mergers, restructurings, related-party transactions, capital policy, disclosure, and major compliance failures now carry increased litigation risk, particularly where minority shareholders claim unfair treatment.
2. Governance reforms increased board accountability
Broader governance reforms taking effect in 2025-26 also increase D&O risk by strengthening independent oversight expectations. These include a higher required proportion of outside directors for certain listed companies and a stricter framework for independent director and auditor appointments, including the so-called 3% rule for auditor-related voting.
These changes can increase exposure for outside directors and audit committee members because they are expected to act more independently, challenge management where necessary, and supervise control environments more actively. In practice, this makes passive or purely formal board participation more difficult to defend in later litigation.
3. Court decisions expanded oversight-based liability
South Korean Supreme Court decisions have reinforced that directors can be personally liable for failing to establish and operate effective internal control systems in high-risk areas, even where they were not directly involved in the underlying misconduct. Commentary in 2026 links this jurisprudence directly to the amended duty of loyalty framework, meaning that inadequate compliance supervision may now be pleaded not only as negligence but also as a breach of loyalty to shareholders.
The practical significance is substantial: boards must be able to show evidence of active supervision, risk identification, escalation, and remediation. Where a company suffers a major compliance event, claimants will increasingly argue that the real failure occurred at the governance and control level.
4. Shadow director’s liability widened the pool of defendants
A 2025 Supreme Court ruling confirmed that unregistered senior executives acting as de facto directors (shadow directors) may be treated as directors for liability purposes, and that the limitations period for these claims can run for 10 years. This development expands the group of individuals who may be exposed to D&O-type claims beyond formally registered board members.
For corporate groups and founder-led businesses, this creates added risk for influential executives, vice presidents, strategy heads, and other senior personnel who shape board-level decisions without formal director status. It also has implications for D&O insurance policy wording, especially insured-person definitions.
5. Labor and industrial-relations developments raised management liability risk
Labor-law reform and court developments have also increased management exposure. The Yellow Envelope Law and related worker-protection measures strengthen protections around labor disputes and reduce the ability of employers to pursue expansive damages claims against unions and workers, while Korean courts continue to scrutinize discriminatory treatment of non-regular and fixed-term workers.
These developments increase the likelihood of allegations that boards failed to ensure lawful labor practices, fair treatment, and proper oversight of industrial-relations strategy. For companies with significant union activity or complex workforce structures, labor disputes can now more readily spill into management-liability territory.
6. Cyber incidents are being framed as management failures
Cybersecurity is now a major D&O issue in South Korea. In the Coupang data leak investigation, authorities reportedly concluded that the breach stemmed from management shortcomings, including weak access control and failure to revoke credentials promptly, rather than from a sophisticated external attack.
At the same time, policymakers in 2026 proposed stricter statutory damages and stronger criminal penalties for personal-data breaches, including possible removal of negligence as a condition for certain statutory damages claims. This combination of incident-driven scrutiny and legal tightening increases the risk of follow-on claims alleging inadequate oversight, delayed disclosure, or failure to maintain reasonable cyber controls.
Cyber risk is an ever-evolving risk that can lead to a wide variety of significant consequences for organizations that experience a cyber security event. According to Bain & Company, the launch of more powerful AI models like Claude Mythos have enabled more sophisticated cyber-attacks and the era of AI-powered attacks at scale has arrived. Bain recommends that cybersecurity be treated as a critical topic for board evaluation and investment in strengthening cybersecurity foundations be urgently considered.
While addressing the AI threat is the immediate priority, planning for emerging quantum computing threats also needs attention. Quantum computing will be able to undermine many of today’s encryption approaches leading to the next wave of sophisticated cybersecurity risk. “Harvest now, decrypt” later attacks could enable bad actors to steal encrypted files and store them until more advanced quantum computing capabilities are developed.
7. AI governance is becoming a board-level exposure
South Korea’s AI Basic Act took effect on January 22, 2026, establishing a national legal framework for trustworthy AI, including obligations for certain high-impact AI uses, transparency measures, and risk-management expectations. Companies deploying AI in customer-facing, safety-critical, or employment-related functions now face stronger expectations around governance, human oversight, and truthful disclosure of AI use.
This raises D&O risk because AI failures can now be connected to multiple theories of liability at once, including oversight failure, misleading disclosure, discrimination, and inadequate internal controls. Boards that use AI in HR, product, compliance, or customer-service functions should expect claimants to test whether directors meaningfully supervised the related legal and operational risks.
8. ESG and climate disclosure pressures continue to grow
Korean companies are also facing a more demanding ESG and climate-disclosure environment as domestic and overseas standards evolve. Boards are expected to oversee ESG management more systematically, including governance structures for environmental and social risk, and to ensure that public reporting is accurate and supportable.
The D&O risk consequence is that ESG statements can become the basis for securities, derivative, or stakeholder claims if disclosures are viewed as incomplete, misleading, or inconsistent with the company’s actual controls and practices. This becomes even more acute where AI tools are used in ESG data collection or climate analysis without adequate governance or validation.
Implications
For Korean organizations, the most important implication is that D&O risk can no longer be viewed primarily through the lens of classic shareholder derivative suits alone. Boards now face overlapping exposure from shareholder disputes, cyber incidents, labor issues, AI deployment, ESG reporting, and regulatory investigations, all of which may be connected back to board oversight and individual fiduciary duties.
A defensible board position in this environment typically requires documented evidence of active supervision, clear allocation of responsibility, meaningful committee reporting, timely escalation, and follow-up remediation where control weaknesses are identified. Companies that cannot demonstrate those basics are more vulnerable not only to primary enforcement actions but also to D&O claims and insurance disputes over coverage, conduct exclusions, and allocation. Solid corporate governance and D&O insurance are two critical components for protecting executives from personal liability.
Points to monitor in the next 12 months
Several issues may further increase D&O exposure over the coming year.
- Implementation of detailed guidance and enforcement practices under the AI Basic Act.
- Progress of tougher personal-data liability reforms and any statutory-damages amendments following recent breach controversies.
- Continued judicial development of oversight-based liability and the use of the amended duty of loyalty in shareholder litigation.
- Greater use of ESG or climate disclosures as a basis for investor or stakeholder claims.
- Expansion of formal information-security evaluation obligations under the Network Act regime.
Conclusion
The current D&O liability environment in South Korea should be understood as a higher-accountability environment in which directors, officers, and senior management face broader personal liability exposure across shareholder, labor, cyber, AI, and ESG matters. The 2025-26 D&O risk trend is clear: more duties, more scrutiny, more identifiable defendants, and a greater willingness by regulators and courts to characterize operational failures as failures of board governance and executive supervision.
The key message for executives is that governance quality, control design, and documentary evidence of board oversight now play a central role in D&O loss prevention. And should a “wrongful act” liability demand arise, it is imperative to have a well-structured D&O liability insurance policy with adequate limits and broad coverage wording for protection. Keep in mind that all insurance policies are legal contracts so the words matter and, therefore, should be reviewed and improved annually. Here is a bit of free advice, if your D&O policy still contains a Y2K exclusion, it very likely has not been updated for a very long time …… I’ll let you do the math!

For more information regarding D&O risk and insurance, contact:
Eric Hoffman
Asia Risk & Insurance Advisors
M: +82-10-2267-2788
E: eric.hoffman@asiariskadvisors.com


