The situation
The number on the table was roughly $45 million in annual revenue, split between a multi-unit franchise operation Hua had built over a decade and a logistics arm Mei had brought into the merger three years earlier. The combined company was mid-negotiation on a credit facility that would fund two more territories, and the board package for the next meeting laid out the numbers a lender would eventually see: margins, debt covenants under discussion, and a valuation range the founders had not yet made public even to their own staff.
That package, forty-some printed pages, was assembled by an assistant, couriered to five directors, and then, according to one director, briefly left on a table in a shared building lobby while the director signed for a separate parcel. Nobody could say for certain how long it sat there or who might have walked past it.
The board included Ha-eun, an independent director appointed to represent a minority investor group. She was not present for the incident but asked, reasonably, what was in the package and who else might have seen it. Hua and Mei did not have a confident answer, and that uncertainty was the actual problem: the company had never had a policy governing how board materials were created, distributed, or destroyed.
Before calling a lawyer, Hua spent a weekend reading governance templates posted online by unrelated companies and cobbled together a one-page confidentiality memo that directors were asked to sign. It required directors to keep documents 'secure' without saying what that meant, said nothing about personal devices or photocopies, and set no rule for how materials would be shared going forward. Two directors, including Ha-eun, declined to sign it as written, pointing out that it created obligations without giving them any way to actually meet them. The financing timeline was now colliding with a governance dispute the founders had accidentally created themselves.
Compounding the pressure, the lender had asked for confirmation that the company's governance practices were sound as part of its credit review, a routine request that suddenly felt loaded. Hua and Mei had spent ten years building a reputation as careful operators, and the prospect of explaining a missing board package, followed by a rejected internal memo, to a lender mid-negotiation was not one either of them wanted to face without a clearer picture of what had actually happened and why.
What the documents showed
Once retained, we asked for the full package as it had been assembled, plus a list of who had received a copy and by what method. That review turned up the actual problem faster than expected. The package included not just the financing figures but an earlier draft term sheet that Mei's team had forgotten to remove, along with two pages of internal notes comparing the company's position against a competitor's, notes that were never meant to leave the boardroom at all.
The courier log and building sign-in sheet, ordinary records nobody had thought to check first, showed the package had been out of a director's physical control for roughly eleven minutes. There was no evidence anyone had opened it, copied it, or photographed it. The lobby in question was accessible to tenants of the building generally, not the public, which narrowed the realistic exposure considerably without eliminating it.
More useful than the timeline was what the exercise revealed about the document itself: it had never been assembled with a distribution list in mind, drafts were not purged before printing, and there was no record of how many physical copies existed at any point. Five directors did not mean five copies; it meant at least seven once assistants' working copies were counted.
We also reviewed the shareholders' agreement and found it silent on information governance beyond a generic confidentiality clause dating from incorporation, the kind of boilerplate that reads as protection but does no actual work once a real incident happens. Ha-eun's objection to the weekend memo turned out to be well founded: the company had no defined 'board materials' category, no rule distinguishing a printed pack from a digital one, and no consequence structure if a director mishandled either.
We also asked the assistant who assembled the package to walk through the process step by step, from pulling files off the shared drive to printing and binding. That walkthrough showed the process had grown informally over several years, with no single person responsible for confirming a package was final before it went to the printer, and no checklist confirming distribution matched the approved board list rather than whoever happened to be on an older contact sheet. The eleven-minute exposure was the visible symptom; the actual defect was a process nobody had ever designed on purpose.
Finally, we compared this incident against how the company handled digital records, which turned out to be inconsistent in the opposite direction: financial statements were kept in a reasonably access-controlled accounting system, but the same figures, once dropped into a board package, left that controlled environment entirely and became a loose physical document with none of the same protection. The company had, in effect, built a secure system and then routed its most sensitive board-level information around it every quarter.
What we did
- Mapped the actual exposure before drafting anything. Before recommending any fix, we reconstructed exactly which documents were in the missing package, cross-referenced them against the term sheet negotiations underway, and confirmed with the lender's counsel that nothing in the package had surfaced on their side. Doing this first, ahead of any policy work, let the founders negotiate from a position of fact rather than guesswork and stopped anyone from overreacting to a worst-case scenario the record did not actually support.
- Withdrew the weekend memo and explained why it had failed. A confidentiality obligation that does not specify method, custody, and consequence is not enforceable in any practical sense; it gives directors nothing to comply with and gives the company nothing to point to later. We recommended scrapping it rather than amending it, since two directors had already refused to sign and starting over avoided arguing about a document already in dispute.
- Built a document classification policy covering both formats. Board materials were divided into standard and restricted categories, with restricted materials, including anything touching valuation, financing terms, or competitive comparisons, requiring digital-only distribution going forward. This removed the physical-custody risk that had caused the incident in the first place, since a restricted document could no longer be printed, couriered, or set down on a table by definition.
- Selected and implemented a controlled access platform. Materials now go into a system with individual director logins, view-only permissions on restricted files, watermarking tied to each director's account, and automatic expiry after each meeting. Nothing restricted leaves the platform as a downloadable or printable file, and the access log shows exactly who opened a document and when, a record the old printed process never generated even when nothing went missing.
- Rewrote the confidentiality provisions in the shareholders' agreement. The old clause was generic boilerplate carried over from incorporation and had never been tested against a real incident, so we replaced it with obligations tied to the new classification system: what counts as a restricted document, what a director must do if a device is lost, and what happens if a restricted file is forwarded outside the platform. That closed the gap Ha-eun had identified and gave the company something enforceable, rather than a clause that only looked protective.
- Ran the new policy past all five directors for actual sign-off. Rather than presenting a finished document and asking for signatures, which was how the weekend memo had failed, we walked each director individually through what changed and why it changed, taking questions and making room for pushback before anything was final. That process produced two rounds of minor revisions, mostly around device-loss timelines, but it ended with unanimous written agreement from all five directors, a documented consent record the original memo never came close to achieving.
- Closed the loop with the lender. Rather than wait to be asked, we prepared a short factual summary the founders could hand the lender proactively, describing exactly what had happened and precisely what had changed to prevent a repeat. Getting ahead of the disclosure meant the founders controlled how the story was told instead of reacting defensively to a question buried in a due-diligence questionnaire, and it meant the financing conversation stayed on schedule rather than stalling on an incomplete explanation raised at the worst possible moment.
- Fixed the process gap behind the incident, not just the incident itself. We assigned a single accountable person to confirm each board package was final, correctly distributed, and stripped of stray drafts before it left the building or the platform, so the underlying process defect the assistant's walkthrough had revealed would not simply recur under a different set of facts next quarter.
The outcome
The financing closed on schedule at roughly the terms originally discussed. No evidence ever surfaced that the missing package had been viewed or used by anyone outside the company, and the eleven-minute exposure window, while real, did not translate into any identifiable harm.
The lender's due diligence team did raise the incident once it appeared in a routine governance questionnaire, and the founders answered with the factual summary already prepared, describing both what happened and what had changed since. Delivering that answer before it was demanded, rather than after, appeared to satisfy the lender; there was no follow-up request and no delay attributed to the issue in the final approval.
The more durable result was structural. The company now runs board materials through a controlled platform with no printed restricted documents at all, and the shareholders' agreement carries confidentiality language specific enough to actually govern a future incident instead of gesturing at one. Ha-eun's early objection, which had briefly looked like an obstacle to the founders, turned out to be the reason the final policy held up; her insistence on specifics is what the group eventually adopted almost unchanged.
The founders also learned something about the limits of assembling governance documents from general templates found online: the memo Hua drafted was not wrong in spirit, but it borrowed language written for a different company's structure and risk profile, and it showed. What replaced it was built around this company's actual documents, actual directors, and the actual incident that exposed the gap, which is the only version of a policy that holds up when it is tested again.
Mei, who had brought the logistics arm into the original merger, later said the exercise changed how she thought about governance generally: a policy is not proof of caution until it has actually been stressed by a real incident and either held or failed. This one, in its second version, held.
What you can learn from this
- A confidentiality clause that does not specify format, custody, and consequence is decoration, not protection; it will not hold up the first time it is actually tested.
- Templates written for a different company's structure can look complete while missing the specific risks your board actually faces.
- When sensitive materials go missing, check ordinary records first, courier logs, sign-in sheets, before assuming the worst; they often narrow the real exposure quickly.
- A director who pushes back on a vague policy is usually pointing at a real gap, not being difficult; treat the objection as information.
- Moving board materials to a controlled platform with expiry and view-only access removes an entire category of risk that no paper policy can fully close.
This is a corporate problem we handle
Start a file online — flat, published fees, reviewed by a licensed lawyer before a dollar is owed.