Home / Insights / Legal Update
Legal Update Commercial Litigation · 10 min read

Quantifying Litigation Risk for the Audit Committee

A practical, board-ready framework for CFOs, General Counsel and audit committee chairs — moving from case-by-case narratives to structured, repeatable litigation risk assessment that can be defended with regulators, auditors and investors.

Shauna Amakye

Director of Legal Services

Share
Quantifying Litigation Risk for the Audit Committee

Litigation is no longer just a legal department issue. For listed and privately held businesses alike, claims and regulatory investigations drive provisions, covenant headroom, investor confidence and, in some cases, strategic options. Yet audit committees often receive litigation updates that are descriptive rather than analytical — case-by-case narratives without a clear sense of portfolio risk, financial impact or decision points.

This insight sets out a practical, board-ready framework for quantifying litigation risk, designed for CFOs, General Counsel and audit committee chairs. The aim is not to turn legal uncertainty into false precision, but to move from anecdote to structured, repeatable assessment that can be defended with regulators, auditors and investors.

1. Why Litigation Risk Belongs on the Audit Committee Agenda

Litigation risk sits at the intersection of legal, financial and governance responsibilities. Individual cases may arise from commercial relationships, employment decisions, regulatory issues or corporate transactions — but their impact is ultimately felt in earnings volatility, provisioning, disclosure and capital allocation.

For audit committees, the key questions are: What is our aggregate exposure to litigation and investigations? How does that exposure move over time? What decisions are we taking — or deferring — in response?

A structured litigation risk assessment framework allows those questions to be answered in a way that aligns with wider risk management and financial reporting processes, rather than relying solely on narrative updates from in-house or external counsel.

Audit committees are increasingly expected to demonstrate that legal risks are understood, monitored and addressed in line with governance and regulatory standards. That expectation is intensified where the business operates in regulated or high-risk sectors, or where disputes intersect with issues such as ESG, culture and executive conduct.

Key drivers include accounting standards on provisions and contingent liabilities, regulatory scrutiny of how firms respond to misconduct and control failures, investor focus on litigation overhang in valuations and deal negotiations, and reputational sensitivity where disputes touch on customers, employees or public policy.

Against that backdrop, qualitative descriptions of "material" or "high-profile" cases are no longer sufficient. Audit committees need a litigation risk framework that is consistent with the organisation's broader risk register and appetite.

2. Common Challenges in Quantifying Litigation Risk

Before designing a framework, it is useful to acknowledge the typical obstacles CFOs and GCs face. Inherent uncertainty means legal outcomes depend on facts, law, judges, regulators and counterparties — all of which can shift. Information asymmetry means boards may see only a snapshot, with underlying documents, advice and negotiations filtered through multiple layers. Inconsistent language means terms such as "strong", "defensible" or "good prospects" are used differently by different lawyers and business units. Siloed reporting means regulatory investigations, commercial disputes, employment claims and class actions may be reported through separate channels. And pressure from auditors and regulators means demands for clearer provisioning rationales can clash with privilege and litigation strategy.

A practical litigation risk assessment for audit committees needs to address these challenges without overwhelming the board with legal detail.

3. Step 1 — Build a Clear Litigation Risk Inventory

Start by agreeing what will be captured in the litigation risk inventory. At a minimum, consider active litigation (court and arbitration proceedings as claimant or defendant), regulatory and enforcement matters (investigations, supervisory interventions and enforcement actions), threatened claims (formal letters before action and disputes where external lawyers are already involved), and structural exposures (issues likely to generate multiple similar claims, for example product, customer, employment or data-handling issues).

Some organisations also include "legal near-misses" — incidents that did not result in claims but revealed control gaps — to support thematic analysis and remediation.

For audit committee purposes, the goal is not to replicate legal case files but to create a manageable portfolio view. Each matter in the inventory should be tagged using a consistent set of fields: business unit or geography; type of dispute (commercial, regulatory, employment, IP, tax); counterparty type (customer, supplier, regulator, employee, investor); forum (High Court, arbitration, tribunal, regulatory process); and strategic importance (for example, linked to a key contract, product or jurisdiction).

This taxonomy underpins later portfolio analysis and helps identify concentrations of litigation risk in particular parts of the business.

4. Step 2 — Apply Consistent Probability and Impact Bands

Audit committees do not need — and should not expect — precise probabilities for each matter. What they do need is a consistent way of understanding likelihood across the portfolio.

A simple three- or four-band scale is usually sufficient: Remote (outcome adverse to the company is considered unlikely); Possible (outcome adverse to the company could occur); Probable / more likely than not (outcome adverse to the company is more likely than not).

Behind those labels, General Counsel should develop internal guidance so that external and internal lawyers use them consistently — referring to prospects of success, evidential risks, counterparty behaviour and procedural posture.

For each matter, impact should be assessed across both financial and non-financial dimensions. Financial dimensions include best estimate of potential liability (or recovery if claimant), range of outcomes across low, mid and high scenarios, associated costs including legal fees, expert costs and management time, and effect on covenants, capital ratios or transaction feasibility. Non-financial dimensions include reputational exposure and media interest, regulatory or political sensitivity, implications for key relationships (regulators, major customers, strategic suppliers), and precedent risk where a decision could trigger further claims.

Impact can be rated using a banded system aligned with the organisation's overall risk appetite — for example, "minor", "moderate", "major", "severe" — with reference thresholds agreed between the CFO, GC and risk function.

5. Step 3 — Connect Litigation Risk to Financial Reporting

Once probability and impact bands are in place, litigation risk assessment can be linked more directly to financial reporting decisions. Probable and quantifiable liabilities may inform provisions. Possible but not probable exposures may inform contingent liability disclosures. Remote risks may still require narrative disclosure if strategically significant.

The CFO and GC should agree thresholds for including matters in the financial reporting pack, how to handle ranges of outcomes and sensitivities, and the documentation required to support provisioning and disclosure judgments in dialogue with auditors and regulators.

For portfolios with significant litigation or regulatory exposure, audit committees may request scenario analysis across a "base case" (expected outcomes), a "downside case" (clustered adverse outcomes), and a "reverse stress" case (assumption that several high-impact matters crystallise simultaneously). This helps boards understand whether litigation risk could meaningfully affect liquidity, leverage, dividend policy, investment capacity or strategic flexibility.

6. Step 4 — Governance: Who Owns Litigation Risk?

Clear ownership is critical to making a litigation risk framework work in practice. General Counsel typically owns the methodology for assessing legal risk, quality control over advice and engagement with external counsel. The CFO owns translation of that risk into financial metrics, provisioning, capital planning and investor messaging. The audit committee oversees the framework, challenges assumptions and ensures that litigation risk is integrated into the wider risk and governance structure.

These roles should be documented in governance materials, including risk committee mandates, reporting calendars and, where necessary, internal policies on escalation and approvals.

Moving from an annual "litigation update" to a disciplined reporting rhythm can materially improve oversight. This means standardised dashboards summarising the portfolio and highlighting movements in probability, impact and key assumptions; exception-based reporting for new matters above a defined threshold or where risk levels change; and periodic "deep dives" on selected cases or themes such as employment claims trends, regulatory investigations or a particular product or geography.

Boards benefit from concise, visual summaries — supported by appendices that can be explored in more detail outside the main meeting where necessary.

7. Step 5 — Use the Portfolio View to Drive Strategy

A portfolio view of litigation risk enables CFOs and GCs to identify cases where early settlement would materially reduce risk or uncertainty, distinguish between "must win" cases (because of precedent or regulatory implications) and those where a commercial resolution may be preferable, and allocate legal budgets and management time to matters with the greatest potential impact on enterprise value.

Litigation risk assessment should not be a static exercise. Thematic analysis of the portfolio can highlight repeated issues in particular contracts or counterparties, control failures or governance weaknesses that recur across multiple matters, and cultural or incentive-related drivers such as sales practices, product design, delegation and oversight.

Those themes should feed into contract review and template improvement, board-level governance and policy changes, training and communication for front-line teams, and investment decisions about compliance, systems and monitoring. In this way, the litigation risk framework supports broader governance, risk and ESG agendas rather than existing in isolation.

8. Practical Questions for Your Next Audit Committee Meeting

  • Do we have a single, coherent inventory of all significant litigation, investigations and threatened claims?
  • Are probability and impact assessed using consistent definitions across the portfolio?
  • How are litigation risk assessments linked to provisions, disclosures and scenario analysis in our financial reporting?
  • What are the top five disputes or investigations that could change our risk profile in the next 12–24 months?
  • What themes emerge from our portfolio — contract types, jurisdictions, products, behaviours — and how are we addressing them?
  • Is responsibility for litigation risk clearly allocated between GC, CFO, the audit committee and the board, and is our reporting cadence fit for purpose?
  • Where could independent external review of our litigation portfolio, enforcement options or settlement strategies add value?

How STA Legal Can Assist

STA Legal is structured around high-value and high-volume disputes, regulatory exposure and governance-sensitive matters, with a particular focus on work where legal risk and commercial risk are tightly intertwined.

Portfolio review and risk mapping. We conduct independent reviews of existing litigation and investigation portfolios, including classification by probability, impact and strategic importance. We stress-test internal assessments, identify outliers and highlight where assumptions may be overly optimistic or pessimistic, and provide board-ready dashboards and briefing papers that translate legal exposure into financial and governance language suitable for audit and risk committees.

Early case assessment and dispute strategy. We apply structured early case assessment techniques to key matters, focusing on prospects, quantum, enforcement and settlement options, advise on the selection of forum and process — court, arbitration, mediation or other ADR — and design tiered response strategies that align litigation posture with reputational, regulatory and stakeholder considerations.

Governance frameworks and audit committee reporting. We work with boards, GCs and CFOs to define roles, escalation thresholds and reporting lines for litigation risk within the broader governance framework, draft or refine litigation risk policies, playbooks and committee templates, and provide training sessions or tailored board briefings on assessing litigation portfolios and reporting legal risk to the board.

Enforcement, recovery and settlement execution. We advise on judgment enforcement and asset recovery strategies to convert favourable decisions and awards into actual cash, both domestically and cross-border, and integrate enforcement prospects into the initial litigation risk assessment so that audit committees understand not just the likelihood of winning, but the realism of recovering.

Feedback into contracts, controls and culture. We review and improve commercial contracts, terms of business and enforcement mechanisms in light of dispute experience, and advise on governance enhancements, policy changes and training programmes where thematic issues emerge from the litigation portfolio.

Found this useful? Share it.

Shauna Amakye

Director of Legal Services

Legal Disclaimer: This article is provided for general information purposes only and does not constitute legal advice. You should not rely on this information as a substitute for specific legal advice tailored to your circumstances. STA Legal accepts no responsibility for any action taken or not taken in reliance on this article. If you require legal advice, please contact us directly.

Keep Reading

Related Insights

All insights →
Executive Exits in Listed and Regulated Businesses
Legal Update ·

Executive Exits in Listed and Regulated Businesses

A practical framework for boards, General Counsel and HR leaders on managing senior executive departures in listed and regulated businesses — balancing disclosure obligations, reputation and legal risk.

Read →
Late Payment Reform: Government Announcement
Legal Update ·

Late Payment Reform: Government Announcement

The most significant reconfiguration of payment obligations in commercial contracts for over a generation — what the March 2026 announcement means for businesses on both sides of the invoice.

Read →
Quantifying Litigation Risk for the Audit Committee
Legal Update ·

Quantifying Litigation Risk for the Audit Committee

A practical, board-ready framework for CFOs, General Counsel and audit committee chairs — moving from case-by-case narratives to structured, repeatable litigation risk assessment that can be defended with regulators, auditors and investors.

Read →

Get Advice

Need legal advice on this matter?

Speak to our team in strict confidence. We'll give you a clear view of your position and options.

Get in Touch