Materiality as a Governance Process

Institutional Thinking · Materiality

Materiality as a Governance Process: What the Conclusion Does Not Show

A materiality determination is often examined afterward as a single question: was the conclusion right? In at least one recent enforcement matter, a regulator treated the process behind that conclusion as a distinct and additional matter – worth its own separate finding, alongside, not instead of, the question of whether the conclusion itself was accurate.

The Condition

From the outside, a materiality determination looks like a single fact: a company decided something was, or was not, material, and disclosed accordingly. The conclusion is what gets filed, what gets reported, what becomes the visible record of the decision.

But a conclusion is an output. It does not, by itself, show how it was reached. It does not show what information was actually in front of the person who reached it, whether that information was complete or still developing, who held the authority to make the call, or when – relative to the underlying facts – the determination was actually made. Two organizations can arrive at the identical conclusion, on the identical set of facts, through processes of very different quality: one with a defined decision-maker working from a structured review of known facts, the other with an ad hoc judgment made under pressure by whoever happened to be available. From the conclusion alone, an outside observer cannot tell these apart.

This distinction has become more than academic in one specific, well-defined regulatory context: the SEC's cybersecurity incident disclosure framework. This piece examines what that framework, and a recent enforcement matter arising under it, show about the difference between a materiality conclusion and the process that produces one – and what that distinction may reveal more broadly about governance conditions where consequential judgment must be exercised before all the facts are settled.

What the Rule Actually Requires

In 2023, the SEC adopted a rule requiring public companies to disclose, on Form 8-K, any cybersecurity incident they determine to be material. The rule's own text – and the SEC's subsequent guidance – are precise about a detail worth sitting with: the four-business-day disclosure clock does not start at the moment an incident is discovered. It starts at the moment the company determines the incident is material, and that determination itself must be made "without unreasonable delay" following discovery. The SEC declined to specify a fixed time limit for reaching that determination, and it also declined to adopt a quantifiable financial threshold for materiality, noting in its adopting release that some cybersecurity incidents may be material without crossing any particular financial line – meaning qualitative factors, not just quantitative ones, are properly part of the assessment.

This structure builds a specific and unusual condition into the rule: materiality is not something to be assessed once, comfortably, after an investigation is complete. It is a determination a company may need to reach while the underlying facts are still developing – while investigators are still working out the scope of an intrusion, while the full extent of data affected remains uncertain, while the eventual business impact is not yet known. The rule does not ask companies to wait for certainty. It asks them to determine materiality "without unreasonable delay" even though certainty, in a live incident, may not yet exist.

In May 2024, the Director of the SEC's Division of Corporation Finance issued a public statement clarifying a related point: Item 1.05 disclosure is specifically for incidents a company has determined to be material – not for incidents where materiality remains undetermined, and not for incidents a company has already concluded are immaterial. Those should be disclosed, if disclosed at all, under a different, non-material item of the same form. The stated purpose of this clarification was to prevent investor confusion between "we have determined this is material" and "we are still figuring out whether this is material" – two very different statements that, absent this clarification, companies had reportedly been blending together in practice.

What the Conclusion Does Not Show About the Process

In December 2024, the SEC settled charges against Flagstar Bancorp arising from a cyberattack the company had experienced in late 2021. The SEC's order found that Flagstar made materially misleading statements about the incident – the company's public notice described "unauthorized access" to its network when, according to the SEC's findings, Flagstar was already aware that the attacker had exfiltrated the personal information of approximately 1.5 million individuals. That finding concerns the conclusion itself: what the company said, measured against what the SEC found it actually knew.

But the order did something else as well, and this is the part most directly relevant to the distinction this piece examines. The SEC separately found that Flagstar had failed to maintain disclosure controls and procedures "designed to ensure that relevant information to assess materiality was considered by disclosure decision makers" in a way that would allow timely decisions about required disclosure. This is not a restatement of whether the ultimate conclusion was right or wrong. It is a finding about the architecture surrounding the conclusion – whether the company had a structure in place that would reliably route the relevant facts to the people responsible for making the materiality call.

It is worth being precise about what this order does and does not establish. It does not establish that every company must adopt a specific documented materiality framework, or that any particular process design is legally required – the order is specific to Flagstar's own facts and its own disclosure controls as the SEC found them. It does not establish that a well-documented process would have excused the underlying misleading statement, since the order treats the substantive disclosure violation and the controls violation as separate charged matters, not as alternative theories where one substitutes for the other. And it does not establish that process deficiency alone, absent a substantive misleading disclosure, would independently produce enforcement – this order involved both, charged together, and does not by itself show what would happen with only one.

What it does establish, narrowly and specifically: in this case, the SEC treated the adequacy of the process that was supposed to get relevant information to the people deciding materiality as a distinct and additional matter from whether the ultimate disclosure was accurate – significant enough to charge separately, under a distinct rule (Exchange Act Rule 13a-15(a), governing disclosure controls and procedures) from the rule governing the disclosure itself.

A separate, earlier set of settlements – against Unisys, Avaya, Check Point, and Mimecast in October 2024, all arising from the 2020 SolarWinds intrusion – shows a related but distinct pattern in a different fact pattern. In that matter, the SEC's order against Unisys specifically found that the company "lacked effective controls around escalation of potentially material cyber incidents to senior management and to disclosure decision-makers" – again, a finding about whether information could reach the right people in time, charged alongside, not instead of, the finding that Unisys's public statements characterizing its cybersecurity risk as merely hypothetical were themselves misleading.

The Distinction

These matters, read carefully and without overstating what they establish, support a distinction worth stating precisely.

A materiality conclusion is not the same thing as a materiality determination process.

The conclusion is the output: material, or not material, disclosed accordingly. The process is everything that produced that output – what evidence was in front of the decision-maker, whether that evidence was complete or still evolving, who held the authority to decide, when the determination was actually reached relative to the underlying facts, and whether a structure existed to reliably route relevant information to that decision-maker in time.

The Flagstar matter shows these can be examined as genuinely separate, additional findings by the same regulator in the same order. The company's conclusion – its public characterization of the incident – was found misleading. Separately, and additionally, the architecture that was supposed to support that conclusion was found deficient. These are not the same finding restated twice. They are two distinct findings about two different things: what was said, and what process existed to inform what was said.

Where the Evidence Stops

It would overstate what these matters show to draw several tempting but unsupported conclusions.

This is not evidence that the SEC has established, or requires, a specific standardized materiality-determination framework applicable across all companies. The Flagstar and SolarWinds-related orders are specific enforcement matters, resolved on their own facts through settlement, not general rulemaking. Settled orders reflect the parties' agreement to resolve the matter without admitting or denying the underlying findings; they establish what the SEC alleged and the company agreed to accept for settlement purposes, not a judicially tested legal standard.

This is not evidence that a documented, well-designed materiality process guarantees a legally correct conclusion. Nothing in these matters suggests that process quality substitutes for accuracy – a company could have an excellent, well-documented process and still reach a wrong conclusion, or reach the right conclusion through a process a regulator later finds deficient in some other respect.

This is not evidence that every organization facing every kind of consequential decision needs the same materiality-determination architecture. These matters arise specifically under a disclosure regime built around a distinct financial-market purpose – informing investors – with its own specific legal test for materiality drawn from established securities case law. The structural lesson about separating conclusion from process may generalize as an observation; the specific legal requirements do not.

And this is not evidence that documentation alone, absent genuine underlying practice, satisfies what the SEC's rule or these orders describe. The order against Flagstar concerns whether a structure existed that would actually route relevant information to decision-makers – not merely whether a policy document existed describing such a structure on paper.

What This Suggests, Read Carefully

None of this is a case for building a specific compliance framework, and this piece does not attempt to supply one. What it suggests is narrower, and more useful for that narrowness: in at least one specific, well-documented regulatory context, a regulator has demonstrated a willingness to treat the process behind a materiality determination as a distinct and additional matter from the conclusion itself – examining not only "was this disclosed correctly" but "did a structure exist that would reliably get the relevant facts to the person who needed to decide, in time to decide it."

This distinction may be worth carrying into other contexts where consequential judgment must be exercised under incomplete information and real time pressure – not because the same legal standard applies, but because the same underlying governance condition recurs: a conclusion, once reached and documented, tends to obscure the process that produced it. Whether that process was disciplined or improvised, well-informed or thin, timely or delayed, is not visible from the conclusion alone. It has to be examined separately, and it is not always examined at all.

Close

A materiality determination, once made, becomes a fact: material, or not. That fact is what survives – in the filing, in the record, in whatever gets examined later. What produced that fact – the evidence available at the time, the authority behind the call, the timing relative to the underlying events – is a separate question, and it does not answer itself simply because the conclusion exists.

The question worth carrying forward is not whether a given materiality conclusion was correct. It is whether, before relying on that conclusion, anyone can actually see the process that produced it – or whether the conclusion is the only thing anyone can see at all.

Sources

Sources informing this Decision Distinction.

U.S. Securities and Exchange Commission

Cybersecurity Risk Management, Strategy, Governance, and Incident Disclosure framework, including Release No. 33-11216 materials.

Used for the timing structure governing materiality determinations and incident disclosure.

SEC Division of Corporation Finance

Erik Gerding statement, May 21, 2024.

Used for the distinction between incidents determined material and incidents whose materiality remains undetermined or has been determined immaterial.

SEC Order — In the Matter of Flagstar Bancorp

Release No. 33-11343 (2024).

Used for the distinction between the substantive disclosure finding and the separate disclosure-controls/process finding.

SEC Order — Unisys Corporation

October 22, 2024 SolarWinds-related settlement.

Used as a narrower supporting example concerning escalation of potentially material cyber incidents to senior management and disclosure decision-makers.

Dechert LLP / Morrison Foerster

Legal commentary quoting and interpreting the SEC adopting release.

Used as credible secondary legal support for the absence of a bright-line financial materiality threshold and the role of qualitative factors.

← Back to Institutional Thinking

Scroll to Top
Scroll to Top