← Back to blog

Half of COVID Risk Language Was Boilerplate: U.S. Compliance Guide

September 1, 2026
Half of COVID Risk Language Was Boilerplate: U.S. Compliance Guide

Risk factor boilerplate is disclosure language that mirrors industry peers rather than describing a firm's own material exposures, measured by researchers through textual and semantic similarity to comparable filings. Recent U.S. research tracking COVID-19 disclosures shows this copying became widespread starting in 2020 and, notably, has not fully reversed. For compliance teams, that stickiness is the practical problem: outdated or generic risk language creates both SEC scrutiny exposure and a measurable gap between what a filing says and what actually threatens the business.


TL;DR:

  • Most risk disclosures are increasingly based on industry templates, with around half of COVID-19 risk language nearly identical across filings by 2021.
  • Textual and semantic analysis methods reveal that companies often paraphrase competitors' risks, which can mask the lack of firm-specific disclosures.
  • Smaller issuers tend to copy boilerplate language longer, as tailoring risk factors is more costly and complex for them, especially in litigious industries.
  • A periodic review should flag repeated risk language over multiple years and link each risk to specific business facts to ensure materiality and accuracy.
  • Using benchmarking tools like Lacuna Index allows compliance teams to identify narrative drift and improve disclosure relevance before regulatory review.

Table of Contents

What Counts as Boilerplate in a Risk Factor Section

Researchers studying disclosure language distinguish two ways of measuring similarity, and the difference matters when a compliance officer is deciding whether a paragraph needs a rewrite. The first method is textual: it counts overlapping tetragrams, four-word sequences that repeat across filings, and calculates the percentage of a company's risk section made up of these repeated strings. The second is semantic: it looks past word-for-word matches to catch language that has been lightly reworded but conveys the same essential meaning as a peer's disclosure, a practice sometimes called "smart copying."

That distinction has real consequences. A textual and semantic method that only flags identical wording will miss firms that paraphrase competitors' risk factors just enough to avoid a plagiarism-style match while still failing to describe their own operations. Courts and reviewers who rely on textual matching alone can undercount the true prevalence of boilerplate, since a company can satisfy a textual screen while still disclosing nothing specific to its own balance sheet or supply chain.

The SEC Rules Governing Risk Factor Disclosure

Item 105 of Regulation S-K requires a separately captioned "Risk Factors" section addressing the most significant risks facing the issuer, and it directs registrants to present those risks in logical groups with descriptive sub-headings rather than a single undifferentiated wall of text. When the risk section runs longer than 15 pages, issuers must add a concise summary near the front of the filing, a rule designed specifically to counteract the tendency toward bloated, repetitive disclosure.

The SEC's own guidance pushes toward plain English and away from generic hedging. Enforcement history and comment-letter trends show the agency has criticized language that reads as generic and hypothetical when a risk has already materialized or when the disclosure obscures firm-specific facts a reasonable investor would want. Boilerplate is not a safe harbor. Volume of text does not substitute for materiality, and reviewers increasingly test whether the words on the page match the risks a company actually faces.

The COVID-19 Numbers: How Fast Boilerplate Spread and Why It Stuck

The clearest empirical test of risk factor drift came from COVID-19 disclosures, where a large multi-year corpus study tracked how quickly companies converged on shared language. The pattern is stark: boilerplate use nearly doubled in a single year and then barely moved for two more.

By 2021, roughly half the words in a typical COVID risk disclosure sat inside sentences that repeated across multiple filers almost verbatim. That is not a rounding artifact. The jump from 25.17% in 2020 to 49.73% in 2021 suggests firms spent the first pandemic year drafting original language under time pressure, then settled into copying once early filers established a template. Larger companies and those facing elevated litigation risk updated earlier and copied less, while smaller issuers with thinner legal budgets tended to hold onto shared language the longest.

COVID boilerplate language rise from 2020 to 2021

The Real Reasons Companies Default to Boilerplate Language

Tailoring a risk factor costs money, as described in detail in pre-deal intelligence resources that highlight the complexities of due diligence. Drafting language specific to a company's supply chain, customer concentration, or debt covenants takes attorney and in-house counsel time that many issuers, particularly smaller ones, would rather spend elsewhere. Copying an established industry template is cheaper and, for many general counsel offices, feels safer.

Litigation dynamics reinforce that calculus. Firms facing a higher baseline risk of securities litigation have more incentive to tailor disclosures precisely, since generic language offers weaker protection if a risk materializes and shareholders sue; that is part of why higher litigation risk firms updated earlier and copied less during COVID-19. Industry leaders effectively seed a template, and smaller competitors follow, a pattern researchers describe as companies entering a copying mode once an initial version circulates. The result is language that updates slowly, if at all, even after the underlying risk changes.

A Drafting Checklist for Reducing Boilerplate Risk

A Drafting Checklist for Reducing Boilerplate Risk — overview diagram

Practitioner guidance converges on four drafting considerations when preparing or refreshing a risk factor section. First, review every hypothetical framing. If a stated risk has already occurred, such as a supply disruption or a data breach, the disclosure needs to say so rather than presenting it as a future possibility. Second, tie forward-looking statements to the specific assumptions behind them so a reader can see what would have to change for the risk to materialize. Third, present risks in logical, sub-headed groups rather than an alphabetical or historical list that buries the most material items. Fourth, confirm whether the risk-factor summary requirement applies once the section passes 15 pages.

A working annual review should include:

  • Flag every risk factor that repeats near-verbatim across the last three fiscal years without a substantive edit.
  • Confirm each material risk ties to a specific, documented business fact, not an industry-wide assumption.
  • Route drafts through legal, finance, and business unit leads before filing, not legal review alone.
  • Keep contemporaneous memos or board minutes linking a stated risk to the specific exposure it describes, since that documentation helps if a disclosure is later challenged.

Teams building this review process into an existing 10-K workflow can pair it with a structured forensic risk factor analysis to identify which sections carry the highest similarity to peer filings before the drafting cycle begins.

How Lacuna Index Flags Boilerplate for Compliance Teams

Lacunaindex applies a forensic methodology built entirely on public records, mining 10-Ks, earnings calls, proxy statements, and press releases without relying on insider access or company cooperation. That approach lets it measure the same kind of textual and semantic drift researchers documented in COVID-19 filings, but applied continuously across sectors rather than in a single retrospective study.

The platform flags repetition against peer language, tracks how far a company's narrative claims drift from what its own filings and subsequent disclosures actually confirm, and scores that gap in an audit-traceable format. For a compliance team, that translates into a prioritized list: which risk factors carry the highest similarity to competitors, where language has gone stale relative to a company's own operational history, and which disclosures merit a closer legal read before the next filing cycle. The same framework supports governance red-flag detection for teams tracking narrative stickiness across an entire sector rather than one issuer at a time.

Why Boilerplate Persists Even When Everyone Knows Better

Mandates alone have not solved this. Rules that ask companies to self-assess materiality without an external benchmark leave too much room for the cheapest compliant answer to win.

Measurable, market-level benchmarking changes that calculus. When similarity to peers becomes a tracked, visible metric rather than an assumption reviewers can't easily verify, the cost of leaving stale language in place rises, and so does the incentive to write what is actually true about the business, not what everyone else already wrote.

— Glen

Put Boilerplate Detection to Work With Lacuna Index

Spotting risk factor drift by eye across dozens of peer filings is slow work, and most compliance teams don't have a spare quarter to run that comparison manually every filing season. Lacunaindex's sector benchmarks give you a free, standing reference for how narrative language and disclosure patterns compare across an entire industry, so you can see where your risk section sits relative to peers before a regulator or a journalist does.

Lacunaindex

From there, the user guide walks through how to read a forensic report and turn a flagged narrative gap into a documented, defensible drafting decision. Start with the sector benchmarks for your industry, then pull a full report on the filers you're tracking most closely this quarter.

Where to Read More on Risk Factor Boilerplate

The University of Michigan repository study contains the full COVID-19 corpus methodology and yearly statistics. The Harvard Law School Forum post summarizes the academic findings for a legal audience. A companion Harvard Forum piece offers the practitioner drafting checklist referenced above, and the Lowenstein market trends guidance lays out the current Item 105 requirements in practical form.

Sources