Disclosure · 36 filers

Audit Committee Oversight

36 companies wrote this into a filing in the last 14 days, up from 29. Below: which of them, and what the corpus says they now owe.

Data measured , page built 22 September 2026 at 16:18 UTC.

36filers, current period
29the period before
6controls it touches
6frameworks
first appears Feb 2008 2008 2026 96 filings in the busiest month
Audit Committee Oversight in 10-K and 10-Q filings, by month. The marked line is the first month any public company in our record used the phrase; everything left of it is nobody writing it down.
Companies disclosing it 36 wrote this into a filing with the SEC
What it obligates 6 controls across 6 frameworks whose text speaks to it
Employers hiring for it no open roles currently name it

The long view, in annual and quarterly filings

A 10-K or 10-Q is a periodic report, so this counts how often the phrase appears in routine annual and quarterly reporting. It moves far more slowly and the numbers are larger. Every month since 2008. The last point is the current month and is still filling, so it always looks lower than it will be.

 
04896
2008 peak 96 in March 2025 2026

Who disclosed it

From SEC full-text search over 8-K filings. Every row links to the filing itself.

CompanyFormFiled
NATIONAL BEVERAGE CORP FIZZ10-K2026-07-01filing
SPECIFICITY, INC. SPTY10-Q2026-08-19filing
MYX Inc.10-K2026-09-02filing
Spectral AI, Inc.10-Q2026-08-11filing
UNIVERSAL LOGISTICS HOLDINGS, INC. ULH10-Q2026-08-13filing
REPLIGEN CORP RGEN10-Q2026-07-29filing
Protagenic Therapeutics, Inc.\new PTIX10-Q2026-08-19filing
Leslie's, Inc. LESL10-Q2026-08-12filing
KESTRA MEDICAL TECHNOLOGIES, LTD. KMTS10-Q2026-09-14filing
RCM TECHNOLOGIES, INC. RCMT10-Q2026-08-13filing
NETLIST INC NLST10-Q2026-08-11filing
PILLARSTONE CAPITAL REIT10-K2026-08-13filing
Standard Nuclear, Inc. STDN10-Q2026-08-27filing
CIRCLE8 GROUP INC10-Q2026-08-19filing
Digital Brands Group, Inc. DBGI10-Q2026-08-19filing
Velo3D, Inc.10-Q2026-08-11filing

The full search on EDGAR

Which industries file it

Companies grouped by the industry classification on their own filing. A count, not a survey.

IndustryCompanies
Chemicals and pharmaceuticals95
Software and IT services44
Holding and investment offices44
Instruments and medical devices31
Electronics and electrical equipment27
Services and entertainment22
Mining and extraction21
Retail18
Industrial machinery16
Banking15

What it obligates

Our corpus holds 6 controls across 6 frameworks whose text speaks to this. Not a judgement: these controls say so, and each is one lookup from its source document. Ordered by how much each framework has to say about it, so the one that will cost you the most work is first. Every name opens that framework in the corpus.

FrameworkControls
French Sapin II Law (Law No. 2016-1691) verified
France
1
Jamaica Data Protection Act 2020 verified
Jamaica
1
IFRS 17
International (IASB)
1
Kazakhstan Law on Personal Data and Their Protection (No. 94-V) verified
Kazakhstan
1
Jordan Draft Personal Data Protection Law (2022) verified
Jordan
1
SOX 404 / ICFR verified
United States
1

What an auditor will ask you to produce

The artefacts named on those controls, most frequently cited first.

How it usually fails

Recorded when each control was verified against its source. This is where programmes that think they are covered turn out not to be.

COSO 2013 Internal Control Integrated Framework Evidence & Implementation Kit

23 controls sit behind COSO Internal Control, and this is the documentation set for them: an adopt-ready artifact per control, and the evidence an auditor asks for against each.

See what is in it, $249

The same set every buyer of this kit receives. Nothing here is produced on request.

COSO Internal Control COBIT 201925 shared controlsSwitzerland New Federal Act on D…13 shared controlsNebraska Data Privacy Act9 shared controlsNigeria Data Protection Act 2023…9 shared controlsSOC 29 shared controlsNIST Cybersecurity Framework 2.09 shared controlsAPPI7 shared controlsBahrain PDPL7 shared controlsGDPR7 shared controlsNIST Privacy Framework7 shared controls
COSO Internal Control holds 72 controls. They appear again inside 222 other frameworks in our corpus; the 10 strongest are shown. Thickness and size both carry the number of controls shared, so work done once counts in every framework on this diagram.
23If you already run COSO Internal Control, that is the 23 controls behind this disclosure, already evidenced.
25And COBIT 2019 is not a separate programme. 25 of its controls are the same controls. If it is on next year's plan, that part of it is already done.

Run as two programmes

48 controls

COSO Internal Control and COBIT 2019 scoped separately, each with its own evidence, its own owner and its own budget line. This is how almost everybody does it.

Run once, counted twice

25 already done

25 of COBIT 2019's controls are controls you evidenced for COSO Internal Control. Same artefacts, same owner, no second effort. The mapping is the only reason anybody knows.

first appears Feb 2008 2008 2026 96 filings in the busiest month
Audit Committee Oversight in 10-K and 10-Q filings, by month. The marked line is the first month any public company in our record used the phrase; everything left of it is nobody writing it down.

What this actually means

Why now
36 public companies wrote this into an 8-K in the last seven days, 24% more than the seven before. That is not sentiment or a survey. It is a count of companies choosing to put a phrase into a document they are legally accountable for.
What comes into scope
Once the phrase is on the record it maps to obligations within COSO Internal Control, PCAOB AS 2201. 27 controls behind those, and the difference between asserting them and evidencing them is the whole of the work.
Who is quietly ahead
Anyone already running COSO Internal Control has done 25 of the controls that carry COBIT 2019 too. Same evidence, second standard. Most organisations run those as two programmes with two budgets because nobody told them the mapping existed.
Who is exposed
8 companies disclosed this for the first time in the last ninety days, out of 448 in total. A first mention is a company deciding it can no longer not say it. Whoever has not yet is either genuinely unaffected or has not looked, and nothing here distinguishes the two.

What this obligates

The instruments in our corpus that govern this disclosure, and how many controls sit behind each. This is not a filing count. It is what applies once a company has written the phrase down.

2 frameworks, 27 controls between them.

COSO Internal Control COBIT 201925 shared controlsSwitzerland New Federal Act on D…13 shared controlsNebraska Data Privacy Act9 shared controlsNigeria Data Protection Act 2023…9 shared controlsSOC 29 shared controlsNIST Cybersecurity Framework 2.09 shared controlsAPPI7 shared controlsBahrain PDPL7 shared controlsGDPR7 shared controlsNIST Privacy Framework7 shared controls
COSO Internal Control holds 72 controls. They appear again inside 222 other frameworks in our corpus; the 10 strongest are shown. Thickness and size both carry the number of controls shared, so work done once counts in every framework on this diagram.

What closing it also moves

The same controls appear in other frameworks through mappings held in our corpus. Work done here is already progress there. This is the part that is not in EDGAR and not in any public dataset: it comes from mappings built and verified by hand, control by control.

COBIT 201925

Counted as controls reached through cross-framework mappings. It measures overlap of work, not compliance with the named framework.

Run as two programmes

48 controls

COSO Internal Control and COBIT 2019 scoped separately, each with its own evidence, its own owner and its own budget line. This is how almost everybody does it.

Run once, counted twice

25 already done

25 of COBIT 2019's controls are controls you evidenced for COSO Internal Control. Same artefacts, same owner, no second effort. The mapping is the only reason anybody knows.

23If you already run COSO Internal Control, that is the 23 controls behind this disclosure, already evidenced.
25And COBIT 2019 is not a separate programme. 25 of its controls are the same controls. If it is on next year's plan, that part of it is already done.

If that number surprised you, the same measurement across every topic we track:
What changed this week →

This is what it looks like when the same failure is named by standards bodies who never spoke to each other:
How compliance programmes fail →

And the companies that have already written this into a filing:
Audit Committee Oversight filers →

Tell me when Audit Committee Oversight files something new

One email when a public company newly discloses this, naming the company and what our corpus says it puts in scope. Nothing else, and one click to stop.

Where this comes from

The left half is public record: SEC full-text search over 8-K filings, counted across a 14 day window against the equivalent window before it. You can check every row.

The right half is ours: 723 frameworks and 20,473 controls, 531 of those frameworks verified against their source documents, with the auditor evidence and common failure modes recorded control by control. Controls appear here because their own text names this term.

Cite this

The Art of Service Signals. Audit Committee Oversight corporate disclosure activity: 36 filers against 29 in the prior period, in 10-K and 10-Q filings, this quarter against the same quarter last year. Accessed 23 September 2026. https://signals.theartofservice.com/t/audit-committee-oversight/

Free to use with attribution, no permission needed. The chart downloads as an SVG with the source printed on it. If you cite it we would like to know, but you do not need to ask.

Today's edition · How programmes fail · The obligation index