Services
Services
SOC & Attestations
SOC & Attestations
Payment Card Assessments
Payment Card Assessments
ISO Certifications
ISO Certifications
Privacy Assessments
Privacy Assessments
Federal Assessments
Federal Assessments
Healthcare Assessments
Healthcare Assessments
Penetration Testing
Penetration Testing
Cybersecurity Assessments
Cybersecurity Assessments
Crypto and Digital Trust
Crypto and Digital Trust
Schellman Training
Schellman Training
ESG & Sustainability
ESG & Sustainability
AI Services
AI Services
Industry Solutions
Industry Solutions
Cloud Computing & Data Centers
Cloud Computing & Data Centers
Financial Services & Fintech
Financial Services & Fintech
Healthcare
Healthcare
Payment Card Processing
Payment Card Processing
US Government
US Government
Higher Education & Research Laboratories
Higher Education & Research Laboratories
About Us
About Us
Leadership Team
Leadership Team
Careers
Careers
Corporate Social Responsibility
Corporate Social Responsibility
Strategic Partnerships
Strategic Partnerships

Helping clients build trust with their customers

Contact a Specialist Build Your Compliance Roadmap

Trusted by The World's Leading Companies

Industries Served

With a deep breadth of experience, we have assembled the most common suite of compliance solutions for your specific industry in mind:

Our Reach

Schellman performs thousands of projects each year for domestic and international clients.

map

How is Schellman Different?

In an industry of norms we have consistently applied our values to set ourselves apart which has allowed us to be a leader in the compliance world.

targeted-services-dark

Targeted Services

We provide IT audit and compliance attestations, and there are no upsells of other consulting services or financial audits.

fixed-fee-pricing-dark

Fix-Fee Pricing

All engagements at Schellman come with no hidden fees, unlike the Big 4 that offer traditional hourly billing.

no-contractors-dark

No Contractors

All auditors are Schellman employees and no work is done “off-shore.”

accessible-smes-dark

Accessible SMEs

Schellman principals, many of whom are former Big 4 auditors, play an active role on all engagements.

Our Methodology

Schellman’s methodology is put to the test hundreds of times per year across different locations and business environments. With a scalable methodology, this approach largely remains the same which gives our clients the ability to include subsidiaries and related entities into a single audit effort.

Our process begins with the end in mind and always aims to lay the groundwork for future projects. With effective communication and timely coordination across these planning activities, Schellman has never missed a deadline and has consistently delivered on its goal of Quality, Above All.

Image

Planning

After the agreement is executed, the first phase of the engagement is planning. This is to ensure that Schellman and the client are fully aware of the what, who, when, why, and how prior to the beginning of testing.

Proper planning is imperative to the success of a project. Schellman has standard processes to cover the important pieces of the engagement.

Image

Understanding

The kickoff is considered the start of the engagement. If needed, Schellman will schedule a call at the beginning of, or just prior to, the kickoff to finalize any outstanding items. Schellman will be available to the client with any questions.

By including communication prior to starting, Schellman ensures that no last-minute changes to the project or team have occurred and the client has the plan prior to the testing and on-site visit.

Image

Testing

Testing and planning is the core of the compliance engagement. Due to the planning and understanding processes, this phase will be an accumulation of planning the evidence needed for the objectives discussed.

Schellman has a no surprise policy and has daily contact with the stakeholders during the testing and planning activities. Furthermore, Schellman will begin documentation of the draft deliverable to be able to provide it to the Client efficiently after this phase. The client will have confidence the Schellman team has completed this phase timely and completely.

Image

Reporting

Schellman’s testing methodology ends with reporting, but the entire assessment is focused on creating a deliverable that is clear, concise, and accurate.

Schellman’s report takes into account the entire process and customizes a report for each client. The draft report will be provided within 3 weeks of the last day of testing and gathering phase, and a final report will be provided within 30 days. This timing is unsurpassed by the industry.

Awards

100% Dedicated to not just audit and compliance attestation, but also our people

 

Awards 23

 

What our customers are saying

Working with some of the best organizations in the world, honest feedback is essential. We survey our clients after every engagement, and here is what some of them had to say:

Image
Quote
After working with this team on several engagements, I am always impressed with their level of flexibility and willingness to work through the assessments. The teams are easy to work with and are always available to provide guidance and education when needed."

PCI DSS Validation | Managed Service Provider

Image
Quote
As someone who has interacted with various audit organizations such as PwC, KPMG, EY, etc., the team at Schellman is always at a higher level in terms of knowledge/expertise, professionalism, and customer advocacy. With other audit firms, my experience has always been similar to driving without power steering where I am having to do more work and struggle to stay in my direction. With the Schellman team, it is like driving with not just power steering, but lane departure warning, collision avoidance braking, and blind spot indicators."

ISO 27001 Certification | Software Company

Image
Quote
I don't know what we would do without our partners at Schellman. They've done a great job supporting all our audits, ad-hoc requests, and providing a great level of service to everyone at our organization. We look forward to many more years of continued partnership."

SOC 1 Assessment | Management Consulting Services Company

CSR Middle

Corporate Social Responsibility

Demonstrating leadership through deliberate actions that support a more sustainable future for the marketplace, our people, the community, and the environment.

Learn More

CSR Middle
Careers Middle

Careers

Schellman is the only Top 100 CPA firm to specialize in IT Audit and Cybersecurity. Not all CPA firms are created equally, and we pride ourselves on our differences. As a smaller firm, we are more visible; you are not one of the masses. Our team is made up of high performers who move quickly and thrive in an open environment.

Learn More

Careers Middle
partnership-shake

Schellman Strategic Partnerships

At Schellman, we deeply understand the significance of our independent audit, assessment, and certification services within the expansive cybersecurity and compliance ecosystem. We take pride in our extensive experience collaborating with diverse providers, always maintaining a steadfast commitment to impartiality and avoiding any revenue sharing or conflicts of interest.

While Schellman does not engage in reselling or participate in referral fees, we firmly believe that fostering alliances throughout the market allows us to deliver exceptional solutions to our clients.

Learn more about becoming a partner

partnership-shake

Connect with a Schellman specialist.

We are a trusted provider to the world’s leading companies with a service delivery model which allows for optimum quality and client experience for organizations of every size and complexity.