<img height="1" width="1" style="display:none" src="https://www.facebook.com/tr?id=1977396509252409&amp;ev=PageView&amp;noscript=1">

Live Webinar May 21st @ 1:00 PM EST: Vulnerability Scanning for PCI & FedRAMP

Contact a Specialist
Industry Solutions
Industry Solutions
Cloud Computing & Data Centers
Cloud Computing & Data Centers
Financial Services & Fintech
Financial Services & Fintech
Healthcare
Healthcare
Payment Card Processing
Payment Card Processing
US Government
US Government
Learning Center
Learning Center
Articles
Articles
Whitepapers
Whitepapers
Case Studies
Case Studies
Events & Live Webinars
Events & Live Webinars
On-Demand Webinars
On-Demand Webinars
Compliance Reliance
Compliance Reliance
About Us
About Us
Leadership Team
Leadership Team
Careers
Careers
Corporate Social Responsibility
Corporate Social Responsibility

APEC Certification

The Asia-Pacific member economies developed a privacy framework as a volunteer system that outlines standards relating to personal information protection as the data moves across borders.

Contact a Specialist Build Your Compliance Roadmap

Controllers and Processors

Controllers that volunteer in the program are assessed by an Accountability Agent against the Cross Border Privacy Rules (CBPR) and if compliant, receive a certification. Processors are assessed against the Privacy Recognition for Processors (PRP) and would also receive a certification if compliant with the program.

APEC Middle-1

APEC for Controllers

Schellman’s APEC CBPR Privacy Certification program evaluates a United States based organization that serves in the role as a controller that collects personal information and transfers information between the participating economies in the APEC region. The organization is assessed against the CBPR certification minimum requirements linked below. These certification standards follow the APEC’s Cross Border Privacy Rules (CBPR) Program Requirements.

View the process Minimum requirements

APEC Middle-1
APEC Wide

APEC for Processors

Schellman’s APEC PRP Certification program evaluates a United States based organization that serves in the role as a processor, processing personal information on behalf of a controller and assists the controller in complying with the relevant privacy requirements. The organization is assessed against PRP certification minimum requirements. Completing this certification, processors are more visible to controllers looking for a certified processor, or vendor.

View the process Minimum requirements

APEC Wide

Our Process

We begin each project with your end goals in mind and to provide preparation for future key project activities. Effective communication and timely coordination of project planning activities are central to our methodology with our clients.

Image

Planning

After the agreement is executed, the first phase of the engagement is planning. This is to ensure that Schellman and the Client are fully aware of the what, who, when, why, and how prior to the beginning of testing.

Proper planning is imperative to the success of a project. Schellman has standard processes to cover the important pieces of the engagement.

Image

Understanding and Kickoff

The kickoff is considered the start of the engagement. If needed, Schellman will schedule a call at the beginning of, or just prior to, the kickoff to finalize any outstanding items. Schellman will be available to the client with any questions.

By including communication prior to starting, Schellman ensures that no last -minute changes to the project or team have occurred and the Client has the plan prior to the testing and on-site visit.

Image

Testing and Gathering

Testing and gathering is the core of the compliance engagement. Due to the planning and understanding processes, this phase will be an accumulation of gathering the evidence needed for the objectives discussed.

Schellman has a no surprise policy and has daily contact with the stakeholders during the testing and gathering activities. Furthermore, Schellman will begin documentation of the draft deliverable to be able to provide it to the Client efficiently after this phase. The Client will have confidence the Schellman team has completed this phase timely and completely.

Image

Reporting

Schellman’s testing methodology ends with reporting, but the entire assessment is focused on creating a deliverable that is clear, concise, and accurate.

Schellman’s report takes into account the entire process and customizes a report for each Client. The draft report will be provided within 2 weeks of the last day of testing and gathering phase, and a final report will be provided within 30 days. This timing is unsurpassed by the industry.

Your APEC Specialist,
Debbie Zaller

Debbie is a Principal at Schellman & Company, LLC.  She leads the Midwest Region along with the Privacy, SOC 2 and SOC 3 service lines and is also on the AICPA’s SOC Specialist Task Force. As Privacy Practice Leader, she serves as the firm’s subject matter expert for APEC certifications. 
  • Fixed-Fee Using an outcome-based, fixed-fee pricing model based on our extensive experience
  • Scope Creep We see less than 5% of our clients that see amendments and are often the result of a scope expansion
  • Low Overhead Low overhead means a flexible financial structure

How much will your audit cost?

Whether it is an ISO 27001 certification, SOC 2 examination or a FedRAMP assessment, companies are often challenged by the need to address customer requirements while ensuring a return on compliance investment.

The most important factor in scoping a potential assessment is understanding what deliverable the recipient (i.e. your customer or partner) is expecting.

Once we have scoped your environment and needs, there are several factors that contribute to Schellman’s pricing:

  • Fixed-Fee Using an outcome-based, fixed-fee pricing model based on our extensive experience
  • Scope Creep We see less than 5% of our clients that see amendments and are often the result of a scope expansion
  • Low Overhead Low overhead means a flexible financial structure

Featured Learning Center Content

 

Schellman Statistics

Schellman includes statistics on the types of complaints received and the outcomes of such complaints publicly accessible on this website. You can learn more on our Statistics and Case Notes page.

View Statistics

Certificate Directory

Check the certification status of our APEC clients by using our Certificate Directory

Certificate Directory

Contact Us

Fill out this form to talk with one of our specialists. We'll be in touch soon to continue the conversation and help you find what you're looking for.

Contact Us

Fill out this form to talk with one of our specialists. We'll be in touch soon to continue the conversation and help you find what you're looking for.