Live Webinar | Building AI Governance That's Audit-Ready on September 23 @ 1:00PM ET

Contact Us
Services
Services
Crypto and Digital Trust
Crypto and Digital Trust
Schellman Training
Schellman Training
Sustainability Services
Sustainability Services
AI Governance
AI Governance
About Us
About Us
Leadership Team
Leadership Team
Corporate Social Responsibility
Corporate Social Responsibility
Careers
Careers
Strategic Partnerships
Strategic Partnerships

The Schellman Blog

Avani Desai

Avani Desai is the CEO at Schellman. Avani has more than 15 years of experience in IT attestation, risk management, compliance and privacy. Avani’s primary focus is on emerging healthcare issues and privacy concerns for organizations. Named as one of the 2017 Global Leaders in Consulting by Consulting Magazine she has also been featured and published in the ISSA Journal, ITSP Magazine, ISACA Journal, Information Security Buzz, Healthcare Tech Outlook, and many more. Avani also sits on the board of Catalist, a not for profit that empowers women by supporting the creation, development and expansion of collective giving through informed grantmaking. In addition, she is co-chair of 100 Women Strong, a female only venture philanthropic fund to solve problems related to women and children in the community.

Blog Feature

Artificial Intelligence | ISO 42001

By: Avani Desai
September 17th, 2026

There have been a lot of conversations about AI safety lately, but one idea really caught my attention: Anthropic CEO Dario Amodei spoke about the need for independent evaluators to have deeper access to AI companies and their models so they can actually test whether the safety measures being put in place are functioning.

Blog Feature

Penetration Testing

By: Avani Desai
September 8th, 2026

Cyber insurance renewals have changed, have you noticed?

Blog Feature

Artificial Intelligence

By: Avani Desai
August 4th, 2026

A Q&A about the EU AI Act with Schellman CEO Avani Desai on risk classification, AI literacy, and the August 2 deadline

Blog Feature

Cybersecurity Assessments | Compliance and Certification | Crypto and Digital Trust

By: Avani Desai
August 20th, 2025

On July 18, 2025, President Trump signed the GENIUS Act into law, marking a major milestone for the U.S. digital asset ecosystem. For the first time, there is a federal framework that governs how payment stablecoins are issued, secured, and monitored.

Blog Feature

SOC Examinations | Artificial Intelligence | SOC 2

By: Avani Desai
August 4th, 2025

Have you read the recently released America’s AI Action Plan yet? If so, you know that it’s full of ambitious goals to strengthen the country’s leadership in artificial intelligence. For me, one part in particular stood out immediately, the White House issued a clear call to action to the data center industry.

Blog Feature

Cybersecurity Assessments | Artificial Intelligence

By: Avani Desai
November 13th, 2024

Even as AI systems become more advanced and enmeshed in daily operations, concerns regarding whether large language models (LLMs) are generating accurate and true information remain paramount throughout the business landscape. Unfortunately, the potential for AI to generate false or misleading information—often referred to as AI “hallucinations”—is very real, and though the possibility poses some significant cybersecurity challenges, there are ways organizations deploying this technology can mitigate the risks.

Blog Feature

Cybersecurity Assessments

By: Avani Desai
October 15th, 2024

As EU member states transpose the NIS 2 Directive into their national laws by October 17, 2024, organizations under its purview must also ensure they’re ready to fully comply with the new cybersecurity regulations. Penalties for non-compliance will include significant fines, so if you haven’t started on any necessary implementations, now is the time.

Blog Feature

Cybersecurity Assessments

By: Avani Desai
September 12th, 2024

As cyber threats continue to grow more complex and difficult to defend against, regulatory cybersecurity requirements are becoming increasingly stringent—the Digital Operational Resilience Act (DORA) is the latest, and it demands your attention. The law comes into full effect in just a few short months—January 2025—and an independent assessment could help ensure you achieve full compliance in time.

{