Upcoming Webinar | Navigating Global Privacy Trends in 2026 on December 3rd @ 1:00 PM ET

Contact Us
Services
Services
Crypto and Digital Trust
Crypto and Digital Trust
Schellman Training
Schellman Training
Sustainability Services
Sustainability Services
AI Services
AI Services
About Us
About Us
Leadership Team
Leadership Team
Corporate Social Responsibility
Corporate Social Responsibility
Careers
Careers
Strategic Partnerships
Strategic Partnerships

The Schellman Blog

Stay up to date with the latest compliance news from the Schellman blog.

Schellman

Schellman is a leading provider of attestation and compliance services. We are the only company in the world that is a CPA firm, a globally licensed PCI Qualified Security Assessor, an ISO Certification Body, HITRUST CSF Assessor, a FedRAMP 3PAO, and most recently, an APEC Accountability Agent. Renowned for expertise tempered by practical experience, Schellman's professionals provide superior client service balanced by steadfast independence. Our approach builds successful, long-term relationships and allows our clients to achieve multiple compliance objectives through a single third-party assessor.

Blog Feature

Artificial Intelligence | HITRUST | ISO 42001

By: Schellman
April 15th, 2025

As AI continues to transform industries worldwide and organizations continue to innovate their use of AI in regular practice, they are also faced with growing pressure to demonstrate that their AI systems are secure, trustworthy, and responsible. With regulatory scrutiny and public concern over widespread use of AI on the rise, aligning with established frameworks and standards has become essential for maintaining credibility and mitigating risk.

Blog Feature

Artificial Intelligence | ISO 42001

By: Schellman
April 7th, 2025

As the adoption of artificial intelligence (AI) continues to grow and evolve across industries, so do concerns about security, trust, and responsible use and management. In response, as a joint effort between the International Organization for Standardization (ISO) and the International Electrotechnical Commission (IEC), the ISO/IEC 42001:2023 framework was officially published in December 2023.

Blog Feature

Cybersecurity Assessments | FedRAMP | News | Federal Assessments

By: Schellman
March 31st, 2025

TAMPA, Fla. – March 31, 2025 – Schellman, a leading provider of attestation and compliance services and a top 50 CPA firm, is pleased to announce that Schellman has expanded its offerings to perform cleared assessments for its clients. As an accredited FedRAMP® Third Party Assessment Organization (3PAO), this enables Schellman to perform Department of Defense (DoD) Impact Level 6 (IL6) assessments as well as other NIST-based assessments, SOC 2 examinations, and penetration testing for DoD systems. This milestone strengthens Schellman’s position as a trusted assessment partner for government and defense-related environments.

Blog Feature

FedRAMP | Federal Assessments

By: Schellman
March 26th, 2025

As more government agencies move sensitive data to the cloud, ensuring security and compliance is of paramount importance. As such, the FedRAMP (Federal Risk and Authorization Management Program) assessment and authorization process is a critical framework to ensure that cloud environments meet federal security standards.

Blog Feature

News | SchellmanLife

By: Schellman
February 11th, 2025

TAMPA, Fla. – Schellman, a leading provider of attestation and compliance services and a top 50 CPA firm, is proud to announce the appointment of Preeya Voss as its new Chief Revenue Officer. Voss brings nearly two decades of experience in SaaS and services revenue leadership, with a proven track record of driving transformative growth across diverse industries and customer segments.

Blog Feature

Education | Artificial Intelligence

By: Schellman
February 10th, 2025

*Disclaimer: This article was written using a translated copy of the South Korea AI Basic Act* After the European Union paved the way for creating a legal framework for artificial intelligence (AI) in early 2024, many wondered what government or jurisdiction would follow. The year continued with discussions on how to best implement AI governance and debates on where the line stands between sufficient governance and proper opportunity for creativity in the technology industry. Fast forward a couple of months, as the world prepared to welcome in the new year those questions were finally answered. In late December 2024, South Korea stepped forward proposing their own legislation regarding AI. By January 21, 2025, they became the second entity to propose AI regulation with the passing of the AI Basic Act. To address the obvious next question of when these regulations will be enforced, the enforcement date stands as January 22, 2026, giving organizations roughly a year to prepare. It’s also worth noting that this act contains six sections with 43 articles, and we've outlined the key points below.

Blog Feature

HIPAA

By: Schellman
January 23rd, 2025

As the overarching regulation for healthcare data in the United States, the Health Insurance Portability and Accountability Act has helped secure what is considered personally identifiable information (PII) and its transfer/disclosure within the sector. Under HIPAA, providers and their business associates (BAs) must meet the law’s requirements, including the administrative safeguards within its Security Rule.

Blog Feature

News

By: Schellman
December 11th, 2024

TAMPA, Fla.--(BUSINESS WIRE)-- Schellman & Company, LLC, a leading provider of attestation and compliance services and top 50 CPA firm, is pleased to announce the carve-out acquisition of the Third-Party Risk Management (TPRM) practice from Connor Consulting. This deal marks another significant milestone in Schellman’s strategic growth through acquisitions and its dedication to delivering tailored, independent compliance and governance assessments.

{