Upcoming Webinar | From Advisory to Audit: Navigating ISO 42001 Implementation and Certification on November 13th @ 1:00 PM ET

Contact Us
Services
Services
Crypto and Digital Trust
Crypto and Digital Trust
Schellman Training
Schellman Training
Sustainability Services
Sustainability Services
AI Services
AI Services
About Us
About Us
Leadership Team
Leadership Team
Corporate Social Responsibility
Corporate Social Responsibility
Careers
Careers
Strategic Partnerships
Strategic Partnerships

Blog

The Schellman Blog

Stay up to date with the latest compliance news from the Schellman blog.

Blog Feature

Penetration Testing | Artificial Intelligence | ISO 42001

By: Josh Tomkiel
November 3rd, 2025

Not only is artificial intelligence changing how businesses operate; it's also changing how cybercriminals attack. As organizations rush to adopt AI systems, they face new security risks that traditional defenses can't handle.

Blog Feature

News | SchellmanLife

By: Schellman
October 28th, 2025

TAMPA, Fla. – October 28, 2025 – Schellman, a leading provider of attestation and compliance services and a top 50 CPA firm, is proud to announce the appointment of Abhi S. Visuvasam as its new Chief Technology Officer. Visuvasam brings over three decades of experience leading enterprise architecture, software engineering, data engineering, platform modernization, and AI/ML initiatives for Fortune 500 companies and high-growth SaaS firms.

Blog Feature

Privacy Assessments

By: Chris Lippert
October 20th, 2025

Many suppliers working with Microsoft are now required to complete the Microsoft Supplier Data Protection Requirements (MSDPR) Independent Assessment each year to maintain Supplier Security and Privacy Assurance (SSPA) compliance. In practice, we continue to see organizations misinformed about what’s actually required, which often leads to unnecessary costs, re-tests, or delays.

Blog Feature

Cybersecurity Assessments | Artificial Intelligence

By: Sully Perella
October 15th, 2025

People interact with Artificial Intelligence (AI) in many ways, but most commonly through written prompts, which is the method that's also the most familiar avenue for basic prompt-hacking techniques. However, the real concern for organizations lies beyond these simple exploits, with sophisticated attacks targeting enterprise AI systems. In this article, we'll explain how an attacker can weaponize AI assistants to extract proprietary data, manipulate decision-making, and even infiltrate corporate networks.

Blog Feature

FedRAMP | Federal Assessments

By: Matt Hungate
October 14th, 2025

FedRAMP 20x is progressing quickly, with phase 2 just around the corner. Designed to modernize and streamline the authorization process, FedRAMP 20x is reshaping how cloud service providers (CSPs) achieve and maintain authorization to operate (ATO) in the federal marketplace.

Blog Feature

Cybersecurity Assessments | Privacy Assessments

By: Emily Heintz
October 13th, 2025

The California Consumer Privacy Act (CCPA) is reminiscent of Michael Meyers, Freddie Krueger, or Ghostface in that no matter how many times you think its presence is done, it keeps coming back with more. While privacy professionals have been tracking the slow rulemaking process for some time, the newly approved regulations may have startled others, fittingly just in time for spooky season.

Blog Feature

Payment Card Assessments | PCI DSS

By: Mark Stoudemire
October 13th, 2025

As organizations continue to transition to PCI DSS v.4.x, they encounter updated requirements for authentication, especially considering the emerging phishing-resistant technologies like passkeys. To help clarify these changes, the PCI Security Standards Council has released two key FAQs: FAQ 1595 and FAQ 1596, offering valuable insights into the use of passkeys, FIDO2-based authentication, and their alignment with multi-factor authentication (MFA) and phishing-resistant protocols.

Blog Feature

Artificial Intelligence

By: Sully Perella
October 6th, 2025

If you thought developing and implementing your AI system was a challenge, just wait until you attempt to ensure your AI system complies with conflicting international laws simultaneously.

{