By:
Ben Montalbano
September 29th, 2026
California's landmark climate disclosure laws, SB 253 (the Climate Corporate Data Accountability Act) and SB 261 (the Climate-Related Financial Risk Act), have been anything but static since they were first signed in 2023. Deadlines have shifted, a federal appeals court has intervened, and the California Air Resources Board (CARB) is still fleshing out how companies will need to comply.
Artificial Intelligence | ISO 42001
By:
Avani Desai
September 17th, 2026
There have been a lot of conversations about AI safety lately, but one idea really caught my attention: Anthropic CEO Dario Amodei spoke about the need for independent evaluators to have deeper access to AI companies and their models so they can actually test whether the safety measures being put in place are functioning.
By:
Nick Rundhaug
September 10th, 2026
Insights from a conversation with Nick Rundhaug, Managing Director and Federal Practice Leader at Schellman. See his full interview here.
By:
Joe Sigman
September 9th, 2026
AI governance has become one of the most consequential disciplines impacting enterprise-level organizations today. It determines not only whether organizations can manage AI-related risks, but whether they can build and prove the trust, accountability, and operational confidence needed to use AI effectively. Despite its importance, governance is often treated as a supporting function focused on policies, checkbox compliance procedures, and assigned responsibility.
By:
Schellman
September 3rd, 2026
Former Chase Chief Risk Officer and McKinsey and BCG senior partner brings decades of risk governance and growth-stage leadership as Schellman builds toward its next chapter.
By:
Matt Hungate
August 31st, 2026
FedRAMP's modernization effort, known as FedRAMP 20x, is continuing to advance. On August 31, 2026, the FedRAMP 20x program opened Class B and Class C as the next phase of its rollout. Under the program's official Consolidated Rules for 2026 (CR26), Class B pipeline replaces the old Low impact level for small-scale cloud services, and the Class C pipeline replaces the old Moderate impact level for common enterprise services.
By:
Nick Rundhaug
August 25th, 2026
This article was drafted based on a LinkedIn Live discussion between Schellman’s Nick Rundhaug and SecureIT's Tim Sandage and Corey Clements. View their full conversation here.