Skip to main content
Category: Standards and Frameworks

Assurance Services Executive Committee

Also known as: ASEC, AICPA Assurance Services Executive Committee
Simply put

The Assurance Services Executive Committee (ASEC) is a senior committee within the AICPA (the Association) that guides the development of assurance and advisory services. It works to identify new service opportunities driven by market needs and emerging technologies, and provides thought leadership in the assurance profession.

Formal definition

ASEC is a senior executive committee of the Association (AICPA) responsible for assurance and advisory services. Its primary objectives include anticipating, identifying, and assessing new service opportunities related to market needs, demands, and emerging technologies, and providing related thought leadership. In the SOC 2 context, ASEC is the AICPA body associated with developing criteria used in assurance engagements, though the specific scope of any given criteria or proposal depends on the applicable engagement and standard.

Why it matters

For SOC 2 practitioners, ASEC matters because it is the AICPA body associated with developing the criteria used in assurance engagements. The Trust Services Criteria that underpin SOC 2 examinations are products of the AICPA's assurance standard-setting ecosystem, and ASEC's role in anticipating market needs and emerging technologies shapes how those criteria evolve over time. Understanding where authoritative criteria originate helps compliance managers and auditors distinguish between the standards themselves and the engagement guidance built on top of them.

ASEC's mandate to identify new service opportunities driven by market demands and emerging technologies is significant in a period of rapid change in areas such as cloud services, digital assets, and other novel risk domains. Because assurance criteria must keep pace with the technologies and business models being examined, a committee focused on thought leadership and new service development influences the direction of the profession that GRC teams rely on. This is distinct from ISO/IEC 27001 governance, which sits under ISO/IEC rather than the AICPA; the two frameworks maintain separate standard-setting bodies, and satisfying one does not automatically satisfy the other.

Because ASEC operates at the level of guiding assurance and advisory services rather than performing individual engagements, its relevance to any specific SOC 2 report is indirect. A SOC 2 report is issued by a licensed CPA firm and attests only to the controls and period covered; ASEC does not perform examinations or issue reports. Its importance lies in shaping the criteria and thought leadership that inform how those examinations are designed and conducted.

Who it's relevant to

Compliance and GRC Managers
Managers overseeing SOC 2 readiness benefit from understanding that the criteria applied in their examinations originate within the AICPA's assurance standard-setting structure, of which ASEC is a part. This context helps them track how criteria may evolve and interpret guidance as it changes, while recognizing that ASEC does not itself perform or issue reports.
Auditors and CPA Firm Practitioners
Practitioners performing SOC 2 examinations under AICPA standards should be aware of ASEC as the senior committee associated with developing assurance criteria and providing thought leadership. Familiarity with its objectives supports staying current as new service opportunities and technology-driven criteria emerge, though the applicable criteria for any given engagement depend on the governing standard and scope.
Security and Risk Leaders Tracking Emerging Technologies
Leaders evaluating assurance options for new technology domains may find ASEC's mandate relevant, since the committee is focused on anticipating service opportunities tied to emerging technologies and market demands. This is useful when assessing whether and how assurance frameworks are evolving to address new risk areas, while keeping in mind that ASEC operates within the AICPA ecosystem and is separate from ISO/IEC governance bodies.

Inside ASEC

AICPA senior committee
The Assurance Services Executive Committee (ASEC) is a senior technical committee operating under the American Institute of Certified Public Accountants (AICPA). It provides direction on assurance and advisory services offered by CPAs.
Trust Services Criteria ownership
ASEC is responsible for developing and maintaining the Trust Services Criteria used in SOC 2 examinations, including the Security category (the Common Criteria) and the optional categories of Availability, Processing Integrity, Confidentiality, and Privacy.
Guidance and updates
The committee issues and periodically revises the criteria and related guidance, so practitioners typically reference the version in effect for a given examination period rather than assuming a static set of criteria.
Relationship to the examination standard
While ASEC develops the Trust Services Criteria applied in a SOC 2 report, the examination itself is performed by a licensed CPA firm under the AICPA's SSAE 18 attestation standard. ASEC sets the subject-matter criteria; it does not itself perform engagements.

Common questions

Answers to the questions practitioners most commonly ask about ASEC.

Does the ASEC issue SOC 2 reports or perform SOC 2 examinations?
No. The ASEC is a senior committee within the AICPA that develops and maintains the standards and criteria used in assurance engagements, including the Trust Services Criteria applied in SOC 2 examinations. It does not perform examinations or issue reports. A SOC 2 examination is an attestation performed by a licensed CPA firm under the AICPA's SSAE 18 standard, and the resulting report is produced by that service auditor, not by the ASEC.
Is the ASEC the body that certifies organizations against SOC 2?
No. SOC 2 is not a certification, so there is no certifying body in the ISO sense. The ASEC's role relates to setting and maintaining the criteria and guidance that underpin these engagements. The evaluation of an organization's controls is carried out by an independent CPA firm as an attestation examination, which results in a report describing the controls and the period or point in time covered.
How do the criteria maintained by the ASEC relate to what my auditor evaluates in a SOC 2 engagement?
The Trust Services Criteria maintained under the ASEC's purview provide the framework against which your service auditor evaluates your controls. In most engagements, the Security category (the Common Criteria) is assessed as it is the required category, while Availability, Processing Integrity, Confidentiality, and Privacy are included depending on the scope you and your auditor define. The auditor selects procedures and forms conclusions using these criteria as the benchmark.
Where do I find the criteria the ASEC is responsible for so my team can prepare for an engagement?
The Trust Services Criteria and related guidance are published by the AICPA. Because criteria and supporting guidance can be revised over time, you should confirm you are working from the current version applicable to your engagement, typically in coordination with your service auditor, who can advise which criteria and reporting framework apply to your defined scope.
Should I map ASEC-maintained Trust Services Criteria to ISO 27001 requirements when running both frameworks?
Mapping between the Trust Services Criteria used in SOC 2 and ISO 27001 is possible but partial. The two frameworks have different structures and objectives, and satisfying one does not automatically satisfy the other. Where organizations pursue both, teams often identify overlapping controls to reduce duplicated effort, but each framework's requirements should still be assessed on its own terms, since gaps and framework-specific expectations typically remain.
Does understanding the ASEC's role change how I scope a SOC 2 Type I versus Type II engagement?
The ASEC's role in maintaining the criteria does not change scoping decisions, which you make with your auditor. A Type I engagement assesses the suitability of the design of controls at a point in time, while a Type II assesses both design and operating effectiveness over a defined review period whose length is set by your scoping decisions rather than fixed. In both cases, the criteria provide the evaluation benchmark, and the report attests only to the controls and period or point in time covered.

Common misconceptions

ASEC issues or grants SOC 2 reports.
ASEC develops and maintains the Trust Services Criteria used as the basis for a SOC 2 examination. The report itself is produced by an independent licensed CPA firm conducting the attestation engagement under SSAE 18; ASEC does not perform engagements or issue reports.
The Trust Services Criteria maintained by ASEC are equivalent to ISO 27001 Annex A controls.
The Trust Services Criteria are a distinct framework used for SOC 2 attestation and should not be conflated with ISO 27001 Annex A reference controls. Mapping between the two is possible but partial, and satisfying one framework does not automatically satisfy the other.
The Trust Services Criteria are fixed and never change.
ASEC periodically revises the criteria and associated guidance. Practitioners should confirm which version applies to the examination period in scope, since criteria and their organization can differ across editions.

Best practices

Confirm the version of the Trust Services Criteria in effect for your examination period, since ASEC periodically revises the criteria and guidance.
Treat the Security category (Common Criteria) as the required foundation and select Availability, Processing Integrity, Confidentiality, or Privacy only where they are relevant to your defined scope.
Keep the roles distinct in internal documentation: ASEC develops the criteria, while an independent licensed CPA firm performs the SSAE 18 attestation that results in the SOC 2 report.
Avoid presenting the Trust Services Criteria as interchangeable with ISO 27001 Annex A controls; if you maintain a crosswalk, document it as a partial mapping rather than an equivalence.
Reference ASEC-published guidance when scoping and describing controls so that the examination aligns with the current authoritative criteria.
Communicate to stakeholders that the criteria define the subject matter of the examination and that a resulting report attests only to the controls and period covered, not to freedom from breaches.