Assurance Services Executive Committee
The Assurance Services Executive Committee (ASEC) is a senior committee within the AICPA (the Association) that guides the development of assurance and advisory services. It works to identify new service opportunities driven by market needs and emerging technologies, and provides thought leadership in the assurance profession.
ASEC is a senior executive committee of the Association (AICPA) responsible for assurance and advisory services. Its primary objectives include anticipating, identifying, and assessing new service opportunities related to market needs, demands, and emerging technologies, and providing related thought leadership. In the SOC 2 context, ASEC is the AICPA body associated with developing criteria used in assurance engagements, though the specific scope of any given criteria or proposal depends on the applicable engagement and standard.
Why it matters
For SOC 2 practitioners, ASEC matters because it is the AICPA body associated with developing the criteria used in assurance engagements. The Trust Services Criteria that underpin SOC 2 examinations are products of the AICPA's assurance standard-setting ecosystem, and ASEC's role in anticipating market needs and emerging technologies shapes how those criteria evolve over time. Understanding where authoritative criteria originate helps compliance managers and auditors distinguish between the standards themselves and the engagement guidance built on top of them.
ASEC's mandate to identify new service opportunities driven by market demands and emerging technologies is significant in a period of rapid change in areas such as cloud services, digital assets, and other novel risk domains. Because assurance criteria must keep pace with the technologies and business models being examined, a committee focused on thought leadership and new service development influences the direction of the profession that GRC teams rely on. This is distinct from ISO/IEC 27001 governance, which sits under ISO/IEC rather than the AICPA; the two frameworks maintain separate standard-setting bodies, and satisfying one does not automatically satisfy the other.
Because ASEC operates at the level of guiding assurance and advisory services rather than performing individual engagements, its relevance to any specific SOC 2 report is indirect. A SOC 2 report is issued by a licensed CPA firm and attests only to the controls and period covered; ASEC does not perform examinations or issue reports. Its importance lies in shaping the criteria and thought leadership that inform how those examinations are designed and conducted.
Who it's relevant to
Inside ASEC
Common questions
Answers to the questions practitioners most commonly ask about ASEC.