Two Executive Protection Standards: The Question Joe LaSorsa Asked

ASIS and BEPP executive protection standards compared through scope, implementation, state regulation and professional competency

Two Executive Protection Standards: The Question Joe LaSorsa Asked

ASIS vs BEPP executive protection standards

ASIS, BEPP and what the profession should do next

By Matthew C. Parker
Independent Security Advisors | EPTraining.us

Executive protection now has more than one private standards framework to evaluate. The real question is not which organization wins, but how the profession compares scope, implementation, regulatory fit, competence and operational value.

The executive protection profession spent years asking for standards. Now we have more than one private framework to evaluate.

ASIS International released its Executive Protection Standard in September 2025. The Board of Executive Protection Professionals reports that ANSI approved ANSI/BEPP EPS-2026 in June 2026. A month later, Joe LaSorsa Jr. asked a reasonable question publicly: if the profession now has both ASIS and BEPP standards, which one should practitioners and organizations use?

That is a useful starting point, but I do not think the profession should reduce the answer to ASIS versus BEPP as though one organization has to win and the other has to lose.

The more important question is what happens when a profession has more than one standards framework. Do we choose one? Use both? Treat them as addressing different parts of the problem? Compare their requirements and keep what works? Can employers use one framework while state regulators retain their own authority? Can an independent certification system eventually assess competencies drawn from more than one recognized source?

Those are harder questions than asking which logo belongs on the cover. They are also the questions that will determine whether standards actually improve executive protection.

This Is Not an Argument Against Standards

ISA has been discussing measurable executive protection training standards since 2011. We did not come to this discussion because standards suddenly became popular. We had been working on the problem for years, and we had already learned that writing a standard is the easy part; making it useful, measurable and relevant to the people doing the work is much harder.

I have no objection to standardization when it solves a real problem. Military training systems use standards because people trained by different instructors still have to perform the same mission. State regulatory systems use requirements because the public has an interest in establishing minimum qualifications. Employers establish their own requirements because a credential that is adequate for one mission may not be adequate for another.

Executive protection needs clarity for the same reasons. But a professional standard has to do more than exist. It has to survive contact with training, regulation, employment and operations.

If a standard cannot be translated into something that can be taught, measured, applied and evaluated, then the profession has gained a document without necessarily gaining a capability.

Two Standards Create Practical Questions

Imagine a corporate security director responsible for building or evaluating an executive protection program. ASIS offers a published Executive Protection Standard. BEPP offers ANSI/BEPP EPS-2026, which carries an American National Standard designation.

Which one should the director use? Should the organization use both? Are they complementary? Do they address different levels of the executive protection problem? Does one provide a stronger program-management framework while the other addresses protective-service delivery in greater detail? How do the documents handle risk, advance work, protective intelligence, staffing, training, competence and program evaluation? How do their requirements interact with state licensing and regulatory systems?

The answers cannot be found by comparing organization names, the profession needs a requirement-by-requirement comparison.

Compare Substance, Not Logos

ISA’s position is straightforward. Read the standards. Compare their scope. Compare their definitions. Compare their requirements. Compare how those requirements are implemented. Compare how each document addresses competence. Compare how an employer could use it. Compare how a training organization could convert it into instruction. Compare how it interacts with applicable state regulation.

Then ask the question that matters most: what becomes better because the standard exists?

Does the employer build a stronger program? Does the training provider teach more clearly? Does the practitioner understand what competent performance looks like? Can an evaluator measure that performance? Does the standard help identify gaps before an incident exposes them? Does it improve protective planning and operations?

Or is the “standard” simply a list a good practices, standard procedures or good advice? Is the “standards” lessons you would learn in training and through experience on the job? Do these “standards” increase a level of competence, or introduce a new practitioner to skills and procedures that speed their development?   

The profession should not choose a standard because its logo is more recognizable. It should not choose one because someone calls it “the standard.” It should not assume that a longer document is automatically better, that an older association is automatically better, or that an ANSI designation settles every professional question.

Standards should compete on usefulness.

ANSI Approval Has a Specific Meaning

BEPP’s standard carries an American National Standard designation. That matters, but it has to be described accurately.

ANSI is a private nonprofit organization. It does not regulate executive protection, issue state licenses or determine who may legally perform protective work. ANSI accredits standards developers’ procedures and approves documents as American National Standards when the applicable voluntary-consensus process satisfies ANSI’s requirements. BEPP became an ANSI-accredited standards developer in 2021.

The words American National Standard therefore describe a voluntary consensus standard developed through an ANSI-accredited process. They do not mean Congress enacted the document, a federal agency imposed it, all fifty states adopted it, or the executive protection profession voted to make it the single governing standard.

An ANSI designation tells us something important about the standards-development process. It does not answer every question about professional adoption, regulatory authority, accessibility, training value or individual competence.

Those distinctions matter because standards, licenses, training certificates and professional certifications are not interchangeable.

The September 2026 GAO Report Adds an Outside Reference Point

A new Government Accountability Office report provides useful evidence for this discussion, but it should not be mistaken for a third executive protection standard.

GAO’s September 2026 review examined the Secret Service and compared important aspects of protective mission, advance planning, training and service requirements with the Diplomatic Security Service and U.S. Marshals Service. GAO also interviewed additional federal, state, local and nonprofit organizations with protection responsibilities. BEPP was one of the ten organizations interviewed.

That is legitimate recognition of BEPP as a participant in the professional discussion. It is not federal adoption of ANSI/BEPP EPS-2026, Secret Service endorsement of BEPP, or a declaration that BEPP is the national authority for private executive protection.

What makes the GAO report valuable to this article is the outside benchmark it provides. GAO found that the federal organizations it examined use similar protective advance-planning structures and train personnel across the phases of protective advance work. GAO also found that eight of the ten organizations it interviewed either looked to the Secret Service for protection and training best practices or incorporated Secret Service training into their curriculum. Seven cited the Diplomatic Security Service and three cited the U.S. Marshals Service as additional sources of best practices.

GAO specifically reported that BEPP members viewed Secret Service and Diplomatic Security Service protection training as similar and believed other organizations could not compare with how those two agencies secure protectees.

That observation supports a point ISA has made for years: when the private sector develops standards, government protective systems remain legitimate professional reference points. They do not give us a private-sector standard to copy word for word, but they do give us mature operational systems against which private requirements can be tested. As a graduate of the FLETC EP training course my instructors and I looked to the Federal Law Enforcement Training Center to voluntarily model its own standards for training. But we also incorporated the requirements of Virginia and other state and federal regulatory agencies. 

So the GAO report strengthens the original question rather than replacing it. When we compare ASIS and BEPP, we should also ask whether their requirements reflect the disciplines found in serious protective operations: threat assessment, advance planning, site assessment, coordination, resource decisions, training, supervision, experience and ongoing review.

GAO Also Reminds Us That Standards Have to Evolve

One additional GAO finding deserves mention because it applies to every standards body, including government agencies.

GAO found that some Secret Service protection policies were not reviewed or updated within the agency’s required time frame and recommended stronger documentation and responsibility for policy review after security incidents. That is a useful warning for the private sector. A standard should never be treated as finished simply because it was published.

Threats change. Technology changes. Protective failures reveal weaknesses. New information becomes available. A credible standards system needs a disciplined process for reviewing those developments and deciding whether the standard, the training or both need to change.

The broader lesson is straightforward: useful standards have to connect to real protective practice, respond to lessons learned and remain capable of improvement.

Standards Need Adoption

Publication is not the same thing as adoption. A standard only becomes meaningful when employers use it, instructors teach from it, professionals understand it, regulators find it useful where appropriate and organizations can show that implementation improved performance.

That creates another reason the profession should resist the temptation to declare a winner too early. ASIS and BEPP may each contain useful requirements. One may be more useful for certain organizations, while another may address different concerns. Some provisions may deserve broader adoption. Others may prove difficult to implement. Some may eventually need revision.

The profession should be able to make those judgments without treating either standards organization as synonymous with executive protection itself.

State Regulation Still Matters

Any national professional discussion also has to respect the authority of the states that regulate protective services.

A voluntary professional standard can establish consistency above a state’s minimum requirements, provide a useful reference for employers or influence training design. It should not create the impression that a private document has displaced a licensing system established by law.

Virginia decides what Virginia requires from a Personal Protection Specialist. North Carolina decides what North Carolina requires for Close Personal Protection licensing. Other states make their own decisions within their legal frameworks.

That does not make national professional standards useless. It means their proper role has to be understood. States regulate. Standards organizations establish voluntary benchmarks. Training organizations educate. Employers establish mission requirements. Professionals demonstrate knowledge, skill and experience.

Those functions can coexist without one organization having to control all of them.

The Question Is Bigger Than ASIS or BEPP

Joe LaSorsa Jr. asked which standard the profession should choose. My answer is that we should first decide what we need the standards ecosystem to accomplish.

Why do we need to assume that only one standard can exist? Could there be a common professional core shared across more than one framework? Could one standard be more useful for organizational program design while another contains useful service-delivery requirements? Could employers select the framework that best fits the mission while still meeting state law? Could independent certification eventually test competencies derived from more than one credible standard?

Those questions move the discussion away from organizational ownership and back toward professional outcomes.

The September 2026 GAO evidence helps because it reminds us that the profession already has outside reference points. We can compare private standards not only with each other but also with mature protective practices, measurable training principles, state requirements and lessons learned from real operations.

That is a healthier standards environment than simply asking which organization gets to define executive protection for everyone else.

Independent Competency Assessment May Be the Bridge

There is another reason the profession does not have to force every standards question into an ASIS-or-BEPP choice. A standard describes expectations. Training prepares people to meet them. Neither function, by itself, proves that an individual can perform the work.

That suggests a future system in which recognized standards help define common competency domains while an independent certification organization tests whether an individual can actually meet them. Experience requirements and recertification could then provide additional confidence without eliminating state licensing authority.

That is the direction we will examine later in this series through an ASE-style model: train, test, demonstrate, experience, recertify and improve.

Such a system would allow standards to evolve without requiring one private organization to own the entire professional ecosystem. Training providers could adapt. Standards could improve. Certification examinations could be updated. Employers could use the credentials that fit their missions. States could continue to regulate legal authority.

What the Profession Should Do Next

The next step should not be a marketing contest. It should be a transparent comparison. Build a crosswalk between ASIS and BEPP. Identify common requirements. Identify meaningful differences. Examine definitions and scope. Compare how each document handles implementation and competence. Determine where requirements can be trained and measured. Examine how each interacts with state regulation.

Then compare the private frameworks with credible protective practice, including the federal systems highlighted in the GAO report. Where the standards agree, the profession may be looking at the beginnings of a common core. Where they differ, the profession should determine whether the difference reflects a legitimate mission distinction, a stronger requirement or simply a different organizational philosophy.

Where neither standard adequately answers the problem, we should be willing to say so and improve the system. That is what professional standards work should look like.

EPTraining.us & ISA’s Position

ASIS has produced one executive protection framework. BEPP has produced another through an ANSI-accredited voluntary-consensus process. Both now deserve serious evaluation.

GAO has added useful evidence, but it has not chosen a winner for the private sector. Nor should it. The GAO report is valuable because it gives us another factual reference point for what mature protective organizations actually do and how important training, planning, experience and policy review remain.

No standards organization should be confused with the profession itself. Executive protection is larger than any standards body, training company, association or credential.

Joe LaSorsa asked which standard the profession should choose. I believe the next question is more important:

What kind of standards ecosystem does executive protection actually need?

My answer is one that allows useful standards to coexist, preserves state regulatory authority, makes requirements measurable, supports independent competency assessment and keeps the focus on protective performance rather than organizational ownership.

No standards organization has to own executive protection for executive protection to have standards.

Standards should serve the profession—not become the profession.


Frequently Asked Questions

Which executive protection standard should professionals use: ASIS or BEPP?

There is no single answer for every practitioner or organization. The two standards should be compared by scope, requirements, implementation, measurability, employer usefulness, compatibility with state regulation and relevance to the protective mission.

Did GAO endorse the BEPP executive protection standard?

No. GAO interviewed BEPP as one of ten organizations in its September 2026 review. The report does not adopt ANSI/BEPP EPS-2026, state that the Secret Service uses it or make it a federal requirement.

Why is the September 2026 GAO report relevant to private executive protection standards?

The report provides an outside reference point for evaluating private standards. It documents protective advance planning, training, experience requirements and the organizations other protective entities look to for best practices.

What did BEPP tell GAO about Secret Service and Diplomatic Security Service training?

GAO reported that BEPP members viewed Secret Service and Diplomatic Security Service protection training as similar and regarded the way those agencies secure protectees as difficult for other organizations to match.

Does ANSI approval make the BEPP standard a federal executive protection standard?

No. ANSI approval identifies the document as an American National Standard developed through an ANSI-accredited voluntary-consensus process. It does not make the document federal law, a national executive protection license or a replacement for state regulation.

Can ASIS and BEPP standards both be useful?

Yes. Different standards may address different parts of the executive protection ecosystem. The profession should compare them openly, identify common requirements and determine which provisions improve programs, training and protective performance.

Should state executive protection licensing be replaced by a private standard?

No. A voluntary professional standard can support consistency and professional development, but it does not automatically replace legal requirements established by state regulators.

What should happen when two executive protection standards disagree?

The profession should compare the underlying requirement, its operational purpose, available evidence, regulatory implications and whether it can be trained and measured. The goal should be the strongest professional outcome, not loyalty to one organization.


Related ISA Resources

External Reference Links

About the Author

Matthew C. Parker is CEO of Independent Security Advisors LLC and Director of Training Operations for EPTraining.us. Us Army retired, he has served as a U.S. Army training leader, Master Instructor, and protective-services practitioner, his assignments included training-department management at the U.S. Army Chemical, Biological, Radiological, and Nuclear School, recognition as Instructor of the Cycle and Instructor of the Year, and instructor service with Army ROTC at Virginia Tech. He has more than three decades of military, government, executive-protection, training, and advisory experience, including international security and training work in Iraq and Ukraine.

For more than a decade, Parker has focused on a question central to the professionalization of executive protection: How do we turn standards into measurable performance? Through ISA and EPTraining.us, he has developed and evaluated protective-services training against regulatory requirements, external standards, operational practice, and demonstrated competency. His position is simple: training prepares the professional; standards define expectations; performance demonstrates competence.

 

ISA Executive Protection Standards Series — Article 3

Publisher 
Independent Security Advisors LLC / EPTraining.us

#ExecutiveProtection #ExecutiveProtectionStandards #ExecutiveProtectionTraining #ASIS #BEPP #ANSI #SecretService #DiplomaticSecurityService #USMarshals #GAO #ProtectiveServices #ProtectiveOperations #ProtectiveAdvance #ProfessionalStandards #ProfessionalCompetency #StateRegulation #SecurityTraining #RiskManagement #ProtectiveIntelligence #IndependentCertification #ExecutiveProtectionCertification #IndependentSecurityAdvisors #EPTrainingUS #MatthewParker #StandardsShouldServeTheProfession