Executive Protection Needs an ASE Model

executive protection certification
Independent Security Advisors | EPTraining.us | ISA Executive Protection Standards Series — Article 6

Executive Protection Needs an ASE Model

executive protection certification

The standards exist. Now the profession needs an independent way to prove who can actually meet them.

By Matthew C. Parker
Independent Security Advisors | EPTraining.us

Executive protection has standards. The next question is whether the individual can actually meet them. Matthew Parker proposed an ASE-style system built around independent testing, demonstrated performance, relevant experience and recertification. It is time to look again at that proposal.

Executive protection organizations are spending a great deal of time talking about standards, certification and competency. I support that discussion. I have been pushing standards for years. So what I do not want lost in the current debate is the fact that some of us did not arrive here because somebody else published a standard, hired a testing company or announced a new certification. Here at ISA we were already working the same problem more than a decade ago.

My concern then, as with now, has always been practical. If we train somebody to protect another human being, what standard are we training that person to? How do we measure whether the student met it? Who outside the school has looked at the program? What does experience count for? And after the person earns a credential, how do we know the person can still do the work five or ten years later?

Why ASE?

ASE is the National Institute for Automotive Service Excellence. It was established in 1972 as an independent nonprofit organization serving the automotive industry. ASE does not require every technician to attend one school or buy one company’s training package before being certified. Technicians can arrive through different schools, manufacturers, employers and career paths, but the certification process gives the industry a common way to measure job-related knowledge and relevant work experience.

That is what attracts me to the model. The training provider prepares the individual. The employer develops experience. The certifying organization measures against a common requirement. The credential can travel with the person instead of being tied permanently to the school that issued the original training certificate.

ASE also requires relevant work experience and recertification. Those two pieces matter as much to me as the examination. A written test can tell me what somebody knows. Experience tells me whether the person has spent time doing the work. Recertification tells me the credential is supposed to represent current ability rather than something earned years ago and never questioned again.

This system solves the standards question. 

We Were Working This Problem in 2011

But, let’s back up a bit to qualify our opinion.

Our standards work did not begin with the current ASIS-versus-BEPP debate. It began in 2011 after local law-enforcement personnel came to us looking for close-protection training they could use to support elected officials. Once we started building the program, we ran into a problem that should sound very familiar today: what exactly was the measurable training standard?

We went looking for one. We examined Department of Defense and federal law-enforcement material, reviewed private-sector practices and used the instructional-systems-design process to identify the tasks a protective professional actually had to perform. The program became longer and harder because we stopped asking what topics should be placed on a syllabus and started asking what the student should actually know and be able to do.

That distinction is important. A list of topics is not a standard. A PowerPoint is not a standard. A course certificate is not a standard. If the student cannot be evaluated against a defined requirement, then all we really know is that the student attended.

Then We Put the Training in Front of Other People

By 2012, we were taking the program through outside regulatory and accreditation processes. I did not want ISA to be the only organization saying ISA training was good. If the program was going to have value to law enforcement, state regulators, employers and students, somebody outside our company needed to be able to examine it against requirements we did not write for ourselves.

That approach became part of how I looked at standards from that point forward. Virginia DCJSNorth Carolina PPSBthe South Carolina Criminal Justice AcademyGeorgia POST, Maryland MPCTC and other outside bodies have all been part of our training history in different ways. The specific approval, recognition or regulatory role is not identical in every state, and I don’t pretend that it is. The point is that outside review was already part of our model.

Our current program still follows the same basic idea. We use measurable learning objectives, written examinations, practical exercises, field application and capstone evaluation. Students do not receive a certificate simply because they paid tuition and occupied a seat.

ISA Started With the Training Problem

For us, this goes back to the shooting of Representative Gabrielle Giffords, when local law-enforcement personnel came to ISA looking for close-protection training they could use to support their own elected officials. We built an initial course, but almost immediately ran into a larger problem: there was no single national, quantifiable private-sector standard we could simply pull off the shelf and use. We didn’t think certification, we were still focused on standards.

So we went looking, and we reviewed what the Department of Defense and the Federal Law Enforcement Training Centers could provide. We looked at the federal protective-service model, military training requirements, state regulation and what was actually being done in the field. When private-sector executive protection providers began asking us about “accredited” training, we expanded into the private sector looking for standards.

The ISA ISD Process Changed the Question

Our search was not a matter of sitting around a table and deciding what topics sounded good in an executive protection course. We used an Instructional Systems Design process—ISD.

ISD forced us to work backward from performance. Questions need to be asked and answered, for example;

  • What does a protection professional actually have to do?
  • Under what conditions?
  • To what standard?
  • What knowledge supports the task?
  • What has to be practiced?
  • What can be tested in writing?
  • What has to be observed?
  • How do we know the student met the requirement?

That process identified the critical skills we believed were required to conduct protective-service operations across different threat levels and client environments. It also reinforced how I looked at the standards question. A list of subjects is not a standard. A course title is not a standard. A certificate showing attendance is not a standard. Our course managers and myself knew if we can’t define the action or task, identify the conditions and the level of acceptable performance, then we didn’t have anything valid.

That same thinking still drives our team today. Our curriculum is built around students understanding and meeting the learning objectives, exposing them to examples of practical work situations and scenarios, and strict testing and evaluation rather than simply the instructor covering a few slides. That history is documented in ISA’s national standards article and our curriculum-development material

But here we were over focused on course design and standards, we were still not looking at certification.

Virginia and FLETC 

Because a training course should lead to a licence or legal ability to seek employment we chose the Virginia Department of Criminal Justice Services Personal Protection Specialist requirements as one of the outside regulatory benchmarks for the program, while also using the FLETC Protective Service Operations program as a federal training model.

That mattered because Virginia was not ISA grading ISA. The state established minimum hours, required content, testing and regulatory expectations. We could build above that floor, but we did not get to redefine the floor whenever it was inconvenient. And the FLETC program provided us with vetted and quantified topics of training and study, standards for operations and training, instructor requirements, safety, curriculum rules and other regulatory requirements.

In 2014, after review by the Commonwealth, ISA became an approved alternative training provider for Virginia’s Personal Protection Specialist 32E and 32I requirements. The current 32E program still demonstrates why I have always considered Virginia an important standards benchmark, it includes threat and vulnerability assessment, legal authority, protective-detail operations, emergency procedures, practical exercises and a comprehensive written examination. Virginia also requires in-service training, and has specific regulations on conducting training.

That is what a real regulatory standard does. It establishes a minimum that exists outside the school.

I have never argued that the state minimum should be the ceiling, quite the opposite. It should not. A good training provider should exceed it. But there is a big difference between exceeding an outside standard and simply declaring your own program excellent because you wrote it yourself.

But now we were officially an accredited training program and our graduates met the requirements for the state licence.  Licence, not certification.

Outside Review Kept Building

Virginia was not the only outside accreditation or approval we pursued. In 2014 we also successfully worked with a university in an effort to connect executive protection training with higher education, this resulted in an education agreement for credit recognition of our program. Later after another exhaustive evaluation of our program, the International Foundation for Protection Officers endorsed the ISA dignitary-executive protection program.

I don’t bring this up to turn this into a history lesson about ISA awards or partnerships. I bring it up because our efforts and intent matters to today’s discussion. We were trying to get our training program evaluated  outside our own walls. State and federal regulators, law-enforcement training boards, higher education and professional organizations.

The effort and intent was always the same, will somebody besides us look at the program and tell us whether the requirements, training and evaluation make sense, and grant us recognition, accreditation or approval.  Not certification.

The SIA Model

executive protection certificationThe United Kingdom gave us another piece of the standards puzzle but also introduced us to the certification question.

In 2015, ISA decided to make its executive-protection training portable beyond one state and go international. So between May 2015 and February 2016, we worked through the UK qualification system and ISA’s dignitary/executive-protection program received recognition with Industry Qualifications Limited, or IQ, an awarding organization within the SIA-recognized qualification system.

ISA training was recognized so graduates could receive credit towards the IQ Level 3 close-protection qualification, and in 2016 we supported the Security Industry Authority model publicly.  UK SIA — historical close-protection qualification requirements

It meant our graduates were certified as meeting the standards and requirements of the UK. 

2018: We Put the Standards on the Record

On November 12, 2018, ISA published Executive Protection Training Standards: A National Priority?

That article documented the work going back to 2011: the original law-enforcement request, the lack of a single national quantifiable training standard, the ISD assessment, the use of Virginia regulation and FLETC as outside benchmarks, the university effort, the IFPO endorsement and the continued push for a national discussion.

The point in 2018 was simple: we were still arguing about standards seven years after we had first run into the problem. And we were still asking whether every school should be allowed to define quality for itself. 

And although introduced to certification in 2015-2016, by 2018 we had withdrawn from the agreement with the IQ due to a lack of interest in UK licencing by our graduates.

2019-2020: Still Asking How the Student Is Measured

The next year we went back to the same question but from the student’s point of view. Since we had little support to establish a national standard within the industry, I argued that a student should be able to ask “What standard am I being trained to?” “Where is that standard documented?” “How will I be measured against it?”

Those questions sound basic, but there not, because if a school cannot answer them, the student is being asked to trust the school’s reputation, marketing and certificate rather than a defined recognized industry accepted requirement. That was the problem I was still trying to solve when we updated the 2018 standards article in 2020, and finally embraced “certification” as opposed to just standards.

2020: We Put ASE on the Table

So, the updated ISA proposal in 2020 to bring a national standard changed to certification. 

By 2020 we had spent years working with state regulation, federal training models, ISD, outside review and the UK qualification system. And we reached the conclusion that a national or federalized private-sector executive protection training standard was neither realistic nor necessary. Private sector employers, government agencies and law enforcement had established executive protection training standards. So I proposed a new private-sector answer.

In that 2020 update I pointed to the National Institute for Automotive Service Excellence—ASE as a model. I proposed an industry-led nonprofit approach, testing in defined skill areas, relevant job-experience requirements and a system that could allow different training providers to prepare people against common certification requirements. I was proposing a way to separate the school from the professional credential.

2026: Why ASE Still Makes Sense

ASE does not certify a technician simply because that person attended one school. Candidates can come through different employers, schools, manufacturers and career paths. They must pass the applicable examination and satisfy the relevant work-experience requirement. ASE credentials are also maintained through recertification.

ASE’s test-development process uses working technicians, manufacturers, aftermarket representatives and educators. In other words, the people who understand the work help define what is tested, but the final credential is not simply a certificate issued by the school that taught the candidate. That is the structure I want us to look at now.

The school trains.
The employer helps develop experience.
The certification body measures against a common requirement.
The professional carries the credential.

The executive protection industry should adapt that structure and embrace certification. 

We Have Had Standards. We Still Have the Same Competency Problem.

The profession is in a different place today. ASIS released its Executive Protection Standard in 2025. The BEPP ANSI/BEPP EPS-2026 was approved as an American National Standard in 2026. We also have the ASIS/IPSB 2020 Executive Protection Professionals Core Competencies Survey, which gives us a documented body of work on what a new executive protection professional should know and be able to do.

But we also have employers and clients who have established the standards for training and experience. Read their job postings, they clearly define what they are looking for, and often will require a candidate to have attended an approved or accredited training school or program. That is progress.

But these standards documents don’t prove that the person standing next to the principal can perform with an acceptable level of competency. You bought a book of standards, so what, a standard, or in many cases a ‘best practice” can define what’s expected, but it doesn’t determine how competent you are. 

We still need an independent way to answer the question I started asking in 2020, Can this person actually do the work?

Standard Vs. Demonstrating Mastery

So the standard has been established page x, para x “an agent will wear suitable clothing”. Lame but ok.

That, and the other executive protection standards in topics like legal issues, protective intelligence, threat assessment, advance planning, transportation, communications, emergency procedures, professional responsibilities and other areas must be taught and the student tested to determine if the agent understands them.

But can the agent conduct an advance? Can they identify vulnerabilities at a site or take threat information and turn it into staffing, movement and transportation decisions? Can a team leader brief a team, recognize a route problem, communicate under pressure and adjust when the original plan no longer works?

These can all be “standards” in your book, but you need to demonstrate mastery beyond a written exam.  We need to certify an agent’s ability to execute an action/task, under specific conditions and to an established evaluated standard. 

Experience?

A requirement/standard for “EP or security experience” does not automatically establish your competent. The standard “A team leader requires 5 years of experience”.

Well service/experience in the military, law enforcement or private sector security/protective service covers a broad number of different positions, assignments and duties. And each may operate differently, and may not conduct advances, moving principals, coordinating with law enforcement, solving transportation problems and making decisions the same way.

Solution, An ASE Model Certification Program

An ASE-type executive protection certification would define what experience counts, how it is verified and what responsibilities the candidate must have actually performed. That matters because judgment comes from doing the work. And while training builds the foundation, experience develops judgment.

Certification should recognize the difference. And the certification testing process will establish the de facto standards of initial training for new EP practitioners. 

The Money Question

Earlier in this series I challenged the cost and accessibility of professional standards, and I challenged what happens when professional terminology starts becoming part of private branding and intellectual-property strategies. The same concern applies here.

I have no objection to people being paid for their work. Standards development costs money. Conferences cost money. My question is what the agent and the profession gets in return. ASIS sells its Executive Protection Standard and provides electronic access as a membership benefit. BEPP sells its standards, and none of that proves bad intent. 

But are we building better protectors, or are we building more things a protector has to buy in order to look professional?

So let’s visit an earlier question, If standards are only available in a paid document, association membership has a cost, membership requires paid training or credits, which leads to attending a paid conference or a paid examination, which leads to continuing education, which leads to renewal, we need to ask whether we have created a competency system or a commercial loop.

An ASE-type model gives us a way to separate those functions.

The Credential Should Be Independent of the School and the Standards Organization

If the same organization writes the standard, sells the standard, controls the training, develops the examination, decides who is competent, issues the credential and controls renewal, then the employer is being asked to trust one private organization from beginning to end.

Under the model I am proposing, ISA and other private sector or government schools could train students. Law-enforcement academies, military programs, corporate-security organizations and experienced practitioners could prepare new agents through employment and mentoring.

The new independent EP certification body would decide whether the agent meets the published competency requirement through testing and examinations. It would establish basic, intermediate and senior levels of certification.

No school, No standards organization and No membership organization would “own the profession”, or have undue influence.

ASIS, BEPP, IPSB, Educators and Employers Can All Contribute

I am not arguing that ASIS, BEPP or IPSB have no role. They do.

ASIS can contribute program-management standards and risk-management requirements. BEPP can contribute operational standards work and the professional examination work being done with Prometric. IPSB can contribute practitioner research, professional education and the competency work it helped support.

State regulators continue to regulate. Training providers train. Employers define mission requirements.

An independent certification organization can take credible work from all of them, conduct a defensible job analysis and answer the question no one of those organizations should have to answer by itself:

Does this individual meet the professional competency requirement?

BEPP and Prometric Are One Part of the Answer

BEPP’s current work with Prometric matters because professionally developed testing is part of the answer. A serious examination built from a job analysis is stronger than a school writing its own test, grading its own students and then presenting the result as an industry credential. But Prometric is a testing partner. Prometric is not ASE, and a written examination is not the entire ASE model.

BEPP’s current public certification material describes a written examination, five years of verifiable security experience, a background check, a three-year certification period and continuing-education requirements for renewal. Those are real requirements.

But now the questions I need to ask are What experience counts? What operational competencies have to be demonstrated? Who observes or verifies that experience or performance? What does recertification prove? Who is doing the background checks?

How much does it cost?

State Licensing Still Has Its Own Job

An independent professional certification should not replace state licensing. Virginia determines what Virginia requires. North Carolina determines what North Carolina requires. Other states make their own decisions under their laws. That is not a weakness in the model. It is the proper division of responsibility.

State license or registration: legal authority where required.
Training: preparation.
Standards: the benchmark.
Experience: practical development and judgment.
Independent certification: verified competence.
Employer: mission fit.

Those functions can work together without pretending they are the same thing.

Recertification Has to Mean More Than Paying Again

A professional credential should not last forever. Executive protection changes too quickly. Threats change. Technology changes. Medical practice changes. Communications change. Surveillance changes. Laws change. We learn from attacks, failures and near misses.

Continuing education can be part of renewal, but credits are not the same thing as competence.

Recertification should show that the professional is still current. It should also recognize credible education from outside the certifying organization. Renewal should not become a system where the only way to keep the credential is to keep buying from the same organization that issued it.

What I Am Proposing

I am proposing an independent executive protection competency-certification system built around six things:

  • Transparent competency requirements that practitioners, employers and training providers can read and understand.
  • Independent testing developed from a defensible job analysis.
  • Practical assessment wherever the competency has to be demonstrated.
  • Relevant documented experience that actually matches the executive protection credential.
  • Meaningful recertification that proves the professional remains current.
  • Respect for state licensing and regulatory authority instead of pretending a private credential replaces the law.

I would start with a public competency crosswalk.

Take the 2020 competency work. Compare it with current ASIS and BEPP standards, state regulatory requirements, mature government protective practices, current research and what employers actually ask practitioners to do.

Identify the common core. Identify advanced and specialty functions. Decide what can be measured through a written examination and what has to be demonstrated. Then let qualified training providers prepare people through different legitimate paths for the same independent credential.

That is an ASE-type program for executive protection.

Standards Should Be the Beginning, Certification the Goal

We spent years asking for executive protection standards. Now we have them. That should not be the end of the conversation.

The harder question is whether the person carrying the credential can actually perform to the standard, and whether an employer can understand how that competence was measured. That is what the profession should build next.

Train. Test. Demonstrate. Experience. Recertify. Improve.

Standards should serve the profession—not become the profession.


Frequently Asked Questions

Who else assisted ISA formulating its training, standards and certification programs?

One critical note, one of my mentors, Dr. Richard W. Kobetz, founder of the Executive Protection Institute, had been working with me through 2017 and 2018 before he passed away in June. I had attended training with Doc in Chicago, and another friend and mentor Tony Scotti recommended I reach out to Doc about our efforts.

Doc had recommended we look at certification vs. standards. If you could establish a certification the requirements to earn it would be a blueprint for standards. 

Tony was also instrumental in helping us build our program by sharing his more than 5 decades of experience training governments, corporations, law enforcement agencies, and military organizations. His training programs had been conducted in over 40 countries. So his advice and mentorship helped us keep focused on our goal. It was Tony and Doc that guided us to look at each state and agency as an opportunity to gain another piece of the foundation our program was built on.   

When did ISA first begin working on executive protection standards?

ISA’s standards work began in 2011 while developing close-protection training for law enforcement. ISA used an Instructional Systems Design process, reviewed federal, military and state requirements, and incorporated outside regulatory benchmarks into the training program.

Was the ISA ASE proposal published in 2018 or 2020?

ISA first published its national-standards article in November 2018. That article documented standards work dating back to 2011. The explicit proposal to use ASE as a model appears in the January 30, 2020 update to that article.

Why is Virginia important to ISA’s standards position?

Virginia provides an outside regulatory standard for Personal Protection Specialists. The state defines minimum training and testing requirements while allowing schools to exceed those requirements. That separation helped shape ISA’s view that training providers should not be the only organizations deciding what counts as competence.

Why does the UK SIA system matter?

The SIA system shows that regulation, qualifications and training can be separated. The regulator licenses, awarding organizations oversee qualifications and approve providers, and training providers teach. ISA does not propose copying the UK system, but the separation of responsibilities is relevant to an independent certification model.

What is an ASE-type executive protection certification system?

It is an independent competency-certification system in which candidates may train through different legitimate pathways but are measured against common job-related requirements, relevant experience and recertification. For executive protection, practical assessment should also be required where performance cannot be measured credibly through a written examination.

Would independent certification replace state licensing?

No. State licensing and registration establish legal authority where required. Independent certification would demonstrate professional competence beyond or alongside those legal requirements.

Why is a written executive protection examination not enough?

A written examination can measure knowledge. Operational competencies such as advance work, site assessment, movement, communications, transportation decisions and emergency response also require practical evaluation where performance can be observed.

Is the concern that ASIS, BEPP or IPSB charge money?

No. Professional standards, testing, training and administration cost money. The concern is whether standards, membership, training, certification, continuing education and renewal become a closed commercial loop in which repeated payment is confused with proving professional competence.


Related ISA Resources

External Reference Links


About the Author

Matthew C. Parker is CEO of Independent Security Advisors LLC and Director of Training Operations for EPTraining.us. U.S. Army retired, combat veteran, master instructor, and protective-services practitioner, his assignments included training-department management at the U.S. Army Chemical, Biological, Radiological, and Nuclear School, recognition as Instructor of the Cycle and Instructor of the Year, and instructor service with Army ROTC at Virginia Tech.

He has more than three decades of military, government, executive-protection, training, and special advisor experience internationally in Africa, Asia, Iraq and Ukraine.

For more than a decade, Parker has focused on a question central to executive protection training and standardsHow do we turn standards into measurable performance? Through ISA and EPTraining.us, he has developed and evaluated protective-services training against regulatory requirements, external standards, operational practice, and demonstrated competency. His position is simple: training prepares the professional; standards define expectations; performance demonstrates competence.


Series ISA Executive Protection Standards Series — Article 6

Publisher Independent Security Advisors LLC / EPTraining.us

#ExecutiveProtection #ExecutiveProtectionTraining #ExecutiveProtectionStandards #ExecutiveProtectionCertification #ProtectiveServices #SecurityTraining #ProfessionalStandards #EPTraining #IndependentSecurityAdvisors