TSP 100 is the AICPA guidance document that defines the Trust Services Criteria and their points of focus. It explains how organisations and auditors should interpret each criterion and gives implementation guidance that helps translate the framework into practical controls, evidence, and audit expectations.
What TSP 100 Covers
TSP 100 is not a control framework in itself, but the interpretive guide that explains how the AICPA Trust Services Criteria and their points of focus should be read, evidenced, and applied in practice. For auditors and organisations, its value is in turning the criteria from abstract principles into a shared testing and implementation baseline.
That distinction matters because TSP 100 shapes what counts as a relevant control, what evidence is persuasive, and how exceptions are judged. It is therefore part reference document, part implementation lens, and part audit expectation setter.
How It Relates to Trust Services Criteria
The Trust Services Criteria are the substance; TSP 100 is the interpretive layer that helps organisations understand how those criteria are meant to work in real environments. It clarifies the relationship between each criterion and its points of focus, which is important when a control objective is broad enough to allow different implementation patterns.
That interpretive role is especially useful when teams need to map policies, configurations, monitoring, and evidence to one criterion without treating the criteria as a checklist of isolated statements. In practice, TSP 100 helps align audit language, control design, and operational evidence around the same security intent.
For readers working on third-party assurance or vendor assessments, the closest external reference point is the SOC 2 Trust Services Criteria (AICPA), because TSP 100 exists to explain how those criteria are interpreted and applied.
Why It Matters for Control Design and Audit Evidence
TSP 100 matters because controls are only useful if they can be defended consistently. The guidance helps organisations decide whether a control is genuinely aligned to the criterion, whether the evidence is sufficiently direct, and whether the implementation is strong enough to satisfy an auditor’s expectation without overfitting to a narrow technical reading.
That is why the document is often used during control design, readiness assessments, and audit preparation. It gives teams a way to translate high-level trust requirements into repeatable operational practices, while still leaving room for environment-specific implementation choices.
A practical reading of the criteria is helped by broader control catalogs such as NIST SP 800-53 Rev 5 Security and Privacy Controls, which similarly connect governance intent to concrete control families like access control, audit, and configuration management.
Common Misunderstandings About TSP 100
A common mistake is to treat TSP 100 as if it were the same thing as the Trust Services Criteria. It is not. The criteria define the control expectations, while TSP 100 explains how to interpret those expectations and where the points of focus fit into the overall assessment.
Another misunderstanding is assuming the document prescribes one fixed technical implementation. In reality, it supports more than one way to satisfy a criterion, as long as the control outcome, evidence quality, and audit logic remain consistent with the intent of the guidance.
For teams that need implementation detail rather than interpretive guidance, the OWASP Cheat Sheet Series is a useful complementary reference because it focuses on practitioner-level control execution across areas such as authentication, secrets handling, and session management.
Risk and Threat Considerations
TSP 100 is usually discussed as an audit and governance document, but the risk lies in misreading it as a substitute for actual control design. If organisations rely on a superficial interpretation, they can end up with controls that look compliant on paper while leaving real gaps in evidence, operating discipline, or control coverage.
Failure mechanism: Weak interpretation can produce incomplete mappings between criteria, controls, and evidence, which then lets gaps survive until audit time or, worse, until a real control failure exposes them.
Impact: The result can be failed audits, costly remediation, inconsistent assurance claims, and reduced trust in the organisation’s reported control posture.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
CIS Controls v8 and NIST CSF 2.0 set the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| CIS Controls v8 | CIS Control 4 — Secure Configuration of Enterprise Assets and Software | TSP 100 supports control evidence and implementation interpretation for security criteria. |
| CIS Control 6 — Access Control Management | Trust Services Criteria commonly depend on access control outcomes and documented enforcement. | |
| CIS Control 8 — Audit Log Management | TSP 100 relies on evidence quality, and audit logging is often core evidence for trust criteria. | |
| Recommendation — Align control evidence to secure configuration baselines that auditors can verify. Document and enforce access control decisions with reviewable evidence. Collect and retain audit logs that substantiate control operation and exceptions. | ||
| NIST CSF 2.0 | GV.OC-01 — Organisational Context | TSP 100 helps organisations interpret trust criteria in the context of their control environment. |
| PR.AA-01 — Identity Management, Authentication, and Access Control | Trust Services Criteria often require demonstrable access governance and authentication controls. | |
| GV.RM-01 — Risk Management Strategy | TSP 100 informs how organisations judge whether controls adequately address trust and assurance risk. | |
| Recommendation — Define control context so trust criteria map cleanly to business and assurance needs. Apply access and authentication controls that support audit-ready assurance evidence. Use a risk strategy that ties assurance criteria to measurable control outcomes. | ||
Practitioner Guidance
Why practitioners should care: TSP 100 is most useful when teams need to prove that their controls are not just present, but defensibly aligned to the Trust Services Criteria. It helps reduce ambiguity between policy language, operational execution, and audit evidence.
Practitioner takeaway: Treat TSP 100 as the interpretive bridge between criterion intent and control evidence, and use it to test whether your implementation would still make sense to an auditor reviewing the underlying objective, not just the documentation.
Related resources from NHI Mgmt Group
- How should teams handle certificate renewals when validity windows shrink to 100 days?
- Why do PAM migrations stall at decommission even after onboarding reaches 100%?
- How should teams size an authorization system when relationship graphs grow from millions to 100 billion entries?
- How should security teams move to a 100% cloud and mobile identity model without creating access sprawl?