Ideally you would have the most current client on the ASA. The only downside is if your end users don't have admin rights on their computer and then log on to the VPN and are unable to upgrade (since the AnyConnect update requires local admin privilege).
If the end user has a newer client than the ASA package it will work fine. You may get some log messages about unsupported attributes as client first authenticates and checks for features that aren't supported on the ASA.