Skip to main content
Image coming soon

The Bank Branch Physical Security Operations Playbook

$199.00
Adding to cart… The item has been added

A focused course, tailored for you

The Bank Branch Physical Security Operations Playbook

Run branch, ATM, cash-handling, and executive-protection programs against the FFIEC and Bank Protection Act expectations you own.

The branch incident log is the first document a bank examiner pulls when they want to know whether physical security is run or just reported.

$199 one-time
Tailored to your situation. Access within 24 hours. 30-day money-back.

Includes a hand-built implementation playbook delivered alongside course access, generated for your specific situation.

Why this course

Senior physical security specialists at large US bank holding companies own a portfolio that does not fit one playbook. The downtown flagship branch, the drive-thru in the strip mall, the ITM-only kiosk, the executive floor in the headquarters tower, the off-site investor day at a hotel ballroom. Each has a different threat profile, a different alarm vendor footprint, a different cash-handling exposure, and a different regulator expectation under the Bank Protection Act and the FFIEC IT Examination Handbook. The senior specialist is the person who has to make the program coherent across all of it, write the standards, run the after-hours access exceptions, sign off on ATM placement risk reviews, brief the Corporate Security Officer when the alarm-activation pattern shifts, coordinate with the field office on executive-residence sweeps, and produce the incident summary that survives examiner scrutiny. The gap most programs have is that the incident log is rich but the taxonomy is inconsistent, so trend analysis is unreliable and the examiner reads inconsistency as immaturity. This course closes that gap and the rest of the operating-model gaps a senior specialist at a top-ten US bank holding company carries.

What you walk away with

  • Run a branch incident taxonomy that maps cleanly to Bank Protection Act and FFIEC physical security expectations and survives examiner scrutiny.
  • Risk-tier every branch, ATM, ITM, and corporate site with a defensible methodology that holds up when a regional president challenges the rating.
  • Operate ATM and ITM physical-security standards covering skimmer detection, anti-tampering, lighting, surveillance, and vestibule access.
  • Coordinate executive protection across the CEO, board, and senior leadership with HR, Legal, and protective intelligence in a single playbook.
  • Author and defend the annual physical security program review the Corporate Security Officer presents to the board risk committee.

The 12 modules

Module 1. The Bank Protection Act baseline, read as an operating spec
Start from the statute the program is actually graded against. Read the Bank Protection Act provisions on minimum standards for opening procedures, employee identification, surveillance, vault and lighting as an operating spec for a branch portfolio. Map each element to the artefact in your program that evidences it. Identify what your program over-delivers on, under-delivers on, or delivers but cannot evidence cleanly. The output is a baseline matrix you can hand to your director.
Module 2. FFIEC physical security expectations beyond the statute
The FFIEC IT Examination Handbook and the Operations booklet add expectations the Bank Protection Act does not name explicitly. Environmental controls, physical access to systems and data, after-hours access logging, escort procedures for vendors. Walk through the examiner-relevant sections clause by clause. Build a translation layer between FFIEC language and the standards your branch managers actually read. The deliverable is a crosswalk your program owner can defend in an examiner meeting.
Module 3. Branch and site risk-tiering that defends against a regional pushback
Most risk-tier methodologies fall apart the moment a regional president argues a branch was downgraded unfairly. Build a transparent, scored methodology with weighted inputs: cash exposure, transaction volume, hold-up history, neighbourhood crime data, alarm-activation history, after-hours access frequency, executive-floor proximity. Run the methodology against ten sample branches. Document a re-tiering trigger schedule so tiers are not static. The output is the defensible scoring rubric and a script for the regional-president conversation.
Module 4. Incident taxonomy that survives examiner trend analysis
Most incident logs are rich but their taxonomy drifts, so year-over-year trend reports are unreliable and the examiner reads inconsistency as immaturity. Rebuild the taxonomy from the categories an examiner will actually slice on: hold-up, burglary, alarm activation, after-hours access exception, ATM skimmer, ATM jackpotting, workplace violence, suspicious activity, executive protection event. Define category boundaries so the same incident is never coded two ways. Map the taxonomy to your incident system and plan the historical conversion.
Module 5. ATM and ITM physical-security standards
Skimmer detection, anti-tampering hardware, lighting standards, surveillance coverage, vestibule access controls, drive-thru considerations, ITM-specific risks, dual-control servicing, cash replenishment routes. Build the ATM and ITM standard your branch operations team will actually follow. Cover the vendor relationships with the ATM manufacturer, the cash-in-transit provider, and the alarm monitoring company. The output is a complete ATM and ITM physical-security standard with a test plan a regional security manager can execute on a random sample of machines.
Module 6. Cash-handling, vault, and cash-in-transit procedures
Vault opening and closing procedures, dual control, time-delay locks, key control, cash recycler reconciliation, currency identifier issues, the handoff to and from the cash-in-transit carrier. Where the Bank Protection Act minimum standards stop and where the bank's own risk appetite kicks in. Build the procedure document that a teller, a branch manager, and an internal audit reviewer can all read consistently. Define the exception process for when the procedure cannot be followed cleanly.
Module 7. Executive protection program design for a US bank holding company
Coverage tiers for the CEO, executive committee, board members, and high-profile public-facing executives. Residential security surveys. Travel security protocols for domestic and international travel. Coordination with Legal and HR on threat assessments. The interaction model with the protective intelligence team and with the field office of federal law enforcement when a credible threat surfaces. The deliverable is a tiered executive protection program document with named roles, escalation thresholds, and an annual review cadence.
Module 8. Workplace violence and active-assailant playbook
Threat assessment intake from HR, the management committee process, the escort-off-premises procedure, run-hide-fight training for branch staff, coordination with local law enforcement, communication protocols during an event, post-event support. The playbook needs to work for a downtown corporate tower and a strip-mall branch. Build the playbook with named decision rights, the training curriculum for branch staff, and the after-action template.
Module 9. Insider risk and after-hours access controls
The most common physical-security failure at a large bank is an after-hours access exception that nobody questioned. Build the access control standard for badge issuance, badge revocation on termination, after-hours access approval, escort requirements for vendors and contractors, dual-occupancy rules for sensitive areas, the link to the joiner-mover-leaver process owned by HR and IT. Define the periodic access review and who owns it. The output is the access control standard plus the exception log structure that an examiner can audit.
Module 10. Investigations, evidence handling, and law-enforcement liaison
When a hold-up happens, when an internal theft surfaces, when an alarm activation is suspicious. Investigation intake, chain-of-custody for surveillance footage and physical evidence, interview protocols, coordination with Legal and HR, the formal liaison relationship with the local field office of federal law enforcement and the local police. Build the investigations standard operating procedure that protects evidence integrity and a witness statement template. Define the threshold at which an incident becomes a formal investigation.
Module 11. Annual physical security program review and the board risk committee
Once a year the Corporate Security Officer presents the physical security program review to the board risk committee. The senior specialist is the person who actually drafts that pack. Build the annual program review pack: incident summary by category, risk-tier movement, top five emerging risks, program maturity self-assessment, the year-ahead roadmap. Anticipate the board questions and prepare the briefing notes. The deliverable is the slide pack template plus the briefing notes.
Module 12. Examiner preparation and the OCC, FDIC, or Federal Reserve cycle
Walk through what a physical security examination by the OCC, FDIC, or Federal Reserve actually covers. The pre-meeting document request list. The branch site visit. The examiner interview with the Corporate Security Officer and the senior specialists. The most common examiner findings and how to evidence remediation. Build the examiner-ready binder structure so that when the request list arrives the response is a curation, not a scramble. The output is the binder structure with named owners for each section.

How this addresses your situation

Specific modules that map to what you said you are dealing with.

The Corporate Security Officer is asking why the same downtown branch keeps surfacing in the alarm-activation pull (modules 3, 4).
An ATM at a drive-thru location was found with a skimmer last week and the vendor relationship needs a hard reset (module 5).
An executive offsite for the CEO at a hotel ballroom needs to be pre-cleared with the field office and the protective intelligence team (module 7).
The annual program review for the board risk committee is on the calendar and the slide pack is still a draft (module 11).

What you get with this course

  • Twelve written course modules covering the full operating model of a senior physical security specialist at a US bank holding company.
  • Downloadable templates: branch risk-tiering scoring rubric, incident taxonomy reference, ATM physical-security standard, executive protection tiered program document, workplace violence playbook, after-hours access exception log, annual program review slide pack, examiner-ready binder structure.
  • Worked examples for every module showing the artefact populated against a realistic bank holding company portfolio.
  • A hand-built implementation playbook tailored to the buyer's role, the bank holding company profile, and the specific portfolio of branches, ATMs, and corporate sites the buyer owns.
  • Lifetime access to the course in the Art of Service learning environment, including updates as the FFIEC handbook and supervisory guidance evolve.
  • 30-day money-back guarantee.

What you will have in hand by Day 1, Week 1, Month 1

Within 24 hours: account in the learning environment is provisioned and the hand-built implementation playbook is delivered alongside it.

Weeks 1 to 2: complete modules 1 to 4 and produce the Bank Protection Act baseline matrix, the FFIEC crosswalk, the branch risk-tiering rubric, and the rebuilt incident taxonomy.

Weeks 3 to 4: complete modules 5 to 8 covering ATM and ITM standards, cash-handling and vault, executive protection, and workplace violence.

Weeks 5 to 6: complete modules 9 to 12 covering access control, investigations, the annual board pack, and examiner preparation.

Ongoing: use the implementation playbook to drive the program against the buyer's specific portfolio.

Before and after

Before

Incident log is rich but the taxonomy drifts, branch risk-tiers are challenged every time a regional president pushes back, the ATM standard has not been refreshed since the last skimmer incident, the executive protection program runs on goodwill from one analyst, and the annual board pack is rebuilt from scratch every year.

After

Incident taxonomy is locked and trend analysis is defensible, branch risk-tiers are scored against a transparent rubric that survives a regional pushback, the ATM and ITM standard is current and tested on a sample of machines, the executive protection program is documented with named roles and escalation thresholds, and the annual board pack is a curation from a maintained program record.

What happens if you do not address this

An examiner finding on physical security at a large US bank holding company does not stay quiet. It surfaces in the supervisory letter, it surfaces in the management response, and it surfaces in the next year's exam scope. The senior physical security specialist is the role accountable for the artefacts the examiner pulls. Without a coherent operating model, the program survives the next cycle on the strength of individual relationships and individual memory, both of which are fragile.

Who it is for

You are a senior individual contributor in Corporate Security at a US bank holding company. You report into a Corporate Security Officer or Director of Physical Security. You own a portfolio of branches, ATMs, and corporate sites, plus a piece of the executive protection program. You write the standards, run the audits, brief leadership, and own the incident response. You are not the guard force; you are the program owner who guards report into.

Who this is NOT for. Contract guard supervisors, alarm-monitoring center operators, and uniformed branch officers without standards-and-program ownership. Also not for cyber-only security professionals who do not own the physical estate.

How it arrives

Text-based course in the Art of Service learning environment, plus downloadable templates and worked examples for every module, plus the hand-built implementation playbook delivered alongside course access.

Time investment. Roughly 25 to 35 hours of focused work across six weeks. Each module is a written walk-through plus templates and worked examples; the implementation playbook is the artefact the buyer applies against their own portfolio.

Why $199 is the right number

Generic physical security certifications cover concepts at a general level without the bank-specific regulatory layer. Bank-specific physical security guidance from industry associations covers the regulatory baseline without translating it into a working operating model. Internal training programs cover the bank's own procedures without giving the senior specialist a view of the program as a whole. This course covers all three layers and ships with the hand-built implementation playbook tailored to the buyer.

FAQ

Is this a guard-force training course?
No. This is a program-ownership course for the senior specialist who writes the standards the guard force operates against.
Does this cover cyber-physical convergence?
It covers the access-control and after-hours access layer where physical and cyber security intersect. It does not replace a dedicated cyber-security curriculum.
How is the implementation playbook tailored?
On purchase, the buyer shares the role, the bank holding company profile, and the portfolio of branches, ATMs, and corporate sites in scope. The implementation playbook is hand-built against that profile and delivered alongside course access.
Will this help me prepare for an examiner cycle?
Module 12 covers examiner preparation explicitly, including the document request list, the site visit, and the examiner interview. The earlier modules produce the artefacts the examiner will pull.
What is the refund policy?
30-day money-back guarantee from the date of purchase.

30-day money-back guarantee. If after a week of working through the materials this is not what you needed, reply to the receipt email and a full refund is processed. No questions, no forms.

Within 24 hours your account in the learning environment is provisioned and the tailored implementation playbook is delivered alongside it.