Skip to main content
Image coming soon

The Bank Physical Security Lead's Branch and ATM Risk Playbook

$199.00
Adding to cart… The item has been added

A focused course, tailored for you

The Bank Physical Security Lead's Branch and ATM Risk Playbook

Build a defensible branch, ATM, and corporate-campus physical security program that holds up to internal audit, regulator scrutiny, and the next robbery review.

When the after-action meeting on a branch incident starts, your standard document, your guard SLA, and your CCTV retention policy must say the same thing. When they do not, the regulator letter follows.

$199 one-time
Tailored to your situation. Access within 24 hours. 30-day money-back.

Includes a hand-built implementation playbook delivered alongside course access, generated for your specific situation.

Why this course

A bank physical security lead carries a job that is invisible until something goes wrong, and then becomes the only topic in the room. Branch robberies, ATM attacks, executive-protection escalations, data-centre badge anomalies, vault dual-control breaches, and guard-vendor performance disputes all land on the same desk. Internal Audit asks for the written standard. Corporate Security asks for the incident pack. Regional Presidents ask why a specific branch did not have a working camera. Regulators ask whether the program matches what is documented. The hard part is not the response on the day. It is the year of work that should have lined up the standards, the contracts, the retention, and the evidence before the incident, so the after-action meeting confirms the program rather than exposes it.

What you walk away with

  • A defensible written branch physical security standard that matches what is actually on the floor in every region.
  • An ATM hardening and incident playbook that holds up under FBI, FinCEN, and regional law enforcement liaison.
  • A guard-vendor contract and scoring framework that lets you replace an underperformer without an operational gap.
  • A CCTV and access-control retention policy that survives subpoena, regulator review, and Internal Audit sampling.
  • An incident review pack template that closes the loop with Internal Audit and Operational Risk after every event.

The 12 modules

Module 1. The Bank Physical Security Standard, Rewritten
Walk through how to draft, version, and govern the written branch and corporate-campus physical security standard so it survives Internal Audit sampling and regulator inquiry. Covers the minimum control set per branch tier, the exception-handling process for legacy locations, the ownership map between Corporate Security and Facilities, and the document-control discipline that prevents the standard and the floor from drifting apart over a calendar year.
Module 2. ATM Hardening, Incident Response, and Law Enforcement Liaison
Build the ATM physical security profile for off-premise, walk-up, and drive-up units including anti-skimming, anti-explosive, anti-ram, dye-pack, and GPS asset-tag standards. Walk through the post-incident workflow with local law enforcement, FBI field office liaison, FinCEN SAR coordination, and the evidence chain that makes a prosecution stick. Includes the on-call escalation script and the 24-hour customer-comms posture.
Module 3. Branch Robbery Response and After-Action Review
Sequence the response from first alert through evidence collection, branch reopening decision, victim and witness care, regulator notification, and the after-action review that lands at Operational Risk Committee. Covers the conflict between speed of reopening and quality of evidence, the language to use in customer communications, and the documentation that anticipates the Regional President's three hardest questions.
Module 4. Executive Protection Routing and Risk-Tiered Travel
Design the risk-tiered executive protection program for the CEO, board, and operating committee covering ground travel, air travel, residential security, and event-based deployments. Walk through the threat-rating model, the vendor versus in-house decision per principal, the intelligence-feed inputs, and the budget defence to the CFO that does not over-promise certainty and does not under-protect the principal who is genuinely at elevated risk.
Module 5. Vault, Cash Handling, and Dual-Control Discipline
Tighten the dual-control standard across the vault, ATM cash replenishment, night drops, and high-value-item handling so that Internal Audit can sample any branch on any week and find the controls working. Covers the access-card and combination-rotation discipline, the camera-coverage minimums on every cash-handling activity, the incident reporting threshold for control breaks, and the remediation pattern that prevents a branch from becoming a repeat offender.
Module 6. Corporate-Campus Access Control and Tailgating
Run the corporate campus, data centre, and operations-centre access-control program covering badge issuance, role-based access groups, visitor management, tailgating prevention, and the quarterly recertification of access rights. Walk through the badge-system audit script, the anomaly detection rules that should trigger investigation, and the integration with HR onboarding and offboarding so a terminated employee loses physical access at the same hour as logical access.
Module 7. Guard-Vendor Contracts, SLAs, and Performance Scoring
Score, manage, and if necessary replace the guard vendor across the bank's footprint without leaving an operational gap. Covers the contract clauses that matter (insurance, sub-contracting, post coverage, training, replacement timelines), the monthly performance scorecard, the missed-post and failed-tour penalty structure, and the transition plan to a successor vendor that protects continuity of coverage from the first hour of the change.
Module 8. CCTV, Access-Control, and Retention Defensible to Subpoena
Build the CCTV and access-control retention policy that survives a subpoena, a regulator request, and an Internal Audit sample without scrambling. Covers retention periods per system tier, the chain-of-custody for footage release, the legal-hold process when an incident is under investigation, the storage-cost defence to the CFO, and the evidence-integrity discipline that prevents a defence attorney from getting footage thrown out.
Module 9. Workplace Violence Prevention and Insider-Threat Convergence
Stand up the workplace violence prevention program covering threat assessment intake, the cross-functional response team (HR, Legal, Security, Employee Assistance), the protective measures during a high-risk termination, and the convergence with insider-threat indicators from logical access. Walk through the case examples that get to the line and do not cross it, and the documentation that protects the bank if litigation follows.
Module 10. Third-Party Site Security for Bank-Branded Locations
Govern the physical security of locations that carry the bank's brand but are not directly operated by Corporate Security (in-store branches, partner-operated ATMs, mortgage-origination offices, wealth-management satellites). Covers the contractual security minimums, the inspection cadence, the incident reporting flow back to Corporate Security, and the brand-risk escalation when a partner location is found out of compliance.
Module 11. Regulator, Internal Audit, and Operational Risk Reporting
Sequence the reporting cadence to OCC examiners, Internal Audit, Operational Risk Committee, and the Board Risk Committee so that physical security is told as a coherent program rather than as a series of incidents. Walk through the metrics that matter (incident rate per branch tier, mean time to evidence, guard-vendor SLA attainment, control-test pass rate), the storytelling pattern that lands with non-security senior leaders, and the question-prep for the toughest standing questions.
Module 12. The Annual Physical Security Program Refresh
Run the once-a-year refresh that pulls the branch standard, the ATM playbook, the guard contracts, the CCTV retention, the executive protection program, and the workplace violence response into a single program document the Chief Risk Officer signs. Covers the calendar of evidence collection, the cross-functional review sequence, the budget defence for the coming fiscal year, and the changelog that makes next year's audit faster than this one's.

How this addresses your situation

Specific modules that map to what you said you are dealing with.

An ATM is attacked overnight and the after-action meeting starts at 08:00 the next morning with the Regional President asking why the dye pack failed.
Internal Audit samples five branches in three regions and finds the written standard does not match the floor in two of them.
The incumbent guard vendor misses three posts in a quarter and the contract renewal sits on your desk next month.
An OCC examiner asks to see the CCTV retention policy and the legal-hold process for an incident from last fiscal year.

What you get with this course

  • Twelve written modules in the Art of Service learning environment, self-paced.
  • Downloadable templates for the branch standard, ATM playbook, guard SLA scorecard, CCTV retention policy, executive protection risk-tier model, workplace violence intake form, and annual program refresh changelog.
  • Worked examples drawn from US retail and corporate banking physical security programs.
  • The hand-built implementation playbook delivered alongside course access, tailored to your specific branch footprint, ATM estate, and corporate campus mix.
  • 30-day money-back guarantee.

What you will have in hand by Day 1, Week 1, Month 1

Within 24 hours of purchase, learning environment access is provisioned and the tailored implementation playbook is delivered.

Modules 1 to 4 are typically worked through in week one alongside the implementation playbook intake.

Modules 5 to 8 in week two, focused on vault, access control, and guard-vendor governance.

Modules 9 to 12 in week three, focused on workplace violence, third-party sites, regulator reporting, and the annual program refresh.

The implementation playbook supports a full program refresh over the following quarter.

Before and after

Before

The branch standard, the guard contract, and the CCTV retention policy do not say the same thing. Every incident review surfaces a control gap that nobody owned. Internal Audit findings carry over from one year to the next. The Regional Presidents call Corporate Security only when something has gone wrong.

After

The standard, the contract, and the retention policy agree on paper and on the floor. Incidents close cleanly with an after-action pack that goes to Operational Risk Committee. Internal Audit findings close in the year they are opened. The Regional Presidents call Corporate Security before they have a problem, because the program is visible and the answers arrive before the questions.

What happens if you do not address this

The next branch robbery, ATM attack, or workplace violence incident is not a hypothetical. When it lands, the difference between a clean after-action pack and a regulator letter is whether the standard, the contract, the retention policy, and the evidence already line up. The work that prevents the regulator letter has to be done before the incident, not in the week after.

Who it is for

Built for the bank physical security lead, head of corporate security, or branch protection manager who owns the written physical security standard, the guard-vendor relationship, the CCTV and access-control estate, ATM hardening, executive protection routing, and the incident review process across a US retail and corporate banking footprint.

Who this is NOT for. Not for cyber or information security leaders whose remit is digital controls only. Not for facilities managers without security accountability. Not for executive protection specialists looking purely for personal-protection tradecraft. This course is for the person who has to defend the bank's physical security program in writing to auditors, regulators, and senior leadership.

How it arrives

Text-based course in the Art of Service learning environment, plus downloadable templates and worked examples for every module, plus the hand-built implementation playbook delivered alongside course access.

Time investment. Roughly 14 to 18 hours of reading, template work, and applied write-up across three weeks of self-paced study.

Why $199 is the right number

ASIS International certification material covers the body of knowledge for the security profession at a generic level, useful for credentialing but not specific to a US bank's branch, ATM, and corporate-campus mix. RIMS and the Bank Administration Institute publish operational risk and branch operations content that touches physical security at the edges. Generic CCTV and access-control vendor training teaches the systems, not the program governance. This course is built specifically for the bank physical security lead who has to defend the written program to Internal Audit, the OCC, and senior leadership.

FAQ

Is this US-specific or international?
The course is built around US retail and corporate banking physical security including OCC examiner expectations, FinCEN SAR coordination, FBI field-office liaison, and US workplace violence law. The control patterns translate to other jurisdictions but the regulator-specific sections assume a US footprint.
Does this replace ASIS or a CPP credential?
No. ASIS membership and the CPP credential are profession-wide qualifications. This course is a program-build playbook specific to bank physical security leadership. Many holders of the CPP will find the bank-specific governance patterns and the regulator-facing reporting cadence to be where the value lies.
How is the implementation playbook tailored?
Within 24 hours of purchase, an intake captures the bank's branch tier mix, ATM estate, corporate campus footprint, current guard-vendor structure, CCTV and access-control platforms, and the most recent Internal Audit findings. The implementation playbook is then hand-built to address that specific program, not delivered as a generic template.
Can a team use one purchase?
The licence covers a single named learner with the option to extend to a team. For team enrolment, the implementation playbook is built once for the program and the learning environment is provisioned per learner.

30-day money-back guarantee. If after a week of working through the materials this is not what you needed, reply to the receipt email and a full refund is processed. No questions, no forms.

Within 24 hours your account in the learning environment is provisioned and the tailored implementation playbook is delivered alongside it.