{
    "api_version": "1",
    "kind": "dse_post",
    "self": "https://update.dsesecurity.com/api/v1/posts/bank-physical-security-annual-review-board-evidence/",
    "item": {
        "id": "https://update.dsesecurity.com/updates/bank-physical-security-annual-review-board-evidence/",
        "slug": "bank-physical-security-annual-review-board-evidence",
        "url": "https://update.dsesecurity.com/updates/bank-physical-security-annual-review-board-evidence/",
        "alternate_urls": {
            "markdown": "https://update.dsesecurity.com/updates/bank-physical-security-annual-review-board-evidence.md",
            "json": "https://update.dsesecurity.com/api/v1/posts/bank-physical-security-annual-review-board-evidence/"
        },
        "title": "Bank physical security annual review: evidence for the board report",
        "summary": "A bank security review should connect procedures, training, device testing, incidents, local risk, and unresolved exceptions so the security officer can report on program effectiveness, not simply equipment presence.",
        "format": {
            "slug": "guide",
            "name": "Guide"
        },
        "priority": {
            "slug": "advisory",
            "name": "Advisory"
        },
        "featured": false,
        "topics": [
            {
                "slug": "access-control",
                "name": "Access Control",
                "url": "https://update.dsesecurity.com/topic/access-control/"
            },
            {
                "slug": "business-continuity",
                "name": "Business Continuity",
                "url": "https://update.dsesecurity.com/topic/business-continuity/"
            },
            {
                "slug": "video-surveillance",
                "name": "Video Surveillance",
                "url": "https://update.dsesecurity.com/topic/video-surveillance/"
            }
        ],
        "author": {
            "name": "DSE Security Editorial Team",
            "url": "https://update.dsesecurity.com/#editorial-team"
        },
        "publisher": {
            "name": "Detection Systems & Engineering",
            "url": "https://dsesecurity.com/"
        },
        "published_at": "2026-07-28T14:22:00+00:00",
        "modified_at": "2026-07-28T14:22:00+00:00",
        "reviewed_on": "2026-07-28",
        "reading_minutes": 3,
        "word_count": 510,
        "potentially_affected": "State-chartered banks that are members of the Federal Reserve System and evaluate their program under 12 CFR 208.61, plus security, facilities, audit, risk, compliance, and board-support teams assisting with the report.",
        "dse_recommendation": "Confirm the institution and offices governed by the rule, then assemble location-aware evidence and document conclusions, exceptions, ownership, and follow-up for the security officer’s annual board report.",
        "primary_source": {
            "name": "Federal Reserve Regulation H: 12 CFR 208.61",
            "url": "https://www.federalreserve.gov/frrs/regulations/section-20861-bank-security-procedures.htm",
            "published_on": "2026-07-28",
            "authority": "www.federalreserve.gov"
        },
        "publishing_principles": "https://update.dsesecurity.com/updates/dse-updates-editorial-methodology/",
        "usage_info": "https://update.dsesecurity.com/usage/",
        "copyright_notice": "Copyright © 2026 Detection Systems & Engineering. All rights reserved.",
        "content_html": "<h2>Source fact: first confirm that this rule applies</h2>\n<p>Federal Reserve Regulation H, <a href=\"https://www.federalreserve.gov/frrs/regulations/section-20861-bank-security-procedures.htm\" target=\"_blank\" rel=\"noopener noreferrer\">12 CFR 208.61</a>, governs bank security procedures for state-chartered banks that are members of the Federal Reserve System; a separate subsection addresses Reserve Banks. It should not be assumed to govern a national bank, insured state nonmember bank, savings association, credit union, fintech, or vendor merely because that organization performs financial services. Legal or compliance personnel should confirm charter, regulator, covered offices, current rule, parallel requirements, and record-retention duties. This article is operational guidance, not legal advice.</p>\n<p>For a covered state member bank, the rule makes the board responsible for compliance and requires a written security program for the main office and branches. The board designates a security officer who develops and administers the program, subject to board approval. The program addresses opening and closing, safeguarding currency and similar valuables, identifying people committing crimes and preserving useful evidence, initial and periodic employee training, and selecting, testing, operating, and maintaining appropriate security devices.</p>\n<p>The security officer must report to the board at least annually on implementation, administration, and effectiveness. The rule does not prescribe a report template, score, page count, or particular certification. Any evidence structure or rating method adopted by the bank should be labeled as its own governance design.</p>\n\n<h2>Review the program as an operating system</h2>\n<p>Reconcile the official office population with the written program, monitoring accounts, device inventory, training population, service records, incidents, and prior commitments. Document scope decisions for drive-throughs, ATM areas, operations sites, temporary facilities, or closed locations. For each covered office, compare the controlled procedure with an observed, authorized opening or closing exercise and current handling of valuables, keys, credentials, exceptions, and after-hours escalation.</p>\n<p>Reassess local crime, exposed values, law-enforcement distance, physical surroundings, staffing, hours, floor plan, lighting, tenant occupancy, and significant incidents. An unchanged equipment list does not prove that safeguards remain appropriate after operating or environmental changes.</p>\n\n<h2>DSE recommendation: produce decision-useful evidence</h2>\n<ol>\n<li>Record the location, control or asset, test method, date, result, tester, reviewer, exception, and linked remediation for each sampled item.</li>\n<li>For alarms, coordinate safe testing with monitoring and confirm event, zone, account, notification, restoration, and return to service. Do not cause an uncoordinated police dispatch.</li>\n<li>For video used to identify offenders or preserve evidence, test representative retrieval, timestamp accuracy, image usefulness under relevant lighting, export, access control, and chain of custody.</li>\n<li>For access, locks, and lighting, sample exterior openings, privileged credentials, after-hours schedules, departed personnel, maintenance, and actual operating conditions.</li>\n<li>Assess training by role, shift, new-hire and refresher coverage, exercises, missed-training remediation, and whether personnel can perform approved actions during and after an event.</li>\n<li>Present significant failures, incomplete coverage, residual risk, compensating measures, required investment, accountable owners, target dates, and prior-year closure evidence.</li>\n</ol>\n<p>A vendor invoice or configuration screenshot can support the record but does not alone prove end-to-end operation. Protect detailed diagrams, response instructions, contact lists, and weaknesses as sensitive records. The annual conclusion should clearly distinguish verified facts, management judgment, sampling limits, and unresolved risk so the board can make informed decisions and the next review can show outcomes.</p>",
        "content_text": "Source fact: first confirm that this rule applies\nFederal Reserve Regulation H, 12 CFR 208.61, governs bank security procedures for state-chartered banks that are members of the Federal Reserve System; a separate subsection addresses Reserve Banks. It should not be assumed to govern a national bank, insured state nonmember bank, savings association, credit union, fintech, or vendor merely because that organization performs financial services. Legal or compliance personnel should confirm charter, regulator, covered offices, current rule, parallel requirements, and record-retention duties. This article is operational guidance, not legal advice.\nFor a covered state member bank, the rule makes the board responsible for compliance and requires a written security program for the main office and branches. The board designates a security officer who develops and administers the program, subject to board approval. The program addresses opening and closing, safeguarding currency and similar valuables, identifying people committing crimes and preserving useful evidence, initial and periodic employee training, and selecting, testing, operating, and maintaining appropriate security devices.\nThe security officer must report to the board at least annually on implementation, administration, and effectiveness. The rule does not prescribe a report template, score, page count, or particular certification. Any evidence structure or rating method adopted by the bank should be labeled as its own governance design.\n\nReview the program as an operating system\nReconcile the official office population with the written program, monitoring accounts, device inventory, training population, service records, incidents, and prior commitments. Document scope decisions for drive-throughs, ATM areas, operations sites, temporary facilities, or closed locations. For each covered office, compare the controlled procedure with an observed, authorized opening or closing exercise and current handling of valuables, keys, credentials, exceptions, and after-hours escalation.\nReassess local crime, exposed values, law-enforcement distance, physical surroundings, staffing, hours, floor plan, lighting, tenant occupancy, and significant incidents. An unchanged equipment list does not prove that safeguards remain appropriate after operating or environmental changes.\n\nDSE recommendation: produce decision-useful evidence\n\nRecord the location, control or asset, test method, date, result, tester, reviewer, exception, and linked remediation for each sampled item.\nFor alarms, coordinate safe testing with monitoring and confirm event, zone, account, notification, restoration, and return to service. Do not cause an uncoordinated police dispatch.\nFor video used to identify offenders or preserve evidence, test representative retrieval, timestamp accuracy, image usefulness under relevant lighting, export, access control, and chain of custody.\nFor access, locks, and lighting, sample exterior openings, privileged credentials, after-hours schedules, departed personnel, maintenance, and actual operating conditions.\nAssess training by role, shift, new-hire and refresher coverage, exercises, missed-training remediation, and whether personnel can perform approved actions during and after an event.\nPresent significant failures, incomplete coverage, residual risk, compensating measures, required investment, accountable owners, target dates, and prior-year closure evidence.\n\nA vendor invoice or configuration screenshot can support the record but does not alone prove end-to-end operation. Protect detailed diagrams, response instructions, contact lists, and weaknesses as sensitive records. The annual conclusion should clearly distinguish verified facts, management judgment, sampling limits, and unresolved risk so the board can make informed decisions and the next review can show outcomes.",
        "content_markdown": "## Source fact: first confirm that this rule applies\n\nFederal Reserve Regulation H, [12 CFR 208.61](https://www.federalreserve.gov/frrs/regulations/section-20861-bank-security-procedures.htm), governs bank security procedures for state-chartered banks that are members of the Federal Reserve System; a separate subsection addresses Reserve Banks. It should not be assumed to govern a national bank, insured state nonmember bank, savings association, credit union, fintech, or vendor merely because that organization performs financial services. Legal or compliance personnel should confirm charter, regulator, covered offices, current rule, parallel requirements, and record-retention duties. This article is operational guidance, not legal advice.\n\nFor a covered state member bank, the rule makes the board responsible for compliance and requires a written security program for the main office and branches. The board designates a security officer who develops and administers the program, subject to board approval. The program addresses opening and closing, safeguarding currency and similar valuables, identifying people committing crimes and preserving useful evidence, initial and periodic employee training, and selecting, testing, operating, and maintaining appropriate security devices.\n\nThe security officer must report to the board at least annually on implementation, administration, and effectiveness. The rule does not prescribe a report template, score, page count, or particular certification. Any evidence structure or rating method adopted by the bank should be labeled as its own governance design.\n\n## Review the program as an operating system\n\nReconcile the official office population with the written program, monitoring accounts, device inventory, training population, service records, incidents, and prior commitments. Document scope decisions for drive-throughs, ATM areas, operations sites, temporary facilities, or closed locations. For each covered office, compare the controlled procedure with an observed, authorized opening or closing exercise and current handling of valuables, keys, credentials, exceptions, and after-hours escalation.\n\nReassess local crime, exposed values, law-enforcement distance, physical surroundings, staffing, hours, floor plan, lighting, tenant occupancy, and significant incidents. An unchanged equipment list does not prove that safeguards remain appropriate after operating or environmental changes.\n\n## DSE recommendation: produce decision-useful evidence\n\n- Record the location, control or asset, test method, date, result, tester, reviewer, exception, and linked remediation for each sampled item.\n\n- For alarms, coordinate safe testing with monitoring and confirm event, zone, account, notification, restoration, and return to service. Do not cause an uncoordinated police dispatch.\n\n- For video used to identify offenders or preserve evidence, test representative retrieval, timestamp accuracy, image usefulness under relevant lighting, export, access control, and chain of custody.\n\n- For access, locks, and lighting, sample exterior openings, privileged credentials, after-hours schedules, departed personnel, maintenance, and actual operating conditions.\n\n- Assess training by role, shift, new-hire and refresher coverage, exercises, missed-training remediation, and whether personnel can perform approved actions during and after an event.\n\n- Present significant failures, incomplete coverage, residual risk, compensating measures, required investment, accountable owners, target dates, and prior-year closure evidence.\n\nA vendor invoice or configuration screenshot can support the record but does not alone prove end-to-end operation. Protect detailed diagrams, response instructions, contact lists, and weaknesses as sensitive records. The annual conclusion should clearly distinguish verified facts, management judgment, sampling limits, and unresolved risk so the board can make informed decisions and the next review can show outcomes."
    },
    "json_ld": {
        "@context": "https://schema.org",
        "@graph": [
            {
                "@type": "Organization",
                "@id": "https://dsesecurity.com/#organization",
                "name": "Detection Systems & Engineering",
                "alternateName": "DSE Security",
                "url": "https://dsesecurity.com/",
                "logo": {
                    "@type": "ImageObject",
                    "url": "https://update.dsesecurity.com/assets/dse-logo.png"
                }
            },
            {
                "@type": "Organization",
                "@id": "https://update.dsesecurity.com/#editorial-team",
                "name": "DSE Security Editorial Team",
                "url": "https://update.dsesecurity.com/",
                "parentOrganization": {
                    "@id": "https://dsesecurity.com/#organization"
                }
            },
            {
                "@type": "WebSite",
                "@id": "https://update.dsesecurity.com/#website",
                "name": "DSE Updates",
                "alternateName": "DSE Security Knowledge Hub",
                "url": "https://update.dsesecurity.com/",
                "inLanguage": "en-US",
                "publisher": {
                    "@id": "https://dsesecurity.com/#organization"
                },
                "potentialAction": {
                    "@type": "SearchAction",
                    "target": {
                        "@type": "EntryPoint",
                        "urlTemplate": "https://update.dsesecurity.com/?q={search_term_string}"
                    },
                    "query-input": "required name=search_term_string"
                }
            },
            {
                "@type": "WebPage",
                "@id": "https://update.dsesecurity.com/updates/bank-physical-security-annual-review-board-evidence/",
                "url": "https://update.dsesecurity.com/updates/bank-physical-security-annual-review-board-evidence/",
                "isPartOf": {
                    "@id": "https://update.dsesecurity.com/#website"
                },
                "lastReviewed": "2026-07-28"
            },
            {
                "@type": "BreadcrumbList",
                "@id": "https://update.dsesecurity.com/updates/bank-physical-security-annual-review-board-evidence/#breadcrumbs",
                "itemListElement": [
                    {
                        "@type": "ListItem",
                        "position": 1,
                        "name": "DSE Updates",
                        "item": "https://update.dsesecurity.com/"
                    },
                    {
                        "@type": "ListItem",
                        "position": 2,
                        "name": "Bank physical security annual review: evidence for the board report",
                        "item": "https://update.dsesecurity.com/updates/bank-physical-security-annual-review-board-evidence/"
                    }
                ]
            },
            {
                "@type": [
                    "Article",
                    "TechArticle"
                ],
                "@id": "https://update.dsesecurity.com/updates/bank-physical-security-annual-review-board-evidence/#article",
                "identifier": "https://update.dsesecurity.com/updates/bank-physical-security-annual-review-board-evidence/",
                "url": "https://update.dsesecurity.com/updates/bank-physical-security-annual-review-board-evidence/",
                "headline": "Bank physical security annual review: evidence for the board report",
                "description": "A bank security review should connect procedures, training, device testing, incidents, local risk, and unresolved exceptions so the security officer…",
                "abstract": "A bank security review should connect procedures, training, device testing, incidents, local risk, and unresolved exceptions so the security officer can report on program effectiveness, not simply equipment presence.",
                "articleBody": "Source fact: first confirm that this rule applies\nFederal Reserve Regulation H, 12 CFR 208.61, governs bank security procedures for state-chartered banks that are members of the Federal Reserve System; a separate subsection addresses Reserve Banks. It should not be assumed to govern a national bank, insured state nonmember bank, savings association, credit union, fintech, or vendor merely because that organization performs financial services. Legal or compliance personnel should confirm charter, regulator, covered offices, current rule, parallel requirements, and record-retention duties. This article is operational guidance, not legal advice.\nFor a covered state member bank, the rule makes the board responsible for compliance and requires a written security program for the main office and branches. The board designates a security officer who develops and administers the program, subject to board approval. The program addresses opening and closing, safeguarding currency and similar valuables, identifying people committing crimes and preserving useful evidence, initial and periodic employee training, and selecting, testing, operating, and maintaining appropriate security devices.\nThe security officer must report to the board at least annually on implementation, administration, and effectiveness. The rule does not prescribe a report template, score, page count, or particular certification. Any evidence structure or rating method adopted by the bank should be labeled as its own governance design.\n\nReview the program as an operating system\nReconcile the official office population with the written program, monitoring accounts, device inventory, training population, service records, incidents, and prior commitments. Document scope decisions for drive-throughs, ATM areas, operations sites, temporary facilities, or closed locations. For each covered office, compare the controlled procedure with an observed, authorized opening or closing exercise and current handling of valuables, keys, credentials, exceptions, and after-hours escalation.\nReassess local crime, exposed values, law-enforcement distance, physical surroundings, staffing, hours, floor plan, lighting, tenant occupancy, and significant incidents. An unchanged equipment list does not prove that safeguards remain appropriate after operating or environmental changes.\n\nDSE recommendation: produce decision-useful evidence\n\nRecord the location, control or asset, test method, date, result, tester, reviewer, exception, and linked remediation for each sampled item.\nFor alarms, coordinate safe testing with monitoring and confirm event, zone, account, notification, restoration, and return to service. Do not cause an uncoordinated police dispatch.\nFor video used to identify offenders or preserve evidence, test representative retrieval, timestamp accuracy, image usefulness under relevant lighting, export, access control, and chain of custody.\nFor access, locks, and lighting, sample exterior openings, privileged credentials, after-hours schedules, departed personnel, maintenance, and actual operating conditions.\nAssess training by role, shift, new-hire and refresher coverage, exercises, missed-training remediation, and whether personnel can perform approved actions during and after an event.\nPresent significant failures, incomplete coverage, residual risk, compensating measures, required investment, accountable owners, target dates, and prior-year closure evidence.\n\nA vendor invoice or configuration screenshot can support the record but does not alone prove end-to-end operation. Protect detailed diagrams, response instructions, contact lists, and weaknesses as sensitive records. The annual conclusion should clearly distinguish verified facts, management judgment, sampling limits, and unresolved risk so the board can make informed decisions and the next review can show outcomes.",
                "datePublished": "2026-07-28T14:22:00+00:00",
                "dateModified": "2026-07-28T14:22:00+00:00",
                "mainEntityOfPage": {
                    "@id": "https://update.dsesecurity.com/updates/bank-physical-security-annual-review-board-evidence/"
                },
                "inLanguage": "en-US",
                "isAccessibleForFree": true,
                "author": {
                    "@id": "https://update.dsesecurity.com/#editorial-team"
                },
                "publisher": {
                    "@id": "https://dsesecurity.com/#organization"
                },
                "image": "https://update.dsesecurity.com/assets/dse-updates-share.png",
                "articleSection": [
                    "Access Control",
                    "Business Continuity",
                    "Video Surveillance"
                ],
                "keywords": [
                    "Access Control",
                    "Business Continuity",
                    "Video Surveillance",
                    "Guide",
                    "Advisory priority"
                ],
                "genre": "Guide",
                "about": [
                    {
                        "@type": "Thing",
                        "name": "Access Control",
                        "url": "https://update.dsesecurity.com/topic/access-control/"
                    },
                    {
                        "@type": "Thing",
                        "name": "Business Continuity",
                        "url": "https://update.dsesecurity.com/topic/business-continuity/"
                    },
                    {
                        "@type": "Thing",
                        "name": "Video Surveillance",
                        "url": "https://update.dsesecurity.com/topic/video-surveillance/"
                    }
                ],
                "wordCount": 510,
                "timeRequired": "PT3M",
                "publishingPrinciples": "https://update.dsesecurity.com/updates/dse-updates-editorial-methodology/",
                "usageInfo": "https://update.dsesecurity.com/usage/",
                "copyrightHolder": {
                    "@id": "https://dsesecurity.com/#organization"
                },
                "copyrightNotice": "Copyright © 2026 Detection Systems & Engineering. All rights reserved.",
                "citation": {
                    "@type": "CreativeWork",
                    "name": "Federal Reserve Regulation H: 12 CFR 208.61",
                    "url": "https://www.federalreserve.gov/frrs/regulations/section-20861-bank-security-procedures.htm",
                    "datePublished": "2026-07-28"
                }
            }
        ]
    }
}