Bank and Credit Union Security Equipment: Requirements, Risk and Buying Decisions

Federal banking rules set a security baseline, and they stop well short of a shopping list for your branch. Which rule applies depends on your institution's primary federal regulator, and several of the decisions that matter most, including the camera strategy, stay risk-based judgments that have to be documented.

So this article separates three things: the equipment the rules name, what your security officer decides, and which parts of a branch need a specialist.

What does federal law actually require in a bank branch?

Banks subject to the federal Bank Protection Act regulations have to designate a security officer, adopt a written security program for each banking office, and have four specifically named security devices in place. A fifth requirement covers whatever additional devices the security officer determines are appropriate, weighed against six risk factors the rule names. Which regulation applies depends on your primary federal regulator. Credit unions work differently: their rule sets five program objectives and names no devices at all.

Here's the whole picture in one place. Notice how much of it is a decision rather than a purchase.

Element

Status in the rule

Who decides

A safe, vault or other secure space for cash

Named device

Required. You size and specify it

Lighting around the vault during darkness

Named device, conditional

Required only if the vault is visible from outside

Alarm that notifies law enforcement

Named device

Required. The text leaves the method open

Tamper-resistant exterior door and window locks

Named device

Required

Cameras

Not a named device

Your security officer, as a documented program decision

Access control, bollards, anything else

Not a named device

Your security officer, weighed against six factors

Written program, training, testing, board report

Required procedures

Obligations no purchase order satisfies


Which security rule applies to your institution?

All of them trace back to section 3 of the Bank Protection Act of 1968, and the three bank rules carry the same four specifically named devices, the same fifth risk-based requirement, and the same six risk factors. The timing and the numbering differ. Confirm your own regulator before relying on any of this.

Institution

Rule

Timing in the text

Approach

FDIC-supervised institution

12 CFR part 326

Officer designated on issuance of federal deposit insurance; written program no later than 180 days

Written program plus minimum devices

National bank

12 CFR part 21, subpart A (OCC)

Officer designated within 30 days after the opening of a new bank, charged with developing the program immediately

Written program plus minimum devices

Federal Reserve member bank

12 CFR 208.61

Officer designated on becoming a member; written program no later than 180 days

Written program plus minimum devices

Federally insured credit union

12 CFR 748.0 (NCUA)

Written program within 90 days of the effective date of insurance

Five program objectives, no prescribed device list


Two differences are worth pulling out of that table.

  • The OCC timing is not the 180 days people assume. It's 30 days to designate the officer, with immediate development of the program.

  • The three bank rules number the same devices differently: the FDIC lists the alarm third and the locks fourth, while the OCC and the Federal Reserve reverse those two. Cite the item, not the number.

Credit unions get objectives instead of hardware, and all five belong in the program:

  • Protect each office from robberies, burglaries, larcenies and embezzlement.

  • Ensure the security and confidentiality of member records.

  • Respond to incidents of unauthorized access to member information.

  • Assist in identifying the people who commit or attempt those acts.

  • Prevent destruction of vital records, which points at 12 CFR part 749 for what counts as vital. This is the objective that brings fire protection into scope alongside theft protection.

Does buying the four devices make a branch compliant?

No, and that's what gets lost once the conversation turns to equipment. The device list sits inside a program with several other obligations, and a purchase order satisfies none of them.

  • Opening and closing procedures: including the safekeeping of currency, negotiable securities and similar valuables at all times.

  • Procedures that help identify offenders and preserve evidence, which is where the camera actually appears.

  • Initial and periodic training: officers and employees on their responsibilities, and on proper conduct during and after a robbery, burglary or larceny.

  • Selecting, testing, operating and maintaining the devices: the rule asks for this in the same breath as owning them.

  • A report to the board at least annually on how the program is implemented and how well it works. For national banks the substance of that report has to appear in the board meeting minutes.

Equipment implements decisions the program should already have made and written down.

The four specific devices, and the fifth risk-based requirement

Each bank rule introduces its device section with the phrase at a minimum, the following security devices, then names four specific devices and adds a fifth, open-ended requirement. The left column quotes the rule. The right column is our reading of how it gets implemented, which is a different kind of statement.

What the rule names

Typical implementation route

A means of protecting cash or other liquid assets, such as a vault, safe, or other secure space

A depository or burglary-rated safe, specified against the criteria below, or a vault

A lighting system for the area around the vault during hours of darkness, if the vault is visible from outside the banking office

Commercial exterior lighting, often already part of the building

An alarm system or other appropriate device for promptly notifying the nearest responsible law enforcement officers

Commonly a monitored alarm with a central station, which is a contract rather than a product

Tamper-resistant locks on exterior doors and exterior windows that may be opened

Commercial door hardware, specified with your locksmith or integrator

Such other devices as the security officer determines to be appropriate

Cameras, access control, bollards and anything else the risk assessment supports


The rule names the six factors for that fifth requirement, so the assessment has a structure to follow:

  • Crime incidence against financial institutions in the area.

  • Valuables exposed to robbery, burglary or larceny.

  • Distance to law enforcement, and for national banks the time officers would ordinarily take to arrive.

  • The cost of the devices under consideration.

  • Other security measures already in effect at the banking office.

  • The physical characteristics of the structure and its surroundings.

Nothing there names a product. Everything past the four specific devices is a documented judgment, so write the reasoning down and keep it with the program.

Are security cameras required in a bank?

Not by the device list. A camera appears a subsection earlier, among the procedures for identifying offenders and preserving evidence, and all three bank rules word that list as procedures which may include, but are not limited to. Three things sit in that list:

  • Retaining a record of any robbery, burglary or larceny committed against the institution.

  • Maintaining a camera that records activity in the banking office.

  • Using identification devices, such as prerecorded serial-numbered bills, or chemical and electronic devices.

That holds across the FDIC, the OCC and the Federal Reserve, so it is structural rather than a quirk of one regulator. Video is common in branches and discretionary in the text, which generally makes camera deployment a risk-based security-program decision that should be documented.

Because the rule frames the purpose as identification and evidence, those are the objectives to design against rather than a camera count. Worth evaluating with your integrator:

  • Identification versus general coverage: which views need to identify a person, and which only need to record that something happened.

  • Lighting and backlight, since a camera facing a glass entrance in afternoon sun can be the one that fails when you need it.

  • Retention and evidence preservation: a procedural obligation as much as a storage spec.

  • Maintenance and testing: an untested camera is a gap in the program as much as in the equipment, since the rule asks for devices to be operated and maintained.

Once those objectives are settled, the hardware follows. Our video surveillance range covers the camera side.

How do you choose a depository safe?

Safes vary considerably in price, and the difference reflects more than size. Work the criteria before the catalog:

  • What you are protecting: the type and volume of assets, and the capacity you need at peak.

  • How deposits go in: a drop slot or rotary hopper lets staff deposit without opening the safe, which is the point on a teller line.

  • Internal access risk, which is what dual-control configurations address and what a single lock does not.

  • Construction and any applicable ratings: verify these on the specific model rather than assuming a category carries them. Burglary and fire ratings are different things.

  • Key and credential administration, including who holds what, how access is revoked, and how you recover from a lost combination.

  • Anchoring, because an unanchored safe is a portable safe.

  • Your insurer's requirements, which sometimes exceed what the regulation asks for.

As of August 2026, our depository range runs from roughly $80 for a single key unit to about $1,570 for a large two-lock model with a digital keypad, with fire-rated safes on a separate line. Deposit method and lock configuration drive most of that spread. Check the product pages for current pricing on a specific model.

One caution on dual control. If internal access is a material risk, evaluate a configuration that stops one employee reaching deposits alone, then confirm the lock configuration, the credential assignment and the written procedures actually enforce it. Two locks that one person holds both keys to isn't dual control at all. Hardware only delivers the control your procedures require.

How should teller-line and restricted-area access be controlled?

This is a design question more than a product question, and it is often where the risk-based requirement gets spent. The objective is separating the public lobby from employee-only areas without creating a problem on the way out.

  • Where the boundary sits: which openings separate lobby from staff space, cash handling, the server room and any area holding member or customer records.

  • The door before the lock: frame, leaf, latch and existing hardware decide what will physically work, so the survey comes before the hardware order.

  • Credentials and revocation, including what happens the day someone leaves and who's authorized to make that change.

  • Access records where they help, since they support both the identification procedures and the opening and closing procedures.

  • Integration with the alarm and with opening and closing procedures, so the controlled door is part of the program rather than a separate system.

One part of this needs care rather than product selection. Doors on an egress path are governed by building and life-safety codes enforced by your local authority, and the provisions covering electrically locked egress doors have been renumbered between recent code editions. Have those openings reviewed against the adopted edition with a qualified door hardware professional. Our guide to fail-safe versus fail-secure hardware explains why that choice changes what happens during a power failure. For the hardware itself, see access control and electric strikes. Transaction drawers and bullet-resistant barriers are engineered per branch and belong with a specialist.

What about the drive-through, ATM island and parking lot?

The risk-based requirement asks about the physical characteristics of the office and its surroundings, which in practice means exactly those three places. Bollards are one common answer for vehicle standoff, and the range is wide for a reason.

A bollard that keeps a delivery van off the glass is a different part from one specified to stop a vehicle at speed. Basic units start around $45 and crash-rated installations run into five figures. Don't treat the first as equivalent to the second. Where the concern is deliberate vehicle impact, or where you need a specific performance rating, get the installation designed rather than picked from a bollard listing.

What needs a specialist instead of a product order?

Being straight about this saves a phone call. Several things on a bank security list aren't retail purchases, and the reason is design rather than availability.

  • Vaults and vault doors: engineered and installed as part of the structure, with the rule treating a vault and a safe as alternatives for the same requirement.

  • Teller lines and bullet-resistant barriers: built to the branch, tied into the counter and the transaction drawer, and specified against a performance level.

  • The alarm has to actually reach law enforcement. That means a monitoring relationship and a tested response path, which is a service rather than a product on a shelf.

  • Night depositories get cut into an exterior wall and coordinated with the general contractor.

What we do carry is the rest: the safes for the cash protection requirement, commercial door hardware for the tamper-resistant locks, and the cameras, access control and bollards that a risk assessment tends to point at.

Frequently asked questions

Which federal security rule applies to my institution?

It depends on your primary federal regulator. FDIC-supervised institutions follow 12 CFR part 326, national banks follow 12 CFR part 21 subpart A from the OCC, Federal Reserve member banks follow 12 CFR 208.61, and federally insured credit unions follow 12 CFR 748.0 from the NCUA. The three bank rules share the same four specifically named devices, the same fifth risk-based requirement and the same six risk factors, though the timing and the numbering differ.

What is the $3,000 rule people mention alongside bank security?

It is unrelated to security equipment. That threshold comes from Bank Secrecy Act recordkeeping obligations, which sit apart from the security program rules covered here. Readers arriving on that question will not find it answered by the device requirements above.

What is the difference between a burglary-rated and a fire-rated safe?

They resist different things. A burglary rating describes resistance to forced entry, while a fire rating describes how long contents are protected at temperature. A safe chosen for cash may do little for paper records, which matters for credit unions because preventing destruction of vital records is one of the five objectives in 12 CFR 748.0. Check the rating on the specific model rather than the category.

When does a bank need a vault specialist or a security integrator?

For anything engineered into the building or requiring a tested response: vaults and vault doors, teller lines and bullet-resistant barriers, night depositories, monitored alarm service, and crash-rated vehicle barriers. An integrator is also the right call for camera and access control design where the objective is identifying people and preserving evidence rather than simply having coverage.

How should a security officer document a risk-based equipment decision?

Work from the six factors the rule names, since they give the assessment its structure: crime incidence in the area, valuables exposed, distance to law enforcement, cost of the devices, other measures already in effect, and the physical characteristics of the office and its surroundings. Record the conclusion for each, what you chose, and what you decided against. Keep it with the program and revisit it on the same cycle as the board report.

A ten-step checklist before you buy anything

Starting from scratch, or inheriting a program nobody has opened in years, this is the sequence that keeps equipment decisions in the right place.

  1. Identify the institution type and the primary federal regulator.

  2. Read the applicable rule and the existing written security program side by side.

  3. Confirm who holds authority to make and approve security decisions, and check the designation is current.

  4. Document the baseline: the devices and procedures the rule names, and whether each is in place and tested.

  5. Assess the location against the six risk factors named in your rule.

  6. Separate the three sources of obligation. Regulatory requirements, insurer requirements and internal policy are not the same thing and shouldn't share a line in your notes.

  7. Define the operational objective before you select equipment for it.

  8. Verify ratings, compatibility, installation and maintenance requirements on the specific model.

  9. Use a specialist for vaults, alarms, barriers and engineered access.

  10. Record the reasoning, test the controls and review the program on the required cycle.

Regulatory text reviewed against the current eCFR in August 2026, and product prices checked the same month. Primary sources: 12 CFR part 326, 12 CFR part 21 subpart A, 12 CFR 208.61, and 12 CFR 748.0. Read the regulation that applies to you before you write the program. Most of these sections are shorter than people expect.