field note
Bank security cameras: what the Bank Protection Act requires
Bank security cameras fall under the Bank Protection Act of 1968. What 12 CFR Part 21 requires, where cameras appear in it, and what the board sees each year.
2026-09-28
Bank security cameras are covered by the Bank Protection Act of 1968, which requires every bank to run a written security program that preserves evidence to help identify people who commit crimes against it, and the regulations name a camera that records activity in the banking office as one way to do that. The camera itself is not on the list of mandatory devices. What the rules do require is a designated security officer, security devices that are tested and maintained, and a report on the program’s effectiveness to the board at least once a year.
That distinction matters because much of what is written about bank camera requirements overstates the rule. This post covers what the regulation actually says, where cameras fit inside it, and what a security officer needs in order to write the annual report honestly across every branch.
What is the Bank Protection Act
The Bank Protection Act of 1968 is the federal law, at 12 U.S.C. 1882, that directs each banking regulator to set minimum security standards for the institutions it supervises. Each regulator implements it in its own rule, and the rules for banks closely track one another:
| Institution | Regulator | Rule |
|---|---|---|
| National banks | OCC | 12 CFR Part 21, Subpart A |
| State member banks | Federal Reserve | 12 CFR 208.61 |
| Institutions the FDIC supervises, including state nonmember banks | FDIC | 12 CFR Part 326, Subpart A |
| Federally insured credit unions | NCUA | 12 CFR Part 748 |
The quotes below come from the OCC’s version, 12 CFR Part 21, as it reads in September 2026. The Federal Reserve and FDIC rules use the same camera language and the same testing and reporting duties. NCUA’s rule for credit unions requires a written security program designed in part to assist in identifying people who commit crimes, with an annual certification of compliance, and does not name cameras.
What the rule requires
Part 21 asks for four things.
A security officer. The board designates a security officer, within 30 days after a new bank opens, with authority to develop and administer a written security program for every banking office.
A written security program. Under 21.3(a), the program must establish procedures for opening and closing and for safekeeping currency and valuables; procedures that will assist in identifying people who commit crimes against the bank and “preserve evidence that may aid in their identification or conviction”; initial and periodic employee training; and the “selecting, testing, operating and maintaining” of appropriate security devices.
Minimum security devices. Under 21.3(b), every national bank must have at least a vault, safe, or other secure space; lighting around the vault during hours of darkness if the vault is visible from outside; tamper-resistant locks on exterior doors and on exterior windows designed to be opened; and an alarm or other device that promptly notifies law enforcement of a robbery, burglary, or larceny. Beyond those, the security officer decides what other devices are appropriate, weighing six factors: the incidence of crimes against financial institutions in the area, the amount of cash and valuables exposed, the distance to law enforcement and their usual response time, the cost of the devices, the other security measures in place, and the physical characteristics of the building and its surroundings.
An annual report. Under 21.4, the security officer reports at least annually to the board on the effectiveness of the security program, and the substance of that report is reflected in the minutes of the board meeting where it is given.
Where the camera fits
The camera appears once in Subpart A, in 21.3(a)(2), as one of the procedures a bank may use to identify offenders and preserve evidence: “Maintaining a camera that records activity in the banking office.” It sits beside prerecorded serial-numbered bills, chemical and electronic identification devices, and keeping a record of every robbery, burglary, or larceny. It is an example of how to meet the evidence requirement rather than an item on the minimum devices list.
Cameras are the most direct way to meet that requirement, which is why the regulation names them. The rule does not set a resolution, a camera count, a retention period, or any particular technology. Guides that list night vision, weatherproofing, or facial recognition as regulatory requirements are describing product features or good practice, not the regulation.
The rest of the rule still reaches the cameras in practice. The program must provide for “selecting, testing, operating and maintaining appropriate security devices,” and paragraph (b) lets the security officer add any device they determine is appropriate. A camera system the program depends on for evidence is only as useful as the testing and maintenance behind it, and the annual report is the board’s statement about whether that program is effective.
Retention: what the rule sets and what it does not
Subpart A sets no retention period for camera footage. Each bank sets its own in its security program, and other obligations shape it: litigation holds, insurance claims, and state law among them. Requirements across industries and states are collected in the video retention requirements reference.
One part of Part 21 does set a clock that can reach video. Subpart B covers Suspicious Activity Reports, and 21.11 requires a national bank to keep a copy of any SAR it files and “the original or business record equivalent of any supporting documentation for a period of five years from the date of the filing of the SAR.” Supporting documentation is identified and maintained by the bank as such. If the bank identifies footage as supporting documentation for a SAR, that footage falls under the five-year requirement.
Where bank cameras go
The six factors in 21.3(b)(5) are the documented basis for deciding what each branch needs, which is why coverage differs from a downtown branch to a rural one. The places that come up at nearly every branch:
- Entrances and exits, framed to identify faces rather than to show the lobby.
- The teller line, from the customer side of the counter.
- The vault and safe deposit area, including who enters and when.
- ATMs and the night deposit, inside and out.
- Drive-up lanes and parking areas, for vehicles and approaches.
A bank that adds cameras beyond the evidence minimum is still adding security devices the program has to test and maintain, so every camera added is also a camera the annual report has to account for.
The annual report, across every branch
The annual report asks whether the security program is effective. For the cameras in it, that question has a factual answer per device: was it recording, was the view intact, was the clock right, and did anything change during the year.
At one branch a security officer can walk the building and look. At forty branches, many of them brought in through acquisitions with systems from different banks, the answer usually comes from branch walk-throughs, vendor service tickets, and a spreadsheet, and what reaches the board is a summary of those. The failures that make the summary wrong are the ordinary ones: a camera that went offline months ago, a view blocked by a new sign, a clock that drifted until footage no longer lines up with teller records, a recorder that is keeping less footage than the policy says it does. The questions examiners and auditors ask about camera systems are in what auditors ask about camera systems.
Doing this across 50 branches
MentatNOC does not make a bank compliant with the Bank Protection Act or with anything else. It produces the record the annual report rests on. It watches recording state and device health rather than reachability alone, and covers credentials, certificates, time, and configuration alongside uptime, for every camera in every branch. What happened to each camera is written to an audit log built so entries cannot be rewritten after the fact, so when the board, an examiner, or an auditor asks whether the cameras were working, the proof already exists. It monitors device health, not video. The evidence side is on the compliance page, and you can see a multi-branch fleet end to end in a live platform demo.
The regulation names the camera once, as an example. The testing, the maintenance, and the annual report are the parts it makes mandatory.