ConceptioArchiveCode of Federal Regulations (eCFR)
Code of Federal Regulations (eCFR)public full text

12 CFR Part 21 — Minimum Security Devices and Procedures, Reports of Suspicious Activities, and Bank Secrecy Act Compliance Program

Office of the Federal Register (NARA) · Code of Federal Regulations (eCFR, Office of the Federal Register)
Code of Federal Regulations (eCFR) · Legal · License: Public Domain
Open Source ↗
departmentofthetreasurypart21
united states, us regulation, us federal regulation, code of federal regulations, cfr, federal regulation, 12, 21, part 21, 12 cfr 21, 12 cfr part 21, banks, and, banking, comptroller of the currency, department of the treasury

PART 21—MINIMUM SECURITY DEVICES AND PROCEDURES, REPORTS OF SUSPICIOUS ACTIVITIES, AND BANK SECRECY ACT COMPLIANCE PROGRAM Authority: 12 U.S.C. 1, 93a, 161, 1462a, 1463, 1464, 1818, 1881-1884, and 3401-3422; 31 U.S.C. 5318. Subpart A—Minimum Security Devices and Procedures Source: 56 FR 29564, June 28, 1991, unless otherwise noted. § 21.1 Purpose and scope of subpart A of this part. (a) This subpart is issued by the Comptroller of the Currency pursuant to section 3 of the Bank Protection Act of 1968 (12 U.S.C. 1882) and is applicable to all national banking associations. It requires each bank to adopt appropriate security procedures to discourage robberies, burglaries, and larcenies and to assist in identifying and apprehending persons who commit such acts. (b) It is the responsibility of a bank's board of directors to comply with this regulation and ensure that a security program which equals or exceeds the standards prescribed by this part is developed and implemented for the bank's main office and branches (as the term “branch” is used in 12 U.S.C. 36). [56 FR 29564, June 28, 1991, as amended at 73 FR 22244, Apr. 24, 2008] § 21.2 Designation of security officer. Within 30 days after the opening of a new bank, the Bank's board of directors shall designate a security officer who shall have the authority, subject to the approval of the board of directors, for immediately developing and administering a written security program to protect each banking office from robberies, burglaries, and larcenies and to assist in identifying and apprehending persons who commit such acts. (Approval by the Office of Management and Budget under control number 1557-0180) § 21.3 Security program. (a) Contents of security program. (1) Establish procedures for opening and closing for business and for the safekeeping of all currency, negotiable securities, and similar valuables at all times; (2) Establish procedures that will assist in identifying persons committing crimes against the institution and that will preserve evidence that may aid in their identification or conviction; such procedures may include, but are not limited to: (i) Using identification devices, such as prerecorded serial-numbered bills, or chemical and electronic devices; (ii) Maintaining a camera that records activity in the banking office; and (iii) Retaining a record of any robbery, burglary or larceny committed or attempted against a banking office; (3) Provide for initial and periodic training of employees in their responsibilities under the security program and in proper employee conduct during and after a robbery; and (4) Provide for selecting, testing, operating and maintaining appropriate security devices, as specified in paragraph (b) of this section. (b) Security devices. (1) A means of protecting cash or other liquid assets, such as a vault, safe, or other secure space; (2) A lighting system for illuminating, during the hours of darkness, the area around the vault, if the vault is visible from outside the banking office; (3) Tamper-resistant locks on exterior doors and exterior windows designed to be opened; (4) An alarm system or other appropriate device for promptly notifying the nearest responsible law enforcement officers of an attempted or perpetrated robbery, burglary or larceny; and (5) Such other devices as the security officer determines to be appropriate, taking into consideration: (i) The incidence of crimes against financial institutions in the area; (ii) The amount of currency or other valuables exposed to robbery, burglary, or larceny; (iii) The distance of the banking office from the nearest responsible law enforcement officers and the time required for such law enforcement officers ordinarily to arrive at the banking office; (iv) The cost of the security devices; (v) Other security measures in effect at the banking office; and (vi) The physical characteristics of the banking office structure and its surroundings. § 21.4 Report. The security officer for a national bank shall report at least annually to the bank's board of directors on the effectiveness of the security program. The substance of such report shall be reflected in the minutes of the Board meeting in which it is given. (Approved by the Office of Management and Budget under control number 1557-0180) Subpart B—Reports of Suspicious Activities § 21.11 Suspicious Activity Report. (a) Purpose and scope. (b) Definitions. (1) FinCEN (2) Institution-affiliated party (3) SAR (c) SARs required. (1) Insider abuse involving any amount. (2) Violations aggregating $5,000 or more where a suspect can be identified. (3) Violations aggregating $25,000 or more regardless of potential suspects. (4) Transactions aggregating $5,000 or more that involve potential money laundering or violate the Bank Secrecy Act. (i) The transaction involves funds derived from illegal activities or is intended or conducted in order to hide or disguise funds or assets derived from illegal activities (including, without limitation, the ownership, nature, source, location, or control of such funds or assets) as part of a plan to violate or evade any law or regulation or to avoid any transaction reporting requirement under Federal law; (ii) The transaction is designed to evade any regulations promulgated under the Bank Secrecy Act; or (iii) The transaction has no business or apparent lawful purpose or is not the sort in which the particular customer would normally be expected to engage, and the institution knows of no reasonable explanation for the transaction after examining the available facts, including the background and possible purpose of the transaction. (d) Time for reporting. (e) Reports to state and local authorities. (f) Exceptions. (2) A national bank need not file a SAR for lost, missing, counterfeit, or stolen securities if it files a report pursuant to the reporting requirements of 17 CFR 240.17f-1. (g) Retention of records. (h) Notification to board of directors Generally. (2) Suspect is a director or executive officer. (i) Compliance. (j) Obtaining SARs. (k) Confidentiality of SARs. (1) Prohibition on disclosure by national banks General rule. (A) Director, Litigation Division, Office of the Comptroller of the Currency; and (B) The Financial Crimes Enforcement Network (FinCEN). (ii) Rules of construction. (A) The disclosure by a national bank, or any director, officer, employee or agent of a national bank of: ( 1 ( 2 ( i ( ii (B) The sharing by a national bank, or any director, officer, employee, or agent of a national bank, of a SAR, or any information that would reveal the existence of a SAR, within the bank's corporate organizational structure for purposes consistent with title II of the Bank Secrecy Act as determined by regulation or in guidance. (2) Prohibition on disclosure by the OCC. (l) Limitation on liability. (m) Exemptions. (2) The OCC will respond in writing to a national bank that submits a request pursuant to paragraph (m)(1) of this section after considering whether the exemption is consistent with the factors in paragraph (m)(1) of this section. Any exemption granted by the OCC under paragraph (m)(1) of this section will continue for the time specified by the OCC. (3) The OCC may extend the period of time or may revoke an exemption granted under paragraph (m)(1) of this section. Exemptions or extensions may be revoked in the sole discretion of the OCC. Before revoking an exemption, the OCC will provide written notice to the national bank of the OCC's intention to revoke an exemption. Such notice will include the basis for the revocation and will provide an opportunity for the national bank to submit a response to the OCC. The OCC will consider any response before deciding whether or not to revoke an exemption and provide written notice to the national bank of the OCC's final decision to revoke an exemption. (4) With respect to requests for exemptions that will also require relief from the requirements of applicable regulations issued by the Department of the Treasury at 31 CFR chapter X, upon receiving approval from both the OCC and FinCEN, the requestor will be relieved of its obligations under this section to the extent stated in such approvals. [61 FR 4337, Feb. 5, 1996, as amended at 75 FR 75583, Dec. 3, 2010; 87 FR 15332, Mar. 18, 2022] Subpart C—Procedures for Monitoring Bank Secrecy Act Compliance § 21.21 Procedures for monitoring Bank Secrecy Act (BSA) compliance. (a) Purpose. (b) Definition of savings association. savings association (c) Establishment of a BSA compliance program Program requirement. (2) Customer identification program. (d) Contents of compliance program. (1) Provide for a system of internal controls to assure ongoing compliance; (2) Provide for independent testing for compliance to be conducted by national bank or savings association personnel or by an outside party; (3) Designate an individual or individuals responsible for coordinating and monitoring day-to-day compliance; and (4) Provide training for appropriate personnel. (Approved by the Office of Management and Budget under control number 1557-0180) [52 FR 2859, Jan. 27, 1987, as amended at 68 FR 25111, May 9, 2003; 76 FR 6687, Feb. 8, 2011; 79 FR 28399, May 16, 2014]

Related documents

Record · ID 505251 · SHA-256 d4f608ebceca505a
Retrieved via Conceptio — every document is proof-bundled with source, license, and retrieval metadata.