RiskWatch
RiskWatch International · Founded 1993 · Annapolis, MD, USA
Bank Protection Act + FFIEC + PCI v4 physical security assessment software with branch-level rollup.
Summary
RiskWatch ships a physical security risk assessment platform built around pre-mapped libraries for the Bank Protection Act of 1968 and 12 CFR 21 (OCC), 12 CFR 208.61 (FRB), 12 CFR 326.3 (FDIC), 12 CFR 748 (NCUA), FFIEC IT Examination Handbook physical-and-environmental controls, PCI DSS v4 Requirement 9 physical access controls, GLBA 501(b) Safeguards Rule, NIST 800-53 PE, ASIS Facility Physical Security Control Standards, and FEMA 426. The platform models the branch, the drive-up, the night-deposit, the vault, the safe-deposit-box room, the ATM head-office reconciliation room, and the cash-in-transit handoff as discrete assessable assets with their own control sets. Likelihood pulls from four crime-data feeds anchored to branch addresses. Customers include US community banks, multi-state regional banks, and bank holding companies running the annual Bank Protection Act security-officer report to the board. The product has been in the field since 1993 and is the only platform in this ranking that pre-maps every requirement a bank physical security officer owes a federal banking examiner in one tenant.
Strengths
- Bank Protection Act 12 CFR 21 + 12 CFR 208.61 + 12 CFR 326.3 + 12 CFR 748 + FFIEC IT Examination Handbook physical-and-environmental + PCI DSS v4 Requirement 9 + GLBA Safeguards Rule + NIST 800-53 PE + ASIS Facility Physical Security Control Standards + FEMA 426 pre-mapped on day one in one tenant
- Branch-level, region-level, and enterprise-level rollup dashboards with year-over-year trends covering the annual security-officer report to the board required under 12 CFR 21.3(b)
- Crime-data overlay from four independent feeds (Cap Index CRIMECAST, Security Gauge, GlobalIncidentMap, World Aware) anchored to branch street addresses so robbery and ATM-attack likelihood traces back to source and last-updated date for the federal banking examiner
- Browser-based mobile TVRA that works offline at rural branches with no cellular signal and syncs when connectivity returns; no findings lost on the annual branch walk
- Discrete asset models for branch lobby, drive-up, night-deposit, vault, safe-deposit-box room, ATM head-office reconciliation room, and cash-in-transit handoff with their own control sets
- Site Risk Cycle with ISO 31000 and NIST 800-30 semi-quantitative scoring; findings convert to tracked remediation tasks with owners and proof-of-close defensible to OCC, FRB, FDIC, NCUA, or state-banking examiners
- Single-tenant deployment with US-only data residency for bank customers under GLBA Safeguards Rule customer-information protection requirements
- 30-day free trial with no credit card and full platform access; the only TVRA-first vendor on this list offering it
Weaknesses
- Not a VMS, access control system, alarm panel, or ATM monitoring head-end; integrates with Genetec, Verkada, Brivo, Avigilon Alta, Milestone, Lenel S2, AlertEnterprise, Solink, and head-office ATM monitoring stacks via APIs and bulk imports rather than deep native connectors
- Brand awareness on G2 and Capterra in bank physical security specifically is lower than Genetec or Verkada; total third-party review volume in this niche sits below 100
- Public pricing is opaque, quote-based and scaled by framework count and branch count; marked partial because typical contract bands are published in the pricing calculator on this page
- No native ATM monitoring or jackpotting-detection telemetry; ATM-event evidence ingests from third-party ATM monitoring head-ends rather than first-party hardware integration
- No native investigations workflow at the Resolver depth; FinCEN SAR filing and 12 CFR 21.11 same-day regulator notice ride on the case-management module rather than a dedicated investigations product
- UI shows operational heritage in some assessment-builder screens; newer cloud-first entrants like Verkada and Avigilon Alta have a more polished first-run experience for non-specialist branch managers
US community banks under $5B, multi-state regional banks $5-25B, and bank holding companies above $25B running annual Bank Protection Act security-officer reports across 5-300+ branches with branch, ATM, vault, and cash-in-transit scope in one tenant.
Single-branch credit unions with one ATM and no holding-company structure that only need a camera plus access bundle and have no FFIEC IT Examination Handbook physical-and-environmental program; Verkada or Brivo is the better fit there.
Key features
- Pre-built libraries for Bank Protection Act 12 CFR 21 / 12 CFR 208.61 / 12 CFR 326.3 / 12 CFR 748, FFIEC IT Examination Handbook physical-and-environmental, PCI DSS v4 Requirement 9, GLBA Safeguards Rule, NIST 800-53 PE, ASIS Facility Physical Security Control Standards, FEMA 426
- Branch-level, region-level, and enterprise-level rollup for the annual board security-officer report under 12 CFR 21.3(b)
- Discrete asset models for branch lobby, drive-up, night-deposit, vault, safe-deposit-box room, ATM head-office reconciliation room, and cash-in-transit handoff
- Four crime-data feeds (Cap Index CRIMECAST, Security Gauge, GlobalIncidentMap, World Aware) anchored to branch street addresses
- Offline mobile site-walk app for rural branches with sync-on-reconnect
- Findings-to-remediation workflow with owners and proof-of-close for examiner-defensible evidence
- Single-tenant deployment with US-only data residency under GLBA
- 30-day free trial with no credit card
Integrations
25+ native. Notable: Microsoft Entra ID (SAML SSO), Okta, Microsoft 365 / SharePoint, Slack, Jira, Salesforce, Custom REST API.
Target size
100 to 25,000 employees · US · Canada