Close the loop after a fraud attempt
Record what happened, preserve the evidence, and make the next-day follow-up visible to your compliance officer, auditor, or insurer.
Download the incident registerOne register, ready to hand over
The workbook uses the incident fields specified for the Vericode fraud workflow. Keep external reference numbers—Scamwatch, ReportCyber, or SMR—beside the actions and outcome so the register stands on its own.
| Date | Staff member | Client / matter reference | Trigger condition | Action taken | Escalations made | External reports lodged | Outcome |
|---|---|---|---|---|---|---|---|
| Complete after each incident | Complete after each incident | Complete after each incident | Complete after each incident | Complete after each incident | Complete after each incident | Complete after each incident | Complete after each incident |
The day-after checklist
- 1
Write the register entry
Record the trigger, action, escalations, external report references, and outcome.
- 2
Preserve the evidence
Keep emails, numbers, notes, recordings, and Vericode record references with the incident file.
- 3
Lodge external reports
Record Scamwatch, ReportCyber, bank, police, insurer, or SMR references where applicable.
- 4
Contact the client safely
Use a known-good channel from the firm's existing records, not details supplied during the incident.
- 5
Check escalation contacts
Confirm the compliance officer, office admin, bank, and insurer details are current.
- 6
Check for a pattern
Ask whether this client record, matter, or payment instruction has been targeted before.
Make the evidence portable
Attach or reference the Vericode verification record, then preserve the source emails, phone numbers, notes, recordings, and external report receipts. The register is the index; the evidence remains with the incident file.