Customer playbook A
When Vericode is down
The verification tool may pause. Your verification procedure does not. Follow these steps in order.
Download the A4 desk cardWhat are you seeing?
| What staff sees | Likely cause | First check |
|---|---|---|
| The code never arrives | The SMS may be delayed | Check the Vericode status page |
| The extension button shows an error | The Vericode API may be unavailable | Check the Vericode status page |
| The dashboard will not load | The Vericode app may be unavailable | Check the Vericode status page |
| Everything is unusually slow | Vericode may be degraded | Check the Vericode status page |
The fallback procedure
- 1
Check the status page
Open status.vericode.com.au. Then follow every step below whenever Vericode is impaired, whether or not the status page confirms it. - 2
Call back using the number on file
If Vericode is impaired, tell the caller you will call back. Hang up. Find the client's number in your firm's existing records and call that number. Never call a number supplied in the current email or conversation. - 3
Write down the check
Use the manual record on the desk card. Record who checked, when, the number called, and the outcome. Keep it with the matter file. - 4
Backfill the record
When service resumes, add the manual verification to Vericode so the audit trail has no gap. - 5
Do not waive the control
Never skip verification because the tool is down. Outages create confusion, and attackers use confusion. Callback verification is a defensible practice, not an apology.
Why callback is the right fallback
Calling a trusted number already held by the firm breaks the attacker's control of the conversation. It follows the LPLC's technology and cyber risk guidance: independently verify changed or sensitive instructions before acting.
LPLC technology and cyber guidance