Financial adviser guide · Procedure and evidence

When the “client” on the phone isn't your client

Scam-era disputes turn a fast instruction into a slow reconstruction: what should the firm have checked, what did it actually check, and what can the client file prove?

The liability lens has shifted

A firm may receive an instruction through the client's genuine mailbox, on a familiar thread and with a signed form. Those facts explain why staff believed it. They do not, by themselves, establish that the client authorised the transaction.

AFCA's scam-complaint work and legal commentary on determinations focus attention on conduct: the warnings given, the risk signals present, the procedure expected and the evidence retained. The receiving-bank rule change effective 12 March 2026 broadens accountability around unauthorised account opening, but it does not transfer an adviser's verification responsibility to the bank.

This determination-driven liability angle is commonly explained by law firms, not product vendors. It matters here because a verification product should be judged as one step inside an AFSL's procedure—not as a promise of a legal result.

The load-bearing argument

After a scam, confidence is not evidence. A defensible file shows the trigger, the independent check, the outcome, the approval and any exception.

How the disputed instruction unfolds

  1. 01

    The instruction looks ordinary

    A withdrawal, rollover or changed-account request arrives from the client's real email address or is supported by a caller who knows the portfolio and recent conversations.

  2. 02

    The firm follows the channel

    Staff test the document, signature or email for surface consistency, but do not independently establish who controls the instruction at that moment.

  3. 03

    Money moves

    The destination belongs to the scam. The genuine client later disputes authority, and the firm's procedure, warnings, records and response become central evidence.

  4. 04

    The dispute reconstructs conduct

    AFCA, insurers, licensees and lawyers do not have the benefit of the original intuition. They work from what the procedure required and what the file proves happened.

A verification-procedure standard

An AFSL can adapt this baseline to its licence, client base, systems and legal advice. The strength is consistency: define the high-risk moment before staff are asked to make an exception.

  1. 01

    Define triggers

    Require a fresh identity check for withdrawals, rollovers, changed bank details, unusual disclosure requests and any instruction departing from the expected pattern.

  2. 02

    Use a trusted record

    Start from the phone number or email already held in the client file. Never use contact details supplied in the same message being verified.

  3. 03

    Separate identity from authority

    Confirm the person independently, then apply the firm's separate checks for authority, account ownership, document validity and approvals.

  4. 04

    Stop on failure

    Do not coach the caller or reveal the failed detail. Preserve the interaction, contact the real client through established records and escalate.

  5. 05

    Retain the outcome

    Keep the verification record, instruction version, destination-account checks, approver and any exception reason with the advice file.

  6. 06

    Review exceptions

    Compliance should test whether urgent or senior-client requests bypass the control. A procedure that permits informal exceptions is not a reliable standard.

The defensible artefact

Turn “we called the client” into a record of the check.

Independent channel

Staff use the mobile number already visible in a browser-based CRM, platform or email client and send the one-time SMS code.

Timestamped result

Each authorised-contact check records who requested it, the masked target, method and outcome in a hash-chained audit trail.

Portable evidence

Compliance-authorised users can export the result as PDF or CSV to retain and review alongside the instruction, approvals and incident material.

Vericode supports the firm's own controls and evidentiary position. It does not guarantee an AFCA, insurance, compliance or fraud outcome and does not satisfy an AFSL condition by itself.

Published guidance

AFCA annual review: scam complaints

AFCA's published annual review provides the dispute context for scam complaints and the conduct examined after loss.

Cited by title; a stable public link was not available at publication.

AFCA receiving-bank rule change

AFCA published rules concerning receiving banks and unauthorised account opening, effective 12 March 2026. The change signals continuing scrutiny across the payment chain; it does not remove an advice firm's own duties.

Cited by title; a stable public link was not available at publication.

Scam lessons from AFCA

Holley Nethercote (HN Law) analyses lessons from AFCA and practical steps licensees can consider to reduce liability in a new era of fraud.

Read source

AFCA rules and the Scams Prevention Framework

HWL Ebsworth discusses AFCA's new rules alongside the developing Australian scams-prevention framework.

Read source
Not legal or financial advice. This general information does not determine an AFSL's obligations or guarantee an AFCA, insurance or compliance outcome. Obtain advice on your circumstances and approved procedures.
Make conduct reconstructable

Define the check, train it and retain its outcome.