Independent channel
Staff use the mobile number already visible in a browser-based CRM, platform or email client and send the one-time SMS code.
Scam-era disputes turn a fast instruction into a slow reconstruction: what should the firm have checked, what did it actually check, and what can the client file prove?
A firm may receive an instruction through the client's genuine mailbox, on a familiar thread and with a signed form. Those facts explain why staff believed it. They do not, by themselves, establish that the client authorised the transaction.
AFCA's scam-complaint work and legal commentary on determinations focus attention on conduct: the warnings given, the risk signals present, the procedure expected and the evidence retained. The receiving-bank rule change effective 12 March 2026 broadens accountability around unauthorised account opening, but it does not transfer an adviser's verification responsibility to the bank.
This determination-driven liability angle is commonly explained by law firms, not product vendors. It matters here because a verification product should be judged as one step inside an AFSL's procedure—not as a promise of a legal result.
The load-bearing argument
After a scam, confidence is not evidence. A defensible file shows the trigger, the independent check, the outcome, the approval and any exception.
A withdrawal, rollover or changed-account request arrives from the client's real email address or is supported by a caller who knows the portfolio and recent conversations.
Staff test the document, signature or email for surface consistency, but do not independently establish who controls the instruction at that moment.
The destination belongs to the scam. The genuine client later disputes authority, and the firm's procedure, warnings, records and response become central evidence.
AFCA, insurers, licensees and lawyers do not have the benefit of the original intuition. They work from what the procedure required and what the file proves happened.
An AFSL can adapt this baseline to its licence, client base, systems and legal advice. The strength is consistency: define the high-risk moment before staff are asked to make an exception.
Require a fresh identity check for withdrawals, rollovers, changed bank details, unusual disclosure requests and any instruction departing from the expected pattern.
Start from the phone number or email already held in the client file. Never use contact details supplied in the same message being verified.
Confirm the person independently, then apply the firm's separate checks for authority, account ownership, document validity and approvals.
Do not coach the caller or reveal the failed detail. Preserve the interaction, contact the real client through established records and escalate.
Keep the verification record, instruction version, destination-account checks, approver and any exception reason with the advice file.
Compliance should test whether urgent or senior-client requests bypass the control. A procedure that permits informal exceptions is not a reliable standard.
Staff use the mobile number already visible in a browser-based CRM, platform or email client and send the one-time SMS code.
Each authorised-contact check records who requested it, the masked target, method and outcome in a hash-chained audit trail.
Compliance-authorised users can export the result as PDF or CSV to retain and review alongside the instruction, approvals and incident material.
Vericode supports the firm's own controls and evidentiary position. It does not guarantee an AFCA, insurance, compliance or fraud outcome and does not satisfy an AFSL condition by itself.
AFCA's published annual review provides the dispute context for scam complaints and the conduct examined after loss.
Cited by title; a stable public link was not available at publication.
AFCA published rules concerning receiving banks and unauthorised account opening, effective 12 March 2026. The change signals continuing scrutiny across the payment chain; it does not remove an advice firm's own duties.
Cited by title; a stable public link was not available at publication.
Holley Nethercote (HN Law) analyses lessons from AFCA and practical steps licensees can consider to reduce liability in a new era of fraud.
Read sourceHWL Ebsworth discusses AFCA's new rules alongside the developing Australian scams-prevention framework.
Read source