VOI
Evidence that the client’s identity was verified using the prescribed or reasonable-steps process at the relevant time.
Identity at engagement and identity in a live settlement interaction are related controls—not the same question.
Verification of identity is foundational. ARNECC’s guidance and LPLC’s discussion of VOI and client authorisation help practitioners understand the identity and authority controls that support electronic conveyancing. Tranche 2 adds customer due diligence for designated legal services, including an ongoing, risk-based view of the customer relationship.
Neither concept should be stretched into a claim it does not make. A passport, licence or identity check completed at engagement does not authenticate every email and caller for the rest of the matter. A criminal can compromise a genuine client’s mailbox after VOI, learn the transaction and insert new payment details without changing the client’s underlying identity.
The day-41 question is about the interaction: does the person giving this high-risk instruction control the trusted contact point previously associated with the client, and did the firm independently check the exact details before funds moved?
Day 1
The firm verifies identity under the applicable conveyancing framework, obtains client authorisation and establishes trusted contact details. The identity-document question is answered for onboarding.
Days 2–40
Contracts, searches, finance, adjustments and correspondence create a rich transaction history. Legitimate emails and calls make later messages feel familiar; compromise during this period can expose that context.
Day 41
A caller or email asks to change the account for settlement proceeds, a deposit, shortfall or trust transfer. The message may know the file because the mailbox or account has been observed.
Before funds move
The firm returns to a trusted contact point established earlier, verifies the person, reads the complete payment details out and back, documents the outcome and escalates any mismatch.
“Day 41” is a frame, not a claim about the average length of a conveyance. The vulnerable moment can occur on any day: whenever a payment destination, contact point or authority changes close enough to money movement that urgency discourages checking.
Evidence that the client’s identity was verified using the prescribed or reasonable-steps process at the relevant time.
Authority for the conveyancer to act and undertake transactions within the scope of the matter.
Risk-based customer identification, verification and ongoing due-diligence obligations for designated services from the applicable commencement.
Whether the person on this call controls the known client phone or email contact now.
Whether a new destination account was genuinely authorised rather than inserted through compromise or impersonation.
Who performed the check, which trusted contact was challenged, when it happened and what outcome preceded the payment decision.
This is not a claim that VOI, client authorisation or CDD are deficient. They solve important problems. The gap appears when a firm assumes a completed identity process automatically authenticates every later communication. A transaction-time control connects the known customer to the live instruction.
KYC and VOI products can collect and validate identity evidence, conduct biometric or database checks where supported, and preserve onboarding results. Those capabilities belong at the identity-establishment layer. This guide does not diminish them.
The caller at settlement may be a criminal using genuine client information from a compromised inbox. Re-running a document check could confirm the real client exists while saying nothing about who controls the current call or whether the new BSB was authorised.
Transaction-time verification uses a different challenge: return to a known contact established before the disputed instruction and test possession now. Then compare the complete instruction verbally and record the outcome. It complements KYC; it is not a substitute for KYC and Vericode is not a full KYC solution.
Continuous verification does not mean repeatedly asking clients for identity documents or treating every interaction as suspicious. It means defining high-risk triggers across the matter and applying an independent identity check when the consequence warrants it.
Useful triggers include a new payment destination, changed contact details, an unexpected representative, urgency that bypasses normal process, a request to disclose sensitive matter information, or a caller who asks staff to rely on details supplied in the current conversation.
With Vericode, staff highlight a known phone number visible in a browser-based practice system, portal or email client, right-click and send a one-time SMS code through MobileMessage or ClickSend using the ACMA-registered sender ID VERICODE. The caller reads it back. Each authorised-contact check creates a timestamped, hash-chained record of requester, masked target, method and outcome; compliance-authorised users can export it as PDF or CSV.
The verification record proves that interaction. The firm still reads the full BSB and account number out and back, applies payment approvals, records the source of the trusted contact and escalates failures. If the check cannot be completed, that is a stop signal—not permission to switch to the number in the incoming message.
Public guidance is cited for context only. No endorsement of Vericode by ARNECC, LPLC, the Law Society of NSW or AICV is implied.
Keep VOI and CDD in their proper place, then verify the person and instruction again at the high-loss moment.