Conveyancing guide · Transaction-time identity

VOI verified the buyer at day 1. Who verified the caller at day 41?

Identity at engagement and identity in a live settlement interaction are related controls—not the same question.

The ownable gap

A correct onboarding check can coexist with a fraudulent settlement call.

Verification of identity is foundational. ARNECC’s guidance and LPLC’s discussion of VOI and client authorisation help practitioners understand the identity and authority controls that support electronic conveyancing. Tranche 2 adds customer due diligence for designated legal services, including an ongoing, risk-based view of the customer relationship.

Neither concept should be stretched into a claim it does not make. A passport, licence or identity check completed at engagement does not authenticate every email and caller for the rest of the matter. A criminal can compromise a genuine client’s mailbox after VOI, learn the transaction and insert new payment details without changing the client’s underlying identity.

The day-41 question is about the interaction: does the person giving this high-risk instruction control the trusted contact point previously associated with the client, and did the firm independently check the exact details before funds moved?

The conveyance verification timeline

Identity assurance has to survive the life of the matter.

  1. 01

    Day 1

    Engagement and VOI

    The firm verifies identity under the applicable conveyancing framework, obtains client authorisation and establishes trusted contact details. The identity-document question is answered for onboarding.

  2. 02

    Days 2–40

    The matter develops

    Contracts, searches, finance, adjustments and correspondence create a rich transaction history. Legitimate emails and calls make later messages feel familiar; compromise during this period can expose that context.

  3. 03

    Day 41

    “Updated details”

    A caller or email asks to change the account for settlement proceeds, a deposit, shortfall or trust transfer. The message may know the file because the mailbox or account has been observed.

  4. 04

    Before funds move

    Transaction-time verification

    The firm returns to a trusted contact point established earlier, verifies the person, reads the complete payment details out and back, documents the outcome and escalates any mismatch.

“Day 41” is a frame, not a claim about the average length of a conveyance. The vulnerable moment can occur on any day: whenever a payment destination, contact point or authority changes close enough to money movement that urgency discourages checking.

The regulatory and operational gap

What is covered—and what still needs a workflow control

Controls that establish identity, authority and risk

VOI

Evidence that the client’s identity was verified using the prescribed or reasonable-steps process at the relevant time.

Client authorisation

Authority for the conveyancer to act and undertake transactions within the scope of the matter.

Tranche 2 CDD

Risk-based customer identification, verification and ongoing due-diligence obligations for designated services from the applicable commencement.

Questions a live instruction still creates

Possession of today’s channel

Whether the person on this call controls the known client phone or email contact now.

Authenticity of a changed instruction

Whether a new destination account was genuinely authorised rather than inserted through compromise or impersonation.

Evidence of the live interaction

Who performed the check, which trusted contact was challenged, when it happened and what outcome preceded the payment decision.

This is not a claim that VOI, client authorisation or CDD are deficient. They solve important problems. The gap appears when a firm assumes a completed identity process automatically authenticates every later communication. A transaction-time control connects the known customer to the live instruction.

KYC tools and live interactions

Documents establish identity. They do not answer the phone.

KYC and VOI products can collect and validate identity evidence, conduct biometric or database checks where supported, and preserve onboarding results. Those capabilities belong at the identity-establishment layer. This guide does not diminish them.

The caller at settlement may be a criminal using genuine client information from a compromised inbox. Re-running a document check could confirm the real client exists while saying nothing about who controls the current call or whether the new BSB was authorised.

Transaction-time verification uses a different challenge: return to a known contact established before the disputed instruction and test possession now. Then compare the complete instruction verbally and record the outcome. It complements KYC; it is not a substitute for KYC and Vericode is not a full KYC solution.

Continuous verification

Verify at the moments when trust changes hands.

Continuous verification does not mean repeatedly asking clients for identity documents or treating every interaction as suspicious. It means defining high-risk triggers across the matter and applying an independent identity check when the consequence warrants it.

Useful triggers include a new payment destination, changed contact details, an unexpected representative, urgency that bypasses normal process, a request to disclose sensitive matter information, or a caller who asks staff to rely on details supplied in the current conversation.

With Vericode, staff highlight a known phone number visible in a browser-based practice system, portal or email client, right-click and send a one-time SMS code through MobileMessage or ClickSend using the ACMA-registered sender ID VERICODE. The caller reads it back. Each authorised-contact check creates a timestamped, hash-chained record of requester, masked target, method and outcome; compliance-authorised users can export it as PDF or CSV.

The verification record proves that interaction. The firm still reads the full BSB and account number out and back, applies payment approvals, records the source of the trusted contact and escalates failures. If the check cannot be completed, that is a stop signal—not permission to switch to the number in the incoming message.

The day-41 control

Do not let day-1 identity become permanent trust in every channel.

Keep VOI and CDD in their proper place, then verify the person and instruction again at the high-loss moment.

General information only. This guide is not legal, financial, AML/CTF compliance or incident-response advice. Follow your firm’s procedures and seek professional advice for your circumstances.