Financial advisers & planners

The email is real. The withdrawal instruction may not be.

An attacker inside a client’s mailbox can send the signed form, answer the familiar thread and call to change bank details. Add an independent verification step—and retain evidence that it happened.

Where the procedure earns its keep

Verify before acting—or before revealing the next useful detail.

A verification procedure is not only a last barrier to a fraudulent transfer. Used earlier, it can prevent information leakage during a convincing pretext call. Focus it on moments where identity, authority and destination account all matter.

01

Withdrawal and rollover forms

A signed form sent from the client’s real, compromised mailbox can still carry the attacker’s instruction.

02

Changed bank details

A familiar voice, personal facts or urgency should not replace a separate check against a known contact channel.

03

Sensitive conversations

Verification can stop a pretext before an adviser discloses balances, holdings or process details that enable the next stage.

Inside the existing workflow

A deliberate pause at the point of risk.

Highlight the client’s phone number wherever it appears in a browser-based CRM, platform or email client. Right-click to send a one-time SMS code; the client reads it back on the call.

Vericode is CRM-agnostic: it works with contact details visible on screen. It does not claim a direct integration with an advice platform.

Turn policy into a repeatable action

Define triggers such as withdrawals, rollovers, changed bank details and unusual information requests. If verification fails, stop and follow the firm’s escalation procedure.

Reasonable steps need evidence

A record an AFSL can put in front of AFCA or its insurer.

Every authorised-contact check creates a timestamped, hash-chained record of who requested it, the masked target, method and outcome. Compliance-authorised users can export the audit as PDF or CSV.

Document the step

Support the firm’s case that a defined verification step was followed at the relevant time.

Trusted delivery context

Verification messages pass through Australian carriers MobileMessage or ClickSend, using the ACMA-registered sender ID VERICODE.

Transparent residency

Customer and verification data—recipient details, messages and verification records—is hosted in Australia. Staff sign-in is handled by our identity provider, WorkOS, in the United States.

Vericode supports a firm’s own controls and evidence. It does not guarantee a compliance, AFCA, insurance or fraud outcome, does not satisfy an AFSL condition by itself, and this page is not financial or legal advice.

Current guidance

Scam disputes turn on conduct and evidence.

AFCA scam complaints

AFCA’s annual review of scam complaints shows how evidence and a firm’s response are scrutinised when losses are disputed.

Read source

AFCA receiving-bank rules

AFCA published updated rules for receiving banks and unauthorised account opening, effective 12 March 2026.

Read source

Reducing licensee liability

Hamilton Locke’s post-AFCA advisory focuses on practical steps licensees can take to reduce scam liability.

Read source

ASIC SMSF rollover alert

ASIC warns consumers about scams involving self-managed super fund rollovers and unexpected contact.

Read source
Make the next instruction defensible

Give advisers a fast check and compliance a durable record.

Start with a narrow set of high-risk triggers, train the escalation path and review the resulting evidence with your licensee.