Before settlement funds move
Verify changed destination accounts and urgent payment instructions against a known contact record before authorising disbursement.
One compromised mailbox and one “updated bank details” message can redirect an entire settlement. Verify the person behind the instruction, then retain a record built for the file.
Verification of identity establishes a person at the start of a matter. It does not prove that a later email, call or account change came from that person. LPLC’s “call first” guidance addresses this gap; a consistent procedure makes the call easier to perform and defend.
Verify changed destination accounts and urgent payment instructions against a known contact record before authorising disbursement.
Apply the same independent check to deposits, refunds, controlled money and instructions affecting the firm’s trust account.
A real mailbox can be compromised. Step outside the email thread and record the check rather than relying on familiar wording.
Highlight the client’s phone number in the browser-based practice system, workspace or email client already on screen. Right-click to send a one-time SMS code; the client reads it back on the call.
The extension is system-agnostic and does not claim a direct practice-management or PEXA integration. Use contact details already held on file—not the new number supplied in the instruction.
Escalate through a second known channel, record suspicious activity and require fresh authority before releasing settlement or trust funds.
Each authorised-contact check records requester, masked target, method, timestamps and outcome. Compliance-authorised users can export the audit as PDF or CSV for file review, insurers and auditors.
SMS is delivered through Australian carriers MobileMessage or ClickSend using the ACMA-registered sender ID VERICODE.
Customer and verification data—recipient details, messages and verification records—is hosted in Australia. Staff sign-in is handled by our identity provider, WorkOS, in the United States.
Tranche 2 brings relevant designated legal services into the AML/CTF regime. Vericode does not replace customer due diligence or guarantee compliance; it gives the firm a documented step for authenticating high-risk client instructions inside the broader program.
LPLC tells practices to call a known number before paying and to make a file note. Vericode operationalises that doctrine with a structured record.
Read sourceLPLC’s practice-risk guide gives firms a broader framework for preventing and responding to cyber fraud.
Read sourceThe Law Society publishes current trust-money and fidelity-fund scam warnings for legal practices.
Read sourceVictorian guidance sets out cyber-security red flags and good practices for lawyers handling client matters.
Read sourceStart with changed bank details, settlement disbursements and trust-account instructions. Define who can authorise release after a failed check and what evidence must be retained.