Conveyancers & property lawyers

Call before you pay. Prove that you did.

One compromised mailbox and one “updated bank details” message can redirect an entire settlement. Verify the person behind the instruction, then retain a record built for the file.

The payment instruction is the risk event

Day-one identity does not authenticate a day-41 bank change.

Verification of identity establishes a person at the start of a matter. It does not prove that a later email, call or account change came from that person. LPLC’s “call first” guidance addresses this gap; a consistent procedure makes the call easier to perform and defend.

01

Before settlement funds move

Verify changed destination accounts and urgent payment instructions against a known contact record before authorising disbursement.

02

Before trust money moves

Apply the same independent check to deposits, refunds, controlled money and instructions affecting the firm’s trust account.

03

When the channel looks genuine

A real mailbox can be compromised. Step outside the email thread and record the check rather than relying on familiar wording.

Operationalise “call first”

A known number, a one-time code, a recorded outcome.

Highlight the client’s phone number in the browser-based practice system, workspace or email client already on screen. Right-click to send a one-time SMS code; the client reads it back on the call.

The extension is system-agnostic and does not claim a direct practice-management or PEXA integration. Use contact details already held on file—not the new number supplied in the instruction.

If the check fails, stop the payment

Escalate through a second known channel, record suspicious activity and require fresh authority before releasing settlement or trust funds.

Evidence for the matter and the firm

A callback becomes a control when it is consistent and reviewable.

Hash-chained record

Each authorised-contact check records requester, masked target, method, timestamps and outcome. Compliance-authorised users can export the audit as PDF or CSV for file review, insurers and auditors.

Recognisable sender

SMS is delivered through Australian carriers MobileMessage or ClickSend using the ACMA-registered sender ID VERICODE.

Transparent residency

Customer and verification data—recipient details, messages and verification records—is hosted in Australia. Staff sign-in is handled by our identity provider, WorkOS, in the United States.

AUSTRAC beachhead

From 1 July 2026, documented verification is an operating discipline—not a future talking point.

Tranche 2 brings relevant designated legal services into the AML/CTF regime. Vericode does not replace customer due diligence or guarantee compliance; it gives the firm a documented step for authenticating high-risk client instructions inside the broader program.

Legal-sector guidance

The doctrine is established. The missing piece is proof.

LPLC — Call first

LPLC tells practices to call a known number before paying and to make a file note. Vericode operationalises that doctrine with a structured record.

Read source

LPLC Cyber Guide

LPLC’s practice-risk guide gives firms a broader framework for preventing and responding to cyber fraud.

Read source

Law Society of NSW scam alerts

The Law Society publishes current trust-money and fidelity-fund scam warnings for legal practices.

Read source

VLSB+C red flags

Victorian guidance sets out cyber-security red flags and good practices for lawyers handling client matters.

Read source
Before the next settlement

Turn “call before you pay” into a procedure the file can show.

Start with changed bank details, settlement disbursements and trust-account instructions. Define who can authorise release after a failed check and what evidence must be retained.