All insights

Trust accounting and IT: what should a firm have in place?

5 min readBy Brendon Whiting, Founder · 23 March 2026

Four things underneath whatever your regulator requires: a verification habit for payment details, tightly restricted access to trust functions, backups that have actually been restored, and records that survive long enough. The regulatory rules are your regulator's; these are the IT controls that make complying with them realistic.

This article is deliberately not about the trust accounting rules themselves, which are state-based, detailed and properly the domain of your regulator and your accountant. It is about the technology underneath, which is where firms are exposed in ways the regulatory framework assumes are handled. A perfectly reconciled trust account is not much comfort if the funds went to a fraudster because someone amended bank details in an email.

That scenario is the one to design against, because it is the realistic threat to a small firm and it is not technically sophisticated. An attacker gets into a mailbox through a phished password and does nothing conspicuous. They read. They learn how the firm writes, who handles settlements, when money moves. Then, at exactly the moment amended details would be expected, they send them. It works not because it is clever but because it is timed, and it has cost Australian firms and their clients a great deal.

The control that defeats it is procedural rather than technical, and it needs to be absolute: any change to bank account details, from anyone, for any reason, is verified by telephone to a number you already held, never a number in the email requesting the change. Write it down, tell every staff member, and make it a rule that cannot be waived because someone is in a hurry, since urgency is exactly the pressure a fraudster manufactures. Multi-factor authentication on every mailbox is the technical half, because it stops the reconnaissance that makes the fraud convincing.

Access to trust functions should be genuinely restricted rather than nominally so. A defined small group with the ability to authorise payments, dual authorisation above a threshold, and accounts protected more strongly than anyone else's in the firm, because those are the credentials worth stealing. This is also an argument for keeping administrative rights away from everyday accounts, since an attacker who lands on a machine with standing administrator access has considerably more room to work.

Records and backups matter differently here because of retention. Trust records generally need keeping for longer than ordinary business documents, and the practical risk is not deletion but attrition: material lost during a system migration, a change of practice management software, or a provider changeover where nobody checked what was in the old system. Retention has to be deliberate and it has to survive change, which means knowing where those records live and confirming they are included in a backup that has actually been restored.

The audit trail is the fourth element and the one that turns a bad situation into a manageable one. Knowing who accessed what and when, both in the practice management system and in the underlying file storage, is what allows a firm to answer questions afterwards. If a mailbox is compromised, the question your regulator, your insurer and your client will ask is what was reached, and only logging answers it. Firms that cannot answer end up assuming the worst and notifying accordingly.

Insurance is worth a mention because it interacts with all of this. Cyber policies increasingly ask specific questions about multi-factor authentication, backups and payment verification procedures, and answering them inaccurately on a renewal is a problem in its own right. Treat the questionnaire as a useful annual audit rather than paperwork, since it is a reasonable summary of what an insurer has learned actually goes wrong in practices like yours.

The honest caveats. None of this is legal or regulatory advice, and your obligations come from your jurisdiction's rules rather than from an IT provider. Technology supports the controls; it does not replace supervision or reconciliation. And no arrangement makes fraud impossible, only much harder and much more likely to be caught early. If you want the technical controls underneath your trust obligations reviewed, call 1800 456 567.

If you do only one thing after reading this, make the payment verification rule explicit and tell every staff member it cannot be waived for urgency, because urgency is the pressure the fraud depends on.

Put controls under the trust obligations

We implement the access control, verification habits and record retention that protect trust funds, alongside your practice management system.

Frequently asked questions

Not a technical break-in. Someone gains access to a mailbox, watches quietly until a settlement approaches, then sends amended account details from a convincing address at the moment everyone expects them. It works because it arrives when it is expected. Verifying details by phone to a previously known number defeats it.

A defined, small group, with dual authorisation for amounts above a threshold you set, and that arrangement should be written down rather than understood. The IT contribution is making sure the accounts holding that authority are the best protected in the firm, since they are the ones worth compromising.

Longer than most business records, and the period is set by your jurisdiction's rules rather than by us. The practical IT implication is that retention has to be deliberate: records must survive system migrations, provider changes and software replacement, which is exactly where long-retention material tends to get lost.

Questions? Let's talk.

Call 1800 456 567 or fill out the form.

  • 30-minute discovery — no jargon, no pressure
  • Plain-English Essential Eight Cyber Security Scorecard
  • A clear plan tailored to your business

Prefer to talk?

Call 1800 456 567

Powered by Calendly — your data is handled securely.

Our office · Level 2, 25 Grenfell Street, Adelaide

By submitting, you agree to our terms and privacy policy. No spam — ever.