Client trust accounting is one of the most heavily scrutinized parts of a law practice, and one of the most attractive targets for fraudsters. The rules on safeguarding client funds come from your state bar and vary in detail, so confirm requirements with your bar's guidance and your accountant. What is consistent across states is that careless handling can lead to discipline, and a technology failure or a fraudulent transfer is no defense on its own.
Whether your firm uses a practice-management platform with built-in trust accounting or a separate accounting package, a few IT controls make the system harder to misuse or attack.
Control who can do what
Role-based permissions
Define roles in the software and assign the minimum permissions required.
- Who can view trust balances?
- Who can enter deposits?
- Who can prepare disbursements?
- Who can approve disbursements?
- Who can edit or delete entries?
- Who can reconcile?
Separate preparation from approval so that no single person can both create and release a payment. In a very small firm where that is hard, add a compensating control, such as a partner reviewing a weekly report of all trust activity.
Unique accounts and strong sign-in
Everyone should use a named account with MFA. Avoid shared logins to the trust system or the bank portal, since shared access eliminates accountability.
Bank portal protections
- Dual authorization for wires and ACH payments above defined thresholds
- Positive pay or similar services if your bank offers them
- Alerts for new payees, changed instructions, and large transactions
- Restrict portal access to specific devices or networks where possible
Protect the process against fraud
Real estate closings, settlements, and estate distributions all involve large payments based on instructions that arrive by email. Combine software controls with procedures.
- Call-back verification for every new or changed payment instruction, using a trusted number.
- Second approval for disbursements over a threshold.
- Documented verification attached to the disbursement record.
- Blocked payment requests by email from partners or staff without confirmation.
- Client notice in engagement letters that wire instructions will never change by email.
Audit trails
Make sure the software logs who created, edited, approved, and deleted records, and that logs cannot be modified by regular users. Review exceptions regularly, such as back-dated entries, deleted transactions, and edits after reconciliation. These logs also help in a dispute or investigation.
Reconciliation support
Many state rules require regular reconciliation, often described as three-way: the bank statement, the firm's trust ledger, and the individual client ledgers. Check your state's requirements. Use software features that support this, and keep records of completed reconciliations, who prepared them, and who reviewed them.
Backups and availability
Trust records must be accurate and retrievable. Ensure that:
- The accounting data is backed up automatically and at least one copy is stored separately from your main network
- You can restore it and have tested doing so
- Retention meets your state's recordkeeping requirement, which commonly spans a number of years. Verify the period with your bar
- Cloud-hosted systems have documented export options
Secure the endpoints
Computers used for trust accounting and banking deserve extra care.
- Keep them patched and protected with endpoint detection
- Use dedicated browsers or profiles for banking
- Do not read personal email or browse casually on those machines
- Lock screens and restrict physical access
Malware that steals banking credentials or alters payment details is a long-standing fraud method, and a hardened workstation reduces the exposure.
Vendor due diligence
If the trust accounting platform is cloud-based, review the provider like any other vendor holding client information. Ask about encryption, MFA, audit logs, data export, uptime, and breach notification. Document the review.
Staff training
Train bookkeepers and assistants on current fraud patterns: spoofed partner requests, altered invoices, and urgent pressure at closing. Give them explicit authority to pause a payment and verify without fear of reprisal.
Cyber insurance considerations
Policies often treat funds-transfer fraud under a separate and lower sublimit, with conditions about verification procedures. Ask your broker how these conditions apply and keep records showing you followed them.
Review periodically
At least twice a year, review who has access to the trust system and bank portal, compare against current staff, and sample recent disbursements for proper approvals.
Where we come in
Counsel Cyber helps firms configure permissions, MFA, endpoint protection and backup for the systems that handle client funds. We are not accountants, so we pair our work with your bookkeeper or CPA. If you would like a controls review of your trust workflow from the IT side, we can help.