ABA Model Rule 1.6 aligned24/7 security operations monitoringAustin, TX ยท Serving TX, AR, LA, OK & KS
(737) 325-2520

Trust Accounting Software and IT Controls: Protecting Client Funds

Client trust funds are among a firm's most sensitive assets. Learn which access, approval, backup and monitoring controls support trust accounting software.

3 min readBy Counsel Cyber Team

Client trust accounting is one of the most heavily scrutinized parts of a law practice, and one of the most attractive targets for fraudsters. The rules on safeguarding client funds come from your state bar and vary in detail, so confirm requirements with your bar's guidance and your accountant. What is consistent across states is that careless handling can lead to discipline, and a technology failure or a fraudulent transfer is no defense on its own.

Whether your firm uses a practice-management platform with built-in trust accounting or a separate accounting package, a few IT controls make the system harder to misuse or attack.

Control who can do what

Role-based permissions

Define roles in the software and assign the minimum permissions required.

  • Who can view trust balances?
  • Who can enter deposits?
  • Who can prepare disbursements?
  • Who can approve disbursements?
  • Who can edit or delete entries?
  • Who can reconcile?

Separate preparation from approval so that no single person can both create and release a payment. In a very small firm where that is hard, add a compensating control, such as a partner reviewing a weekly report of all trust activity.

Unique accounts and strong sign-in

Everyone should use a named account with MFA. Avoid shared logins to the trust system or the bank portal, since shared access eliminates accountability.

Bank portal protections

  • Dual authorization for wires and ACH payments above defined thresholds
  • Positive pay or similar services if your bank offers them
  • Alerts for new payees, changed instructions, and large transactions
  • Restrict portal access to specific devices or networks where possible

Protect the process against fraud

Real estate closings, settlements, and estate distributions all involve large payments based on instructions that arrive by email. Combine software controls with procedures.

  1. Call-back verification for every new or changed payment instruction, using a trusted number.
  2. Second approval for disbursements over a threshold.
  3. Documented verification attached to the disbursement record.
  4. Blocked payment requests by email from partners or staff without confirmation.
  5. Client notice in engagement letters that wire instructions will never change by email.

Audit trails

Make sure the software logs who created, edited, approved, and deleted records, and that logs cannot be modified by regular users. Review exceptions regularly, such as back-dated entries, deleted transactions, and edits after reconciliation. These logs also help in a dispute or investigation.

Reconciliation support

Many state rules require regular reconciliation, often described as three-way: the bank statement, the firm's trust ledger, and the individual client ledgers. Check your state's requirements. Use software features that support this, and keep records of completed reconciliations, who prepared them, and who reviewed them.

Backups and availability

Trust records must be accurate and retrievable. Ensure that:

  • The accounting data is backed up automatically and at least one copy is stored separately from your main network
  • You can restore it and have tested doing so
  • Retention meets your state's recordkeeping requirement, which commonly spans a number of years. Verify the period with your bar
  • Cloud-hosted systems have documented export options

Secure the endpoints

Computers used for trust accounting and banking deserve extra care.

  • Keep them patched and protected with endpoint detection
  • Use dedicated browsers or profiles for banking
  • Do not read personal email or browse casually on those machines
  • Lock screens and restrict physical access

Malware that steals banking credentials or alters payment details is a long-standing fraud method, and a hardened workstation reduces the exposure.

Vendor due diligence

If the trust accounting platform is cloud-based, review the provider like any other vendor holding client information. Ask about encryption, MFA, audit logs, data export, uptime, and breach notification. Document the review.

Staff training

Train bookkeepers and assistants on current fraud patterns: spoofed partner requests, altered invoices, and urgent pressure at closing. Give them explicit authority to pause a payment and verify without fear of reprisal.

Cyber insurance considerations

Policies often treat funds-transfer fraud under a separate and lower sublimit, with conditions about verification procedures. Ask your broker how these conditions apply and keep records showing you followed them.

Review periodically

At least twice a year, review who has access to the trust system and bank portal, compare against current staff, and sample recent disbursements for proper approvals.

Where we come in

Counsel Cyber helps firms configure permissions, MFA, endpoint protection and backup for the systems that handle client funds. We are not accountants, so we pair our work with your bookkeeper or CPA. If you would like a controls review of your trust workflow from the IT side, we can help.