Pre-Settlement Flash Audit for Perth Private Client Accountants: Verify Voice-Instruction Wire Transfers Before They Move
Your client is offshore. A voicemail lands on your office line, in their voice, authorising a same-day transfer from the family trust account to a new payee. The tone is right, the phrasing is right, even the small verbal tics are right. You have a window of hours, not days, to decide whether to act. The Pre-Settlement Flash Audit is a one-shot diagnostic that surfaces the indicators most often present on synthetic-voice instructions before funds leave the trust.
Why it matters now
Private client accountants holding authority over family trust disbursements, estate distributions, and SMSF transfers are an attractive target for synthetic-voice fraud: a single instruction can move six or seven figures, and the verification chain often relies on a phone call to a number associated with the principal. The Office of the Australian Information Commissioner administers the Privacy Act 1988 (Cth), which applies to accounting practices with annual turnover above $3 million and to many smaller practices that opt in or that handle health, tax file number, or credit information. Under the Notifiable Data Breaches scheme, an APP entity that suffers unauthorised access to or disclosure of personal information likely to result in serious harm must notify affected individuals and the OAIC. The Australian Cyber Security Centre has published guidance flagging deepfake audio and video as an emerging social-engineering vector, and Scamwatch tracks payment-redirection fraud against professional services as one of the highest-loss categories.
The 5-minute view
- The Privacy Act 1988 (Cth) regulates how APP entities — including accounting practices above the $3M turnover threshold and many below it — handle personal information, with 13 Australian Privacy Principles administered by the OAIC
- The Notifiable Data Breaches scheme requires APP entities to notify the OAIC and affected individuals of eligible data breaches likely to result in serious harm
- Synthetic-voice (deepfake audio) instructions are a recognised emerging social-engineering vector; the Australian Cyber Security Centre publishes general threat guidance at https://www.cyber.gov.au/
- Common indicators on synthetic-voice instructions include: caller-ID spoofing or unusual inbound routing, instruction urgency framed around an unreachable principal, payee details that diverge from prior history, and refusal or inability to switch to a known video channel for re-verification
- A flash audit checks the structural risk on a specific transaction: the call metadata, the principal’s prior instruction pattern with your firm, the payee’s history on the file, and whether the instruction matches known synthetic-voice fraud signatures
- Out-of-band verification on a previously-recorded number — not the number that placed the call — is the single most effective control available to a private client accountant under time pressure
What DRMO does about it
The Pre-Settlement Flash Audit is a single-transaction diagnostic delivered against one trust or estate disbursement file. You submit the file reference, the recording or transcript of the voice instruction, the payee details, and the prior instruction history with that principal. We run a fixed-scope review covering: inbound call metadata (where available from your telephony provider), acoustic indicators consistent with published synthetic-voice signatures, the principal’s prior instruction pattern with your firm (frequency, channel, payee history), and the instruction’s alignment with the principal’s documented authority on the file. The deliverable is a 15-page PDF audit report identifying the specific indicators present and the recommended verification steps before funds release.
This is the Pre-Settlement Flash Audit (L2 service shape) from the DRMO service catalogue, productised for single-transaction use without requiring a discovery call.
The deliverable
- 15-page PDF audit report scoped to one disbursement file
- Executive summary with a Red / Amber / Green status and the recommended next action
- Per-indicator review with the underlying evidence cited (call metadata, acoustic markers, payee history)
- Verification checklist for your trust accounting team to complete before funds release, including the out-of-band call-back protocol
- Privacy Act considerations summary: notes on whether the incident, if confirmed, would meet the threshold for the OAIC’s Notifiable Data Breaches scheme
- Delivered via email within 1 business day of file submission and payment
CTA
Run the Pre-Settlement Flash Audit — AUD $499
A single-transaction productised offer. No discovery call required. Suitable for any trust, estate, or SMSF disbursement file where a payment instruction has been received by voice — recorded message, live call, or voicemail — from a principal who cannot be re-verified in person on the same day.
This door provides operational support for Privacy Act obligations; it does not provide legal advice.
Sources
- Office of the Australian Information Commissioner — The Privacy Act: https://www.oaic.gov.au/privacy/the-privacy-act
- Australian Cyber Security Centre — general threat guidance: https://www.cyber.gov.au/
- Australian Competition and Consumer Commission — Scamwatch: https://www.scamwatch.gov.au/
DRMO capability references:
- Pre-Settlement Flash Audit (L2 service shape, single-transaction productised offer)