Could your systems survive cross-examination?
Exhibit A is your inbox.
·25 August 2026·About 5 minutes
“So there is a copy in the matter file.”
“Yes.”
“And the email it arrived in?”
This examination never happened. There is no proceeding, no complaint, and nothing here is a prediction about any firm. The room is invented. The questions are not. They are what a practice gets asked eventually, by a client, an insurer, a regulator, or a partner in a corridor who has just read something.
So: a principal is in the chair. The subject is not the matter. The subject is what the firm did with a client's identity documents, and the examiner is unhurried and faintly bored, which is the worst kind.
Three questions get asked. None of them is difficult, and none of them is about whether the firm did anything wrong. What makes them hard is that the answers are not in anybody's head. They are in a mail system, a folder structure and a set of permissions. And the uncomfortable part is not that something has been lost. Nothing has been lost. It is the pause.
The first question: where is it?
"Your firm verified Ms Brennan's identity in 2019."
"We did."
"How?"
"She sent a photograph of her driver's licence."
"Sent it where?"
"To the office."
"To a person, or to an address?"
"To our general enquiries address. Whoever was on it that morning would have forwarded it to the person doing the onboarding."
"And that person did what?"
"Saved it to the matter."
"So there is a copy in the matter file."
"Yes."
"And the email it arrived in?"
There is a pause here. There is always a pause here. The pause is not evasion, and everyone in the room knows it. It is a principal doing arithmetic in their head, in public, about a mail system they have never once had cause to think about.
Because the email is still there. It is in the general enquiries mailbox. It is in the sent items of whoever forwarded it. It is in the inbox of whoever received it, and if that person left in 2022, it may be in an archive that was kept in case anyone needed anything, which nobody has, and which nobody has looked at since.
Exhibit A is your inbox. Exhibit B is the folder the office copier saves its scans to. Nobody has opened it in six years. Every scan since has gone into it anyway.
The second question: who can reach it?
"Who at your firm can open the folder where the matter file sits?"
"The legal team."
"Which people?"
"The solicitors, the paralegals. Support staff, for filing."
"By name?"
"I would have to check."
"Does anyone who has left the firm still appear on that list?"
"No."
"You have checked?"
"...We would have removed them."
There is a difference between we removed them and we would have removed them, and everybody in the profession can hear it. "Everyone" is not a list. It is the word people use when there is not one.
The third question: what removes it?
"Ms Brennan has not instructed your firm since 2019."
"No."
"Her licence is still in your system."
"Presumably."
"What removes it?"
"Eventually, someone would."
"Is that person named anywhere? Is there a date?"
Nothing about that exchange requires bad faith, bad practice or a bad firm. It requires only a system that was built to keep things, by people who were right to want it to, and which was never told when to delete anything.
A court has already asked a version of this
Leave the imagined room for a moment, because there is a real judgment worth reading.
In May 2022, in ASIC v RI Advice Group Pty Ltd [2022] FCA 496, Justice Rofe of the Federal Court declared that RI Advice had contravened its obligations by failing to have documentation and controls for cyber security and cyber resilience "in place that were adequate to manage risk". Among the incidents before the court: unauthorised access to an authorised representative's file server over about three and a half months, resulting in the potential compromise of the personal information of several thousand clients, and an unauthorised person using an employee's email account to send phishing emails to over 150 clients.
Her Honour put the standard in a sentence worth keeping.
“It is not possible to reduce cybersecurity risk to zero, but it is possible to materially reduce cybersecurity risk through adequate cybersecurity documentation and controls to an acceptable level.”
— Justice Rofe, ASIC v RI Advice Group Pty Ltd [2022] FCA 496
Three things about that case matter. It was decided on agreed facts, so nobody was cross-examined about anything. RI Advice is a financial services licensee, and the provisions engaged were the licence obligations in sections 912A(1)(a) and 912A(1)(h) of the Corporations Act, which do not apply to legal practice. And a declaration is not a finding about anybody else.
The point is not that the case applies to law firms. It doesn't. The point is that an Australian court has now been asked whether an organisation's arrangements for protecting client information were adequate, has examined that question on the evidence, and has answered it. The question exists now. It has a shape, and somebody has argued it.
What the answers sound like from a practice that has checked
They are short. That is the clear sign.
Where is it. "In one place, and I can show you the list."
Who can reach it. "Four people. Here they are. Access ends the day someone leaves, and it is a documented step, not a favour."
What removes it. "A rule that runs on its own. Nobody has to remember."
None of those answers require a bigger firm or a bigger budget. They require somebody to have asked the question once, with nothing at stake.
That is the work we do at efex. Setting up who can reach what, keeping a record of who opened it, and keeping the systems that hold it configured to keep people out and monitored for the times somebody tries to get in, so the question never arrives the hard way.
Ask yourself the three questions first
They are not invented for this article. They are three of the thirteen in our AML/CTF technology and data checklist: whether you could find every copy of a client's identity documents if asked today, how quickly access ends when someone leaves, and what removes a licence scan when it must be removed.
The checklist takes about three minutes to complete. Every question is multiple choice, nothing is uploaded, and no client file is opened. "I am not sure" is a real answer and it reports back as not yet verified rather than as a failure, which is worth knowing before you start.
The examination in this article is imaginary. The three questions are not.
Take the checklist here.
Or read what applies to legal practices: it.efex.com.au/aml-ctf/legal.
Thirteen questions. About three minutes. No client files.
Or talk it through first. Thirty minutes, no obligation, with somebody who does this work every day.
These articles explain what the regulators have published and what it commonly means in practice. General information only, not legal or compliance advice.
