A story we hear too often
The Thursday a client asked her adviser to move $400,000, except she had not
the founder of a 12-person registered investment adviser
Elena has run the firm on LaSalle Street for eleven years. Twelve people, 340 households, a custodian relationship she has never had to apologize to. Thursday afternoons she reviews the money-movement queue before the operations lead sends it.
There is a request from a client Elena has known for twenty years: $400,000 to a new account at a bank in another state, ‘for the closing on the lake house.’ The email is from the client’s real address. The tone is right. The lake house is real; they talked about it in April.
This is the moment. In the version the SEC writes up, the operations lead sends it, the custodian releases it, the client calls Monday asking about a balance, and the firm learns that her email had been read for two months by someone who knew about the lake house because she did.
In Elena’s version, the firm’s rule is that any new account gets a phone call to the client on the number on file, no exceptions, and the operations lead makes it. The client is at the dentist. She never sent it. The custodian flags the receiving account that afternoon, and Elena’s incident response program, the one Reg S-P now requires, gets its first real entry.
The email is from the client’s real address, the tone is right, and the lake house is real.
What changes the ending
- A call-back rule for every new account or changed instruction, written into the money-movement procedure (CIS Control 14, Security Awareness and Skills Training, and 17, Incident Response)
- MFA and login monitoring on every adviser and operations mailbox, with forwarding rules watched (CIS Controls 5 and 9)
- A written incident response program that names who calls the custodian, the client and, within 30 days, the affected individuals (CIS Control 17 and SEC Regulation S-P)