Can a North Carolina law firm use online banking to manage its client trust account given the duty to safeguard client funds?
Apply this to your situation
This page answers the general question as of 2012. Ezel answers yours: whether it's allowed on your facts, under the current North Carolina Rules of Professional Conduct, with citations.
Plain-English summary
The inquiry asks whether, given the duty to safeguard client funds, a firm may use online banking, which allows transfers, third-party payments, wire transfers, and statement and check-image access over a bank's secure website, to manage a trust account, despite the risk of theft by hackers. The opinion answers yes, conditioned on meeting the firm's fiduciary and recordkeeping duties. Rule 1.15 requires a lawyer to preserve client property, deposit client funds in a separate trust account, and manage that account under strict recordkeeping and procedural requirements; the rule is silent about online banking, but does not forbid it.
The recordkeeping requirements are in Rule 1.15-3. The opinion quotes Rule 1.15-3(b)(3), which requires the lawyer to keep records of all instructions or authorizations to transfer, disburse, or withdraw trust funds, including electronic transfers and debits, showing the amount, date, and recipient, and, for a general trust account, the client or person to whom the funds belong. If the online-banking software does not create an official bank record of that required information when money is transferred out of the trust account, the lawyer must handle such transfers by a method that does produce the required records.
To meet the fiduciary obligations, the opinion requires reasonable care to minimize risk: the lawyer must stay educated about the dynamic risks of online banking and ensure the firm invests in proper protection and multiple layers of security. It describes affirmative duties, including regular self-education on security risks; active end-user security through strong password policies, encryption, and security software, and the use of an information-technology consultant; and training of all staff who help manage the trust account. The opinion deliberately sets no specific mandatory security measures, reasoning that fixed requirements would create a false sense of security in a changing environment; instead it requires due diligence and frequent education, applying the same diligence and competence the lawyer owes clients. It draws on [Proposed] 2011 FEO 6, RPC 209, and 98 FEO 15.
In practice
Under the North Carolina rules as they stood at the time of the opinion, conduct in which a firm manages a trust account through online banking is permitted if the Rule 1.15 fiduciary duties and the Rule 1.15-3 recordkeeping requirements are met and the lawyer exercises reasonable care against loss or theft. Per the opinion, when the banking software will not generate an official record of a transfer's amount, date, and recipient, the lawyer must use another method that captures those records.
Per the opinion, the duty of reasonable care is ongoing rather than a one-time setup: the lawyer must stay educated about evolving online-banking risks and maintain layered end-user security, and must train staff who assist with the account. The opinion declines to prescribe specific security measures, requiring due diligence and regular education instead.
Common questions
Q: Can a law firm use online banking for its client trust account?
A: Yes. The opinion concludes online banking may be used to manage a trust account provided the Rule 1.15 fiduciary and recordkeeping obligations can be fulfilled and the lawyer uses reasonable care to minimize the risk of loss or theft.
Q: What records must the firm keep for electronic transfers out of the trust account?
A: Per Rule 1.15-3(b)(3), the lawyer must keep records of all authorizations to transfer, disburse, or withdraw trust funds, including electronic transfers and debits, showing the amount, date, and recipient (and the client or owner for a general trust account); if the software will not make that official record, the transfer must be handled another way that does.
Q: Does the opinion set specific security requirements?
A: No. The opinion declines to set mandatory security measures, reasoning they would create a false sense of security where risks change continually, and instead requires due diligence and frequent, regular education.
Q: What ongoing steps does a lawyer have to take?
A: The opinion lists affirmative duties: regular self-education on online-banking security risks; active end-user security such as strong passwords, encryption, security software, and using an IT consultant; and training staff who help manage the trust account in the firm's security measures.
Background and rules framework
The opinion applies North Carolina Rule 1.15 (safekeeping property, the analogue of Model Rule 1.15) and its detailed recordkeeping subpart, Rule 1.15-3, particularly Rule 1.15-3(b)(3) on records of trust-account transfers. It connects the analysis to the firm's general fiduciary duty to safeguard client property and to prior North Carolina authority, including [Proposed] 2011 FEO 6 (technology and client data), RPC 209 (fiduciary duty to safeguard client property), and 98 FEO 15 (due care in selecting a depository bank).
Citations and references
Rules of Professional Conduct:
- MR 1.15 / NC Rule 1.15, Rule 1.15-3, Rule 1.15-3(b)(3) (safekeeping property; trust-account recordkeeping; records of transfers)
Other opinions cited:
- NC [Proposed] 2011 FEO 6: duties of confidentiality and preservation of client property when using internet-based technology.
- NC RPC 209: general fiduciary duty to safeguard client property.
- NC 98 FEO 15: due care in selecting a depository bank for a trust account.
See also
- NC State Bar 2011 FEO 6: Cloud Software (SaaS)
- SC Bar Ethics Op. 25-01: Trust Debits via Pay.gov
- NY State Bar Op. 758: Electronic Trust Records
Source
- Landing page: https://www.ncbar.gov/for-lawyers/ethics-and-governing-rules/ethics-opinions/opinions/2011-formal-ethics-opinion-7/
Original opinion text
Reproduced from the official source for research purposes. The linked source is authoritative.
Inquiry:
Most banks and savings and loans provide “online banking” which allows customers to access accounts and conduct financial transactions over the internet on a secure website operated by the bank or savings and loan. Transactions that may be conducted via on-line banking include account-to-account transfers, payments to third parties, wire transfers, and applications for loans and new accounts. Online banking permits users to view recent transactions and view and/or download cleared check images and bank statements. Additional services may include account management software.
Financial transactions conducted over the internet are subject to the risk of theft by hackers and other computer criminals. Given the duty to safeguard client property, particularly the funds that a client deposits in a lawyer’s trust account, may a law firm use online banking to manage a trust account?
Opinion:
Yes, provided the lawyers use reasonable care to minimize the risk of loss or theft of client property specifically including the regular education of the firm’s managing lawyers on the ever-changing security risks of online banking and the active maintenance of end-user security.
As noted in [Proposed] 2011 FEO 6, Subscribing to Software as a Service While Fulfilling the Duties of Confidentiality and Preservation of Client Property, the use of the internet to transmit and store client data (or, in this instance, data about client property) presents significant challenges. In this complex and technical environment, a lawyer must be able to fulfill the fiduciary obligations to protect confidential client information and property from risk of disclosure and loss. The lawyer must protect against security weaknesses unique to the internet, particularly “end-user” vulnerabilities found in the lawyer’s own law office. The lawyer must also engage in frequent and regular education about the security risks presented by the internet.
Rule 1.15 requires a lawyer to preserve client property, to deposit client funds entrusted to the lawyer in a separate trust account, and to manage that trust account according to strict recordkeeping and procedural requirements. See also RPC 209 (noting the “general fiduciary duty to safeguard the property of a client”) and 98 FEO 15 (requiring a lawyer to exercise “due care” when selecting depository bank for trust account). The rule is silent, however, about online banking.
Nevertheless, online banking may be used to manage a client trust account if the recordkeeping and fiduciary obligations in Rule 1.15 can be fulfilled. The recordkeeping requirements for trust accounts are set forth in Rule 1.15-3. Rule 1.15-3(b)(3) specifically requires a lawyer to maintain the following records relative to the transfer of funds from the trust account:
all instructions or authorizations to transfer, disburse, or withdraw funds from the trust account (including electronic transfers or debits), or a written or electronic record of any such transfer, disbursement, or withdrawal showing the amount, date, and recipient of the transfer or disbursement, and, in the case of a general trust account, also showing the name of the client or other person to whom the funds belong;
If the online banking software does not provide a method for making an official bank record of the required information when money is transferred from the trust account to another account, such transfers must be handled by a method that provides the required records.
To fulfill the fiduciary obligations in Rule 1.15, a lawyer managing a trust account must use reasonable care to minimize the risks to client funds on deposit in the trust account by remaining educated as to the dynamic risks involved in online banking and insuring that the law firm invests in proper protection and multiple layers of security to address those risks. See [Proposed] 2011 FEO 6.
A lawyer who is managing a trust account has affirmative duties to regularly educate himself as to the security risks of online banking; to actively maintain end-user security at the law firm through safety practices such as strong password policies and procedures, the use of encryption, and security software, and the hiring of an information technology consultant to advise the lawyer or firm employees; and to insure that all staff members who assist with the management of the trust account receive training on and abide by the security measures adopted by the firm. Understanding the contract with the depository bank and the use of the resources and expertise available from the bank are good first steps toward fulfilling the lawyer’s fiduciary obligations.
This opinion does not set forth specific security requirements because mandatory security measures would create a false sense of security in an environment where the risks are continually changing. Instead, due diligence and frequent and regular education are required. A lawyer must fulfill his fiduciary obligation to safeguard client funds by applying the same diligence and competency to manage the risks of on-line banking that a lawyer is required to apply when representing clients.
Get today's answer for your situation
You just read a 2012 opinion on this question. Ezel checks the current North Carolina Rules of Professional Conduct and answers your specific situation, with citations.
Opens in Ezel Pro. Every answer cites the rules it relies on.