The letter of authorization: how client money leaves a custodian on a scanned signature
Somewhere between an adviser's instruction and a custodian's execution there is supposed to be a client. In the standing letter of authorization model, the client's participation happened once, on paper, possibly years ago, and every transfer since has inherited it.
How does client money leave a custodian?
On a letter of authorization — frequently a scanned signature on a PDF, checked against a signature card. A tri-party arrangement means the adviser instructs, the custodian executes and the client is absent from the transaction that moves their money.
- Custody rules focus on who holds assets and how they are safeguarded. Instruction authenticity is handled by forms and signature comparison — a control designed for wet ink.
- Three parties have a stake in one fact and none can verify it independently.
- A tri-party receipt removes the callback from the critical path rather than trying to make callbacks more reliable.
Part of Private capital and fund identity
The arrangement, and why it exists
An adviser cannot generally move client money to a third party without triggering custody obligations. The standing letter of authorization exists to make that workable: the client signs a form authorising transfers to a specified third party, and the adviser instructs the custodian against it.
There is nothing improper about this. It is a documented arrangement operating within a recognised framework, and it exists because clients genuinely want their advisers to handle recurring transfers without a fresh signature every quarter.
The design assumption is that the form establishes the client's intent, and that subsequent instructions are administrative execution of that intent. The assumption holds until the adviser's email is compromised.
Three parties, one unverifiable fact
| Party | What they know | What they cannot establish |
|---|---|---|
| Client | That they signed a form, once | That this transfer is one they wanted |
| Adviser | That they received an instruction | That it came from the client |
| Custodian | That the adviser instructed them | Anything about the client's involvement |
The custodian is in the weakest position and carries significant operational exposure. They execute against an adviser instruction and a form on file, with no relationship to the underlying instruction at all.
Why signature comparison is not a control
Custodians compare signatures on disbursement forms against specimens on file. That control was designed for an era of wet-ink instruments delivered physically.
Against a scanned signature lifted from any document the client has ever signed — a tax form, a prior instruction, a contract — it detects nothing. Against a signature reproduced from a public filing, it detects nothing. The comparison is performed by staff processing volume, not by document examiners.
The callback loop, again
The standard compensating control is a callback to the client. Where the adviser's email is compromised and the attacker has the client's contact details from the same inbox, the callback reaches whoever the attacker arranged.
Where the callback uses a number from the custodian's own records, it is stronger — and it is also the reason disbursements take days, which is the friction clients complain about.
The tri-party receipt
Restructure the flow so the client's participation is per-instruction rather than per-arrangement.
- The client enrols a credential once, at account opening, alongside the existing paperwork.
- For each disbursement, the client signs a canonical statement rendering the full amount, the full destination account and routing details, and the date.
- The adviser transmits the instruction with the receipt attached.
- The custodian verifies the signature offline against a published key before executing.
- All three parties retain the receipt.
The callback disappears from the critical path, which means disbursements get faster, not slower. That is the argument that gets this adopted — clients experience an improvement, not a new hurdle.
The adoption problem, named
Custodians must accept an external artefact, and custodians move slowly for good reasons. An adviser cannot unilaterally change what a custodian will act on.
The realistic path is that advisers implement it as an internal control first — client-signed instructions retained by the adviser, verifiable by the examiner — while the custodian continues its existing process. That already answers the examination question and the internal governance question. Custodian integration follows when enough advisers hold the artefact.
What an examiner sees
Under the SEC's 2026 attention to fraudulent transfers, an adviser able to produce a client-signed instruction per disbursement is in a different position from one producing a form from 2021 and a callback log.
That is worth stating plainly to a principal who is weighing the implementation effort: the control and the examination answer are the same artefact.
Why signature comparison is the weakest link
| Step | Reality |
|---|---|
| Compare to the signature card | A human comparing two images |
| Confirm the adviser's authority | Against a standing authorisation |
| Check the destination | Sometimes; frequently third-party destinations are permitted |
| Contact the client | Rarely, and by a number on file |
Objections and honest limits
“Advisers have discretionary authority.” Over investment decisions. Moving cash to a third-party destination is a different act, and treating both as covered by one standing authorisation is where the loss sits.
“We call the client on large disbursements.” Which helps if the number predates the request, and if the caller can be authenticated — neither of which a voice call now establishes.
Putting the client back in the flow
- Separate cash movement from investment discretion. Two different authorities, two different bars.
- Require the client's signature on third-party destinations. The case where loss concentrates.
- Render the destination in full. Not a masked account on a PDF.
- Hold first disbursements to a new destination. A short delay, and the only thing that makes recovery possible.
Terms used here
- Letter of authorization
- A client instruction permitting a disbursement, commonly presented as a PDF with a scanned signature.
- Signature card
- The specimen signature a custodian compares an instruction against.
- Third-party disbursement
- Payment to an account not in the client's name — the highest-risk category and often permitted by standing authority.
Frequently asked questions
Does this require the custodian to change anything? Not initially. An adviser can implement it as an internal control and retain the receipts. Custodian verification is the stronger end state and requires their participation.
What about recurring transfers the client has already authorised? Those can run under a standing signed delegation with a ceiling and an expiry, rather than an open-ended form. Anything outside the delegation requires a fresh signature.
Will clients tolerate signing each disbursement? It replaces a callback they currently field. Firms that have piloted this report clients prefer the gesture to the phone call.
Does this satisfy the custody rule? The custody rule addresses possession and control of assets, not instruction authenticity. This does not change a firm's custody status and no artefact does.
Isn't discretionary authority enough? It covers investment decisions. Moving cash to a third-party account is a different act, and conflating the two is where losses occur.
Why is signature comparison weak? It is a human comparing two images, against a specimen an attacker can obtain from any prior signed document.
What is the highest-risk disbursement? One to an account not in the client's name. That is where a client signature should be mandatory.
Where this fits in Manav
Manav binds the authorising individual to the exact instruction being given — the amount, the destination and the entity — and produces a receipt an administrator, a custodian or an LP can verify without calling the issuer.
Sources and further reading
- SEC — Custody of funds or securities of clients (Rule 206(4)-2)
- SEC Division of Examinations priorities
- Custodian third-party disbursement procedures and signature verification practice.
- FBI IC3 2025 Internet Crime Report
- ILPA — industry guidance and model documents