Catch the misdirected email before it leaves.
Send a client’s file to the wrong address and the firm may be reporting a notifiable data breach, first to the OAIC and then, worse, to the client. Email Risk Protection checks every outbound email against the client record and challenges the one that looks wrong before it goes.
A controls walkthrough for your compliance and IT teams.
Every check, on the record.
Every send checked, every challenge raised, every correction made. An override is recorded too, with the adviser’s reason attached. Alcova builds that record, and the firm can produce it when ASIC asks how email risk is managed.
Oversight of the control, not the adviser.
The risky send gets a second look.
The check raises the challenge when an email does not square with the client record: the recipient, the attachment, the account named. The adviser settles it, correcting the email or sending anyway with a reason. The call stays with the adviser.
The challenge as the adviser sees it, in Outlook, before the send leaves.
Hi Margaret Chen, confirming your rollover is underway. Your TFN 123 456 789, account 4471 0093 5520 and date of birth 04/09/1961 are on file. Paperwork for the Chen Family SMSF is attached.
- Name
- TFN
- Account number
- Date of birth
- SMSF
PII caught and flagged before the draft can leave.
Client data rarely leaves with a bang. It leaves by routine.
Misdirected email is one of the most common ways client data leaves a firm. It is rarely dramatic, and that is exactly what makes it hard to catch.
Autocomplete fills in a name that looks right and isn’t.
The email is fine, the file attached belongs to another client.
A reply carries an old conversation into a new one.
A firm-level breach figure is awaiting sign off.
Caught at send, not flagged next quarter.
Most data-loss tooling tells you a breach happened after the fact. By then the client data has already left the firm.
Told after the fact
The alert arrives in a report or a review, once the email has already gone. The data is out, and the work is forensic.
Stopped before it leaves
The check runs in the moment, before the message leaves Outlook. Advisers stay fast; compliance stays informed. Prevention, not a post-mortem.
It runs where the work already happens.
Advisers keep writing and sending in Outlook. The add-in runs the check at the point of send, reading the outbound email against the client record in Salesforce, Microsoft Dynamics or a system the firm built itself. That timing is the difference between a mistake stopped and a mistake reported after the fact.
- Outlook add-in, deployed across the adviser desktop.
- Your CRM, read for the client records already in it.
- A challenge at send, when an email does not square with the record.
Two connections, the check at send, the outcome. Not the mechanism.
It acts on the message in front of it.
The check reads two things: the outbound email and the client record. It does not sit in the mailbox reading old mail, and Alcova never trains AI on email content.
It leaves your CRM cleaner than it found it.
Checking an email means reading the client record behind it, and sometimes the record is the problem. A stale address, an old account, two entries for one client, all flagged for your ops team to put right. Each fix makes the CRM a little more accurate.
Email risk is one control. Operator runs the rest.
Operator, Alcova’s platform for the work behind advice, applies the same discipline to documents, records and file notes. How it works covers the email check itself. See Operator for the platform.
The questions a review asks first.
Does Alcova read all our email?
No. It checks each email as it is sent. It does not sit in your mailbox or scan your history; it acts on the message in front of it.
Does it slow advisers down?
No. The check runs in real time at the point of send. When a send is challenged, settling it takes a moment: correct the email, or send anyway with a reason.
Which systems does it work with?
A Microsoft Outlook add-in for email, and your CRM, whether that is Salesforce, Microsoft Dynamics, or an internal system, for client context.
Will advisers have to change how they work?
No. They keep working in Outlook as they do now. There is no new app, and nothing changes until a send needs a second look.
Where does our data go?
Your data stays in Australia, encrypted in transit and at rest, and email content is never used to train AI. More detail is on Security.
Is it certified?
SOC 2 Type II. The report is available through our Trust Centre.
See it run on your systems.
The walkthrough shows the check running in Outlook, against the CRM your firm already uses, and we take the hardest questions on the spot: the record, the overrides, where your data sits. Bring the people who will say no. If that is you, come and say no yourself.
Request a walkthrough →