Trust Account Audits

State Bar Defense Attorneys Trust Account Audits
Trust Audits (California) | State Bar Investigations Defense | East Bay Law P.C.
California State Bar Investigations Defense

Trust Audits

When the State Bar audits your client trust account (IOLTA), every transaction, ledger, and reconciliation is in play. This page explains why audits happen, what records you must produce, common charging theories, defense themes, and mitigation strategies under California’s trust accounting rules and CTAPP.

Talk to counsel early →

Overview

A trust audit is a targeted review of your compliance with CRPC 1.15 and California’s Client Trust Account Protection Program (CTAPP). Audits may be complaint-driven, triggered by a bank overdraft notice, or arise during a broader disciplinary investigation. The Office of Chief Trial Counsel (OCTC) will typically demand bank statements, canceled checks, deposit slips, client ledgers, monthly three-way reconciliations, fee agreements, billing statements, and any internal policies showing how you safeguard client funds.

Audits focus on systems as much as numbers. Even if no client loses money, commingling, delayed deposits, negative client balances, and the lack of monthly three-way reconciliations can support charges. On the other hand, a lawyer who promptly identifies and corrects an error, documents restitution, and demonstrates robust controls can often resolve matters with reduced discipline.

Key idea: Trust audits are about controls. Written procedures, segregation of duties, and timely reconciliations are your first line of defense — and your strongest mitigation if issues surface.

Key Authorities (California)

  • CRPC 1.15 — Safekeeping Funds: deposits, disbursements, records, monthly three-way reconciliations, and prohibition on commingling.
  • CTAPP — Annual self-assessment, education, and recordkeeping requirements for client trust accounts (IOLTA and non-IOLTA).
  • Bus. & Prof. Code § 6091 — Production/inspection of trust records in connection with a complaint or investigation.
  • Bus. & Prof. Code § 6091.5 — Financial institutions report trust account insufficient-funds activity (overdraft notices) to the State Bar.
  • CRPC 1.4 — Client communication duties when errors or delays affect funds.
  • CRPC 5.3 — Supervision of nonlawyer staff involved with banking and bookkeeping.
  • Bus. & Prof. Code § 6106 — Moral turpitude (charged when there is concealment, falsified ledgers, or knowing misappropriation).
The precise citations on your notice will vary, but these are the pillars of California trust-account compliance and audit authority.

What Is a Trust Audit?

A trust audit is an official request to verify that your handling of client funds matches the Rules. Auditors compare bank activity to your internal books to confirm each dollar is traceable to a client matter and no funds are disbursed without collected funds, earned fees, or written client authorization where required.

Expect the auditor to test sample months (often three consecutive months) and then expand if exceptions appear. A clean three-way reconciliation — bank statement balance, book balance, and sum of client ledgers — is the core proof of compliance under CRPC 1.15.

Why Audits Are Triggered

  • Overdraft alert: Your bank reported an insufficient-funds event on an IOLTA account B&P § 6091.5.
  • Complaint-driven: A client or third party alleges delayed payment, unreturned funds, or unaccounted retainers CRPC 1.15.
  • Referral from other matters: During a separate investigation, OCTC spots red flags in your accounting.
  • Random/CTAPP-related: Compliance sampling based on CTAPP declarations or risk signals.
Important: An overdraft notice does not automatically mean misappropriation — but it guarantees scrutiny. Document the cause and your corrective steps immediately.

Records You’ll Be Asked For

  • Monthly bank statements for all trust accounts (IOLTA and non-IOLTA).
  • Canceled checks (front/back), wire advices, ACH confirmations, deposit slips, and check images.
  • Client-by-client subsidiary ledgers showing every receipt and disbursement.
  • Cash receipts/disbursements journals (books) for the trust account.
  • Monthly three-way reconciliations signed and dated by the reviewing attorney CRPC 1.15.
  • Fee agreements, invoices, settlement statements, and written client consents for costs/fees withdrawals.
  • Policies and procedures for deposits, approvals, and transfers; role descriptions for staff CRPC 5.3.
  • Proof of CTAPP self-assessment completion and any training records.
Pro tip: Name files systematically (e.g., 2025-03 BankStmt.pdf, 2025-03 Reconciliation.pdf, Client-Smith Ledger.csv) so your package is easy to verify.

Audit Process & Timeline

  1. Notice & preservation: You receive a records demand with a response deadline. Freeze shredding and ensure data holds on banking portals and practice software.
  2. Initial production: Provide the requested period (often 3–6 months). If you lack a document, say so and give an expected date — then fix the gap.
  3. Sampling & expansion: If exceptions appear, expect follow-up for adjacent months or specific clients.
  4. Interviews: Bookkeeper/staff may be asked about workflows. Supervisory duties are assessed CRPC 5.3.
  5. Findings: Outcomes range from no action to a Notice of Disciplinary Charges, depending on severity, intent, and remediation.

Common Charges & Theories

  • CRPC 1.15(a), (d): Commingling; failure to promptly deposit/withdraw; failure to maintain records and reconciliations.
  • CRPC 1.15(c): Disbursements without collected funds or adequate documentation.
  • CRPC 1.15(f): Failure to promptly distribute funds to clients/third parties.
  • CRPC 5.3: Inadequate supervision of staff handling deposits, checks, or ledgers.
  • CRPC 1.4: Failure to inform clients of material issues affecting funds.
  • Bus. & Prof. Code § 6106: Moral turpitude (knowing misappropriation, falsified records, concealment).

Defense Themes & Mitigation

Frame the case around reasonableness and remediation

  • Systems existed: Written procedures, segregation of duties, and monthly three-way reconciliations were in place CRPC 1.15.
  • Isolated error, not intent: The issue was a one-off posting or timing error; no client loss; immediate correction and documentation.
  • Prompt restitution: Any shortage was repaid immediately from the lawyer’s funds; affected clients notified CRPC 1.4.
  • Independent review: Outside CPA or consultant performed a retrospective reconciliation and validated current controls.
  • Enhanced controls: Implemented dual approvals, limited access, immutable audit trails, and monthly sign-offs.
  • Training & supervision: Bookkeeper and staff retrained; responsibilities clarified; periodic spot checks scheduled CRPC 5.3.
Mitigation package checklist: Timeline of events; bank proof; before/after policies; reconciliations; restitution proof; client notices; vendor NDAs; CPA letter.

Controls That Impress Auditors

  • Dual control: No single person can create, approve, and execute a disbursement.
  • Least-privilege access: Data-entry staff have view-only banking and cannot issue wires or checks.
  • Three-way reconciliation: Completed monthly, reviewed by the attorney, signed and dated.
  • Client-level ledgers: Never allow negative balances; investigate anomalies immediately.
  • Deposits: Daily batching with scanned deposit slips tied to matter numbers.
  • Disbursements: Written client authorization or earned-fees documentation for every withdrawal.
  • Change management: Any new software or bank tool is documented, tested, and approved.
One-page “Controls Map”: List each workflow (deposits, transfers, reconciliations, settlements), the control owner, the reviewer, and frequency. Auditors love this.
CTAPP alignment: Keep proof of your annual self-assessment and any education completed; it supports your culture of compliance.

FAQs

Do I have to produce operating-account records too?

Often yes, if they relate to transfers to/from trust or to show fee-earned status. Produce what the notice requests and confer about scope if overbroad.

Is an overdraft notice a discipline case?

It’s a signal, not a conclusion. Provide a documented explanation, reconciliations, and proof of correction to limit exposure.

Can my bookkeeper handle reconciliations alone?

They can prepare them, but an attorney should review and sign monthly. Avoid having one person prepare, approve, and disburse.

What if I’m missing months of reconciliations?

Reconstruct with bank data and ledgers, retain a CPA if needed, and produce the rebuilt reconciliations with a clear timeline of corrective actions.

Facing a Trust Audit? We Can Help.

We defend California attorneys in trust-account investigations and audits. Our approach is practical: reconstruct records fast, demonstrate controls, and present a mitigation package that shows compliance under CRPC 1.15 and CTAPP.

Schedule a confidential consultation

East Bay Law P.C.
2719 Encinal Ave, Suite C, Alameda, CA
P: 510-200-8190    F: 510-263-5819

© East Bay Law P.C. • Educational information for California attorneys under investigation; not legal advice.