Digital settlement

Cyber security duties of firms and lenders on a settlement network

What rule 7 of the national participation rules asks of every law practice and lender using a settlement network: training, certificates, access, and what to do when something is compromised.

· 18 min read

Kooky
Written by
Kooky

Builder of Shaka, the payment router that pays every agent their commission on closing date.

About Kooky and Shaka →

Every Queensland property transfer handled by a professional passes through a law practice's computers and, usually, a lender's. The settlement network itself is run by an operator, but the people who log in, prepare the documents and sign them work in ordinary offices, on ordinary machines, with ordinary email. The rules that govern electronic conveyancing accept this, and so they place a set of security duties on the users of a network as well as on its operator.

Those duties sit in rule 7 of the Model Participation Rules, the rule book the Australian Registrars' National Electronic Conveyancing Council (ARNECC) writes for the organisations that use a network, which it calls subscribers. ARNECC explains the rule in its Guidance Note 8, "System Security and Integrity", updated in August 2024. This guide sets out what the rule and the guidance say, in the order a firm or a lender would meet them: who may log in, how they are trained, how signing is protected, what has to happen when something goes wrong, and what follows if the duties are not met. It describes the general rules. How they apply to a particular practice depends on that practice's own circumstances and on its agreement with its operator.

Rule 7where the security duties of subscribers sit
1subscriber administrator required, at the least, per network
5 yearslook-back for a user's insolvency history

Source: ARNECC Model Participation Rules version 7, rules 7.2.3 and 7.3.2.

Where the duties come from in Queensland

The Model Participation Rules are a national template. ARNECC's definitions page describes them as a uniform set of rules that the registrars determine as the participation rules subscribers have to comply with in each jurisdiction. In Queensland, Titles Queensland's eConveyancing page states that the Registrar of Titles determines the participation rules for subscribers and the operating requirements for operators under the Electronic Conveyancing National Law (Queensland). ARNECC's Queensland page lists the Queensland Participation Rules version 7 as effective from 2 April 2024, following the national model that ARNECC published in January 2024.

Related readReserved, lodged, paid: how purchase money crosses between banks

A subscriber, in ARNECC's words, is a legal entity registered to use a network to complete conveyancing transactions electronically, either as a transacting party or on behalf of one. That covers the law practice acting for a buyer or a seller and the lender that takes or releases a mortgage. Rule 7 does not distinguish between them. A sole practitioner and a national bank owe the same list of duties, and the test for whether enough has been done is scaled to the circumstances, as the section on "reasonable steps" below explains.

Guidance Note 8 is advice, not a rule. ARNECC's guidance notes say of themselves that they do not amount to legal advice and do not override legislation or a registrar's requirements. What the note adds is the registrars' own reading of the rule, with examples.

The note also gives the reason for the duties. Security obligations, it says, help to manage the risk of fraud and misuse in advance and to give confidence to those who rely on the system. It adds a fact that shapes everything else: all activity undertaken within an electronic lodgment network is traceable.

According to Guidance Note 8, which points to rule 3 of the Model Participation Rules, the security duties have to be met when an organisation applies to become a subscriber and continuously for as long as it remains one. One duty outlasts the subscription. Rule 3(c), as the note explains it, keeps the obligation in rule 7.7, the duty to notify when a transaction is at risk, alive after a subscriber has left the network.

Related readPaper or screen: the nine dealings Queensland lawyers must lodge online

The practical meaning is that security under these rules is not a one-off onboarding test. A firm that passed its operator's checks on the day it joined is still bound, years later, to keep its user list accurate, its people trained and its certificates under control.

Protection measures: the general duty

Rule 7.1 is the widest of the duties. A subscriber has to take reasonable steps to comply with the security policy of each operator whose network it uses. It also must not do anything that it knows, or ought reasonably to know, is likely to harm the operation, security, integrity, stability or overall efficiency of a network, and must not fail to do something within its reasonable control where the failure is likely to have the same effect.

Guidance Note 8 turns this into concrete items. A subscriber has to use and maintain the technology required to access the network, install virus protection software as the operator specifies, take reasonable steps to protect its security items, and follow the operator's security policy on training and monitoring its users.

The note gives one example of each kind of breach. A harmful act: allocating a digital certificate to a person known to have been involved in property fraud. A harmful omission: failing to keep software updated, since, as the note observes, software updates include security patches. It also explains the phrase "ought reasonably to know" as what a reasonable person in the subscriber's position would know in the circumstances.

Neither the rule nor the note names an outside technical standard. Guidance Note 8 does not refer to a government cyber security framework or a list of controls; it leaves the detail to each operator's security policy and to the "reasonable steps" test. A firm looking for a checklist of specific settings will therefore find it in its operator's policy and its participation agreement, not in the national rules.

Related readQueensland without paper title deeds: what proves ownership now
The yardstick

What "reasonable steps" means in rule 7

Guidance Note 8 defines reasonable steps as those an ordinarily prudent subscriber would have taken in the circumstances and in the ordinary course of its business. Whether the test is met depends on the facts of each case, so the same rule can ask different things of a two-person practice and a large lender.

Who may log in, and the checks on them

Rule 7.2.1 requires a subscriber to take reasonable steps to ensure that only its users access a network. A user, under the rules, is an individual who is a principal, officer, employee, agent or contractor of the subscriber and has been authorised by it to use the network on its behalf.

Rule 7.2.3 then sets conditions about the people themselves. As the rule is set out in version 7, a subscriber has to ensure that its users have not been subject to an insolvency event within the previous five years, have not been convicted of fraud or of an offence of dishonesty that bears on the conduct of conveyancing, have not been disqualified from managing a corporation, and are not subject to disciplinary action or to a restriction on their use of a network.

Two roles attract an extra step. Before a subscriber first allocates a digital certificate to a signer, or appoints someone as a subscriber administrator, it has to carry out a police background check. Guidance Note 8 explains the purpose: to confirm that the person has no conviction for fraud, for an indictable offence that may affect the conduct of a conveyancing transaction, or for dishonesty in business, professional or commercial activities.

The note answers four practical questions about these checks:

  1. Which check? A national police check for a person in Australia. For someone outside Australia, a recent arrival or an international resident, an international police check, at the subscriber's discretion.
  2. Does an older check count? A check already carried out before the certificate was allocated satisfies the requirement.
  3. What if the check discloses something? It is for the subscriber to decide whether the outcome affects its compliance.
  4. What about a charge that is still pending? The subscriber uses its judgment about bringing the person on. If a conviction follows, it has to revoke the person's signing rights or administrator role and their access immediately, and notify the registrar and every operator.

Rules 7.2.4 and 7.2.5 soften the burden for certain categories. Legal practitioners, licensed conveyancers, public servants, holders of a credit licence and government or statutory office holders are deemed to meet the character conditions. The rules add a qualification: an operator or a registrar may still ask for evidence where there is a reasonable suspicion.

Related readRequisitions at Titles Queensland: when a lodged dealing is sent back

There is also a rule about machines. Rule 7.2.2 allows application-to-application technology, software that speaks to the network directly, to be used for access and data entry. It prohibits that technology from being used to digitally sign or to perform a subscriber administrator's functions. Signing and administration stay with identified individuals.

Training: everyone who touches the systems

The training duty is the part of rule 7 that reaches furthest into an office. Under rule 7.2.1 and Guidance Note 8, each user has to receive training appropriate to their use of the network, and that training has to include cyber security awareness. The note then extends a narrower version of the training to people who never log in to the network at all.

Who has to be trained, and in whatCyber security awareness training under rule 7.2.1
PersonSecure use of the networkSecure use of the firm's systemsSecure use of email
A user of the networkYesYesYes
Anyone else with access to the subscriber's systemsNot requiredYesYes

Source: ARNECC Guidance Note 8, section 5.2. "Anyone else" covers other principals, officers, employees, agents and contractors. "Email" includes other electronic communication.

The reason given in the note is that weaknesses in a subscriber's own systems could lead to attacks on other systems. A receptionist's inbox is part of the same office network as the conveyancing clerk's workstation.

The rules do not fix how often the training is repeated. Guidance Note 8 leaves the frequency to the subscriber, to be decided in light of its participation agreement, the operator's security policy and what the note calls the frequently changing landscape of cyber security. Operators may require training to be completed at set times. On timing for a new user, the note says only what best practice would be: that the training is completed before the person is given access to a network.

Access rights and the subscriber administrator

Rule 7.3 deals with housekeeping, and Guidance Note 8 treats it as a security matter in its own right. A subscriber has to keep three things current within each network it uses: its users' access credentials, the signing rights linked to those credentials, and the administrative rights linked to them. Access credentials, in the rules' definition, are a user identification and password together with any other details needed to access a network.

Related readVerification of identity: the check before a Queensland e-settlement

Each subscriber also has to have at least one subscriber administrator for each network at all times. This is the user authorised to make changes to credentials and rights. The note's advice is brief: the administrator "should be chosen carefully". The reason appears in rule 7.3.3. A change to credentials made by an authorised person is treated as made by the subscriber itself, and the subscriber gives up the right to argue later that the person lacked authority. Whatever the administrator does, the firm has done.

The note records that operators assess compliance with these duties during what it calls the subscriber review process, together with the related duties on sharing credentials and misusing certificates.

Digital certificates and signing

Signing is where the security of the system is most concentrated, and rule 7.5 is correspondingly detailed. The rules define a digital certificate as an electronic certificate, signed by a certification authority, that identifies a key holder or the business the key holder represents and ties that person to a pair of cryptographic keys. The private key of the pair is the one that has to be kept secret, and rule 7.5.1 provides that documents requiring a digital signature are signed using a private key.

From there the duties run as follows. A subscriber has to obtain at least one digital certificate and keep it valid. Any information it gives to a certification authority, a registration authority or an operator has to be, in the words of rule 7.5.4, "correct, complete and not false or misleading". It has to take reasonable steps to ensure that only signers digitally sign, that a certificate is used only by the signer it was allocated to, that signers do not let others use their credentials or certificates, and that every user's access credentials are used only by that user.

Related readThe client authorisation: the form that lets a lawyer sign for you

On storage, the guidance is practical. A signer has to keep the certificate safe and secure in the signer's control, but Guidance Note 8 says that this does not necessarily mean it has to be in the signer's possession at all times; the signer may use other facilities, and the note's example is locking it in a safe.

The note also explains why sharing is treated so seriously. It likens the use of another person's digital signature to the forgery of a signature on paper. Because every action on a network is traceable to a set of credentials, a shared login or a borrowed certificate destroys the record of who actually did what.

Finally, rule 7.10 requires a subscriber to give the certifications set out in the certification rules whenever it digitally signs. Those certifications are the statements a subscriber makes about the transaction when it signs; they are the subject of ARNECC's separate Guidance Note 3.

When someone leaves or changes role

Rule 7.8 covers departures, and its wording moves between two speeds.

Promptly: a subscriber has to revoke a person's access, signing rights or administrative rights when that person is no longer meant to be a user, signer or subscriber administrator, and, where appropriate, ask the certification authority to revoke the signer's digital certificate. The same word applies where a registrar or an operator has restricted the subscriber's use of a network: the subscriber has to prevent its users from accessing the network outside those restrictions.

Immediately: authority to digitally sign has to be withdrawn from any person who ceases to be the subscriber's employee, agent or contractor.

Guidance Note 8 describes prompt revocation as essential to protecting the integrity of the titles register. In office terms, removing network rights belongs on the same list as collecting keys on a person's last day.

A compromised security item: what the rules require

The rules define security items as user access credentials, passphrases, private keys, digital certificates, electronic workspace identifiers and other items specified from time to time. An item is compromised when it is lost or stolen, or reproduced, modified, disclosed or used without proper authority. A stolen laptop holding a certificate qualifies. So does a password given away in response to a deceptive email.

Rule 7.9 applies as soon as a subscriber becomes aware that a security item has been, or is likely to have been, compromised. For any item, the first step is to revoke the affected user's authority and prevent access at once. Where the item is a digital certificate, the rule sets out a fuller sequence.

If a digital certificate is compromisedThe sequence in rule 7.9.1, as Guidance Note 8 explains it
  1. Cut off accessImmediately revoke the user's authority to access the affected network or networks.
  2. Check the workspacesImmediately check every electronic workspace in which the private key was used to sign.
  3. UnsignUnsign the affected documents, as rule 7.9.2 requires.
  4. Tell the certification authorityPromptly notify it, and have the certificate revoked or cancelled.
  5. Tell the operatorsPromptly notify every affected network operator.

Rule 7.9.2 deals with the worst case: the subscriber becomes aware, or suspects, that a private key has been used to sign a document without its authority or its client's. Where it is possible, the subscriber has to unsign the document immediately. Where it is not possible, it has to notify the relevant operator immediately.

A transaction at risk: the duty to speak up

Rule 7.7 uses a different defined word. A conveyancing transaction is jeopardised when the integrity of the titles register is put at risk, by fraud or by other means. The trigger described in Guidance Note 8 is broad: the subscriber knows, has information, or believes that a transaction is jeopardised.

Two duties follow, both marked "immediately". Under rule 7.7.1 the subscriber unsigns its documents where that is possible and notifies the operator and the registrar. Under rule 7.7.2 it notifies the other participating subscribers, the firms and lenders on the other sides of the same transaction, of information that is incorrect, omitted, false or misleading, or of the fact that the transaction is jeopardised. Guidance Note 8 qualifies the second duty with the words "to the extent permitted by law".

Triggers and deadlines in rule 7The rules use two speeds: immediately and promptly
EventWhat the subscriber doesSpeed
Transaction jeopardisedUnsign where possible; notify operator, registrar and other subscribersImmediately
Security item compromisedRevoke the user's accessImmediately
Certificate compromisedNotify certification authority and affected operatorsPromptly
Private key used without authorityUnsign, or notify the operator if that is impossibleImmediately
Person leaves the subscriberWithdraw authority to signImmediately
Person changes roleRevoke the rights no longer neededPromptly

Source: ARNECC Model Participation Rules version 7, rules 7.7 to 7.9.

As noted earlier, this notification duty is the one that continues after an organisation has stopped being a subscriber.

How compliance is checked, and what failure costs

Two layers of supervision apply. The first is the operator. Guidance Note 8 says operators monitor compliance through the subscriber review process, and that a subscriber's failure to comply with that process is a suspension event under Schedule 7 of the Model Participation Rules. The note lists the possible consequences of breaching rule 7: removal of the subscriber's access to a network, and the possibility that the breach amounts to a material breach or to negligence that threatens the operation, security, integrity or stability of the network.

The second layer is the registrar. ARNECC's page on subscriber compliance records that section 33 of the Electronic Conveyancing National Law gives the registrar in each jurisdiction the power to conduct a compliance examination, either to find out whether the participation rules have been complied with or to investigate suspected or alleged misconduct by a subscriber. The same page states that a subscriber is obliged to cooperate fully, and that the procedure is set out in Schedule 5 of the participation rules. ARNECC published a document on common errors found in these examinations in December 2024.

Rule 9 of the Model Participation Rules provides for the registrar to direct that a subscriber be suspended or terminated, and requires subscribers to comply with directions restricting their access or use.

Insurance sits alongside these controls. Rule 4.4 requires subscribers to be insured, and Schedule 6, the insurance rules, sets the figures for professional indemnity and fidelity cover: at least $1,500,000 per claim including legal costs, an excess of no more than $20,000 per claim, and an annual aggregate of at least $20,000,000. The schedule treats Australian legal practitioners, law practices and licensed conveyancers as compliant where they hold the professional indemnity and fidelity insurance their own legislation requires, and exempts self-insuring bodies such as authorised deposit-taking institutions and Crown entities.

The operator's side of the bargain

The duties on firms and lenders have a counterpart. Operators are bound by the operating requirements each registrar determines from ARNECC's Model Operating Requirements, and Titles Queensland's questions-and-answers page on eConveyancing states that operators maintain stringent information technology standards with independent certifications, while Titles Queensland applies cyber security controls of its own.

The most recent model, version 7.2, is dated May 2026 on its cover. The explanatory notes ARNECC issued with the consultation draft in February 2026 anticipated a start in June 2026. Those notes describe 27 new definitions, among them "Security Incident", "System Error", "Incident Response" and "Post Incident Review Report". They describe new performance levels for operators covering response times, restoration times and notification according to the severity of an incident, recovery point objectives that cap the data loss an operator may tolerate, and a requirement to give the registrar a post-incident review with a root cause analysis. They also describe a duty on operators to invest each year at least 10 per cent of their average gross revenue from conveyancing transactions over the preceding three years. Each registrar determines version 7.2 for its own state.

ARNECC also released consultation drafts of version 8 of both rule books in May 2026 and briefed stakeholders on them in June. Until a registrar determines a new version, the duties described in this guide are those of version 7.

The network records who did what. Rule 7 exists so that the record can be believed.

Kooky, from Shaka

Kooky edits Queensland Estate and builds Shaka, the payment router he made for Queensland property professionals. One payment comes in, and every agent, agency and party in the deal receives their signed share on closing date.