Prove authorization with the institution recovery code held in secure configuration. No email link is used.
Every attempt, successful or not, is written to the audit log.