AI Voice Agent Compliance Checklist for UK Contact Centres: FCA, OFCOM, and GDPR Requirements Before You Go Live

Arkadas Kilic
Author: Arkadas Kilic, Founder & CEO, Rel8 CX

Deploying an AI voice agent in a UK contact centre is not a technology decision alone. It is a regulatory commitment. Before your agent handles a single live call, you need to satisfy at least three overlapping compliance frameworks: FCA rules (if you operate in financial services), OFCOM's requirements for automated calling systems, and UK GDPR. Miss any one of them and you are exposed to enforcement action, fines, and reputational damage.

This checklist covers what you must have in place before go-live. It is written for compliance leads, contact centre heads, and technical architects who are accountable for getting this right.


Why Compliance Cannot Be Retrofitted

The most common mistake we see is teams building an AI voice agent first and then asking the compliance team to review it. By that point, architectural decisions have been made that are expensive to undo. Consent flows are baked into call scripts. Data routing is hardcoded. Logging is an afterthought.

Compliance needs to be designed in from day one. That is not a legal opinion. It is an engineering reality.


Section 1: FCA Requirements (Financial Services)

If your contact centre handles regulated financial products, mortgages, insurance, investments, or credit, the FCA's Consumer Duty (in force since July 2023) applies directly to how your AI voice agent operates.

1.1 Consumer Duty: Outcomes You Must Evidence

The FCA requires firms to deliver good outcomes across four areas. Your AI voice agent must be designed to support all four:

Checklist items:

1.2 Vulnerable Customer Identification

FCA guidance (FG21/1) requires firms to identify and respond to vulnerability. Your AI voice agent must have a defined process for this.

At minimum:

Checklist items:

1.3 Call Recording and Supervision

FCA SYSC rules require firms to record calls where regulated advice or sales occur. AI voice agent calls are not exempt.

Checklist items:

Section 2: OFCOM Requirements

OFCOM regulates the use of automated calling systems in the UK under the Privacy and Electronic Communications Regulations (PECR) and the Communications Act 2003. Even if you are not in financial services, these rules apply.

2.1 Automated Calling System Rules

Under PECR, you cannot use an automated calling system to make calls to individuals without prior consent unless you have a legitimate interest that overrides the individual's rights. For outbound AI voice agent calls, this means:

Checklist items:

2.2 Abandoned Call Rules

OFCOM's abandoned call policy sets a hard limit: no more than 3% of calls answered by a live person can be abandoned in any 24-hour period. If your AI voice agent is handling outbound calls at scale, you need to monitor this actively.

Additionally, if a call is abandoned, you must:

Checklist items:

2.3 Caller Line Identification

OFCOM requires that outbound automated calls present a valid CLI (Caller Line Identification). You cannot withhold your number or use a non-dialable number.

Checklist items:

Section 3: UK GDPR Requirements

The UK GDPR (retained post-Brexit and supplemented by the Data Protection Act 2018) governs how your AI voice agent processes personal data. The key obligations are consent, transparency, data minimisation, and rights around automated decision-making.

3.1 Lawful Basis for Processing

Your AI voice agent processes personal data on every call. You need a documented lawful basis before processing begins. For most contact centre use cases:

Checklist items:

3.2 Article 22: Automated Decision-Making

Article 22 of the UK GDPR gives individuals the right not to be subject to decisions based solely on automated processing that produce legal or significant effects. This is directly relevant if your AI voice agent:

If your agent does any of these, you must either:

1. Ensure a human is meaningfully involved in the decision (not just rubber-stamping)

2. Obtain explicit consent from the customer

3. Demonstrate the decision is necessary for a contract

Checklist items:

3.3 Transparency and the Right to Know

Customers have the right to know they are speaking with an AI system. This is not just an ethical position. Under UK GDPR transparency requirements (Articles 13 and 14), you must inform individuals about automated processing at the point of data collection.

OFCOM's guidance on AI in telecommunications also supports disclosure at the start of the call.

Checklist items:

3.4 Data Minimisation and Retention

Your AI voice agent will generate call recordings, transcripts, intent classifications, sentiment scores, and session metadata. All of it is personal data. You need a retention schedule for each data type.

Typical retention periods for UK contact centres:

Checklist items:

3.5 International Data Transfers

If your AI voice agent infrastructure runs on cloud services that process data outside the UK, you need a transfer mechanism in place. Since Brexit, the UK has its own adequacy decisions and the International Data Transfer Agreement (IDTA) replaces Standard Contractual Clauses for UK transfers.

Checklist items:

Section 4: Operational Compliance Controls

Regulatory compliance is not a one-time checklist. It requires ongoing operational controls.

4.1 Monitoring and Quality Assurance

4.2 Incident Response

4.3 Model and Script Change Control


The Architecture Decisions That Drive Compliance

Compliance requirements translate directly into architecture decisions. These are the ones that matter most:

Stay AWS native. Processing data within AWS UK regions (eu-west-2) keeps you within a well-understood regulatory boundary. You get encryption at rest and in transit by default, CloudTrail for audit logging, and IAM for access control. These are not nice-to-haves. They are the foundation of your compliance posture. Build consent into the telephony layer. Consent checks should happen before the call connects, not inside the AI agent logic. Use Amazon Connect contact flows to screen against suppression lists and validate consent records before routing to the AI agent. Log everything at the infrastructure level. Do not rely on the AI agent to log its own behaviour. Use CloudWatch, S3, and DynamoDB to capture call metadata, decisions, and outcomes independently of the agent. This gives you an audit trail that cannot be altered by a model update. Separate inference from data storage. The AI model should not have persistent access to customer data. Pass only what is needed for the current call session, and clear the session context on call end. This limits your data minimisation exposure significantly.

Summary Checklist: Go-Live Gate

Before any AI voice agent goes live in a UK contact centre, the following must be signed off:

FCA (if applicable) OFCOM UK GDPR Operational

How We Build This at Rel8 CX

At Rel8 CX, we build AI voice agents for regulated UK contact centres. Compliance is not a final review step. It is an input to architecture from day one. We work within AWS native services, design consent and escalation logic into the telephony layer, and deliver production-ready systems in 4 to 6 weeks.

Every engagement includes a compliance architecture review, a DPIA support pack, and a go-live gate checklist aligned to FCA, OFCOM, and UK GDPR requirements.

If you are planning to deploy an AI voice agent in a regulated UK contact centre and want to get the compliance architecture right before you build, not after, Book a discovery call.

Ready to put AI agents into production?

Book a discovery call. We will assess your use case and show you what 4 to 6 weeks to production looks like.

Book a Discovery Call