AI Voice Agent Compliance Checklist for UK Contact Centres: FCA, OFCOM, and GDPR Requirements Before You Go Live
Author: Arkadas Kilic, Founder & CEO, Rel8 CXDeploying an AI voice agent in a UK contact centre is not a technology decision alone. It is a regulatory commitment. Before your agent handles a single live call, you need to satisfy at least three overlapping compliance frameworks: FCA rules (if you operate in financial services), OFCOM's requirements for automated calling systems, and UK GDPR. Miss any one of them and you are exposed to enforcement action, fines, and reputational damage.
This checklist covers what you must have in place before go-live. It is written for compliance leads, contact centre heads, and technical architects who are accountable for getting this right.
Why Compliance Cannot Be Retrofitted
The most common mistake we see is teams building an AI voice agent first and then asking the compliance team to review it. By that point, architectural decisions have been made that are expensive to undo. Consent flows are baked into call scripts. Data routing is hardcoded. Logging is an afterthought.
Compliance needs to be designed in from day one. That is not a legal opinion. It is an engineering reality.
Section 1: FCA Requirements (Financial Services)
If your contact centre handles regulated financial products, mortgages, insurance, investments, or credit, the FCA's Consumer Duty (in force since July 2023) applies directly to how your AI voice agent operates.
1.1 Consumer Duty: Outcomes You Must Evidence
The FCA requires firms to deliver good outcomes across four areas. Your AI voice agent must be designed to support all four:
- Products and services: The agent must only discuss products appropriate for the customer. If a customer profile indicates vulnerability, the agent must not push complex products.
- Price and value: The agent cannot use scripting that obscures fees or creates false urgency.
- Consumer understanding: Call scripts must be clear, not misleading, and tested for comprehension. The FCA has been explicit that automated systems are not exempt from this standard.
- Consumer support: Customers must be able to reach a human. If your AI voice agent blocks escalation or makes it unreasonably difficult, that is a Consumer Duty breach.
- [ ] Agent scripts reviewed by compliance against Consumer Duty outcome standards
- [ ] Escalation to human agent available at every stage of the call, not just at the end
- [ ] Vulnerable customer detection logic documented and tested
- [ ] Evidence framework in place to demonstrate good outcomes to FCA if requested
1.2 Vulnerable Customer Identification
FCA guidance (FG21/1) requires firms to identify and respond to vulnerability. Your AI voice agent must have a defined process for this.
At minimum:
- The agent must recognise distress signals in speech (hesitation, confusion, emotional language) and route to a human
- Vulnerability flags from CRM must be passed to the agent session at call start
- Agents must not attempt to complete a sale or collect a debt from a customer who has indicated financial difficulty without human review
- [ ] Vulnerability detection logic implemented and tested with real call samples
- [ ] CRM vulnerability flags integrated into agent session context
- [ ] Escalation triggered automatically when vulnerability signals detected
- [ ] Human agent briefed on context before transfer, not starting blind
1.3 Call Recording and Supervision
FCA SYSC rules require firms to record calls where regulated advice or sales occur. AI voice agent calls are not exempt.
- All calls must be recorded in full
- Recordings must be retained for a minimum of 5 years (MiFID II firms: 7 years)
- Recordings must be retrievable within a reasonable timeframe for FCA review
- AI-generated transcripts can supplement but cannot replace audio recordings
- [ ] Full call audio recorded and stored, not just transcripts
- [ ] Retention period configured: 5 years minimum, 7 years for MiFID II scope
- [ ] Storage location documented (must be UK or adequacy-covered jurisdiction)
- [ ] Retrieval process tested and documented
Section 2: OFCOM Requirements
OFCOM regulates the use of automated calling systems in the UK under the Privacy and Electronic Communications Regulations (PECR) and the Communications Act 2003. Even if you are not in financial services, these rules apply.
2.1 Automated Calling System Rules
Under PECR, you cannot use an automated calling system to make calls to individuals without prior consent unless you have a legitimate interest that overrides the individual's rights. For outbound AI voice agent calls, this means:
- You must have explicit consent for marketing calls
- Consent must be granular: consent to receive calls from your firm does not automatically cover AI-delivered calls
- You must maintain a suppression list and screen against the Telephone Preference Service (TPS) before every outbound campaign
- [ ] Consent records stored and linked to each customer record
- [ ] TPS screening automated before every outbound call batch
- [ ] Consent language reviewed to confirm it covers automated voice contact
- [ ] Suppression list updated at least every 28 days (OFCOM best practice)
2.2 Abandoned Call Rules
OFCOM's abandoned call policy sets a hard limit: no more than 3% of calls answered by a live person can be abandoned in any 24-hour period. If your AI voice agent is handling outbound calls at scale, you need to monitor this actively.
Additionally, if a call is abandoned, you must:
- Play a message within 2 seconds of the customer saying hello
- The message must identify your organisation and provide a freephone number
- You cannot call the same number again within 72 hours after an abandoned call
- [ ] Abandoned call rate monitored in real time with alerting at 2.5% threshold
- [ ] Abandoned call message recorded and compliant with OFCOM wording requirements
- [ ] 72-hour suppression logic implemented for abandoned call numbers
- [ ] Daily reporting on abandoned call rates retained for 6 months
2.3 Caller Line Identification
OFCOM requires that outbound automated calls present a valid CLI (Caller Line Identification). You cannot withhold your number or use a non-dialable number.
Checklist items:- [ ] Valid, dialable CLI presented on all outbound calls
- [ ] CLI number answered by a human or returns a callback option if called back
- [ ] CLI not spoofed or rotated to avoid identification
Section 3: UK GDPR Requirements
The UK GDPR (retained post-Brexit and supplemented by the Data Protection Act 2018) governs how your AI voice agent processes personal data. The key obligations are consent, transparency, data minimisation, and rights around automated decision-making.
3.1 Lawful Basis for Processing
Your AI voice agent processes personal data on every call. You need a documented lawful basis before processing begins. For most contact centre use cases:
- Contract performance covers calls where the customer initiated contact to manage their account
- Legitimate interests may cover some outbound service calls, but requires a Legitimate Interests Assessment (LIA)
- Consent is required for marketing calls and for any processing that goes beyond the original purpose
- [ ] Lawful basis documented for each call type handled by the AI voice agent
- [ ] LIA completed and signed off where legitimate interests is the basis
- [ ] Privacy notice updated to reference AI voice agent processing
- [ ] Data Protection Impact Assessment (DPIA) completed before go-live
3.2 Article 22: Automated Decision-Making
Article 22 of the UK GDPR gives individuals the right not to be subject to decisions based solely on automated processing that produce legal or significant effects. This is directly relevant if your AI voice agent:
- Approves or declines a credit application
- Sets an insurance premium
- Determines eligibility for a product or service
- Initiates a debt collection action
If your agent does any of these, you must either:
1. Ensure a human is meaningfully involved in the decision (not just rubber-stamping)
2. Obtain explicit consent from the customer
3. Demonstrate the decision is necessary for a contract
Checklist items:- [ ] Decisions made by or influenced by the AI voice agent mapped and categorised
- [ ] Any decision with legal or significant effect routed for human review before action taken
- [ ] Customer-facing language explains when automated processing is used
- [ ] Process for customers to request human review documented and operational
3.3 Transparency and the Right to Know
Customers have the right to know they are speaking with an AI system. This is not just an ethical position. Under UK GDPR transparency requirements (Articles 13 and 14), you must inform individuals about automated processing at the point of data collection.
OFCOM's guidance on AI in telecommunications also supports disclosure at the start of the call.
Checklist items:- [ ] AI disclosure scripted into the opening of every call (within the first 10 seconds)
- [ ] Disclosure language reviewed by legal: it must be clear, not buried in small print
- [ ] Privacy notice updated to reference AI voice processing
- [ ] Customer able to request human agent immediately after disclosure
3.4 Data Minimisation and Retention
Your AI voice agent will generate call recordings, transcripts, intent classifications, sentiment scores, and session metadata. All of it is personal data. You need a retention schedule for each data type.
Typical retention periods for UK contact centres:
- Call recordings: 5 to 7 years (FCA scope), 12 months (general customer service)
- Transcripts: same as recordings if they contain personal data
- Sentiment and intent data: 90 days unless there is a documented business need
- Session metadata (caller ID, timestamps, routing): 12 months
- [ ] Data map completed for all data generated by the AI voice agent
- [ ] Retention schedule documented and implemented in storage layer
- [ ] Automated deletion configured and tested
- [ ] Data subject access request (DSAR) process covers AI voice agent data
3.5 International Data Transfers
If your AI voice agent infrastructure runs on cloud services that process data outside the UK, you need a transfer mechanism in place. Since Brexit, the UK has its own adequacy decisions and the International Data Transfer Agreement (IDTA) replaces Standard Contractual Clauses for UK transfers.
Checklist items:- [ ] Data processing locations mapped for all components: telephony, AI inference, storage, logging
- [ ] IDTA or UK adequacy decision in place for any non-UK processing
- [ ] Data Processing Agreements signed with all third-party processors
- [ ] Transfer Impact Assessment completed where required
Section 4: Operational Compliance Controls
Regulatory compliance is not a one-time checklist. It requires ongoing operational controls.
4.1 Monitoring and Quality Assurance
- [ ] At least 10% of AI voice agent calls reviewed by a human QA team each week
- [ ] Compliance scoring applied to call reviews (FCA Consumer Duty outcomes mapped to QA criteria)
- [ ] Escalation failure rate tracked: target below 1% of calls where escalation was requested but not completed
- [ ] Monthly compliance report produced and reviewed by a named accountable person
4.2 Incident Response
- [ ] Process documented for what happens if the AI voice agent gives incorrect information
- [ ] ICO breach notification process in place: 72-hour window for notifiable breaches
- [ ] FCA notification process documented for material operational incidents
- [ ] Call affected customers identified and contacted within 5 business days of a confirmed mis-statement incident
4.3 Model and Script Change Control
- [ ] Any change to agent scripts or underlying model behaviour goes through compliance review before deployment
- [ ] Version control maintained for all prompt configurations and call flow logic
- [ ] Regression testing includes compliance test cases, not just functional test cases
- [ ] Change log retained for 3 years minimum
The Architecture Decisions That Drive Compliance
Compliance requirements translate directly into architecture decisions. These are the ones that matter most:
Stay AWS native. Processing data within AWS UK regions (eu-west-2) keeps you within a well-understood regulatory boundary. You get encryption at rest and in transit by default, CloudTrail for audit logging, and IAM for access control. These are not nice-to-haves. They are the foundation of your compliance posture. Build consent into the telephony layer. Consent checks should happen before the call connects, not inside the AI agent logic. Use Amazon Connect contact flows to screen against suppression lists and validate consent records before routing to the AI agent. Log everything at the infrastructure level. Do not rely on the AI agent to log its own behaviour. Use CloudWatch, S3, and DynamoDB to capture call metadata, decisions, and outcomes independently of the agent. This gives you an audit trail that cannot be altered by a model update. Separate inference from data storage. The AI model should not have persistent access to customer data. Pass only what is needed for the current call session, and clear the session context on call end. This limits your data minimisation exposure significantly.Summary Checklist: Go-Live Gate
Before any AI voice agent goes live in a UK contact centre, the following must be signed off:
FCA (if applicable)- [ ] Consumer Duty outcomes mapped to agent design
- [ ] Vulnerable customer logic implemented and tested
- [ ] Call recording in place with correct retention periods
- [ ] Escalation to human available at every call stage
- [ ] TPS screening automated
- [ ] Consent records validated and granular
- [ ] Abandoned call monitoring live with alerting
- [ ] Valid CLI presented on all outbound calls
- [ ] DPIA completed and signed off
- [ ] AI disclosure in opening script
- [ ] Article 22 decision map completed
- [ ] Retention schedules implemented and tested
- [ ] IDTA or adequacy decision in place for all processing locations
- [ ] QA process live with compliance scoring
- [ ] Incident response process documented
- [ ] Change control process covers scripts and model configuration
- [ ] Named accountable person assigned for ongoing compliance
How We Build This at Rel8 CX
At Rel8 CX, we build AI voice agents for regulated UK contact centres. Compliance is not a final review step. It is an input to architecture from day one. We work within AWS native services, design consent and escalation logic into the telephony layer, and deliver production-ready systems in 4 to 6 weeks.
Every engagement includes a compliance architecture review, a DPIA support pack, and a go-live gate checklist aligned to FCA, OFCOM, and UK GDPR requirements.
If you are planning to deploy an AI voice agent in a regulated UK contact centre and want to get the compliance architecture right before you build, not after, Book a discovery call.
Ready to put AI agents into production?
Book a discovery call. We will assess your use case and show you what 4 to 6 weeks to production looks like.
Book a Discovery Call