AI Voice Agent RFP Template: 12 Questions Every UK Contact Centre Must Ask Before Signing a Contract
By Arkadas Kilic, Founder & CEO at Rel8 CXMost AI voice agent procurement processes fail before the first line of code is written. A contact centre signs a contract based on a polished demo, a vague statement of work, and a vendor promise of "seamless integration." Six months later, the project is still in a staging environment, compliance sign-off is stalled, and the original budget is gone.
This is not a technology problem. It is a procurement problem.
The 12 questions below are drawn from real enterprise deployments across regulated UK industries. Use them verbatim in your RFP, or adapt them to your context. Either way, get written answers before you sign anything.
Why Standard IT Procurement Questions Are Not Enough
AI voice agents are not telephony infrastructure. They are autonomous systems that make decisions in real time, handle sensitive customer data, and operate inside regulatory frameworks including FCA consumer duty obligations, UK GDPR, and PCI DSS for payment flows. Standard IT procurement templates do not account for any of this.
You need questions that surface:
- Whether the vendor has actually shipped production systems or only proof-of-concept demos
- How compliance is architected, not just promised
- What the real go-live timeline looks like, not the sales deck timeline
- Who owns the model behaviour when something goes wrong
The 12 RFP Questions
1. Can you provide three production references from UK-regulated industries where your AI voice agent is live at scale?
Demos are not references. Ask for organisations in financial services, insurance, utilities, or healthcare where the system is handling live customer calls today, not in pilot. Request permission to speak directly with the technology or operations lead at each reference, not the procurement contact.
What to look for: Vendors who hesitate, offer only case study PDFs, or reference clients in unregulated US markets are telling you something important.
2. What is your documented go-live timeline from contract signature to production calls, and what are the contractual milestones?
A credible AI voice agent deployment in an enterprise contact centre should reach production in 4 to 6 weeks for a defined scope. If a vendor quotes 6 to 12 months for a standard inbound call flow, ask them to break down exactly where that time goes. If they cannot, the timeline is a guess.
Require contractual milestones with defined deliverables at each stage: environment setup, integration testing, compliance review, UAT, and production cutover.
3. How is UK GDPR compliance architected in your solution, and where is customer data processed and stored?
This is not a question for the sales team. Require a written data processing agreement and a data flow diagram before evaluation. Specifically ask:
- Is voice data processed inside UK or EU data centres?
- What is the data retention period for call recordings and transcripts?
- How are subject access requests handled within the 30-day statutory window?
- Who is the data processor and who is the data controller under your contract structure?
For FCA-regulated organisations, also ask how the solution supports Consumer Duty obligations around fair treatment and outcome monitoring.
4. Describe your PCI DSS compliance architecture for calls that involve payment card data.
If any call flow involves a customer reading card numbers or CVVs, the voice agent must operate within a PCI DSS compliant environment. Ask the vendor to specify:
- Their current PCI DSS certification level and scope
- Whether DTMF masking is implemented to prevent card data appearing in transcripts
- How they handle pause-and-resume recording during payment flows
- Whether their architecture has been validated by a Qualified Security Assessor
A vendor who cannot answer this in writing should not be handling payment calls in your contact centre.
5. What AWS services underpin your architecture, and are you an AWS Partner with demonstrated Amazon Connect expertise?
For UK contact centres running on Amazon Connect, or evaluating it, this question filters out vendors who bolt a third-party AI layer on top of your telephony platform. Native AWS builders use Amazon Connect, Amazon Lex, Amazon Bedrock, and related services in an architecture that keeps data inside your AWS account and reduces integration risk.
Ask for the vendor's AWS Partner tier, any AWS competencies held, and the CVs of the engineers who will be on your project.
6. Who builds the solution: your engineers or subcontractors?
This question reveals whether you are buying a managed delivery or a reseller arrangement. Ask specifically:
- Are the engineers on your project employees of your company?
- Do you use subcontractors or offshore delivery partners for any part of this engagement?
- Who is accountable if the solution does not perform as specified?
Subcontracting is not automatically a problem, but undisclosed subcontracting in a regulated environment is. You need to know who has access to your data and your systems.
7. How does the AI voice agent handle calls it cannot resolve, and what is the escalation architecture?
Every production voice agent will encounter calls outside its designed scope. Ask the vendor to walk you through the exact escalation logic:
- What triggers a transfer to a human agent?
- How is context passed to the agent at the point of transfer (caller intent, entities captured, sentiment score)?
- What happens if no human agent is available?
- How are escalation rates monitored and what is the target escalation rate for your use case?
A well-architected system should achieve a containment rate of 60 to 80 percent for standard inbound query types within 90 days of go-live, with escalation rates tracked in real time.
8. What does your quality assurance and testing framework look like before go-live?
Ask for the vendor's test plan documentation, not a verbal description. Specifically:
- How many test scenarios are executed before production cutover?
- Is there automated regression testing for prompt or model changes?
- How are edge cases and adversarial inputs tested (callers who attempt to manipulate the agent)?
- What is the sign-off process for compliance-sensitive call flows?
For regulated industries, require that the QA framework includes a compliance review stage with documented sign-off.
9. How are model updates and prompt changes managed in production, and what is your change control process?
AI voice agents are not static software. The underlying models change, prompts are updated, and call flows evolve. Ask:
- Who has permission to modify prompts and call flows in production?
- Is there a staging environment where changes are tested before deployment?
- How are changes logged and auditable?
- What is the rollback procedure if a change degrades performance?
For FCA-regulated firms, change control is not optional. It is an audit requirement.
10. What SLAs do you offer for system availability, response latency, and incident resolution, and what are the financial remedies for breach?
Get specific numbers in writing:
- Minimum uptime SLA (99.9 percent is the baseline for enterprise contact centre workloads)
- Maximum acceptable response latency for the AI to begin speaking after a caller pauses (under 1 second is the standard for natural conversation)
- P1 incident response time and resolution time
- Financial remedies: service credits, termination rights, or both
A vendor who will not commit to financial remedies for SLA breach does not believe in their own reliability numbers.
11. How do you monitor AI agent performance in production, and what reporting do we receive?
Ask for a sample dashboard or reporting pack. Specifically:
- What metrics are tracked in real time (containment rate, escalation rate, call duration, sentiment, intent recognition accuracy)?
- How are failed interactions flagged for review?
- What is the process for identifying and correcting systematic errors in agent behaviour?
- Who owns performance optimisation after go-live: your team, our team, or a shared model?
Production AI voice agents require ongoing performance management. A vendor who treats go-live as the end of the engagement will leave you with a degrading system.
12. What are the contract exit provisions, and who owns the intellectual property, trained models, and call data at termination?
This is the question most procurement teams ask last, if at all. Ask it first:
- What notice period is required to terminate?
- Who owns the call recordings, transcripts, and any fine-tuned model weights at termination?
- Is there a data portability obligation on the vendor?
- What is the data destruction timeline and process after contract end?
- Are there any lock-in provisions that prevent migration to another platform?
For regulated organisations, data ownership and portability are not negotiable points. They are compliance requirements.
How to Score Vendor Responses
Once you have written responses to all 12 questions, score each vendor across four dimensions:
| Dimension | Weight | What You Are Assessing |
|---|---|---|
| Production evidence | 30% | Real references, real go-live timelines |
| Compliance architecture | 30% | Written, specific, auditable answers |
| Technical depth | 25% | AWS nativeness, integration approach, QA rigour |
| Commercial terms | 15% | SLA remedies, IP ownership, exit provisions |
Any vendor who scores below 60 percent on compliance architecture should be removed from consideration regardless of their score on other dimensions.
Red Flags That Should End the Evaluation
- Cannot provide UK production references in regulated industries
- Refuses to provide a data processing agreement before contract signature
- Cannot specify where customer data is processed and stored
- Quotes a go-live timeline longer than 12 weeks for a defined scope without detailed justification
- Cannot name the engineers who will work on your project
- Has no documented change control process for production systems
- Will not commit to financial remedies for SLA breach
What Good Looks Like
A vendor who can answer all 12 questions in writing, with specifics, within five business days of receiving your RFP is a vendor who has shipped production systems before. They know the answers because they have lived the problems.
At Rel8 CX, we build enterprise-grade AI voice agents on AWS for UK contact centres in regulated industries. We go from contract to production in 4 to 6 weeks. Every engagement includes compliance architecture as a deliverable, not an afterthought. We answer all 12 of these questions in writing before any contract is signed.
If you are running an AI voice agent procurement and want to pressure-test your shortlist, or if you want to understand what a production-ready architecture looks like before you start the process, talk to us.
Book a discovery callReady to put AI agents into production?
Book a discovery call. We will assess your use case and show you what 4 to 6 weeks to production looks like.
Book a Discovery Call