FCA Consumer Duty and AI Voice Agents: What Regulated Contact Centres Need to Know Before Deploying in Collections, Mortgage Servicing, and Insurance
Author: Arkadas Kilic, Founder & CEO, Rel8 CXThe FCA's Consumer Duty regulation came into full force in July 2023 for open products and July 2024 for closed books. It is not a checkbox exercise. It is a fundamental shift in how the regulator expects firms to demonstrate that customers are receiving good outcomes, not just adequate process.
AI voice agents are now being deployed at scale across UK regulated contact centres. The efficiency case is clear: autonomous handling of inbound collections calls, mortgage payment queries, and insurance renewals at a fraction of the cost of live agents. But the compliance case is where most deployments fall short, or never make it to production at all.
This post sets out exactly what Consumer Duty requires of AI voice agent deployments, where the risk concentrations sit across collections, mortgage servicing, and insurance, and what enterprise-grade compliance architecture looks like in practice.
What Consumer Duty Actually Requires of Automated Interactions
Consumer Duty is built on four outcome areas. Each one creates specific obligations for AI voice agent deployments:
1. Products and ServicesThe product or service must be designed to meet the needs of the target market. An AI voice agent that routes a customer in financial difficulty toward a standard payment flow, without identifying vulnerability or offering appropriate forbearance options, is not meeting this standard.
2. Price and ValueCustomers must receive fair value. In an insurance context, this means an AI agent handling renewals cannot present pricing in a way that obscures the customer's right to shop around or challenge an auto-renewal uplift.
3. Consumer UnderstandingCommunications must be clear, fair, and not misleading. AI voice agents must communicate in plain language, confirm understanding, and not use scripting that creates false urgency or obscures material information. The FCA has been explicit: complexity in financial products does not excuse complexity in customer communications.
4. Consumer SupportFirms must provide support that meets the needs of their customers, including those with characteristics of vulnerability. This is the highest-risk area for AI voice agent deployments. An agent that cannot detect distress signals, cannot escalate to a human, and cannot adapt its interaction style to a vulnerable customer is a regulatory liability.
The Three Highest-Risk Deployment Contexts
Collections
Collections is the context where Consumer Duty pressure is most acute. The FCA's 2024 review of consumer credit firms found that 42% of firms reviewed had inadequate processes for identifying vulnerable customers in collections journeys. An AI voice agent in collections that lacks real-time vulnerability detection is not compliant.
Specific requirements for collections deployments:
- Vulnerability signal detection: The agent must be able to identify linguistic and behavioural signals of financial distress, mental health challenges, or bereavement, and escalate or adapt accordingly. This is not optional.
- Forbearance presentation: When a customer indicates difficulty, the agent must be capable of presenting the full range of forbearance options available, not just the lowest-cost option for the firm.
- No pressure tactics: Any scripting that creates artificial urgency around payment deadlines must be reviewed against the Consumer Duty standard. The FCA has specifically flagged this in debt collection contexts.
- Full interaction logging: Every interaction must be logged with sufficient granularity to demonstrate, in a supervisory review, that the customer received good outcomes. Audio, transcript, and decision-point metadata all need to be retained.
Mortgage Servicing
Mortgage servicing introduces additional complexity because of the Financial Services and Markets Act 2023 provisions and the FCA's specific guidance on mortgage arrears handling (MCOB 13). AI voice agents handling payment queries, arrears conversations, or rate change notifications must:
- Present options for customers in arrears in line with MCOB 13 requirements, including the right to a reasonable period to consider options
- Not make any statement that could be construed as threatening possession proceedings prematurely
- Identify customers who may be in negative equity or facing payment shock from rate resets, and route them to appropriate support
- Maintain a complete audit trail of what was communicated, when, and what the customer's response was
The mortgage servicing context also creates a specific challenge around consent and recording. Under GDPR and the FCA's data governance expectations, firms must be able to demonstrate that call recordings and transcripts are stored securely, with appropriate retention periods and access controls.
Insurance
In insurance, the Consumer Duty intersects with the FCA's pricing practices rules (PS21/5) and the ongoing scrutiny of auto-renewal practices. AI voice agents handling renewals, mid-term adjustments, or claims first notification of loss (FNOL) must:
- Present renewal pricing transparently, including the prior year's premium where required
- Not use scripting that discourages customers from exercising their right to cancel or switch
- In FNOL contexts, avoid any language that could be interpreted as pre-judging a claim or discouraging a legitimate claim
- Identify customers who may have changed circumstances that affect their coverage needs, and route them to an advisor rather than completing a renewal autonomously
The FCA's 2024 multi-firm review of insurance pricing found that automated renewal journeys were one of the top three areas of concern. Deploying an AI voice agent in this context without explicit Consumer Duty mapping is a significant risk.
What Enterprise-Grade Compliance Architecture Looks Like
Most AI voice agent deployments in regulated environments fail not because the AI is incapable, but because the surrounding architecture is not built for compliance. Here is what production-ready compliance architecture requires:
Real-Time Vulnerability Detection
This is not a post-call analysis function. It must operate in real time, during the interaction, so the agent can adapt its behaviour before harm occurs. This requires:
- Acoustic and linguistic signal processing integrated into the conversation flow
- A defined escalation path that triggers within seconds of a vulnerability signal being detected
- Human agent availability to receive escalations, with context passed seamlessly so the customer does not have to repeat themselves
Immutable Audit Trails
Every decision the AI agent makes must be logged in a way that cannot be altered after the fact. This means:
- Interaction transcripts stored in immutable storage (AWS S3 with Object Lock is the standard we use)
- Decision-point metadata captured at each branch in the conversation flow
- Timestamps accurate to the millisecond for regulatory review purposes
- Retention periods configured to meet FCA requirements (typically six years for most regulated products)
Consent and Disclosure Management
Customers must be informed they are speaking with an automated system. This is both a Consumer Duty requirement and a matter of basic transparency. The disclosure must be:
- Delivered at the start of every interaction, not buried in a pre-call IVR menu
- Recorded as a confirmed event in the audit trail
- Accompanied by a clear opt-out path to a human agent
Escalation Architecture
An AI voice agent that cannot escalate is not compliant in a regulated environment. The escalation architecture must:
- Trigger on vulnerability signals, customer request, or agent uncertainty
- Pass full context to the receiving human agent, including transcript and any vulnerability flags
- Complete within a defined SLA (we build to a 30-second maximum transfer time)
- Be tested regularly as part of the firm's operational resilience framework
Model Governance and Change Management
The FCA expects firms to be able to explain the decisions their automated systems make. This has direct implications for how AI voice agents are built and governed:
- Prompt engineering and conversation flow changes must go through a formal change management process
- Model behaviour must be tested against a defined set of Consumer Duty scenarios before any change goes to production
- There must be a named individual with accountability for the AI system's compliance performance
The Deployment Timeline Reality
Firms that attempt to build Consumer Duty compliant AI voice agent infrastructure from scratch, using internal teams without regulated contact centre experience, typically spend 9 to 18 months and still do not reach production. The reasons are consistent: the compliance architecture is underestimated, the escalation logic is built as an afterthought, and the audit trail requirements are not understood until a supervisory review forces a rebuild.
We build production AI voice agents for regulated contact centres in 4 to 6 weeks. That timeline is achievable because we have built the compliance architecture before, we know where the FCA scrutiny lands, and we build on AWS native services that are already enterprise-grade from day one.
Questions to Ask Before Any Deployment
If you are evaluating an AI voice agent deployment for a regulated contact centre, these are the questions that will determine whether you are building something compliant or building a regulatory risk:
1. How does the system detect and respond to vulnerability signals in real time?
2. What is the escalation path, and what is the maximum transfer time to a human agent?
3. Where are interaction transcripts stored, and are they immutable?
4. How are conversation flow changes governed and tested before deployment?
5. Who holds accountability for the system's Consumer Duty compliance performance?
6. Has the system been tested against the FCA's four outcome areas with documented evidence?
7. How does the system handle a customer who requests a human agent?
If the vendor or internal team cannot answer all seven questions with specifics, the deployment is not ready.
The Bottom Line
Consumer Duty does not prohibit AI voice agents in regulated contact centres. It requires that those agents deliver good outcomes, that firms can prove it, and that vulnerable customers are protected in real time, not identified in a post-call review.
The firms that will deploy successfully are the ones that treat compliance architecture as a first-class engineering requirement, not a layer added at the end. That means immutable audit trails, real-time vulnerability detection, robust escalation paths, and formal model governance, all built before the first live call.
We build this infrastructure for collections, mortgage servicing, and insurance contact centres. We go from requirements to production in 4 to 6 weeks, and every deployment is built to withstand FCA supervisory scrutiny from day one.
Book a discovery callReady to put AI agents into production?
Book a discovery call. We will assess your use case and show you what 4 to 6 weeks to production looks like.
Book a Discovery Call